Files
nixos/manifests
emily fcb5a89727
buildbot/nix-eval Build done. (1 warning)
buildbot/nix-build Build done.
fix: correct pve1 IP to 10.42.0.4, rename stale joel/opnsense refs
pve1 is a static/DHCP-reserved Proxmox host at 10.42.0.4 (previously
mislabeled 'joel' in some places). 10.42.1.1 is the UDM Pro gateway
IP, not pve1 -- OPNsense was retired in favor of Ubiquiti. Removes
the stale duplicate PVE1 DHCP reservation at 10.42.1.1 and drops the
now-redundant 'joel' entry from network.json (consolidated into
pve1).
2026-08-08 00:44:21 -05:00
..
2025-10-19 21:48:30 -05:00
2026-08-05 20:07:35 -05:00
2026-08-03 20:46:20 -05:00
2026-08-05 20:07:35 -05:00
2026-08-05 20:07:35 -05:00
2025-12-29 00:42:14 -06:00
2025-07-07 21:48:47 -05:00
2025-11-23 14:43:15 -06:00
2025-05-26 17:10:01 -05:00

Stands up my personal infrastructure in a Kubernetes environment.

First Thing First

In order to properly get things up and going, you will need to create a secret to allow the external secrets to log into BitWarden Password Manager. For obvious reasont this cannot be safely added to this repository. As such, it is suggested you create this manually.

kubectl create namespace bitwarden
kubectl create secret generic bitwarden-cli --namespace bitwarden --from-literal=BW_USERNAME=my_username --from-literal=BW_PASSWORD=my_password
# Alternative to the preceding line if you don't want the data in your shell history
kubectl create secret generic bitwarden-cli  --namespace bitwarden --from-file=./BW_USERNAME.txt --from-file=./BW_PASSWORD.txt
# And yet an entirely other option, if I'm logged into my own systems
sudo cat /run/agenix/bw_secret | kubectl apply -f -

Now Configure Cluster Services

To apply this you need to install kubectl, kustomize, and helm. It can then by applied by simply invoking the command:

# Working directory is assumed to be the manifests directory
./apply.sh

Once the basic cluster stuff is setup, you can just apply this directory with

kubectl apply -k .