apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization # Patch: Fügt Checksums der element-values.yaml und des turn_shared_secret zur # HelmRelease hinzu. Damit wird Flux die HelmRelease neu-synced (und synapse-main neu # gestartet), wenn sich die jeweilige ConfigMap/Secret ändert - siehe Issue #38's # Rotations-Mechanismus, der turn-secret-checksum bei jeder Rotation bumpt. patches: - target: kind: HelmRelease name: matrix-stack namespace: matrix patch: |- - op: add path: /metadata/annotations/element-config-checksum value: "401f8a87d0ef5d91d2e5032d4aede42c" - op: add path: /metadata/annotations/turn-secret-checksum value: "d220c0e4ff8f7106328c8827d47e8734" resources: - matrix-postgres-auth.yaml - cert-issuer.yaml - matrix-certificates.yaml # Neue Dateien: - custom-configs/synapse-values.yaml - custom-configs/element-values.yaml - custom-configs/mas-secret.yaml - element-web-docs-configmap.yaml - element-web-docs-server.yaml # TURN Server für WebRTC - coturn-secret.yaml - coturn.yaml - synapse-turn-secret.yaml # HelmRelease (muss ganz unten stehen, damit die ConfigMaps vorher da sind!) - element-server-suite.yaml # Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat - apex-ingress.yaml # Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat - networkpolicy.yaml # Backup zur Hetzner Storage Box (Issues #6 + #15) - synapse-backup-secret.yaml - synapse-backup.yaml # Automatisierte TURN-Secret-Rotation (Issue #38) - turn-secret-rotation-secret.yaml - turn-secret-rotation.yaml