Compare commits

...

2 Commits

Author SHA1 Message Date
titver968
83f1e5d98f openproject deleted seaweedfs commented 2025-12-10 10:33:02 +01:00
titver968
6d913d015e seaweedfs commented 2025-12-10 10:32:16 +01:00
4 changed files with 108 additions and 251 deletions

View File

@@ -1,8 +0,0 @@
#apiVersion: v1
#kind: Namespace
#metadata:
# name: openproject
# labels:
# pod-security.kubernetes.io/enforce: privileged
# pod-security.kubernetes.io/audit: privileged
# pod-security.kubernetes.io/warn: privileged

View File

@@ -1,9 +0,0 @@
#apiVersion: v1
#kind: Secret
#metadata:
# name: postgresql-auth
# namespace: openproject
#type: Opaque
#stringData:
# postgres-password: InnoPG2025
# password: InnoDB2025

View File

@@ -1,126 +0,0 @@
#apiVersion: argoproj.io/v1alpha1
#kind: Application
#metadata:
# name: openproject
# finalizers:
# - resources-finalizer.argocd.argoproj.io
#spec:
# project: default
# source:
# repoURL: 'https://charts.openproject.org'
# chart: openproject
# targetRevision: 11.*.*
# helm:
# values: |
# develop: false
#
# environment:
# EMAIL_DELIVERY_METHOD: "smtp"
# SMTP_ADDRESS: "smtp.innohub.local"
# SMTP_PORT: "25"
# SMTP_DOMAIN: "innovation-hub-niedersachsen.de"
# SMTP_AUTHENTICATION: "none"
# SMTP_ENABLE_STARTTLS_AUTO: "false"
#
# cron:
# enabled: false
# environment:
# IMAP_HOST: "smtp.innovation-hub-niedersachsen.de"
# IMAP_PORT: 993
# IMAP_SSL: "true"
# IMAP_USERNAME: "openproject"
# IMAP_PASSWORD: "openproject-imap-password"
# schedule: "*/5 * * * *"
# ingress:
# enabled: true
# ingressClassName: traefik
# annotations:
# kubernetes.io/ingress.class: traefik
# traefik.ingress.kubernetes.io/router.entrypoints: websecure
# traefik.ingress.kubernetes.io/router.tls: "true"
# cert-manager.io/cluster-issuer: lets-encrypt
# host: "openproject.innovation-hub-niedersachsen.de"
# path: /
# pathType: "Prefix"
# tls:
# enabled: true
# secretName: openproject-tls
#
# openproject:
# https: true
# hsts: true
# seed_locale: "de"
# useTmpVolumes: "false"
# admin_user:
# password: "admin"
# password_reset: true
# name: "OpenProject Admin"
# mail: "inno-netz@zpd.polizei.niedersachsen.de"
#
# resources:
# requests:
# memory: "1Gi"
# limits:
# memory: "2Gi"
#
# appInit:
# resources:
# requests:
# memory: "512Mi"
# limits:
# memory: "1Gi"
#
# memcached:
# global:
# readOnlyRootFilesystem: false
#
# containerSecurityContext:
# readOnlyRootFilesystem: false
#
# persistence:
# enabled: false
# accessModes:
# - "ReadWriteOnce"
#
# s3:
# enabled: true
# auth:
# accessKeyId: "K7mNpQ2vRxL9wYtH3Zc8"
# secretAccessKey: "jX9fK2mP5nQ8rT1vW4yZ7bN0cM3hL6gF9dS2aE5k"
# host: "sws3.innovation-hub-niedersachsen.de"
# port: 443
# bucketName: "openproject"
# region: "eu-central-1"
#
# postgresql:
# bundled: true
# auth:
# existingSecret: "postgresql-auth"
# username: "openproject"
# # password: "openproject123"
# # postgresPassword: "postgres123"
# database: "openproject"
# global:
# readOnlyRootFilesystem: false
# primary:
# persistence:
# enabled: true
# size: 8Gi
# service:
# type: ClusterIP
# ports:
# postgresql: 5432
#
# destination:
# server: 'https://kubernetes.default.svc'
# namespace: openproject
#
# syncPolicy:
# managedNamespaceMetadata:
# labels:
# pod-security.kubernetes.io/enforce: "privileged"
# automated:
# selfHeal: true
# prune: true
# syncOptions:
# - CreateNamespace=true

View File

@@ -1,108 +1,108 @@
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: seaweedfs
finalizers:
- resources-finalizer.argocd.argoproj.io
spec:
project: default
source:
repoURL: "https://seaweedfs.github.io/seaweedfs/helm"
chart: seaweedfs
targetRevision: "4.*.*"
helm:
values: |
global:
extraEnvironmentVars:
WEED_CLUSTER_DEFAULT: "sw"
WEED_CLUSTER_SW_MASTER: "seaweedfs-master.seaweedfs:9333"
WEED_CLUSTER_SW_FILER: "seaweedfs-filer.seaweedfs:8888"
master:
enabled: true
replicas: 1
data:
type: existingClaim
claimName: seaweedfs-master-data-longhorn
volume:
enabled: true
replicas: 1
dataDirs:
- name: data1
type: existingClaim
claimName: seaweedfs-volume-data-longhorn
maxVolumes: 0
idx:
type: existingClaim
claimName: seaweedfs-volume-idx-longhorn
filer:
enabled: true
replicas: 1
data:
type: existingClaim
claimName: seaweedfs-filer-data-longhorn
# s3:
# enabled: false
# port: 8333
# domainName: "sws3.innovation-hub-niedersachsen.de"
# allowEmptyFolder: true
# enableAuth: true
# allowDeleteBucketNotEmpty: true
s3:
enabled: true
replicas: 1
port: 8333
enableAuth: true
existingConfigSecret: admin-s3-secret
existingConfigSecretKey: seaweedfs_s3_config
extraEnvironmentVars:
WEED_S3_ALLOWED_ORIGINS: "*"
WEED_FILER: "seaweedfs-filer.seaweedfs.svc.cluster.local:8888"
extraArgs:
- "-allowedOrigins=*"
- "-filer=seaweedfs-filer.seaweedfs:8888"
service:
type: ClusterIP
ports:
- name: http
port: 8333
targetPort: 8333
protocol: TCP
ingress:
enabled: true
className: traefik
annotations:
traefik.ingress.kubernetes.io/router.entrypoints: websecure
traefik.ingress.kubernetes.io/router.tls: "true"
cert-manager.io/cluster-issuer: "lets-encrypt"
traefik.ingress.kubernetes.io/router.middlewares: seaweedfs-s3-cors@kubernetescrd
host: "sws3.innovation-hub-niedersachsen.de"
hosts:
- host: sws3.innovation-hub-niedersachsen.de
paths:
- path: /
pathType: Prefix
tls:
- secretName: sws3.innovation-hub-niedersachsen.de-tls
hosts:
- sws3.innovation-hub-niedersachsen.de
destination:
server: "https://kubernetes.default.svc"
namespace: seaweedfs
syncPolicy:
managedNamespaceMetadata:
labels:
pod-security.kubernetes.io/enforce: "privileged"
automated:
selfHeal: true
prune: true
syncOptions:
- CreateNamespace=true
#apiVersion: argoproj.io/v1alpha1
#kind: Application
#metadata:
# name: seaweedfs
# finalizers:
# - resources-finalizer.argocd.argoproj.io
#spec:
# project: default
# source:
# repoURL: "https://seaweedfs.github.io/seaweedfs/helm"
# chart: seaweedfs
# targetRevision: "4.*.*"
# helm:
# values: |
# global:
# extraEnvironmentVars:
# WEED_CLUSTER_DEFAULT: "sw"
# WEED_CLUSTER_SW_MASTER: "seaweedfs-master.seaweedfs:9333"
# WEED_CLUSTER_SW_FILER: "seaweedfs-filer.seaweedfs:8888"
#
# master:
# enabled: true
# replicas: 1
# data:
# type: existingClaim
# claimName: seaweedfs-master-data-longhorn
#
# volume:
# enabled: true
# replicas: 1
# dataDirs:
# - name: data1
# type: existingClaim
# claimName: seaweedfs-volume-data-longhorn
# maxVolumes: 0
# idx:
# type: existingClaim
# claimName: seaweedfs-volume-idx-longhorn
#
# filer:
# enabled: true
# replicas: 1
# data:
# type: existingClaim
# claimName: seaweedfs-filer-data-longhorn
# # s3:
# # enabled: false
# # port: 8333
# # domainName: "sws3.innovation-hub-niedersachsen.de"
# # allowEmptyFolder: true
# # enableAuth: true
# # allowDeleteBucketNotEmpty: true
#
# s3:
# enabled: true
# replicas: 1
# port: 8333
# enableAuth: true
# existingConfigSecret: admin-s3-secret
# existingConfigSecretKey: seaweedfs_s3_config
#
# extraEnvironmentVars:
# WEED_S3_ALLOWED_ORIGINS: "*"
# WEED_FILER: "seaweedfs-filer.seaweedfs.svc.cluster.local:8888"
# extraArgs:
# - "-allowedOrigins=*"
# - "-filer=seaweedfs-filer.seaweedfs:8888"
#
# service:
# type: ClusterIP
# ports:
# - name: http
# port: 8333
# targetPort: 8333
# protocol: TCP
#
# ingress:
# enabled: true
# className: traefik
# annotations:
# traefik.ingress.kubernetes.io/router.entrypoints: websecure
# traefik.ingress.kubernetes.io/router.tls: "true"
# cert-manager.io/cluster-issuer: "lets-encrypt"
# traefik.ingress.kubernetes.io/router.middlewares: seaweedfs-s3-cors@kubernetescrd
# host: "sws3.innovation-hub-niedersachsen.de"
# hosts:
# - host: sws3.innovation-hub-niedersachsen.de
# paths:
# - path: /
# pathType: Prefix
# tls:
# - secretName: sws3.innovation-hub-niedersachsen.de-tls
# hosts:
# - sws3.innovation-hub-niedersachsen.de
#
# destination:
# server: "https://kubernetes.default.svc"
# namespace: seaweedfs
#
# syncPolicy:
# managedNamespaceMetadata:
# labels:
# pod-security.kubernetes.io/enforce: "privileged"
# automated:
# selfHeal: true
# prune: true
# syncOptions:
# - CreateNamespace=true