Basic Kubernetes configuration up and running

Add postgres operator and cluster
Create gitlab database declaratively
Update flake
YES, YES, I KNOW THE PASSWORDS ARE DUMB AND WORLD READABLE
This commit is contained in:
Greg Hellings
2025-05-26 12:20:29 -05:00
parent 7a60c58a74
commit 3110cff93c
18 changed files with 279 additions and 58 deletions
+1
View File
@@ -5,3 +5,4 @@ result
# On home-manager only installs, this is built into the same dir # On home-manager only installs, this is built into the same dir
# where I am storing my repo # where I am storing my repo
nix.conf nix.conf
manifests/postgres/charts
+7
View File
@@ -0,0 +1,7 @@
{
"languages": {
"YAML": {
"tab_size": 2
}
}
}
Generated
+37 -55
View File
@@ -93,11 +93,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1747521943, "lastModified": 1747964474,
"narHash": "sha256-GMAJcB8oB9cC+TbYTE7QDfw9fwHZyloxUWnUpHnQRko=", "narHash": "sha256-i73u8NLiqewGy0iIriH4XizatLnAojXxzrBqHJEz49E=",
"owner": "lnl7", "owner": "lnl7",
"repo": "nix-darwin", "repo": "nix-darwin",
"rev": "b9b927dd1f24094b271e8ec5277a672dc4fc860d", "rev": "93562b65cf68612a544779c9f77536f9dff01096",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -165,22 +165,6 @@
} }
}, },
"flake-compat_3": { "flake-compat_3": {
"flake": false,
"locked": {
"lastModified": 1696426674,
"narHash": "sha256-kvjfFW7WAETZlt09AgDn1MrtKzP7t90Vf7vypd3OL1U=",
"owner": "edolstra",
"repo": "flake-compat",
"rev": "0f9255e01c2351cc7d116c072cb317785dd33b33",
"type": "github"
},
"original": {
"owner": "edolstra",
"repo": "flake-compat",
"type": "github"
}
},
"flake-compat_4": {
"flake": false, "flake": false,
"locked": { "locked": {
"lastModified": 1733328505, "lastModified": 1733328505,
@@ -315,11 +299,11 @@
"systems": "systems_6" "systems": "systems_6"
}, },
"locked": { "locked": {
"lastModified": 1710146030, "lastModified": 1731533236,
"narHash": "sha256-SZ5L6eA7HJ/nmkzGG7/ISclqe6oZdOZTNoesiInkXPQ=", "narHash": "sha256-l0KFg5HjrsfsO/JpG+r7fRrqm12kzFHyUHqHCVpMMbI=",
"owner": "numtide", "owner": "numtide",
"repo": "flake-utils", "repo": "flake-utils",
"rev": "b1d9ab70662946ef0850d488da1c9019f3a9752a", "rev": "11707dc2f618dd54ca8739b309ec4fc024de578b",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -356,11 +340,11 @@
] ]
}, },
"locked": { "locked": {
"lastModified": 1747688838, "lastModified": 1747955385,
"narHash": "sha256-FZq4/3OtGV/cti9Vccsy2tGSUrxTO4hkDF9oeGRTen4=", "narHash": "sha256-AKoBFaEGN02tGvBlkwVIDOGXouHvrTTfOUcvBDGxkxQ=",
"owner": "nix-community", "owner": "nix-community",
"repo": "home-manager", "repo": "home-manager",
"rev": "45c2985644b60ab64de2a2d93a4d132ecb87cf66", "rev": "a868570581f0dbdef7e33c8c9bb34b735dfcbacf",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -441,11 +425,11 @@
}, },
"nix-hardware": { "nix-hardware": {
"locked": { "locked": {
"lastModified": 1747684167, "lastModified": 1747900541,
"narHash": "sha256-l6jbonaboCBlB8lCjBkrqgh2zEnvt6F3f4dOU/8CLd4=", "narHash": "sha256-dn64Pg9xLETjblwZs9Euu/SsjW80pd6lr5qSiyLY1pg=",
"owner": "nixos", "owner": "nixos",
"repo": "nixos-hardware", "repo": "nixos-hardware",
"rev": "e8f38b2c19c0647e39021c3d47172ff5469af8a9", "rev": "11f2d9ea49c3e964315215d6baa73a8d42672f06",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -600,11 +584,11 @@
}, },
"nixpkgs_3": { "nixpkgs_3": {
"locked": { "locked": {
"lastModified": 1747467164, "lastModified": 1747885982,
"narHash": "sha256-JBXbjJ0t6T6BbVc9iPVquQI9XSXCGQJD8c8SgnUquus=", "narHash": "sha256-rSuxACdwx5Ndr2thpjqcG89fj8mSSp96CFoCt0yrdkY=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "3fcbdcfc707e0aa42c541b7743e05820472bdaec", "rev": "a16efe5d2fc7455d7328a01f4692bfec152965b3",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -616,11 +600,11 @@
}, },
"nixpkgs_4": { "nixpkgs_4": {
"locked": { "locked": {
"lastModified": 1747542820, "lastModified": 1747744144,
"narHash": "sha256-GaOZntlJ6gPPbbkTLjbd8BMWaDYafhuuYRNrxCGnPJw=", "narHash": "sha256-W7lqHp0qZiENCDwUZ5EX/lNhxjMdNapFnbErcbnP11Q=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "292fa7d4f6519c074f0a50394dbbe69859bb6043", "rev": "2795c506fe8fb7b03c36ccb51f75b6df0ab2553f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -648,27 +632,27 @@
}, },
"nixpkgs_6": { "nixpkgs_6": {
"locked": { "locked": {
"lastModified": 1713805509, "lastModified": 1744868846,
"narHash": "sha256-YgSEan4CcrjivCNO5ZNzhg7/8ViLkZ4CB/GrGBVSudo=", "narHash": "sha256-5RJTdUHDmj12Qsv7XOhuospjAjATNiTMElplWnJE9Hs=",
"owner": "NixOS", "owner": "NixOS",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "1e1dc66fe68972a76679644a5577828b6a7e8be4", "rev": "ebe4301cbd8f81c4f8d3244b3632338bbeb6d49c",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "NixOS", "owner": "NixOS",
"ref": "nixpkgs-unstable",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "ebe4301cbd8f81c4f8d3244b3632338bbeb6d49c",
"type": "github" "type": "github"
} }
}, },
"nixunstable": { "nixunstable": {
"locked": { "locked": {
"lastModified": 1747542820, "lastModified": 1747744144,
"narHash": "sha256-GaOZntlJ6gPPbbkTLjbd8BMWaDYafhuuYRNrxCGnPJw=", "narHash": "sha256-W7lqHp0qZiENCDwUZ5EX/lNhxjMdNapFnbErcbnP11Q=",
"owner": "nixos", "owner": "nixos",
"repo": "nixpkgs", "repo": "nixpkgs",
"rev": "292fa7d4f6519c074f0a50394dbbe69859bb6043", "rev": "2795c506fe8fb7b03c36ccb51f75b6df0ab2553f",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -686,11 +670,11 @@
"systems": "systems_4" "systems": "systems_4"
}, },
"locked": { "locked": {
"lastModified": 1747683610, "lastModified": 1747945641,
"narHash": "sha256-Jis9/4lnr3pn1AIRgCnoeiReKs2MGy6COWc6JtAEESo=", "narHash": "sha256-Ts16c+kptbC3YDwPcB/NqXFVMHPNYKeFD7LkiawbWCU=",
"owner": "nix-community", "owner": "nix-community",
"repo": "nixvim", "repo": "nixvim",
"rev": "14c7f5f8968940d1730b5e935dd1d9f3e461a2d3", "rev": "46fd0b184cbc5f1bdc5a8325cb973fc54e49ab68",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -707,11 +691,11 @@
"treefmt-nix": "treefmt-nix" "treefmt-nix": "treefmt-nix"
}, },
"locked": { "locked": {
"lastModified": 1747683907, "lastModified": 1747973449,
"narHash": "sha256-dgEK4d1QPNFhv0s5s9lpvEWOVBlRZENp7TVh8V8qYDU=", "narHash": "sha256-e+DaBDI6xzd7KW+1u3jHhEzdF2Ajx5hP0bF2CFiS/F8=",
"owner": "nix-community", "owner": "nix-community",
"repo": "NUR", "repo": "NUR",
"rev": "64046fedb710701f87e5e86390b4dbe77f1d733b", "rev": "e4fcae418dde38789f3f59ea07ad289a4b9bcffe",
"type": "github" "type": "github"
}, },
"original": { "original": {
@@ -931,28 +915,26 @@
}, },
"vsext": { "vsext": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_3",
"flake-utils": "flake-utils_3", "flake-utils": "flake-utils_3",
"nixpkgs": "nixpkgs_6" "nixpkgs": "nixpkgs_6"
}, },
"locked": { "locked": {
"lastModified": 1739984805, "lastModified": 1747965670,
"narHash": "sha256-cX3UzBy65e2CafN6a6WJr3aXQm4gvYD+Ym1epuY600k=", "narHash": "sha256-O91kjsTL7xccgTQr2KITmGhhLTpX9zh+oRvvV8ScOrg=",
"owner": "greg-hellings", "owner": "nix-community",
"repo": "nix-vscode-extensions", "repo": "nix-vscode-extensions",
"rev": "f5671be9dec0adee120e30436d6450abea4ced42", "rev": "d3099346fa5e9e33d0989a4e6afc3e8dedd25311",
"type": "github" "type": "github"
}, },
"original": { "original": {
"owner": "greg-hellings", "owner": "nix-community",
"ref": "fix-json",
"repo": "nix-vscode-extensions", "repo": "nix-vscode-extensions",
"type": "github" "type": "github"
} }
}, },
"wsl": { "wsl": {
"inputs": { "inputs": {
"flake-compat": "flake-compat_4", "flake-compat": "flake-compat_3",
"nixpkgs": [ "nixpkgs": [
"nixunstable" "nixunstable"
] ]
+1 -1
View File
@@ -42,7 +42,7 @@
nixvimunstable.url = "github:nix-community/nixvim/main"; nixvimunstable.url = "github:nix-community/nixvim/main";
nixunstable.url = "github:nixos/nixpkgs/nixos-unstable"; nixunstable.url = "github:nixos/nixpkgs/nixos-unstable";
nurpkgs.url = "github:nix-community/NUR"; nurpkgs.url = "github:nix-community/NUR";
vsext.url = "github:greg-hellings/nix-vscode-extensions/fix-json"; vsext.url = "github:nix-community/nix-vscode-extensions";
wsl = { wsl = {
url = "github:nix-community/NixOS-WSL"; url = "github:nix-community/NixOS-WSL";
inputs.nixpkgs.follows = "nixunstable"; inputs.nixpkgs.follows = "nixunstable";
+1 -1
View File
@@ -9,7 +9,7 @@
10.42.1.3 printer.thehellings.lan 10.42.1.3 printer.thehellings.lan
10.42.1.4 chronicles chronicles.thehellings.lan nas.thehellings.lan s3.thehellings.lan 10.42.1.4 chronicles chronicles.thehellings.lan nas.thehellings.lan s3.thehellings.lan
10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan 10.42.1.5 genesis genesis.thehellings.lan dns dns.thehellings.lan smart smart.thehellings.lan speedtest.thehellings.lan nixcache.thehellings.lan gitcache.thehellings.lan
10.42.1.6 isaiah isaiah.thehellings.lan minio-01.thehellings.lan 10.42.1.6 isaiah isaiah.thehellings.lan minio-01.thehellings.lan pgadmin.thehellings.lan
10.42.1.7 hosea hosea.thehellings.lan 10.42.1.7 hosea hosea.thehellings.lan
10.42.1.8 jeremiah jeremiah.thehellings.lan minio-02.thehellings.lan 10.42.1.8 jeremiah jeremiah.thehellings.lan minio-02.thehellings.lan
10.42.1.9 ivr ivr.thehellings.lan 10.42.1.9 ivr ivr.thehellings.lan
+1 -1
View File
@@ -149,7 +149,7 @@
in in
[ [
"--tls-san ${ip}" "--tls-san ${ip}"
"--bind-address ${ip}" #"--bind-address ${ip}"
]; ];
pipewire = { pipewire = {
enable = true; enable = true;
+15
View File
@@ -0,0 +1,15 @@
Stands up my personal infrastructure in a Kubernetes environment.
To apply this you need to install kubectl, kustomize, and helm. It can then by applied
by simply invoking the command:
```bash
# Working directory is assumed to be the manifests directory
./apply.sh
```
Once the basic cluster stuff is setup, you can just apply this directory with
```bash
kubectl apply -k .
```
+11
View File
@@ -0,0 +1,11 @@
#!/usr/bin/env bash
# Get the directory where the script is located
SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )"
# Change to the script directory
cd "$SCRIPT_DIR"
kubectl apply -k namespaces
kustomize build postgres --enable-helm | kubectl apply -f - --server-side --force-conflicts
kubectl apply -k .
+6
View File
@@ -0,0 +1,6 @@
namespace: db
resources:
- postgres-cluster.yaml
- postgres-gitlab.yaml
- postgres-pgadmin.yaml
+26
View File
@@ -0,0 +1,26 @@
apiVersion: postgresql.cnpg.io/v1
kind: Cluster
metadata:
name: postgres
spec:
instances: 3
storage:
size: 10Gi
primaryUpdateStrategy: unsupervised
managed:
roles:
- name: gitlab
ensure: present
comment: Gitlab user
login: true
superuser: false
passwordSecret:
name: postgres-user-gitlab
- name: pgadmin
ensure: present
comment: PG Admin user
login: true
superuser: true
passwordSecret:
name: postgres-user-pgadmin
+21
View File
@@ -0,0 +1,21 @@
apiVersion: v1
kind: Secret
metadata:
name: postgres-user-gitlab
labels:
cnpg.io/reload: "true"
type: kubernetes.io/basic-auth
stringData:
# Currently this is set to "gitlab"
username: gitlab
password: gitlab
---
apiVersion: postgresql.cnpg.io/v1
kind: Database
metadata:
name: database-gitlab
spec:
name: gitlab
owner: gitlab
cluster:
name: postgres
+118
View File
@@ -0,0 +1,118 @@
apiVersion: v1
kind: Secret
metadata:
name: postgres-user-pgadmin
labels:
cnpg.io/reload: "true"
type: kubernetes.io/basic-auth
stringData:
username: pgadmin
password: pgadmin
---
apiVersion: v1
kind: ConfigMap
metadata:
name: config-pgadmin
data:
servers.json: |
{
"Servers": {
"1": {
"Name": "Postgres",
"Group": "Servers",
"Port": 5432,
"Username": "pgadmin",
"Host": "postgres-rw",
"SSLMode": "allow",
"MaintenanceDB": "postgres"
}
}
}
---
apiVersion: v1
kind: Service
metadata:
name: service-pgadmin
spec:
ports:
- protocol: TCP
port: 80
targetPort: http
selector:
app: pgadmin
type: ClusterIP
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: pgadmin
spec:
serviceName: service-pgadmin
podManagementPolicy: Parallel
replicas: 1
updateStrategy:
type: RollingUpdate
selector:
matchLabels:
app: pgadmin
template:
metadata:
labels:
app: pgadmin
spec:
terminationGracePeriodSeconds: 10
containers:
- name: pgadmin
image: "dpage/pgadmin4:9.3"
imagePullPolicy: Always
env:
- name: PGADMIN_DEFAULT_EMAIL
value: greg@thehellings.com
- name: PGADMIN_DEFAULT_PASSWORD
valueFrom:
secretKeyRef:
name: postgres-user-pgadmin
key: password
- name: PGADMIN_SERVER_JSON_FILE
value: /config-pgadmin-vol/servers.json
ports:
- name: http
containerPort: 80
protocol: TCP
volumeMounts:
- name: config-pgadmin-vol
mountPath: /config-pgadmin-vol/
readOnly: true
- name: pgadmin-data
mountPath: /var/lib/pgadmin
volumes:
- name: config-pgadmin-vol
configMap:
name: config-pgadmin
volumeClaimTemplates:
- metadata:
name: pgadmin-data
spec:
accessModes: ["ReadWriteOnce"]
resources:
requests:
storage: 3Gi
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: ingress-pgadmin
annotations:
ingressClassName: traefik
spec:
rules:
- host: pgadmin.thehellings.lan
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: service-pgadmin
port:
number: 80
+3
View File
@@ -0,0 +1,3 @@
resources:
- namespaces
- databases
+4
View File
@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: db
+2
View File
@@ -0,0 +1,2 @@
resources:
- db.yaml
+13
View File
@@ -0,0 +1,13 @@
namespace: db
helmCharts:
# Install the operator first (with CRDs)
- name: cloudnative-pg
repo: "https://cloudnative-pg.github.io/charts/"
version: "0.23.2"
namespace: cnpg-system
releaseName: cnpg
includeCRDs: true
valuesInline:
crds:
create: true
+11
View File
@@ -0,0 +1,11 @@
#!/usr/bin/env bash
# Get the directory where the script is located
SCRIPT_DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" &> /dev/null && pwd )"
# Change to the script directory
cd "$SCRIPT_DIR"
kubectl delete -k .
kustomize build postgres --enable-helm | kubectl delete -f -
kubectl delete -k namespaces
+1
View File
@@ -23,6 +23,7 @@ in
age.secrets.kubernetesToken.file = ../../secrets/kubernetes/kubernetesToken.age; age.secrets.kubernetesToken.file = ../../secrets/kubernetes/kubernetesToken.age;
environment.systemPackages = [ environment.systemPackages = [
pkgs.kubectl-cnpg
pkgs.kubernetes-helm pkgs.kubernetes-helm
pkgs.kustomize pkgs.kustomize
pkgs.k9s pkgs.k9s