Files
nixos/manifests
root df2f9d69fe
buildbot/nix-eval Build done. (1 warning)
fix: address PR feedback + expand infrastructure coverage
- Replace unpoller-credentials plain Secret with ExternalSecret
  pulling from Bitwarden item 15bfc957-5de5-49b2-ab6c-b41800e71564
  via bitwarden-login ClusterSecretStore (username + password)
- Pull UP_UNIFI_DEFAULT_USER from secret as well (was hardcoded)

- Add OpenWRT access point (10.42.0.3) to genesis DNS hosts file
  as ap.thehellings.lan (discovered during network scan)

- Add blackbox exporter to genesis (port 9115, ICMP module)
  for probing non-NixOS infrastructure that has no node_exporter:
  OpenWRT AP, Joel, pve1, chronicles, nas1, odoo, mattermost,
  homeassistant, USW-Pro-HD-24 UniFi switch

- Add infra_ping scrape job to Prometheus using blackbox prober
  targeting all non-NixOS LAN hosts via genesis blackbox exporter
2026-03-25 09:25:16 -05:00
..
2025-11-23 14:43:36 -06:00
2025-10-19 21:48:30 -05:00
2025-10-22 16:18:02 -05:00
2026-03-09 17:33:36 -05:00
2025-12-29 00:42:14 -06:00
2025-11-26 20:44:43 -06:00
2025-07-07 21:48:47 -05:00
2025-11-23 14:43:15 -06:00
2025-05-26 17:10:01 -05:00

Stands up my personal infrastructure in a Kubernetes environment.

First Thing First

In order to properly get things up and going, you will need to create a secret to allow the external secrets to log into BitWarden Password Manager. For obvious reasont this cannot be safely added to this repository. As such, it is suggested you create this manually.

kubectl create namespace bitwarden
kubectl create secret generic bitwarden-cli --namespace bitwarden --from-literal=BW_USERNAME=my_username --from-literal=BW_PASSWORD=my_password
# Alternative to the preceding line if you don't want the data in your shell history
kubectl create secret generic bitwarden-cli  --namespace bitwarden --from-file=./BW_USERNAME.txt --from-file=./BW_PASSWORD.txt
# And yet an entirely other option, if I'm logged into my own systems
sudo cat /run/agenix/bw_secret | kubectl apply -f -

Now Configure Cluster Services

To apply this you need to install kubectl, kustomize, and helm. It can then by applied by simply invoking the command:

# Working directory is assumed to be the manifests directory
./apply.sh

Once the basic cluster stuff is setup, you can just apply this directory with

kubectl apply -k .