unbound was bundled inside apps/pihole/ and invisible in the apps/ listing. Now apps/unbound/ (deployment + service + kustomization); it stays in the pihole namespace, whose Namespace object remains owned by apps/pihole. No resource changes — server-side dry-run clean (36 resources). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
35 lines
742 B
YAML
35 lines
742 B
YAML
# pihole-svc is type LoadBalancer → k3s klipper-lb (svclb) binds host ports
|
|
# 8000/53/67 on the nodes it schedules on. NodePorts are pinned so they
|
|
# survive re-creation.
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: pihole-svc
|
|
namespace: pihole
|
|
spec:
|
|
type: LoadBalancer
|
|
externalTrafficPolicy: Cluster
|
|
selector:
|
|
app: pihole
|
|
ports:
|
|
- name: http-admin
|
|
port: 8000
|
|
targetPort: 80
|
|
nodePort: 31120
|
|
protocol: TCP
|
|
- name: tcp-53
|
|
port: 53
|
|
targetPort: 53
|
|
nodePort: 32580
|
|
protocol: TCP
|
|
- name: udp-53
|
|
port: 53
|
|
targetPort: 53
|
|
nodePort: 31281
|
|
protocol: UDP
|
|
- name: udp-67
|
|
port: 67
|
|
targetPort: 67
|
|
nodePort: 31025
|
|
protocol: UDP
|