Auto-Deploy on Push / verify-and-notify (push) Canceled after 0s
Live-tested Issue #38's rotation: after merging the automated rotation PR, coturn restarted quickly (Kustomization-level, 1m interval), but synapse-main lagged behind since it depends on this separate HelmRelease with its own 5m interval - a real (self-healing, but avoidable) window where coturn had the new TURN secret and Synapse still had the old one, which would reject each other's credentials/relayed media. Matching the interval to production-apps's 1m tightens that window without needing any new automation. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
99 lines
2.7 KiB
YAML
99 lines
2.7 KiB
YAML
apiVersion: helm.toolkit.fluxcd.io/v2
|
||
kind: HelmRelease
|
||
metadata:
|
||
name: matrix-stack
|
||
namespace: matrix
|
||
spec:
|
||
# Shortened from 5m to match production-apps Kustomization's 1m interval - narrows the
|
||
# window between coturn (Kustomization-only, no Helm indirection) and synapse-main
|
||
# (behind this HelmRelease) picking up a rotated TURN secret after Issue #38's
|
||
# automated-rotation PR gets merged. Self-heals either way, just faster now.
|
||
interval: 1m
|
||
chart:
|
||
spec:
|
||
chart: matrix-stack
|
||
version: "26.4.0"
|
||
sourceRef:
|
||
kind: HelmRepository
|
||
name: element-ess-oci
|
||
namespace: flux-system
|
||
|
||
# NEU: Hier zieht Flux deine Puzzleteile zusammen
|
||
valuesFrom:
|
||
- kind: ConfigMap
|
||
name: ess-synapse-custom
|
||
valuesKey: values.yaml
|
||
- kind: ConfigMap
|
||
name: ess-element-custom
|
||
valuesKey: values.yaml
|
||
- kind: Secret
|
||
name: ess-mas-values-secret
|
||
valuesKey: values.yaml
|
||
- kind: Secret
|
||
name: synapse-turn-secret
|
||
valuesKey: values.yaml
|
||
|
||
values:
|
||
# Top-Level: serverName – das ist dein Matrix-Homeserver-Name
|
||
serverName: axion1337.chat
|
||
|
||
# Cert-Manager für automatische Zertifikatsgenerierung
|
||
certManager:
|
||
clusterIssuer: letsencrypt-prod
|
||
|
||
# Interner Postgres an (default ist eh true, hier nur zur Klarheit)
|
||
postgres:
|
||
enabled: true
|
||
|
||
# Synapse – API auf matrix.axion1337.chat
|
||
synapse:
|
||
enabled: true
|
||
ingress:
|
||
host: matrix.axion1337.chat
|
||
additional:
|
||
oembed:
|
||
config: |
|
||
oembed_enabled: true
|
||
|
||
# Matrix Authentication Service – braucht eine Subdomain
|
||
matrixAuthenticationService:
|
||
enabled: true
|
||
ingress:
|
||
host: account.axion1337.chat
|
||
|
||
# Matrix RTC (Element Call) – braucht auch eine Subdomain
|
||
matrixRTC:
|
||
enabled: true
|
||
ingress:
|
||
host: mrtc.axion1337.chat
|
||
# Chart default (20Mi request+limit) OOM-killed the authorisation service after
|
||
# ~74 days of uptime (2026-07-28) - too tight for a long-running Go service.
|
||
resources:
|
||
requests:
|
||
memory: 64Mi
|
||
cpu: 50m
|
||
limits:
|
||
memory: 128Mi
|
||
|
||
# Element Web
|
||
elementWeb:
|
||
enabled: true
|
||
image:
|
||
registry: rohana.axion1337.de
|
||
repository: sorb/threadnet-web
|
||
tag: v0.2.3-elementcall-h264
|
||
ingress:
|
||
host: axion1337.chat
|
||
|
||
# Element Admin
|
||
elementAdmin:
|
||
enabled: true
|
||
ingress:
|
||
host: admin.axion1337.chat
|
||
|
||
# Well-Known auf der Apex-Domain (axion1337.chat/.well-known/matrix/*)
|
||
# Aktiviert – notwendig für MatrixRTC-Discovery
|
||
wellKnownDelegation:
|
||
enabled: true
|
||
ingress:
|
||
className: "none" # Deaktiviert den Chart-Ingress, wir erstellen einen eigenen |