Captured 2026-07-26 from rpi-master (k3s v1.30.3) and cleaned of runtime fields. Six apps as per-app kustomizations: vaultwarden, searxng, home-assistant, nginx, pihole(+unbound), unified-streaming. Intentional divergences from live state: - pihole WEBPASSWORD and USP_LICENSE_KEY moved from inline plaintext env to secretKeyRef (secrets gitignored; templates in secret.example.yaml) - HA ingress defaultBackend fixed (pointed at nonexistent service) - unifiedstreaming-svc kept as ClusterIP (LoadBalancer could never bind port 80 behind svclb-traefik) Validated against the live cluster with kubectl apply --dry-run=server: no immutable-field conflicts; one-time kubectl replace procedure for the two env->secretKeyRef migrations documented in README. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
54 lines
1.0 KiB
YAML
54 lines
1.0 KiB
YAML
# pihole-svc is type LoadBalancer → k3s klipper-lb (svclb) binds host ports
|
|
# 8000/53/67 on the nodes it schedules on. NodePorts are pinned so they
|
|
# survive re-creation.
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: pihole-svc
|
|
namespace: pihole
|
|
spec:
|
|
type: LoadBalancer
|
|
externalTrafficPolicy: Cluster
|
|
selector:
|
|
app: pihole
|
|
ports:
|
|
- name: http-admin
|
|
port: 8000
|
|
targetPort: 80
|
|
nodePort: 31120
|
|
protocol: TCP
|
|
- name: tcp-53
|
|
port: 53
|
|
targetPort: 53
|
|
nodePort: 32580
|
|
protocol: TCP
|
|
- name: udp-53
|
|
port: 53
|
|
targetPort: 53
|
|
nodePort: 31281
|
|
protocol: UDP
|
|
- name: udp-67
|
|
port: 67
|
|
targetPort: 67
|
|
nodePort: 31025
|
|
protocol: UDP
|
|
---
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: unbound-service
|
|
namespace: pihole
|
|
spec:
|
|
type: ClusterIP
|
|
selector:
|
|
app: unbound
|
|
ports:
|
|
- name: udp-53
|
|
port: 53
|
|
targetPort: 53
|
|
protocol: UDP
|
|
- name: tcp-53
|
|
port: 53
|
|
targetPort: 53
|
|
protocol: TCP
|