Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(nfs): configure local nfs #4406

Merged
merged 3 commits into from
Jan 28, 2025
Merged

feat(nfs): configure local nfs #4406

merged 3 commits into from
Jan 28, 2025

Conversation

jazzlyn
Copy link
Collaborator

@jazzlyn jazzlyn commented Jan 28, 2025

No description provided.

@tyriis-automation
Copy link
Contributor

tyriis-automation bot commented Jan 28, 2025

🦙 MegaLinter status: ✅ SUCCESS

Descriptor Linter Files Fixed Errors Elapsed time
✅ EDITORCONFIG editorconfig-checker 13 0 0.04s
✅ REPOSITORY gitleaks yes no 2.96s
✅ YAML prettier 9 0 0.44s
✅ YAML yamllint 9 0 0.35s

See detailed report in MegaLinter reports
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

MegaLinter is graciously provided by OX Security

@tyriis-automation
Copy link
Contributor

--- HelmRelease: kube-tools/snapshot-controller ServiceAccount: kube-tools/snapshot-controller

+++ HelmRelease: kube-tools/snapshot-controller ServiceAccount: kube-tools/snapshot-controller

@@ -1,11 +0,0 @@

----
-apiVersion: v1
-kind: ServiceAccount
-metadata:
-  name: snapshot-controller
-  namespace: kube-tools
-  labels:
-    app.kubernetes.io/name: snapshot-controller
-    app.kubernetes.io/instance: snapshot-controller
-    app.kubernetes.io/managed-by: Helm
-
--- HelmRelease: kube-tools/snapshot-controller ClusterRole: kube-tools/snapshot-controller

+++ HelmRelease: kube-tools/snapshot-controller ClusterRole: kube-tools/snapshot-controller

@@ -1,122 +0,0 @@

----
-kind: ClusterRole
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
-  name: snapshot-controller
-rules:
-- apiGroups:
-  - ''
-  resources:
-  - persistentvolumes
-  verbs:
-  - get
-  - list
-  - watch
-- apiGroups:
-  - ''
-  resources:
-  - persistentvolumeclaims
-  verbs:
-  - get
-  - list
-  - watch
-  - update
-- apiGroups:
-  - ''
-  resources:
-  - events
-  verbs:
-  - list
-  - watch
-  - create
-  - update
-  - patch
-- apiGroups:
-  - snapshot.storage.k8s.io
-  resources:
-  - volumesnapshotclasses
-  verbs:
-  - get
-  - list
-  - watch
-- apiGroups:
-  - snapshot.storage.k8s.io
-  resources:
-  - volumesnapshotcontents
-  verbs:
-  - create
-  - get
-  - list
-  - watch
-  - update
-  - delete
-  - patch
-- apiGroups:
-  - snapshot.storage.k8s.io
-  resources:
-  - volumesnapshotcontents/status
-  verbs:
-  - patch
-- apiGroups:
-  - snapshot.storage.k8s.io
-  resources:
-  - volumesnapshots
-  verbs:
-  - create
-  - get
-  - list
-  - watch
-  - update
-  - patch
-  - delete
-- apiGroups:
-  - snapshot.storage.k8s.io
-  resources:
-  - volumesnapshots/status
-  verbs:
-  - update
-  - patch
-- apiGroups:
-  - groupsnapshot.storage.k8s.io
-  resources:
-  - volumegroupsnapshotclasses
-  verbs:
-  - get
-  - list
-  - watch
-- apiGroups:
-  - groupsnapshot.storage.k8s.io
-  resources:
-  - volumegroupsnapshotcontents
-  verbs:
-  - create
-  - get
-  - list
-  - watch
-  - update
-  - delete
-  - patch
-- apiGroups:
-  - groupsnapshot.storage.k8s.io
-  resources:
-  - volumegroupsnapshotcontents/status
-  verbs:
-  - patch
-- apiGroups:
-  - groupsnapshot.storage.k8s.io
-  resources:
-  - volumegroupsnapshots
-  verbs:
-  - get
-  - list
-  - watch
-  - update
-  - patch
-- apiGroups:
-  - groupsnapshot.storage.k8s.io
-  resources:
-  - volumegroupsnapshots/status
-  verbs:
-  - update
-  - patch
-
--- HelmRelease: kube-tools/snapshot-controller ClusterRoleBinding: kube-tools/snapshot-controller

+++ HelmRelease: kube-tools/snapshot-controller ClusterRoleBinding: kube-tools/snapshot-controller

@@ -1,14 +0,0 @@

----
-kind: ClusterRoleBinding
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
-  name: snapshot-controller
-subjects:
-- kind: ServiceAccount
-  name: snapshot-controller
-  namespace: kube-tools
-roleRef:
-  kind: ClusterRole
-  name: snapshot-controller
-  apiGroup: rbac.authorization.k8s.io
-
--- HelmRelease: kube-tools/snapshot-controller Role: kube-tools/snapshot-controller

+++ HelmRelease: kube-tools/snapshot-controller Role: kube-tools/snapshot-controller

@@ -1,19 +0,0 @@

----
-kind: Role
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
-  name: snapshot-controller
-  namespace: kube-tools
-rules:
-- apiGroups:
-  - coordination.k8s.io
-  resources:
-  - leases
-  verbs:
-  - get
-  - watch
-  - list
-  - delete
-  - update
-  - create
-
--- HelmRelease: kube-tools/snapshot-controller RoleBinding: kube-tools/snapshot-controller

+++ HelmRelease: kube-tools/snapshot-controller RoleBinding: kube-tools/snapshot-controller

@@ -1,14 +0,0 @@

----
-kind: RoleBinding
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
-  name: snapshot-controller
-  namespace: kube-tools
-subjects:
-- kind: ServiceAccount
-  name: snapshot-controller
-roleRef:
-  kind: Role
-  name: snapshot-controller
-  apiGroup: rbac.authorization.k8s.io
-
--- HelmRelease: kube-tools/snapshot-controller Deployment: kube-tools/snapshot-controller

+++ HelmRelease: kube-tools/snapshot-controller Deployment: kube-tools/snapshot-controller

@@ -1,63 +0,0 @@

----
-apiVersion: apps/v1
-kind: Deployment
-metadata:
-  name: snapshot-controller
-  namespace: kube-tools
-  labels:
-    app.kubernetes.io/name: snapshot-controller
-    app.kubernetes.io/instance: snapshot-controller
-    app.kubernetes.io/managed-by: Helm
-spec:
-  replicas: 1
-  revisionHistoryLimit: 10
-  selector:
-    matchLabels:
-      app.kubernetes.io/name: snapshot-controller
-      app.kubernetes.io/instance: snapshot-controller
-  template:
-    metadata:
-      labels:
-        app.kubernetes.io/name: snapshot-controller
-        app.kubernetes.io/instance: snapshot-controller
-    spec:
-      serviceAccountName: snapshot-controller
-      securityContext: {}
-      containers:
-      - name: snapshot-controller
-        securityContext:
-          capabilities:
-            drop:
-            - ALL
-          readOnlyRootFilesystem: true
-          runAsNonRoot: true
-          runAsUser: 1000
-        image: registry.k8s.io/sig-storage/snapshot-controller:v8.2.0
-        imagePullPolicy: IfNotPresent
-        args:
-        - --http-endpoint=:8080
-        - --leader-election=true
-        - --leader-election-namespace=$(NAMESPACE)
-        ports:
-        - name: http
-          containerPort: 8080
-          protocol: TCP
-        readinessProbe:
-          httpGet:
-            port: http
-            path: /healthz/leader-election
-            scheme: HTTP
-        livenessProbe:
-          httpGet:
-            port: http
-            path: /healthz/leader-election
-            scheme: HTTP
-        env:
-        - name: NAMESPACE
-          valueFrom:
-            fieldRef:
-              fieldPath: metadata.namespace
-        resources: {}
-      hostNetwork: false
-      dnsPolicy: ClusterFirst
-
--- HelmRelease: backup-system/snapshot-controller ServiceAccount: backup-system/snapshot-controller

+++ HelmRelease: backup-system/snapshot-controller ServiceAccount: backup-system/snapshot-controller

@@ -0,0 +1,11 @@

+---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: snapshot-controller
+  namespace: backup-system
+  labels:
+    app.kubernetes.io/name: snapshot-controller
+    app.kubernetes.io/instance: snapshot-controller
+    app.kubernetes.io/managed-by: Helm
+
--- HelmRelease: backup-system/snapshot-controller ClusterRole: backup-system/snapshot-controller

+++ HelmRelease: backup-system/snapshot-controller ClusterRole: backup-system/snapshot-controller

@@ -0,0 +1,122 @@

+---
+kind: ClusterRole
+apiVersion: rbac.authorization.k8s.io/v1
+metadata:
+  name: snapshot-controller
+rules:
+- apiGroups:
+  - ''
+  resources:
+  - persistentvolumes
+  verbs:
+  - get
+  - list
+  - watch
+- apiGroups:
+  - ''
+  resources:
+  - persistentvolumeclaims
+  verbs:
+  - get
+  - list
+  - watch
+  - update
+- apiGroups:
+  - ''
+  resources:
+  - events
+  verbs:
+  - list
+  - watch
+  - create
+  - update
+  - patch
+- apiGroups:
+  - snapshot.storage.k8s.io
+  resources:
+  - volumesnapshotclasses
+  verbs:
+  - get
+  - list
+  - watch
+- apiGroups:
+  - snapshot.storage.k8s.io
+  resources:
+  - volumesnapshotcontents
+  verbs:
+  - create
+  - get
+  - list
+  - watch
+  - update
+  - delete
+  - patch
+- apiGroups:
+  - snapshot.storage.k8s.io
+  resources:
+  - volumesnapshotcontents/status
+  verbs:
+  - patch
+- apiGroups:
+  - snapshot.storage.k8s.io
+  resources:
+  - volumesnapshots
+  verbs:
+  - create
+  - get
+  - list
+  - watch
+  - update
+  - patch
+  - delete
+- apiGroups:
+  - snapshot.storage.k8s.io
+  resources:
+  - volumesnapshots/status
+  verbs:
+  - update
+  - patch
+- apiGroups:
+  - groupsnapshot.storage.k8s.io
+  resources:
+  - volumegroupsnapshotclasses
+  verbs:
+  - get
+  - list
+  - watch
+- apiGroups:
+  - groupsnapshot.storage.k8s.io
+  resources:
+  - volumegroupsnapshotcontents
+  verbs:
+  - create
+  - get
+  - list
+  - watch
+  - update
+  - delete
+  - patch
+- apiGroups:
+  - groupsnapshot.storage.k8s.io
+  resources:
+  - volumegroupsnapshotcontents/status
+  verbs:
+  - patch
+- apiGroups:
+  - groupsnapshot.storage.k8s.io
+  resources:
+  - volumegroupsnapshots
+  verbs:
+  - get
+  - list
+  - watch
+  - update
+  - patch
+- apiGroups:
+  - groupsnapshot.storage.k8s.io
+  resources:
+  - volumegroupsnapshots/status
+  verbs:
+  - update
+  - patch
+
--- HelmRelease: backup-system/snapshot-controller ClusterRoleBinding: backup-system/snapshot-controller

+++ HelmRelease: backup-system/snapshot-controller ClusterRoleBinding: backup-system/snapshot-controller

@@ -0,0 +1,14 @@

+---
+kind: ClusterRoleBinding
+apiVersion: rbac.authorization.k8s.io/v1
+metadata:
+  name: snapshot-controller
+subjects:
+- kind: ServiceAccount
+  name: snapshot-controller
+  namespace: backup-system
+roleRef:
+  kind: ClusterRole
+  name: snapshot-controller
+  apiGroup: rbac.authorization.k8s.io
+
--- HelmRelease: backup-system/snapshot-controller Role: backup-system/snapshot-controller

+++ HelmRelease: backup-system/snapshot-controller Role: backup-system/snapshot-controller

@@ -0,0 +1,19 @@

+---
+kind: Role
+apiVersion: rbac.authorization.k8s.io/v1
+metadata:
+  name: snapshot-controller
+  namespace: backup-system
+rules:
+- apiGroups:
+  - coordination.k8s.io
+  resources:
+  - leases
+  verbs:
+  - get
+  - watch
+  - list
+  - delete
+  - update
+  - create
+
--- HelmRelease: backup-system/snapshot-controller RoleBinding: backup-system/snapshot-controller

+++ HelmRelease: backup-system/snapshot-controller RoleBinding: backup-system/snapshot-controller

@@ -0,0 +1,14 @@

+---
+kind: RoleBinding
+apiVersion: rbac.authorization.k8s.io/v1
+metadata:
+  name: snapshot-controller
+  namespace: backup-system
+subjects:
+- kind: ServiceAccount
+  name: snapshot-controller
+roleRef:
+  kind: Role
+  name: snapshot-controller
+  apiGroup: rbac.authorization.k8s.io
+
--- HelmRelease: backup-system/snapshot-controller Deployment: backup-system/snapshot-controller

+++ HelmRelease: backup-system/snapshot-controller Deployment: backup-system/snapshot-controller

@@ -0,0 +1,63 @@

+---
+apiVersion: apps/v1
+kind: Deployment
+metadata:
+  name: snapshot-controller
+  namespace: backup-system
+  labels:
+    app.kubernetes.io/name: snapshot-controller
+    app.kubernetes.io/instance: snapshot-controller
+    app.kubernetes.io/managed-by: Helm
+spec:
+  replicas: 1
+  revisionHistoryLimit: 10
+  selector:
+    matchLabels:
+      app.kubernetes.io/name: snapshot-controller
+      app.kubernetes.io/instance: snapshot-controller
+  template:
+    metadata:
+      labels:
+        app.kubernetes.io/name: snapshot-controller
+        app.kubernetes.io/instance: snapshot-controller
+    spec:
+      serviceAccountName: snapshot-controller
+      securityContext: {}
+      containers:
+      - name: snapshot-controller
+        securityContext:
+          capabilities:
+            drop:
+            - ALL
+          readOnlyRootFilesystem: true
+          runAsNonRoot: true
+          runAsUser: 1000
+        image: registry.k8s.io/sig-storage/snapshot-controller:v8.2.0
+        imagePullPolicy: IfNotPresent
+        args:
+        - --http-endpoint=:8080
+        - --leader-election=true
+        - --leader-election-namespace=$(NAMESPACE)
+        ports:
+        - name: http
+          containerPort: 8080
+          protocol: TCP
+        readinessProbe:
+          httpGet:
+            port: http
+            path: /healthz/leader-election
+            scheme: HTTP
+        livenessProbe:
+          httpGet:
+            port: http
+            path: /healthz/leader-election
+            scheme: HTTP
+        env:
+        - name: NAMESPACE
+          valueFrom:
+            fieldRef:
+              fieldPath: metadata.namespace
+        resources: {}
+      hostNetwork: false
+      dnsPolicy: ClusterFirst
+

@tyriis-automation
Copy link
Contributor

--- kubernetes/kube-nas/apps/kube-tools/snapshot-controller/app Kustomization: flux-system/snapshot-controller HelmRelease: kube-tools/snapshot-controller

+++ kubernetes/kube-nas/apps/kube-tools/snapshot-controller/app Kustomization: flux-system/snapshot-controller HelmRelease: kube-tools/snapshot-controller

@@ -1,36 +0,0 @@

----
-apiVersion: helm.toolkit.fluxcd.io/v2
-kind: HelmRelease
-metadata:
-  labels:
-    app.kubernetes.io/name: snapshot-controller
-    kustomize.toolkit.fluxcd.io/name: snapshot-controller
-    kustomize.toolkit.fluxcd.io/namespace: flux-system
-  name: snapshot-controller
-  namespace: kube-tools
-spec:
-  chart:
-    spec:
-      chart: snapshot-controller
-      sourceRef:
-        kind: HelmRepository
-        name: piraeus-charts
-        namespace: flux-system
-      version: 4.0.1
-  install:
-    crds: CreateReplace
-    remediation:
-      retries: 3
-  interval: 30m
-  upgrade:
-    cleanupOnFail: true
-    crds: CreateReplace
-    remediation:
-      retries: 3
-      strategy: rollback
-  values:
-    controller:
-      replicaCount: 1
-      serviceMonitor:
-        create: false
-
--- kubernetes/kube-nas/apps Kustomization: flux-system/flux-apps Kustomization: flux-system/snapshot-controller

+++ kubernetes/kube-nas/apps Kustomization: flux-system/flux-apps Kustomization: flux-system/snapshot-controller

@@ -13,21 +13,23 @@

     labels:
       app.kubernetes.io/name: snapshot-controller
   decryption:
     provider: sops
     secretRef:
       name: sops-age
-  interval: 10m
-  path: ./kubernetes/kube-nas/apps/kube-tools/snapshot-controller/app
+  interval: 30m
+  path: ./kubernetes/kube-nas/apps/backup-system/snapshot-controller/app
   postBuild:
     substituteFrom:
     - kind: ConfigMap
       name: cluster-settings
     - kind: Secret
       name: cluster-secrets
   prune: true
+  retryInterval: 1m
   sourceRef:
     kind: GitRepository
     name: home-ops
-  targetNamespace: kube-tools
+  targetNamespace: backup-system
+  timeout: 5m
   wait: true
 
--- kubernetes/kube-nas/apps/backup-system/snapshot-controller/app Kustomization: flux-system/snapshot-controller HelmRelease: backup-system/snapshot-controller

+++ kubernetes/kube-nas/apps/backup-system/snapshot-controller/app Kustomization: flux-system/snapshot-controller HelmRelease: backup-system/snapshot-controller

@@ -0,0 +1,36 @@

+---
+apiVersion: helm.toolkit.fluxcd.io/v2
+kind: HelmRelease
+metadata:
+  labels:
+    app.kubernetes.io/name: snapshot-controller
+    kustomize.toolkit.fluxcd.io/name: snapshot-controller
+    kustomize.toolkit.fluxcd.io/namespace: flux-system
+  name: snapshot-controller
+  namespace: backup-system
+spec:
+  chart:
+    spec:
+      chart: snapshot-controller
+      sourceRef:
+        kind: HelmRepository
+        name: piraeus-charts
+        namespace: flux-system
+      version: 4.0.1
+  install:
+    crds: CreateReplace
+    remediation:
+      retries: 3
+  interval: 30m
+  upgrade:
+    cleanupOnFail: true
+    crds: CreateReplace
+    remediation:
+      retries: 3
+      strategy: rollback
+  values:
+    controller:
+      replicaCount: 1
+      serviceMonitor:
+        create: false
+

@jazzlyn jazzlyn merged commit 5497fe8 into main Jan 28, 2025
16 checks passed
@jazzlyn jazzlyn deleted the feature/setup-nfs-storage branch January 28, 2025 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant