Files
axion1337.chat-gitops/apps/production/kustomization.yaml
T
Thore Cimbal 2154f7fe77 fix(wiki): replace remaining Wiki.js favicons; split branding ConfigMap
The browser tab still showed Wiki.js because only favicon.ico + 16/32 were
replaced — the larger icons the tab picks (android-chrome-192, apple-touch-180,
mstile-150) were still the defaults. Add ThreadNet versions and subPath-mount
them. Adding these pushed the single branding ConfigMap to ~1.04 MB (the 1 MiB
etcd limit), so split the 604 KB background into its own platform-branding-bg
ConfigMap mounted at /_assets/img/bg; authLoginBgUrl follows.
2026-08-13 12:00:00 +00:00

112 lines
4.4 KiB
YAML

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
# Patch: Fügt Checksums der element-values.yaml und des turn_shared_secret zur
# HelmRelease hinzu. Damit wird Flux die HelmRelease neu-synced (und synapse-main neu
# gestartet), wenn sich die jeweilige ConfigMap/Secret ändert - siehe Issue #38's
# Rotations-Mechanismus, der turn-secret-checksum bei jeder Rotation bumpt.
patches:
- target:
kind: HelmRelease
name: matrix-stack
namespace: matrix
patch: |-
- op: add
path: /metadata/annotations/element-config-checksum
value: "401f8a87d0ef5d91d2e5032d4aede42c"
- op: add
path: /metadata/annotations/turn-secret-checksum
value: "05aad8b742fb02c42f4c1a5629ae31e1"
resources:
- matrix-postgres-auth.yaml
- cert-issuer.yaml
- matrix-certificates.yaml
# Neue Dateien:
- custom-configs/synapse-values.yaml
- custom-configs/element-values.yaml
- custom-configs/mas-secret.yaml
- element-web-docs-configmap.yaml
- element-web-docs-server.yaml
# TURN Server für WebRTC
- coturn-secret.yaml
- coturn.yaml
- synapse-turn-secret.yaml
# HelmRelease (muss ganz unten stehen, damit die ConfigMaps vorher da sind!)
- element-server-suite.yaml
# Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat
- apex-ingress.yaml # Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat
- networkpolicy.yaml
# Backup zur Hetzner Storage Box (Issues #6 + #15)
- synapse-backup-secret.yaml
- synapse-backup.yaml
# Automatisierte TURN-Secret-Rotation (Issue #38)
- turn-secret-rotation-secret.yaml
- turn-secret-rotation.yaml
# Draupnir Moderationsbot (Issue #18)
- draupnir-secret.yaml
- draupnir-pvc.yaml
- draupnir.yaml
# ClamAV für Media-Scanning via Synapse-Modul (Issue #19)
- clamav-pvc.yaml
- clamav.yaml
# Client-seitiger Scan-Dienst für verschlüsselte Räume (Issue #19-Erweiterung)
- clamav-http-scanner.yaml
- concierge-bot.yaml
# Wiki.js (Plattform-Wiki, ADR-0014, #0048)
- wikijs-postgres-secret.yaml # SOPS, von sorb angelegt
- wikijs-admin-secret.yaml # SOPS, randomisiert — Bootstrap durch den Konfig-Job
- wikijs-oidc-secret.yaml # SOPS, client_id/secret für die OIDC-Strategy
- wikijs-git-secret.yaml # SOPS, Git-Storage-PAT nach Gitea (ADR-0015)
- wikijs-postgres.yaml
- wikijs.yaml
- wiki-ingress.yaml
- wikijs-config.yaml # Konfig-Job (headless Setup + OIDC + Rollen)
- wikijs-postgres-backup.yaml # Nächtliches Borg-Backup der Wiki-DB (#0048)
# Synapse-Modul als eigene Datei gepflegt (lintbar/testbar), aber als ConfigMap gemounted -
# disableNameSuffixHash, da der Name in synapse-values.yaml's eingebettetem values.yaml
# referenziert wird (kustomize kann Referenzen nicht in opaken YAML-Strings umschreiben).
configMapGenerator:
# ⚠️ Bewusst OHNE disableNameSuffixHash: Der Hash im ConfigMap-Namen aendert
# sich mit dem Skript, kustomize zieht die Referenz im Deployment nach, und
# der Pod startet dadurch von selbst neu. Ohne das haetten wir wieder den
# Fall aus gitops#50 - geaenderte Datei im Repo, alter Stand im laufenden
# Prozess, und niemand merkt es.
- name: concierge-bot-script
namespace: matrix
files:
- concierge-bot.py
- name: synapse-clamav-module
namespace: matrix
files:
- clamav_spam_checker.py
options:
disableNameSuffixHash: true
- name: wikijs-config-script
namespace: matrix
files:
- wikijs-config.py
options:
disableNameSuffixHash: true
# Gemeinsame Branding-Assets (eine Quelle). Binärdateien -> kustomize legt sie als
# binaryData ab. MIT Namens-Hash: ändert sich ein Asset, zieht der Deployment-Verweis
# nach und der Pod startet mit dem neuen Bild neu. Kann später auch in Authentik/Element
# gemountet werden, um dieselbe Datei nicht mehrfach zu pflegen.
- name: platform-branding
namespace: matrix
files:
- branding/logo.png
- branding/favicon.ico
- branding/favicons/favicon-32x32.png
- branding/favicons/favicon-16x16.png
- branding/favicons/android-chrome-192x192.png
- branding/favicons/apple-touch-icon.png
- branding/favicons/mstile-150x150.png
# Hintergrundbild separat: alpenglow.jpg (604 KB) würde die obige ConfigMap ans
# 1-MiB-Limit bringen. Eigene ConfigMap, eigener Mount-Pfad (/_assets/img/bg/).
- name: platform-branding-bg
namespace: matrix
files:
- branding/alpenglow.jpg