Serve the ThreadNet logo and the shared platform login background (alpenglow.jpg, same file Authentik and Element use) as public static files under /_assets/img/branding, mounted from a single platform-branding ConfigMap. This avoids two bad patterns: linking the background via an external URL (runtime dependency on axion1337.chat) and uploading the logo as a gated Wiki.js asset (which 404/403s on the unauthenticated login page unless guests get read:assets). Wiki.js serves /wiki/assets publicly at /_assets, so mounted files need no read:assets — guests stay locked out of pages. The config job sets logoUrl and authLoginBgUrl to the local paths and enables dark mode as default. The ConfigMap uses a name hash so a branding change rolls the pod. It can later be mounted into Authentik/Element too, keeping one source of truth for the shared assets.
99 lines
3.8 KiB
YAML
99 lines
3.8 KiB
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
# Patch: Fügt Checksums der element-values.yaml und des turn_shared_secret zur
|
|
# HelmRelease hinzu. Damit wird Flux die HelmRelease neu-synced (und synapse-main neu
|
|
# gestartet), wenn sich die jeweilige ConfigMap/Secret ändert - siehe Issue #38's
|
|
# Rotations-Mechanismus, der turn-secret-checksum bei jeder Rotation bumpt.
|
|
patches:
|
|
- target:
|
|
kind: HelmRelease
|
|
name: matrix-stack
|
|
namespace: matrix
|
|
patch: |-
|
|
- op: add
|
|
path: /metadata/annotations/element-config-checksum
|
|
value: "401f8a87d0ef5d91d2e5032d4aede42c"
|
|
- op: add
|
|
path: /metadata/annotations/turn-secret-checksum
|
|
value: "05aad8b742fb02c42f4c1a5629ae31e1"
|
|
|
|
resources:
|
|
- matrix-postgres-auth.yaml
|
|
- cert-issuer.yaml
|
|
- matrix-certificates.yaml
|
|
# Neue Dateien:
|
|
- custom-configs/synapse-values.yaml
|
|
- custom-configs/element-values.yaml
|
|
- custom-configs/mas-secret.yaml
|
|
- element-web-docs-configmap.yaml
|
|
- element-web-docs-server.yaml
|
|
# TURN Server für WebRTC
|
|
- coturn-secret.yaml
|
|
- coturn.yaml
|
|
- synapse-turn-secret.yaml
|
|
# HelmRelease (muss ganz unten stehen, damit die ConfigMaps vorher da sind!)
|
|
- element-server-suite.yaml
|
|
# Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat
|
|
- apex-ingress.yaml # Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat
|
|
- networkpolicy.yaml
|
|
# Backup zur Hetzner Storage Box (Issues #6 + #15)
|
|
- synapse-backup-secret.yaml
|
|
- synapse-backup.yaml
|
|
# Automatisierte TURN-Secret-Rotation (Issue #38)
|
|
- turn-secret-rotation-secret.yaml
|
|
- turn-secret-rotation.yaml
|
|
# Draupnir Moderationsbot (Issue #18)
|
|
- draupnir-secret.yaml
|
|
- draupnir-pvc.yaml
|
|
- draupnir.yaml
|
|
# ClamAV für Media-Scanning via Synapse-Modul (Issue #19)
|
|
- clamav-pvc.yaml
|
|
- clamav.yaml
|
|
# Client-seitiger Scan-Dienst für verschlüsselte Räume (Issue #19-Erweiterung)
|
|
- clamav-http-scanner.yaml
|
|
- concierge-bot.yaml
|
|
# Wiki.js (Plattform-Wiki, ADR-0014, #0048)
|
|
- wikijs-postgres-secret.yaml # SOPS, von sorb angelegt
|
|
- wikijs-admin-secret.yaml # SOPS, randomisiert — Bootstrap durch den Konfig-Job
|
|
- wikijs-oidc-secret.yaml # SOPS, client_id/secret für die OIDC-Strategy
|
|
- wikijs-postgres.yaml
|
|
- wikijs.yaml
|
|
- wiki-ingress.yaml
|
|
- wikijs-config.yaml # Konfig-Job (headless Setup + OIDC + Rollen)
|
|
|
|
# Synapse-Modul als eigene Datei gepflegt (lintbar/testbar), aber als ConfigMap gemounted -
|
|
# disableNameSuffixHash, da der Name in synapse-values.yaml's eingebettetem values.yaml
|
|
# referenziert wird (kustomize kann Referenzen nicht in opaken YAML-Strings umschreiben).
|
|
configMapGenerator:
|
|
# ⚠️ Bewusst OHNE disableNameSuffixHash: Der Hash im ConfigMap-Namen aendert
|
|
# sich mit dem Skript, kustomize zieht die Referenz im Deployment nach, und
|
|
# der Pod startet dadurch von selbst neu. Ohne das haetten wir wieder den
|
|
# Fall aus gitops#50 - geaenderte Datei im Repo, alter Stand im laufenden
|
|
# Prozess, und niemand merkt es.
|
|
- name: concierge-bot-script
|
|
namespace: matrix
|
|
files:
|
|
- concierge-bot.py
|
|
- name: synapse-clamav-module
|
|
namespace: matrix
|
|
files:
|
|
- clamav_spam_checker.py
|
|
options:
|
|
disableNameSuffixHash: true
|
|
- name: wikijs-config-script
|
|
namespace: matrix
|
|
files:
|
|
- wikijs-config.py
|
|
options:
|
|
disableNameSuffixHash: true
|
|
# Gemeinsame Branding-Assets (eine Quelle). Binärdateien -> kustomize legt sie als
|
|
# binaryData ab. MIT Namens-Hash: ändert sich ein Asset, zieht der Deployment-Verweis
|
|
# nach und der Pod startet mit dem neuen Bild neu. Kann später auch in Authentik/Element
|
|
# gemountet werden, um dieselbe Datei nicht mehrfach zu pflegen.
|
|
- name: platform-branding
|
|
namespace: matrix
|
|
files:
|
|
- branding/logo.png
|
|
- branding/alpenglow.jpg
|