Restores the Borg archives into a throwaway postgres inside the pod and passes only when rows actually land — the pg_restore exit code is not proof, counted rows are. Production is never touched; the repos are only read. Automated rather than a documented cadence: a check nobody performs is the same mistake as an untested backup, one level up. Runs on the 4th at 04:20, after the nightly jobs. Verified manually before commit (synapse 31908 rows, MAS 16085, wiki 251). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
109 lines
4.3 KiB
YAML
109 lines
4.3 KiB
YAML
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
kind: Kustomization
|
|
|
|
# Patch: Fügt Checksums der element-values.yaml und des turn_shared_secret zur
|
|
# HelmRelease hinzu. Damit wird Flux die HelmRelease neu-synced (und synapse-main neu
|
|
# gestartet), wenn sich die jeweilige ConfigMap/Secret ändert - siehe Issue #38's
|
|
# Rotations-Mechanismus, der turn-secret-checksum bei jeder Rotation bumpt.
|
|
patches:
|
|
- target:
|
|
kind: HelmRelease
|
|
name: matrix-stack
|
|
namespace: matrix
|
|
patch: |-
|
|
- op: add
|
|
path: /metadata/annotations/element-config-checksum
|
|
value: "401f8a87d0ef5d91d2e5032d4aede42c"
|
|
- op: add
|
|
path: /metadata/annotations/turn-secret-checksum
|
|
value: "05aad8b742fb02c42f4c1a5629ae31e1"
|
|
|
|
resources:
|
|
- matrix-postgres-auth.yaml
|
|
- cert-issuer.yaml
|
|
- matrix-certificates.yaml
|
|
# Neue Dateien:
|
|
- custom-configs/synapse-values.yaml
|
|
- custom-configs/element-values.yaml
|
|
- custom-configs/mas-secret.yaml
|
|
- element-web-docs-configmap.yaml
|
|
- element-web-docs-server.yaml
|
|
# TURN Server für WebRTC
|
|
- coturn-secret.yaml
|
|
- coturn.yaml
|
|
- synapse-turn-secret.yaml
|
|
# HelmRelease (muss ganz unten stehen, damit die ConfigMaps vorher da sind!)
|
|
- element-server-suite.yaml
|
|
# Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat
|
|
- apex-ingress.yaml # Custom Apex Ingress für Element Web + Well-Known auf axion1337.chat
|
|
- networkpolicy.yaml
|
|
# Backup zur Hetzner Storage Box (Issues #6 + #15)
|
|
- synapse-backup-secret.yaml
|
|
- synapse-backup.yaml
|
|
# Monatliche Restore-Probe: spielt die Sicherungen isoliert zurueck (#0030)
|
|
- restore-drill.yaml
|
|
# Automatisierte TURN-Secret-Rotation (Issue #38)
|
|
- turn-secret-rotation-secret.yaml
|
|
- turn-secret-rotation.yaml
|
|
# Draupnir Moderationsbot (Issue #18)
|
|
- draupnir-secret.yaml
|
|
- draupnir-pvc.yaml
|
|
- draupnir.yaml
|
|
# ClamAV für Media-Scanning via Synapse-Modul (Issue #19)
|
|
- clamav-pvc.yaml
|
|
- clamav.yaml
|
|
# Client-seitiger Scan-Dienst für verschlüsselte Räume (Issue #19-Erweiterung)
|
|
- clamav-http-scanner.yaml
|
|
- concierge-bot.yaml
|
|
# Wiki.js (Plattform-Wiki, ADR-0014, #0048)
|
|
- wikijs-postgres-secret.yaml # SOPS, von sorb angelegt
|
|
- wikijs-admin-secret.yaml # SOPS, randomisiert — Bootstrap durch den Konfig-Job
|
|
- wikijs-oidc-secret.yaml # SOPS, client_id/secret für die OIDC-Strategy
|
|
- wikijs-git-secret.yaml # SOPS, Git-Storage-PAT nach Gitea (ADR-0015)
|
|
- wikijs-postgres.yaml
|
|
- wikijs.yaml
|
|
- wiki-ingress.yaml
|
|
- wikijs-config.yaml # Konfig-Job (headless Setup + OIDC + Rollen)
|
|
- wikijs-postgres-backup.yaml # Nächtliches Borg-Backup der Wiki-DB (#0048)
|
|
|
|
# Synapse-Modul als eigene Datei gepflegt (lintbar/testbar), aber als ConfigMap gemounted -
|
|
# disableNameSuffixHash, da der Name in synapse-values.yaml's eingebettetem values.yaml
|
|
# referenziert wird (kustomize kann Referenzen nicht in opaken YAML-Strings umschreiben).
|
|
configMapGenerator:
|
|
# ⚠️ Bewusst OHNE disableNameSuffixHash: Der Hash im ConfigMap-Namen aendert
|
|
# sich mit dem Skript, kustomize zieht die Referenz im Deployment nach, und
|
|
# der Pod startet dadurch von selbst neu. Ohne das haetten wir wieder den
|
|
# Fall aus gitops#50 - geaenderte Datei im Repo, alter Stand im laufenden
|
|
# Prozess, und niemand merkt es.
|
|
- name: concierge-bot-script
|
|
namespace: matrix
|
|
files:
|
|
- concierge-bot.py
|
|
- name: synapse-clamav-module
|
|
namespace: matrix
|
|
files:
|
|
- clamav_spam_checker.py
|
|
options:
|
|
disableNameSuffixHash: true
|
|
- name: wikijs-config-script
|
|
namespace: matrix
|
|
files:
|
|
- wikijs-config.py
|
|
options:
|
|
disableNameSuffixHash: true
|
|
# Gemeinsame Branding-Assets (eine Quelle). Binärdateien -> kustomize legt sie als
|
|
# binaryData ab. MIT Namens-Hash: ändert sich ein Asset, zieht der Deployment-Verweis
|
|
# nach und der Pod startet mit dem neuen Bild neu. Kann später auch in Authentik/Element
|
|
# gemountet werden, um dieselbe Datei nicht mehrfach zu pflegen.
|
|
- name: platform-branding
|
|
namespace: matrix
|
|
files:
|
|
- branding/logo.png
|
|
- branding/alpenglow.jpg
|
|
- branding/favicon.ico
|
|
- branding/favicons/favicon-32x32.png
|
|
- branding/favicons/favicon-16x16.png
|
|
- branding/favicons/android-chrome-192x192.png
|
|
- branding/favicons/apple-touch-icon.png
|
|
- branding/favicons/mstile-150x150.png
|