16 Commits

Author SHA1 Message Date
jasonwitty 7769762afb Deploy searxng ai-summary-20260814
Validate and Deploy to K3s / validate (push) Successful in 17s
Validate and Deploy to K3s / deploy (push) Successful in 1m7s
From fork commit 1fa83635c: the model name pattern now accepts version
pinned names such as gemini-1.5-pro@001, which gateways use routinely.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 11:37:05 -07:00
jasonwitty 92ec6ea1be Point tududi AI assistant at the local Ollama
Validate and Deploy to K3s / validate (push) Successful in 20s
Validate and Deploy to K3s / deploy (push) Successful in 27s
tududi speaks the OpenAI chat completions API for its daily brief and
task/project insights, so it can use the Ollama box directly instead of a
hosted provider -- nothing about the task list leaves the network.

LLM_API_KEY has to be set even though Ollama ignores it; without a key
the generation endpoints answer 503 and the UI shows a not-configured
state. It is a secret so the value can be swapped for a real one if the
provider ever changes.

gemma4:e4b was checked against the JSON-only replies these features parse
and answered correctly in about five seconds.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 14:01:32 -07:00
jasonwitty 7b084dbddd Add dashwise and tududi
Validate and Deploy to K3s / validate (push) Successful in 19s
Validate and Deploy to K3s / deploy (push) Successful in 23s
Two self-hosted apps behind traefik, both keeping their state on the
GlusterFS volume that is mounted on every node:

- dashwise (home.wittyoneoff.com) is an all-in-one image running its web
  server, a bundled PocketBase and valkey side by side. Only port 3000 is
  published: the frontend resolves its backend as window.location.origin
  and every PocketBase call is made server-side, so 8090 stays inside the
  pod. It is on the service so the PocketBase admin UI can be reached with
  kubectl port-forward.

- tududi (tududi.wittyoneoff.com) stores a SQLite database and user
  uploads. Both are VOLUMEs in the image, so both are backed by the claim
  -- as one volume mounted twice with subPath, because naming the same
  claim as two volume entries wedges kubelet, which is what happened with
  limesurvey.

Both images are pinned to tags that publish an arm64 manifest. dashwise
:latest and :stable are amd64 only and would not start on these nodes.

Namespaces and secrets are applied out of band, as with the other apps.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:46:58 -07:00
jasonwitty 9fd2a54e2e Deploy searxng ai-summary-20260811c
Validate and Deploy to K3s / validate (push) Successful in 23s
Validate and Deploy to K3s / deploy (push) Successful in 36s
From fork commit 054b3a5c0: the AI summary error box now names the
reason, so a failure can be diagnosed from a phone.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 12:18:57 -07:00
jasonwitty d712d5c5d0 Deploy searxng ai-summary-20260811b
Validate and Deploy to K3s / validate (push) Successful in 15s
Validate and Deploy to K3s / deploy (push) Successful in 35s
From fork commit 0cc374886: the AI summary request is also repeated when
the LLM server answers 5xx, which is the failure that arrives at once
rather than as a timeout.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:58:59 -07:00
jasonwitty 95159a4d32 Deploy searxng ai-summary-20260811
Validate and Deploy to K3s / validate (push) Successful in 17s
Validate and Deploy to K3s / deploy (push) Successful in 35s
From fork commit 4a582c0a1: the AI summary request is repeated once when
the LLM server does not answer in time, which is what happens while an
idle Ollama loads the model back into memory.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 11:46:27 -07:00
jasonwitty 4da446ef74 update to vaultwarden/server:1.37.0
Validate and Deploy to K3s / validate (push) Successful in 18s
Validate and Deploy to K3s / deploy (push) Successful in 48s
2026-08-10 00:32:26 -07:00
jasonwitty 0d9a12caec Deploy searxng ai-summary-20260808
Validate and Deploy to K3s / validate (push) Failing after 10m7s
Validate and Deploy to K3s / deploy (push) Has been cancelled
From fork commit c7e8bba48: password inputs are styled like text inputs
(the AI summary API key field rendered white) and the field description
is shortened.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-08 21:39:21 -07:00
jasonwitty 3a1cc1eb50 Deploy searxng ai-summary-20260807
Validate and Deploy to K3s / validate (push) Successful in 21s
Validate and Deploy to K3s / deploy (push) Failing after 14m20s
From fork commit 8edc36875: the AI Summary preferences tab is only shown
when the plugin is activated in settings.yml, users can configure an API
key for their own LLM server, and grounding is on by default.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-07 13:23:48 -07:00
jasonwitty 16cd367d26 Deploy searxng ai-summary-20260805 (LLM server API key support)
Validate and Deploy to K3s / validate (push) Successful in 17s
Validate and Deploy to K3s / deploy (push) Successful in 55s
New multi-arch image (amd64+arm64) built from searxng fork ce400f993:
the ai_summary plugin can now authenticate to the LLM server with an
ai_summary.api_key, sent only to the configured base_url.

secret.example.yaml documents the ai_summary block, including the new
optional api_key.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-05 23:32:07 -07:00
jasonwitty 0c691e863d Fix searxng TZ: America/Los Angeles -> America/Los_Angeles
Validate and Deploy to K3s / validate (push) Successful in 18s
Validate and Deploy to K3s / deploy (push) Successful in 31s
The space made it an invalid tzdata name, so the container silently fell
back to UTC. Standard searxng container config, unrelated to the
ai_summary fork changes.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-05 12:04:42 -07:00
jasonwitty 0cb0cc7620 Pin searxng to the live image tag ai-summary-20260728-3
The manifest pinned :ai-summary-20260727, two builds behind the running
deployment. Applying this repo would have rolled the instance back past
the OpenAI chat-completions switch and the Brave-iOS streaming fallback.
kubectl diff against the live deployment is now empty.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-05 11:58:43 -07:00
jasonwitty c41da37032 update searxng to latest development build with ai summary.
Validate and Deploy to K3s / validate (push) Successful in 17s
Validate and Deploy to K3s / deploy (push) Successful in 8m0s
2026-07-27 15:40:28 -07:00
jasonwitty 53232fe9fe Split unbound into its own app directory
Validate and Deploy to K3s / validate (push) Successful in 16s
Validate and Deploy to K3s / deploy (push) Successful in 21s
unbound was bundled inside apps/pihole/ and invisible in the apps/
listing. Now apps/unbound/ (deployment + service + kustomization); it
stays in the pihole namespace, whose Namespace object remains owned by
apps/pihole. No resource changes — server-side dry-run clean (36
resources).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-26 08:59:21 -07:00
jasonwitty fe72f1e85a Fix pihole for v6: pin digest, listeningMode=ALL, v6 password env, readiness probe
Validate and Deploy to K3s / validate (push) Failing after 1m41s
Validate and Deploy to K3s / deploy (push) Has been skipped
A fresh node pull of pihole:latest silently upgraded v5->v6 (Core v6.2.2).
v6's default listeningMode=LOCAL drops DNS from non-attached subnets, which
killed all cross-node svclb DNS the moment the pod rescheduled off its old
node. v6 also ignores the WEBPASSWORD env.

- image pinned by digest (Core v6.2.2)
- FTLCONF_dns_listeningMode=ALL
- admin password via FTLCONF_webserver_api_password <- pihole-admin secret
- tcpSocket:53 readiness probe so rollout status waits for FTL

Applied to the cluster via kubectl replace; DNS verified answering on all
four node IPs, admin API auth verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-26 02:56:50 -07:00
jasonwitty 8afac39d03 Import manifests reverse-engineered from live cluster
Captured 2026-07-26 from rpi-master (k3s v1.30.3) and cleaned of runtime
fields. Six apps as per-app kustomizations: vaultwarden, searxng,
home-assistant, nginx, pihole(+unbound), unified-streaming.

Intentional divergences from live state:
- pihole WEBPASSWORD and USP_LICENSE_KEY moved from inline plaintext env
  to secretKeyRef (secrets gitignored; templates in secret.example.yaml)
- HA ingress defaultBackend fixed (pointed at nonexistent service)
- unifiedstreaming-svc kept as ClusterIP (LoadBalancer could never bind
  port 80 behind svclb-traefik)

Validated against the live cluster with kubectl apply --dry-run=server:
no immutable-field conflicts; one-time kubectl replace procedure for the
two env->secretKeyRef migrations documented in README.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-26 02:13:56 -07:00