Captured 2026-07-26 from rpi-master (k3s v1.30.3) and cleaned of runtime fields. Six apps as per-app kustomizations: vaultwarden, searxng, home-assistant, nginx, pihole(+unbound), unified-streaming. Intentional divergences from live state: - pihole WEBPASSWORD and USP_LICENSE_KEY moved from inline plaintext env to secretKeyRef (secrets gitignored; templates in secret.example.yaml) - HA ingress defaultBackend fixed (pointed at nonexistent service) - unifiedstreaming-svc kept as ClusterIP (LoadBalancer could never bind port 80 behind svclb-traefik) Validated against the live cluster with kubectl apply --dry-run=server: no immutable-field conflicts; one-time kubectl replace procedure for the two env->secretKeyRef migrations documented in README. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
76 lines
2.1 KiB
YAML
76 lines
2.1 KiB
YAML
# Originally installed via helm chart vaultwarden-5.1.0 (release record no longer
|
|
# in cluster); managed as a raw manifest since. Selector labels are immutable —
|
|
# do not change them.
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: bitwarden-vaultwarden
|
|
namespace: bitwarden
|
|
labels:
|
|
app.kubernetes.io/instance: bitwarden
|
|
app.kubernetes.io/name: vaultwarden
|
|
spec:
|
|
replicas: 1
|
|
revisionHistoryLimit: 3
|
|
selector:
|
|
matchLabels:
|
|
app.kubernetes.io/instance: bitwarden
|
|
app.kubernetes.io/name: vaultwarden
|
|
strategy:
|
|
type: Recreate
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app.kubernetes.io/instance: bitwarden
|
|
app.kubernetes.io/name: vaultwarden
|
|
spec:
|
|
affinity:
|
|
nodeAffinity:
|
|
requiredDuringSchedulingIgnoredDuringExecution:
|
|
nodeSelectorTerms:
|
|
- matchExpressions:
|
|
- key: cpu
|
|
operator: In
|
|
values:
|
|
- arm
|
|
- key: controller
|
|
operator: NotIn
|
|
values:
|
|
- "true"
|
|
containers:
|
|
- name: bitwarden-vaultwarden
|
|
image: vaultwarden/server:1.35.4
|
|
imagePullPolicy: IfNotPresent
|
|
env:
|
|
- name: DATA_FOLDER
|
|
value: config
|
|
ports:
|
|
- name: http
|
|
containerPort: 80
|
|
protocol: TCP
|
|
- name: websocket
|
|
containerPort: 3012
|
|
protocol: TCP
|
|
startupProbe:
|
|
tcpSocket:
|
|
port: 80
|
|
failureThreshold: 30
|
|
periodSeconds: 5
|
|
livenessProbe:
|
|
tcpSocket:
|
|
port: 80
|
|
failureThreshold: 3
|
|
periodSeconds: 10
|
|
readinessProbe:
|
|
tcpSocket:
|
|
port: 80
|
|
failureThreshold: 3
|
|
periodSeconds: 10
|
|
volumeMounts:
|
|
- name: config
|
|
mountPath: /config
|
|
volumes:
|
|
- name: config
|
|
persistentVolumeClaim:
|
|
claimName: bitwarden-gvolume0
|