Author SHA1 Message Date
Renovate 874dc11927 Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.9.0 2026-09-10 20:35:57 +00:00
Renovate e9c8100f53 Merge pull request 'Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.8.2' (#422) from renovate/ghcr.io-remsky-kokoro-fastapi-cpu-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-09-06 02:02:12 +00:00
Renovate 00082171a3 Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.8.2 2026-09-06 02:02:08 +00:00
Lumpiasty aa681fc963 Merge pull request 'Update Helm release open-webui to v16.5.0' (#417) from renovate/open-webui-16.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #417
2026-09-04 22:18:40 +00:00
Renovate 32b71be47a Update Helm release open-webui to v16.5.0 2026-09-04 02:01:55 +00:00
Renovate 76da17f808 Merge pull request 'Update Helm release openbao to v0.29.4' (#421) from renovate/openbao-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-09-04 02:01:51 +00:00
Renovate 5eeab70a99 Update Helm release openbao to v0.29.4 2026-09-04 02:01:43 +00:00
Renovate 4f5de9294c Merge pull request 'Update Helm release authentik to v2026.8.1' (#418) from renovate/authentik-2026.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-09-02 02:01:45 +00:00
Renovate 2e18084008 Update Helm release authentik to v2026.8.1 2026-09-02 02:01:38 +00:00
Renovate ee9e7f1905 Merge pull request 'Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.5' (#416) from renovate/ghcr.io-fluxcd-flux-cli-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-09-01 02:01:37 +00:00
Renovate 6ebfdeb989 Merge pull request 'Update dependency fluxcd/flux2 to v2.9.5' (#415) from renovate/fluxcd-flux2-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-09-01 02:01:34 +00:00
Renovate 923b37e171 Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.5 2026-09-01 02:01:33 +00:00
Renovate ef2e7987f0 Update dependency fluxcd/flux2 to v2.9.5 2026-09-01 02:01:28 +00:00
Renovate 9ce13dc207 Merge pull request 'Update Helm release woodpecker to v3.7.3' (#414) from renovate/woodpecker-3.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-31 02:01:31 +00:00
Renovate 9985851e82 Update Helm release woodpecker to v3.7.3 2026-08-31 02:01:27 +00:00
Lumpiasty 598330097f Merge pull request 'Update Helm release open-webui to v16.1.0' (#411) from renovate/open-webui-16.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #411
2026-08-29 23:02:37 +00:00
Renovate d4293e4e29 Merge pull request 'Update Helm release openbao to v0.29.3' (#413) from renovate/openbao-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-28 02:01:57 +00:00
Renovate a800b218c4 Update Helm release openbao to v0.29.3 2026-08-28 02:01:48 +00:00
Renovate 056d762dc9 Update Helm release open-webui to v16.1.0 2026-08-26 02:01:44 +00:00
Renovate e3dfba7170 Merge pull request 'Update Helm release woodpecker to v3.7.2' (#410) from renovate/woodpecker-3.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-25 02:01:46 +00:00
Renovate 928f3d1005 Merge pull request 'Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.8.1' (#409) from renovate/ghcr.io-remsky-kokoro-fastapi-cpu-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is running
2026-08-25 02:01:41 +00:00
Renovate 0d81ee473f Update Helm release woodpecker to v3.7.2 2026-08-25 02:01:40 +00:00
Renovate 4fb53636f1 Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.8.1 2026-08-25 02:01:36 +00:00
Lumpiasty 6241b81f02 Merge pull request 'Update dependency kaneo to v2.22.0' (#408) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #408
2026-08-22 22:30:33 +00:00
Renovate 5b8833325d Update dependency kaneo to v2.22.0 2026-08-22 22:26:23 +00:00
Lumpiasty ed3da857d5 Merge pull request 'Update dependency kaneo to v2.20.0' (#397) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #397
2026-08-22 22:14:52 +00:00
Lumpiasty f3cc1f3688 Merge pull request 'Update Helm release cilium to v1.20.1' (#390) from renovate/cilium-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #390
2026-08-22 21:58:57 +00:00
Lumpiasty de8bb69cdc Merge pull request 'Update Helm release woodpecker to v3.7.1' (#396) from renovate/woodpecker-3.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #396
2026-08-22 21:39:10 +00:00
Lumpiasty ea29623106 Merge pull request 'Update Helm release authentik to v2026.8.0' (#405) from renovate/authentik-2026.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #405
2026-08-22 21:38:58 +00:00
Lumpiasty b0cbe885a5 Merge pull request 'Update Helm release openbao to v0.29.2' (#401) from renovate/openbao-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is running
Reviewed-on: #401
2026-08-22 21:38:46 +00:00
Lumpiasty 2ade45b3dc Merge pull request 'Update golang Docker tag to v1.27' (#407) from renovate/golang-1.x into fresh-start
ci/woodpecker/push/build-images Pipeline is running
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #407
2026-08-22 21:38:33 +00:00
Lumpiasty 4af96d3c5d Merge pull request 'Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.8.0' (#395) from renovate/ghcr.io-remsky-kokoro-fastapi-cpu-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #395
2026-08-22 21:38:23 +00:00
Lumpiasty 0f557f8c09 Security hotfix gitea 1.27.2
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-08-22 17:21:56 +02:00
Renovate 6ff0796946 Update golang Docker tag to v1.27
ci/woodpecker/push/build-images Pipeline is running
2026-08-20 02:01:33 +00:00
Renovate 851a2096e3 Update dependency kaneo to v2.20.0
ci/woodpecker/push/build-images Pipeline is running
2026-08-20 02:01:26 +00:00
Renovate e1ef81db71 Merge pull request 'Update registry.k8s.io/coredns/coredns Docker tag to v1.14.7' (#406) from renovate/registry.k8s.io-coredns-coredns-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline failed
2026-08-20 02:01:25 +00:00
Renovate c64e6e73f9 Update registry.k8s.io/coredns/coredns Docker tag to v1.14.7 2026-08-20 02:01:23 +00:00
Renovate cf021a776d Update Helm release openbao to v0.29.2 2026-08-19 02:02:40 +00:00
Renovate 29d9cfbcbf Update Helm release cilium to v1.20.1 2026-08-19 02:02:25 +00:00
Renovate 255b29fb6c Update Helm release authentik to v2026.8.0 2026-08-19 02:02:19 +00:00
Renovate 7d0ece3fb1 Merge pull request 'Update quay.io/openbao/openbao Docker tag to v2.6.2' (#404) from renovate/quay.io-openbao-openbao-2.x into fresh-start
ci/woodpecker/push/build-images Pipeline failed
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-19 02:02:14 +00:00
Renovate bb391b641f Update quay.io/openbao/openbao Docker tag to v2.6.2
ci/woodpecker/push/build-images Pipeline failed
2026-08-19 02:02:08 +00:00
Renovate 0990af576e Update Helm release woodpecker to v3.7.1 2026-08-18 02:02:21 +00:00
Renovate 7d3d036912 Merge pull request 'Update Helm release cert-manager-webhook-ovh to v0.9.16' (#403) from renovate/cert-manager-webhook-ovh-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-18 02:02:00 +00:00
Renovate d31e792530 Update Helm release cert-manager-webhook-ovh to v0.9.16 2026-08-18 02:01:53 +00:00
Renovate 96ef9a9925 Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.8.0 2026-08-16 20:13:24 +00:00
Lumpiasty 1b6b8eee16 Increase valkey storage
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-16 21:20:18 +02:00
Renovate aa7842a5d5 Merge pull request 'Update Helm release vault-secrets-operator to v1.5.1' (#402) from renovate/vault-secrets-operator-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline failed
2026-08-13 02:01:01 +00:00
Renovate 7d6158af20 Update Helm release vault-secrets-operator to v1.5.1 2026-08-13 02:00:56 +00:00
Renovate fd2afb45f5 Merge pull request 'Update Helm release cert-manager-webhook-ovh to v0.9.15' (#400) from renovate/cert-manager-webhook-ovh-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-09 02:01:26 +00:00
Renovate 1073ee27e1 Update Helm release cert-manager-webhook-ovh to v0.9.15 2026-08-09 02:01:21 +00:00
Renovate 29f1f31bd0 Merge pull request 'Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.4' (#399) from renovate/ghcr.io-fluxcd-flux-cli-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-07 20:54:39 +00:00
Renovate 304235ccd6 Merge pull request 'Update dependency fluxcd/flux2 to v2.9.4' (#398) from renovate/fluxcd-flux2-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-08-07 20:54:38 +00:00
Renovate 9705084504 Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.4 2026-08-07 20:54:37 +00:00
Renovate 2c3db3c0a2 Update dependency fluxcd/flux2 to v2.9.4 2026-08-07 20:54:26 +00:00
Lumpiasty fe391afe1a increase gitea valkey storage
ci/woodpecker/cron/renovate Pipeline was successful
2026-08-06 18:29:18 +02:00
Lumpiasty e69f3ce4ae Merge pull request 'Update kaneo to v2.12.1' (#393) from renovate/kaneo into fresh-start
ci/woodpecker/cron/renovate Pipeline failed
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #393
2026-07-31 23:41:47 +00:00
Lumpiasty 39cb9626fe remove kaneo image tag pin 2026-08-01 01:41:06 +02:00
Lumpiasty c1eadb29d1 Merge pull request 'Update Helm release open-webui to v16' (#394) from renovate/open-webui-16.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #394
2026-07-31 23:37:35 +00:00
Lumpiasty 9d8cda8228 remove image tag pin 2026-08-01 01:37:11 +02:00
Renovate ba90001ec8 Update Helm release open-webui to v16 2026-08-01 01:37:08 +02:00
Renovate ece05f6119 Update kaneo to v2.12.1 2026-07-31 02:01:37 +00:00
Renovate 129279192a Merge pull request 'Update Helm release open-webui to v15.2.1' (#392) from renovate/open-webui-15.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-31 02:01:22 +00:00
Renovate a703b8ef4c Update Helm release open-webui to v15.2.1 2026-07-31 02:01:16 +00:00
Lumpiasty 33d30a1f6a Merge pull request 'Update renovate/renovate Docker tag to v44' (#391) from renovate/renovate-renovate-44.x into fresh-start
ci/woodpecker/cron/renovate Pipeline was successful
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #391
2026-07-29 21:36:23 +00:00
Lumpiasty d3e794233b Merge pull request 'Update gitea.lumpiasty.xyz/lumpiasty/supervisord:latest Docker digest to 2676d13' (#386) from renovate/gitea.lumpiasty.xyz-lumpiasty-supervisord-latest into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #386
2026-07-29 21:34:38 +00:00
Renovate 3f2e7bff23 Update renovate/renovate Docker tag to v44 2026-07-29 21:17:26 +00:00
Renovate 1f6e7f6d06 Merge pull request 'Update Helm release immich to v2.0.3' (#389) from renovate/immich-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-29 21:17:11 +00:00
Renovate 27a07fb5d9 Merge pull request 'Update Helm release cert-manager to v1.21.1' (#388) from renovate/cert-manager-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-29 21:17:07 +00:00
Renovate 0790de0fdf Update Helm release immich to v2.0.3 2026-07-29 21:17:07 +00:00
Renovate 0261f900d7 Update Helm release cert-manager to v1.21.1 2026-07-29 21:16:59 +00:00
Renovate b3135998f6 Update gitea.lumpiasty.xyz/lumpiasty/supervisord:latest Docker digest to 2676d13 2026-07-29 21:16:57 +00:00
Lumpiasty aff867b774 automatically merge digest updates
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-29 23:15:57 +02:00
Renovate 4c31107f8c Merge pull request 'Update kaneo to v2.9.10' (#387) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-29 02:01:12 +00:00
Renovate 6b15082274 Update kaneo to v2.9.10 2026-07-29 02:01:08 +00:00
Lumpiasty 94d7817a07 bump openwebui image tag
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-28 18:54:37 +02:00
Lumpiasty 63e502735c Merge pull request 'Update Helm release cert-manager to v1.21.0' (#358) from renovate/cert-manager-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #358
2026-07-28 15:52:55 +00:00
Lumpiasty 2b687712cb Merge pull request 'Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.6.0' (#360) from renovate/ghcr.io-remsky-kokoro-fastapi-cpu-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #360
2026-07-28 15:52:15 +00:00
Lumpiasty c7ceb45ba1 Merge pull request 'Update quay.io/openbao/openbao Docker tag to v2.6.1' (#366) from renovate/quay.io-openbao-openbao-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline failed
ci/woodpecker/push/build-images Pipeline was successful
Reviewed-on: #366
2026-07-28 15:52:02 +00:00
Lumpiasty bd33268bc0 Merge pull request 'Update Helm release k8up to v4.10.0' (#374) from renovate/k8up-4.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #374
2026-07-28 15:51:52 +00:00
Lumpiasty c4143d95fc Merge pull request 'Update Helm release gitea to v12.7.0' (#377) from renovate/gitea-12.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #377
2026-07-28 15:50:24 +00:00
Lumpiasty 146a251669 Merge pull request 'Update gitea.lumpiasty.xyz/lumpiasty/supervisord:latest Docker digest to 86e4837' (#378) from renovate/gitea.lumpiasty.xyz-lumpiasty-supervisord-latest into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #378
2026-07-28 15:50:11 +00:00
Lumpiasty 3400bcc421 Merge pull request 'Update Helm release valkey to v0.11.0' (#383) from renovate/valkey-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #383
2026-07-28 15:50:02 +00:00
Lumpiasty 45365dd01f Merge pull request 'Update Helm release vault-secrets-operator to v1.5.0' (#384) from renovate/vault-secrets-operator-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #384
2026-07-28 15:49:47 +00:00
Renovate 8e84550bfb Merge pull request 'Update kaneo to v2.9.9' (#385) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-27 17:31:30 +00:00
Renovate ed4e59dac1 Update kaneo to v2.9.9 2026-07-27 17:31:17 +00:00
Renovate 2aca37a14c Update Helm release vault-secrets-operator to v1.5.0 2026-07-25 02:02:21 +00:00
Renovate d86ad8e56a Update Helm release valkey to v0.11.0 2026-07-25 02:02:17 +00:00
Renovate 81518b132a Update gitea.lumpiasty.xyz/lumpiasty/supervisord:latest Docker digest to 86e4837 2026-07-25 02:01:58 +00:00
Renovate 0ba8aa2889 Update quay.io/openbao/openbao Docker tag to v2.6.1
ci/woodpecker/push/build-images Pipeline was successful
2026-07-24 02:02:53 +00:00
Renovate c2cde1836c Merge pull request 'Update Helm release openbao to v0.28.6' (#382) from renovate/openbao-0.x into fresh-start
ci/woodpecker/cron/renovate Pipeline was successful
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-24 02:02:06 +00:00
Renovate 3b957ca449 Merge pull request 'Update Helm release authentik to v2026.5.6' (#381) from renovate/authentik-2026.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-24 02:02:01 +00:00
Renovate c748950996 Update Helm release openbao to v0.28.6 2026-07-24 02:02:01 +00:00
Renovate 7fecb4e456 Merge pull request 'Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.3' (#380) from renovate/ghcr.io-fluxcd-flux-cli-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-24 02:01:56 +00:00
Renovate c0729a67bd Update Helm release authentik to v2026.5.6 2026-07-24 02:01:56 +00:00
Renovate b423498c41 Merge pull request 'Update dependency fluxcd/flux2 to v2.9.3' (#379) from renovate/fluxcd-flux2-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-24 02:01:53 +00:00
Renovate 26585e64ae Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.3 2026-07-24 02:01:53 +00:00
Renovate 41147dc02f Update dependency fluxcd/flux2 to v2.9.3 2026-07-24 02:01:48 +00:00
Lumpiasty d4931833f0 Merge pull request 'Update debian Docker tag to v13.6' (#365) from renovate/debian-13.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/build-images Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #365
2026-07-23 17:07:07 +00:00
Lumpiasty 6524a14745 increase amdgpu timeout
ci/woodpecker/push/flux-reconcile-source Pipeline failed
ci/woodpecker/cron/renovate Pipeline failed
2026-07-23 00:12:10 +02:00
Lumpiasty 858e121c55 Merge pull request 'Update gitea.lumpiasty.xyz/lumpiasty/supervisord:latest Docker digest to c7adeea' (#367) from renovate/gitea.lumpiasty.xyz-lumpiasty-supervisord-latest into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is pending
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #367
2026-07-21 15:44:09 +00:00
Renovate edd56e84d7 Update gitea.lumpiasty.xyz/lumpiasty/supervisord:latest Docker digest to c7adeea
ci/woodpecker/push/build-images Pipeline was successful
2026-07-21 15:40:56 +00:00
Lumpiasty 87b6003b23 add ca-certificates to the supervisord image
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/build-images Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-21 17:33:00 +02:00
Renovate ef3b8a271e Update Helm release gitea to v12.7.0 2026-07-20 02:02:01 +00:00
Renovate f7b8cbb9aa Merge pull request 'Update kaneo to v2.9.8' (#376) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-20 02:01:50 +00:00
Renovate 4c21fcb5ff Update kaneo to v2.9.8 2026-07-20 02:01:39 +00:00
Renovate 3a7d2fbd10 Merge pull request 'Update kaneo to v2.9.7' (#375) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-19 02:01:46 +00:00
Renovate 9bdc88061f Update kaneo to v2.9.7 2026-07-19 02:01:41 +00:00
Renovate d6747ca3d5 Update Helm release k8up to v4.10.0 2026-07-18 14:22:11 +00:00
Renovate fffb888676 Merge pull request 'Update registry.k8s.io/coredns/coredns Docker tag to v1.14.6' (#373) from renovate/registry.k8s.io-coredns-coredns-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-18 14:22:04 +00:00
Renovate b4880ad3ff Update registry.k8s.io/coredns/coredns Docker tag to v1.14.6 2026-07-18 14:21:51 +00:00
Renovate fbde3d9faf Merge pull request 'Update kaneo to v2.9.5' (#372) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-18 14:21:50 +00:00
Renovate a8db4f4e4b Merge pull request 'Update Helm release cilium to v1.19.6' (#371) from renovate/cilium-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-18 14:21:46 +00:00
Renovate eae60867b8 Update kaneo to v2.9.5 2026-07-18 14:21:39 +00:00
Renovate 98a7c15e50 Update Helm release cilium to v1.19.6 2026-07-18 14:21:11 +00:00
Renovate ff5b4655b9 Merge pull request 'Update kaneo to v2.9.1' (#370) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-16 02:01:36 +00:00
Renovate ac7e12ec4e Merge pull request 'Update Helm release immich to v2.0.2' (#369) from renovate/immich-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-16 02:01:30 +00:00
Renovate 91e36289e6 Update kaneo to v2.9.1 2026-07-16 02:01:30 +00:00
Renovate 68ab235d06 Merge pull request 'Update Helm release authentik to v2026.5.5' (#368) from renovate/authentik-2026.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-16 02:01:25 +00:00
Renovate dfb1a5f8d2 Update Helm release immich to v2.0.2 2026-07-16 02:01:25 +00:00
Renovate 7489a0900a Update Helm release authentik to v2026.5.5 2026-07-16 02:01:19 +00:00
Renovate e32beb1002 Update debian Docker tag to v13.6
ci/woodpecker/push/build-images Pipeline is running
2026-07-15 02:01:37 +00:00
Renovate 2755d5e406 Merge pull request 'Update Helm release openbao to v0.28.5' (#364) from renovate/openbao-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-15 02:01:37 +00:00
Renovate 5f50a177a0 Update Helm release openbao to v0.28.5 2026-07-15 02:01:18 +00:00
Lumpiasty 847d7bfca7 update supervisord
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-14 21:59:54 +02:00
Lumpiasty cd59a087c7 add dependencies to supervisord
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/build-images Pipeline was successful
2026-07-14 21:53:01 +02:00
Renovate 0bee3a3ca7 Merge pull request 'Update Helm release cert-manager-webhook-ovh to v0.9.14' (#363) from renovate/cert-manager-webhook-ovh-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-14 02:02:02 +00:00
Renovate de0170ce8c Merge pull request 'Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.2' (#362) from renovate/ghcr.io-fluxcd-flux-cli-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-14 02:01:55 +00:00
Renovate 524c27a3ed Update Helm release cert-manager-webhook-ovh to v0.9.14 2026-07-14 02:01:54 +00:00
Renovate bcf3dbd63b Merge pull request 'Update dependency fluxcd/flux2 to v2.9.2' (#361) from renovate/fluxcd-flux2-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-14 02:01:50 +00:00
Renovate 0db6c52c1b Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.2 2026-07-14 02:01:50 +00:00
Renovate 381ba41c0f Update dependency fluxcd/flux2 to v2.9.2 2026-07-14 02:01:43 +00:00
Lumpiasty cf5eeccdae remove ffmpeg subpath mount
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-13 00:33:00 +02:00
Lumpiasty d8de1ec47b update supervisord image
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-13 00:30:55 +02:00
Lumpiasty 714d83eb86 add useful dependencies to supervisord
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/build-images Pipeline was successful
2026-07-13 00:26:40 +02:00
Lumpiasty bb7e358b25 move llama-swap workspace to /root
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-13 00:08:26 +02:00
Lumpiasty 806a6f38d4 add WORKSPACE env var to supervisord image
ci/woodpecker/push/build-images Pipeline was successful
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-13 00:06:08 +02:00
Lumpiasty 89d610886f Use correct arch image of supervisord
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-12 23:44:08 +02:00
Lumpiasty 5e566bd6b7 trigger images rebuild on ci changes
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/build-images Pipeline was successful
2026-07-12 23:41:46 +02:00
Lumpiasty dfbd89d4cf build correct arch supervisord
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-12 23:35:16 +02:00
Lumpiasty ea888c57fb use supervisord instead of gitops llama.cpp
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-12 23:32:47 +02:00
Lumpiasty 2d980550eb move coredns image under docker/
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/build-images Pipeline was successful
2026-07-12 23:14:19 +02:00
Lumpiasty ef6a2d4b46 make build-images ci job parallel
ci/woodpecker/push/flux-reconcile-source Pipeline was canceled
2026-07-12 23:08:07 +02:00
Lumpiasty 23c5b8e51a add supervisord image build
ci/woodpecker/push/flux-reconcile-source Pipeline was canceled
ci/woodpecker/push/build-images Pipeline was canceled
2026-07-12 23:03:27 +02:00
Renovate 0cb5e02099 Merge pull request 'Update Helm release immich to v2.0.1' (#359) from renovate/immich-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-12 20:49:17 +00:00
Renovate 5fe2bb7e06 Update ghcr.io/remsky/kokoro-fastapi-cpu Docker tag to v0.6.0 2026-07-12 20:49:16 +00:00
Renovate c5f9a0b2e2 Update Helm release immich to v2.0.1 2026-07-12 20:49:12 +00:00
Renovate 4b702f5323 Update Helm release cert-manager to v1.21.0 2026-07-09 02:01:17 +00:00
Renovate 1b2ec339f3 Merge pull request 'Update Helm release authentik to v2026.5.4' (#357) from renovate/authentik-2026.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-09 02:01:17 +00:00
Renovate af47861ff0 Update Helm release authentik to v2026.5.4 2026-07-09 02:01:11 +00:00
Renovate c02b794091 Merge pull request 'Update woodpeckerci/plugin-docker-buildx Docker tag to v6.1.1' (#356) from renovate/woodpeckerci-plugin-docker-buildx-6.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-08 02:01:56 +00:00
Renovate ad7fe9fa2a Merge pull request 'Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.1' (#355) from renovate/ghcr.io-fluxcd-flux-cli-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is pending
2026-07-08 02:01:50 +00:00
Renovate d660175bf3 Update woodpeckerci/plugin-docker-buildx Docker tag to v6.1.1 2026-07-08 02:01:50 +00:00
Renovate bf6b3361ea Merge pull request 'Update dependency fluxcd/flux2 to v2.9.1' (#354) from renovate/fluxcd-flux2-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is pending
2026-07-08 02:01:45 +00:00
Renovate ff0f6143db Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.1 2026-07-08 02:01:44 +00:00
Renovate 1bed69e6cf Update dependency fluxcd/flux2 to v2.9.1 2026-07-08 02:01:37 +00:00
Lumpiasty 82a5f98c0f add Qwythos LLM
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-07 21:56:10 +02:00
Lumpiasty c7b9f37fe0 update llama-swap image
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-07 00:01:37 +02:00
Lumpiasty 1390e482d2 Merge pull request 'Update Helm release cloudnative-pg to v0.29.0' (#346) from renovate/cloudnative-pg-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was canceled
ci/woodpecker/cron/renovate Pipeline was successful
Reviewed-on: #346
2026-07-04 21:05:33 +00:00
Lumpiasty f2643ef8a2 Merge pull request 'Update Helm release open-webui to v15' (#347) from renovate/open-webui-15.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was canceled
Reviewed-on: #347
2026-07-04 21:05:15 +00:00
Lumpiasty 0a9c5825db Merge pull request 'Update dependency fluxcd/flux2 to v2.9.0' (#348) from renovate/fluxcd-flux2-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #348
2026-07-04 21:03:02 +00:00
Lumpiasty e5ad95bbff Merge pull request 'Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.0' (#349) from renovate/ghcr.io-fluxcd-flux-cli-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was canceled
Reviewed-on: #349
2026-07-04 21:02:53 +00:00
Lumpiasty 4e56905d13 Merge pull request 'Update ghcr.io/usekaneo/kaneo Docker tag to v2.9.0' (#353) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #353
2026-07-04 20:52:32 +00:00
Renovate 4cdd24c700 Update ghcr.io/usekaneo/kaneo Docker tag to v2.9.0 2026-07-04 20:52:02 +00:00
Lumpiasty 4fd0f59dac add regex renovate manager to catch kaneo image
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-04 22:50:39 +02:00
Lumpiasty da023b5b13 Merge pull request 'Update Helm release valkey to v0.10.0' (#340) from renovate/valkey-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #340
2026-07-04 20:44:11 +00:00
Lumpiasty ad7dbcf267 Merge pull request 'Update dependency kaneo to v2.9.0' (#350) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #350
2026-07-04 20:35:58 +00:00
Lumpiasty 961dfd5e03 fix security issue of using default auth secret
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-07-04 22:28:37 +02:00
Lumpiasty 1680761f1f Merge pull request 'Update Helm release immich to v2' (#352) from renovate/immich-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
Reviewed-on: #352
2026-07-04 20:03:23 +00:00
Lumpiasty ae5917e7ee reduce renovate PR churn
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-04 22:00:00 +02:00
Renovate 56d74c84b1 Update Helm release immich to v2 2026-07-03 02:05:14 +00:00
Renovate 116f2fc8e2 Update Helm release open-webui to v15 2026-07-02 02:05:06 +00:00
Renovate 13765f7c2c Merge pull request 'Update Helm release vault-secrets-operator to v1.4.1' (#351) from renovate/vault-secrets-operator-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-07-02 02:01:08 +00:00
Renovate 0bc71af19e Update Helm release vault-secrets-operator to v1.4.1 2026-07-02 02:01:03 +00:00
Renovate bb84765e5e Update kaneo to v2.9.0 2026-07-01 02:01:41 +00:00
Renovate 0371891ba4 Update ghcr.io/fluxcd/flux-cli Docker tag to v2.9.0 2026-07-01 02:01:09 +00:00
Renovate 040358a169 Update dependency fluxcd/flux2 to v2.9.0 2026-07-01 02:01:04 +00:00
Renovate 39f675c5c9 Update Helm release cloudnative-pg to v0.29.0 2026-06-30 02:00:58 +00:00
Renovate 4891e8151d Merge pull request 'Update kaneo to v2.7.8' (#345) from renovate/kaneo into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-30 02:00:58 +00:00
Renovate 14163d3b06 Update kaneo to v2.7.8 2026-06-30 02:00:55 +00:00
Renovate 2e69373417 Merge pull request 'Update Helm release woodpecker to v3.6.5' (#343) from renovate/woodpecker-3.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is running
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-28 02:01:41 +00:00
Renovate 6738932ed4 Update Helm release woodpecker to v3.6.5 2026-06-28 02:01:36 +00:00
Renovate f50a4baa9a Merge pull request 'Update Helm release cert-manager to v1.20.3' (#342) from renovate/cert-manager-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline is running
2026-06-26 02:01:24 +00:00
Renovate 706966fca7 Update Helm release cert-manager to v1.20.3 2026-06-26 02:01:16 +00:00
Lumpiasty e3f11537a4 allow ts3 server query raw from internet
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-22 23:54:26 +02:00
Lumpiasty b336866044 Export ClusterIP services to router via BGP
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-06-22 15:57:27 +02:00
Lumpiasty a5464cf7a4 hide IoT WiFi and enable mac filter
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-06-22 15:19:57 +02:00
Renovate 6cec5c234b Merge pull request 'Update registry.k8s.io/coredns/coredns Docker tag to v1.14.4' (#341) from renovate/registry.k8s.io-coredns-coredns-1.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-21 02:01:27 +00:00
Renovate cdee1a0798 Update registry.k8s.io/coredns/coredns Docker tag to v1.14.4 2026-06-21 02:01:26 +00:00
Lumpiasty 4034628449 Fast fail connection when WAN failover
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-21 02:38:24 +02:00
Lumpiasty 1e86dc5e2b Detect GPON blackhole using ping
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
2026-06-21 02:00:32 +02:00
Renovate dbb1aeb62e Update Helm release valkey to v0.10.0 2026-06-19 02:01:13 +00:00
Renovate b1751ec427 Merge pull request 'Update Helm release openebs to v4.5.1' (#339) from renovate/openebs-4.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-19 02:01:13 +00:00
Renovate b9458c46bd Update Helm release openebs to v4.5.1 2026-06-19 02:01:09 +00:00
Renovate 6f73511e2b Merge pull request 'Update quay.io/openbao/openbao Docker tag to v2.5.5' (#338) from renovate/quay.io-openbao-openbao-2.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-18 02:01:32 +00:00
Renovate de1a31f98b Merge pull request 'Update Helm release openbao to v0.28.4' (#337) from renovate/openbao-0.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is pending
2026-06-18 02:01:25 +00:00
Renovate 319f1c3009 Update quay.io/openbao/openbao Docker tag to v2.5.5 2026-06-18 02:01:25 +00:00
Renovate c513c575d2 Update Helm release openbao to v0.28.4 2026-06-18 02:01:20 +00:00
Renovate 6f7c4c91b4 Merge pull request 'Update Helm release cilium to v1.19.5' (#336) from renovate/cilium-1.x into fresh-start
ci/woodpecker/cron/renovate Pipeline was successful
ci/woodpecker/push/flux-reconcile-source Pipeline failed
2026-06-17 02:01:25 +00:00
Renovate 4df35f496f Merge pull request 'Update alpine Docker tag to v3.24.1' (#335) from renovate/alpine-3.x into fresh-start
ci/woodpecker/push/flux-reconcile-source Pipeline is pending
2026-06-17 02:01:10 +00:00
Renovate 8214677d03 Update Helm release cilium to v1.19.5 2026-06-17 02:01:09 +00:00
Renovate a01ec90b06 Update alpine Docker tag to v3.24.1 2026-06-17 02:01:07 +00:00
Lumpiasty d10c3efe68 increase gitea storage size
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/cron/renovate Pipeline was successful
2026-06-16 23:25:21 +02:00
Lumpiasty ae7f58240c Merge pull request 'Update golang Docker tag to v1.26' (#331) from renovate/golang-1.x into fresh-start
ci/woodpecker/cron/renovate Pipeline was successful
ci/woodpecker/push/flux-reconcile-source Pipeline was successful
ci/woodpecker/push/coredns-build Pipeline was successful
Reviewed-on: #331
2026-06-15 23:08:36 +00:00
Renovate 60ba0cfe90 Update golang Docker tag to v1.26
ci/woodpecker/push/coredns-build Pipeline was successful
2026-06-13 02:01:21 +00:00
47 changed files with 658 additions and 1517 deletions
@@ -2,11 +2,12 @@ when:
- event: push - event: push
path: path:
include: include:
- mikrotik/coredns/** - docker/**
- .woodpecker/build-images.yaml
steps: steps:
- name: Get registry creds from OpenBao - name: Get registry creds from OpenBao
image: quay.io/openbao/openbao:2.5.4 image: quay.io/openbao/openbao:2.6.2
environment: environment:
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200 VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
ROLE_ID: ROLE_ID:
@@ -21,8 +22,8 @@ steps:
- 'printf "PLUGIN_USERNAME=%s\n" "$(bao kv get -mount secret -field REGISTRY_USERNAME container-registry)" > /woodpecker/registry.env' - 'printf "PLUGIN_USERNAME=%s\n" "$(bao kv get -mount secret -field REGISTRY_USERNAME container-registry)" > /woodpecker/registry.env'
- 'printf "PLUGIN_PASSWORD=%s\n" "$(bao kv get -mount secret -field REGISTRY_PASSWORD container-registry)" >> /woodpecker/registry.env' - 'printf "PLUGIN_PASSWORD=%s\n" "$(bao kv get -mount secret -field REGISTRY_PASSWORD container-registry)" >> /woodpecker/registry.env'
- name: Build and push - name: Build and push mikrotik coredns
image: woodpeckerci/plugin-docker-buildx:6.1.0 image: woodpeckerci/plugin-docker-buildx:6.1.1
privileged: true privileged: true
settings: settings:
registry: gitea.lumpiasty.xyz registry: gitea.lumpiasty.xyz
@@ -31,12 +32,32 @@ steps:
tags: tags:
- latest - latest
- ${CI_COMMIT_SHA:0:8} - ${CI_COMMIT_SHA:0:8}
dockerfile: mikrotik/coredns/Dockerfile dockerfile: docker/coredns/Dockerfile
context: mikrotik/coredns/ context: docker/coredns/
env_file: /woodpecker/registry.env env_file: /woodpecker/registry.env
cache_images:
- gitea.lumpiasty.xyz/lumpiasty/coredns-mikrotik:buildcache
depends_on: ["Get registry creds from OpenBao"]
- name: Build and push supervisord
image: woodpeckerci/plugin-docker-buildx:6.1.1
privileged: true
settings:
registry: gitea.lumpiasty.xyz
repo: gitea.lumpiasty.xyz/lumpiasty/supervisord
platforms: linux/amd64
tags:
- latest
- ${CI_COMMIT_SHA:0:8}
dockerfile: docker/supervisord/Dockerfile
context: docker/supervisord/
env_file: /woodpecker/registry.env
cache_images:
- gitea.lumpiasty.xyz/lumpiasty/supervisord:buildcache
depends_on: ["Get registry creds from OpenBao"]
- name: Invalidate OpenBao token - name: Invalidate OpenBao token
image: quay.io/openbao/openbao:2.5.4 image: quay.io/openbao/openbao:2.6.2
environment: environment:
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200 VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
commands: commands:
@@ -44,3 +65,6 @@ steps:
- bao write -f auth/token/revoke-self - bao write -f auth/token/revoke-self
when: when:
- status: [success, failure] - status: [success, failure]
depends_on:
- Build and push mikrotik coredns
- Build and push supervisord
+3 -3
View File
@@ -6,7 +6,7 @@ skip_clone: true
steps: steps:
- name: Get kubernetes access from OpenBao - name: Get kubernetes access from OpenBao
image: quay.io/openbao/openbao:2.5.4 image: quay.io/openbao/openbao:2.6.2
environment: environment:
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200 VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
ROLE_ID: ROLE_ID:
@@ -35,13 +35,13 @@ steps:
--namespace flux-system --namespace flux-system
- kubectl config use-context cluster - kubectl config use-context cluster
- name: Reconcile git source - name: Reconcile git source
image: ghcr.io/fluxcd/flux-cli:v2.8.8 image: ghcr.io/fluxcd/flux-cli:v2.9.5
environment: environment:
KUBECONFIG: /woodpecker/kubeconfig KUBECONFIG: /woodpecker/kubeconfig
commands: commands:
- flux reconcile source git flux-system - flux reconcile source git flux-system
- name: Invalidate OpenBao token - name: Invalidate OpenBao token
image: quay.io/openbao/openbao:2.5.4 image: quay.io/openbao/openbao:2.6.2
environment: environment:
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200 VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
commands: commands:
+4 -3
View File
@@ -6,7 +6,7 @@ skip_clone: true
steps: steps:
- name: Get renovate token from OpenBao - name: Get renovate token from OpenBao
image: quay.io/openbao/openbao:2.5.4 image: quay.io/openbao/openbao:2.6.2
environment: environment:
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200 VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
ROLE_ID: ROLE_ID:
@@ -21,7 +21,8 @@ steps:
- bao kv get -mount secret -field RENOVATE_TOKEN renovate > /woodpecker/renovate_token - bao kv get -mount secret -field RENOVATE_TOKEN renovate > /woodpecker/renovate_token
- bao kv get -mount secret -field GITHUB_COM_TOKEN renovate > /woodpecker/github_com_token - bao kv get -mount secret -field GITHUB_COM_TOKEN renovate > /woodpecker/github_com_token
- name: Run Renovate - name: Run Renovate
image: renovate/renovate:43.222.1 image: renovate/renovate:44
pull: true
environment: environment:
RENOVATE_AUTODISCOVER: "true" RENOVATE_AUTODISCOVER: "true"
RENOVATE_ENDPOINT: https://gitea.lumpiasty.xyz/api/v1 RENOVATE_ENDPOINT: https://gitea.lumpiasty.xyz/api/v1
@@ -34,7 +35,7 @@ steps:
- export GITHUB_COM_TOKEN=$(cat /woodpecker/github_com_token) - export GITHUB_COM_TOKEN=$(cat /woodpecker/github_com_token)
- /usr/local/sbin/renovate-entrypoint.sh renovate - /usr/local/sbin/renovate-entrypoint.sh renovate
- name: Invalidate OpenBao token - name: Invalidate OpenBao token
image: quay.io/openbao/openbao:2.5.4 image: quay.io/openbao/openbao:2.6.2
environment: environment:
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200 VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
commands: commands:
+6
View File
@@ -25,6 +25,12 @@
network: iot network: iot
mode: ap mode: ap
ssid: szafa ssid: szafa
hidden: '1' # Stop broadcasting SSID
macfilter: allow # Apply MAC filter allowing only specific addresses
maclist:
- 80:64:7c:99:21:20 # Thermomether
- C0:F8:53:89:E5:EF # Smart plug
- C0:F8:53:89:E3:42 # smart plug
encryption: psk2 encryption: psk2
key: "{{ openwrt_iot_wifi_password }}" key: "{{ openwrt_iot_wifi_password }}"
disabled: '0' disabled: '0'
+59
View File
@@ -1,8 +1,56 @@
--- ---
- name: Configure WAN connection marking
community.routeros.api_modify:
path: ip firewall mangle
data:
- action: mark-connection
chain: forward
connection-state: new
new-connection-mark: wan-gpon
out-interface: pppoe-gpon
passthrough: true
comment: Mark connections going out GPON
- action: mark-connection
chain: forward
connection-state: new
new-connection-mark: wan-lte
out-interface: vlan6
passthrough: true
comment: Mark connections going out LTE
handle_absent_entries: remove
handle_entries_content: remove_as_much_as_possible
ensure_order: true
- name: Configure IPv4 firewall filter rules - name: Configure IPv4 firewall filter rules
community.routeros.api_modify: community.routeros.api_modify:
path: ip firewall filter path: ip firewall filter
data: data:
- action: reject
chain: forward
connection-mark: wan-gpon
out-interface: vlan6
protocol: tcp
reject-with: tcp-reset
comment: Fast-fail TCP connections that shifted from GPON to LTE
- action: reject
chain: forward
connection-mark: wan-gpon
out-interface: vlan6
reject-with: icmp-network-unreachable
comment: Fast-fail non-TCP connections that shifted from GPON to LTE
- action: reject
chain: forward
connection-mark: wan-lte
out-interface: pppoe-gpon
protocol: tcp
reject-with: tcp-reset
comment: Fast-fail TCP connections that shifted from LTE to GPON
- action: reject
chain: forward
connection-mark: wan-lte
out-interface: pppoe-gpon
reject-with: icmp-network-unreachable
comment: Fast-fail non-TCP connections that shifted from LTE to GPON
- action: fasttrack-connection - action: fasttrack-connection
chain: forward chain: forward
connection-state: established,related connection-state: established,related
@@ -208,6 +256,11 @@
dst-port: 30033 dst-port: 30033
out-interface: vlan4 out-interface: vlan4
protocol: tcp protocol: tcp
- action: accept
chain: allow-ports
dst-port: 10011
out-interface: vlan4
protocol: tcp
- action: accept - action: accept
chain: allow-ports chain: allow-ports
comment: Allow HTTP comment: Allow HTTP
@@ -267,6 +320,12 @@
dst-port: 30033 dst-port: 30033
protocol: tcp protocol: tcp
to-addresses: 10.44.0.0 to-addresses: 10.44.0.0
- action: dst-nat
chain: dstnat
dst-address: 139.28.40.212
dst-port: 10011
protocol: tcp
to-addresses: 10.44.0.0
- action: src-nat - action: src-nat
chain: srcnat chain: srcnat
comment: src-nat from LAN to TS3 to some Greenland address comment: src-nat from LAN to TS3 to some Greenland address
+34 -4
View File
@@ -12,15 +12,44 @@
scope: 30 scope: 30
suppress-hw-offload: false suppress-hw-offload: false
target-scope: 10 target-scope: 10
- disabled: false - comment: GPON Monitor 1
disabled: false
distance: 1
dst-address: 1.0.0.1/32
gateway: pppoe-gpon
routing-table: main
scope: 10
suppress-hw-offload: false
target-scope: 10
- comment: GPON Monitor 2
disabled: false
distance: 1
dst-address: 8.8.4.4/32
gateway: pppoe-gpon
routing-table: main
scope: 10
suppress-hw-offload: false
target-scope: 10
- comment: GPON Default 1
disabled: false
distance: 1 distance: 1
dst-address: 0.0.0.0/0 dst-address: 0.0.0.0/0
gateway: pppoe-gpon gateway: 1.0.0.1
check-gateway: ping
routing-table: main routing-table: main
scope: 30 scope: 30
suppress-hw-offload: false suppress-hw-offload: false
target-scope: 10 target-scope: 11
vrf-interface: pppoe-gpon - comment: GPON Default 2
disabled: false
distance: 2
dst-address: 0.0.0.0/0
gateway: 8.8.4.4
check-gateway: ping
routing-table: main
scope: 30
suppress-hw-offload: false
target-scope: 11
handle_absent_entries: remove handle_absent_entries: remove
handle_entries_content: remove_as_much_as_possible handle_entries_content: remove_as_much_as_possible
@@ -32,6 +61,7 @@
distance: 1 distance: 1
dst-address: 2000::/3 dst-address: 2000::/3
gateway: 2001:470:70:dd::1 gateway: 2001:470:70:dd::1
check-gateway: ping
scope: 30 scope: 30
target-scope: 10 target-scope: 10
- comment: Tailnet - comment: Tailnet
+1
View File
@@ -10,6 +10,7 @@
password: "{{ routeros_pppoe_password }}" password: "{{ routeros_pppoe_password }}"
# Using CoreDNS container with DNS64 # Using CoreDNS container with DNS64
use-peer-dns: false use-peer-dns: false
add-default-route: false
user: "{{ routeros_pppoe_username }}" user: "{{ routeros_pppoe_username }}"
handle_absent_entries: remove handle_absent_entries: remove
handle_entries_content: remove_as_much_as_possible handle_entries_content: remove_as_much_as_possible
+1 -1
View File
@@ -18,7 +18,7 @@ spec:
chart: chart:
spec: spec:
chart: authentik chart: authentik
version: 2026.5.3 version: 2026.8.1
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: authentik name: authentik
+3 -3
View File
@@ -7,7 +7,7 @@ metadata:
name: gitea-shared-storage-lvmhdd name: gitea-shared-storage-lvmhdd
namespace: openebs namespace: openebs
spec: spec:
capacity: 10Gi capacity: "21474836480"
ownerNodeID: anapistula-delrosalae ownerNodeID: anapistula-delrosalae
shared: "yes" shared: "yes"
thinProvision: "no" thinProvision: "no"
@@ -20,7 +20,7 @@ metadata:
name: gitea-shared-storage-lvmhdd name: gitea-shared-storage-lvmhdd
spec: spec:
capacity: capacity:
storage: 10Gi storage: 20Gi
accessModes: accessModes:
- ReadWriteOnce - ReadWriteOnce
persistentVolumeReclaimPolicy: Retain persistentVolumeReclaimPolicy: Retain
@@ -41,6 +41,6 @@ spec:
- ReadWriteOnce - ReadWriteOnce
resources: resources:
requests: requests:
storage: 10Gi storage: 20Gi
storageClassName: hdd-lvmpv storageClassName: hdd-lvmpv
volumeName: gitea-shared-storage-lvmhdd volumeName: gitea-shared-storage-lvmhdd
+3 -1
View File
@@ -17,13 +17,15 @@ spec:
chart: chart:
spec: spec:
chart: gitea chart: gitea
version: 12.6.0 version: 12.7.0
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: gitea-charts name: gitea-charts
namespace: gitea namespace: gitea
interval: 12h interval: 12h
values: values:
image:
tag: 1.27.2 # REMOVE ME after new helm chart version includes this update
postgresql-ha: postgresql-ha:
enabled: false enabled: false
+3 -3
View File
@@ -7,7 +7,7 @@ metadata:
name: gitea-valkey-primary-lvmhdd-0 name: gitea-valkey-primary-lvmhdd-0
namespace: openebs namespace: openebs
spec: spec:
capacity: 1Gi capacity: "4294967296"
ownerNodeID: anapistula-delrosalae ownerNodeID: anapistula-delrosalae
shared: "yes" shared: "yes"
thinProvision: "no" thinProvision: "no"
@@ -20,7 +20,7 @@ metadata:
name: gitea-valkey-primary-lvmhdd-0 name: gitea-valkey-primary-lvmhdd-0
spec: spec:
capacity: capacity:
storage: 1Gi storage: 4Gi
accessModes: accessModes:
- ReadWriteOnce - ReadWriteOnce
persistentVolumeReclaimPolicy: Retain persistentVolumeReclaimPolicy: Retain
@@ -41,6 +41,6 @@ spec:
- ReadWriteOnce - ReadWriteOnce
resources: resources:
requests: requests:
storage: 1Gi storage: 4Gi
storageClassName: hdd-lvmpv storageClassName: hdd-lvmpv
volumeName: gitea-valkey-primary-lvmhdd-0 volumeName: gitea-valkey-primary-lvmhdd-0
+1 -1
View File
@@ -18,7 +18,7 @@ spec:
chart: chart:
spec: spec:
chart: valkey chart: valkey
version: 0.9.4 version: 0.11.0
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: valkey name: valkey
+1 -1
View File
@@ -18,7 +18,7 @@ spec:
chart: chart:
spec: spec:
chart: immich chart: immich
version: 1.2.6 version: 2.0.3
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: secustor name: secustor
+4
View File
@@ -15,6 +15,10 @@ spec:
protocol: TCP protocol: TCP
port: 30033 port: 30033
targetPort: 30033 targetPort: 30033
- name: rawquery
protocol: TCP
port: 10011
targetPort: 10011
type: LoadBalancer type: LoadBalancer
externalTrafficPolicy: Local externalTrafficPolicy: Local
ipFamilyPolicy: PreferDualStack ipFamilyPolicy: PreferDualStack
+23
View File
@@ -0,0 +1,23 @@
---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: kaneo-app-secret
namespace: kaneo
spec:
type: kv-v2
mount: secret
path: kaneo
destination:
create: true
name: kaneo-app-secret
type: Opaque
transformation:
excludeRaw: true
templates:
auth_secret:
text: '{{ get .Secrets "auth_secret" }}'
vaultAuthRef: kaneo
+1
View File
@@ -2,6 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- namespace.yaml - namespace.yaml
- app-secret.yaml
- oauth-secret.yaml - oauth-secret.yaml
- postgres-volume.yaml - postgres-volume.yaml
- postgres-cluster.yaml - postgres-cluster.yaml
+5 -3
View File
@@ -8,7 +8,7 @@ spec:
interval: 24h interval: 24h
url: https://github.com/usekaneo/kaneo.git url: https://github.com/usekaneo/kaneo.git
ref: ref:
tag: v2.7.7 tag: v2.22.0
ignore: | ignore: |
# exclude all # exclude all
/* /*
@@ -53,11 +53,13 @@ spec:
enabled: false enabled: false
kaneo: kaneo:
image:
tag: "2.7.3" # renovate: depName=ghcr.io/usekaneo/kaneo registryUrl=https://ghcr.io
env: env:
clientUrl: "https://kaneo.lumpiasty.xyz" clientUrl: "https://kaneo.lumpiasty.xyz"
disablePasswordRegistration: true disablePasswordRegistration: true
existingSecret:
enabled: true
name: kaneo-app-secret
key: auth_secret
database: database:
external: external:
enabled: true enabled: true
-444
View File
@@ -1,444 +0,0 @@
# yaml-language-server: $schema=https://raw.githubusercontent.com/mostlygeek/llama-swap/refs/heads/main/config-schema.json
healthCheckTimeout: 600
logToStdout: "both" # proxy and upstream
macros:
base_args: "--no-warmup --port ${PORT} --mlock --no-mmap"
common_args: "--fit-target 256 --no-warmup --port ${PORT} --no-mmap -tb 12 -t 6"
cpu_args: "--no-warmup --port ${PORT} -ngl 0"
ctx_64k: "--ctx-size 65536"
ctx_128k: "--ctx-size 131072"
ctx_256k: "--ctx-size 131072"
qwen35_think_args: "--temp 1.0 --top-p 0.95 --top-k 20 --min-p 0.00 -ctk q4_0 -ctv q4_0 --presence_penalty 1.5 --reasoning on"
qwen35_nothink_args: "--temp 0.7 --top-p 0.80 --top-k 20 --min-p 0.00 -ctk q4_0 -ctv q4_0 --presence_penalty 1.5 --reasoning off"
qwen35_35b_heretic_mmproj: "--mmproj-url https://huggingface.co/unsloth/Qwen3.5-35B-A3B-GGUF/resolve/main/mmproj-F16.gguf --mmproj /root/.cache/llama.cpp/unsloth_Qwen3.5-35B-A3B-GGUF_mmproj-F16.gguf"
qwen35_4b_heretic_mmproj: "--mmproj-url https://huggingface.co/unsloth/Qwen3.5-4B-GGUF/resolve/main/mmproj-F16.gguf --mmproj /root/.cache/llama.cpp/unsloth_Qwen3.5-4B-GGUF_mmproj-F16.gguf"
gemma4_sampling: "--temp 1.0 --top-p 0.95 --top-k 64 -ctk q4_0 -ctv q4_0"
gemma4_nothink_sampling: "--temp 1.0 --top-p 0.95 --top-k 64 -ctk q4_0 -ctv q4_0 --reasoning off"
hooks:
on_startup:
preload:
- "Qwen3.5-0.8B-GGUF-nothink:Q4_K_XL"
- "parakeet-tdt_ctc-1.1b"
# matrix replaces groups (they are mutually exclusive).
# The small 0.8B model runs alongside any LLM.
# FLUX runs alone — it needs all available VRAM and will evict the 0.8B first.
matrix:
vars:
q8: "Qwen3.5-0.8B-GGUF-nothink:Q4_K_XL"
stt: "parakeet-tdt_ctc-1.1b"
flux: "flux2-klein-4b:Q4_K_M"
coder: "Qwen3-Coder-Next-GGUF:Q4_K_M"
q35t: "Qwen3.5-35B-A3B-GGUF:Q4_K_M"
q35nt: "Qwen3.5-35B-A3B-GGUF-nothink:Q4_K_M"
q35ht: "Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M"
q35hnt: "Qwen3.5-35B-A3B-heretic-GGUF-nothink:Q4_K_M"
q4t: "Qwen3.5-4B-GGUF:Q4_K_M"
q4nt: "Qwen3.5-4B-GGUF-nothink:Q4_K_M"
q4ht: "Qwen3.5-4B-heretic-GGUF:Q4_K_M"
q4hnt: "Qwen3.5-4B-heretic-GGUF-nothink:Q4_K_M"
g26xl: "gemma-4-26B-A4B-it-qat:UD-Q4_K_XL"
g26xlnt: "gemma-4-26B-A4B-it-qat-nothink:UD-Q4_K_XL"
g26mtp: "gemma-4-26B-A4B-it-qat-mtp:UD-Q4_K_XL"
g26mtpnt: "gemma-4-26B-A4B-it-qat-mtp-nothink:UD-Q4_K_XL"
g26ht: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL"
g26hnt: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-nothink:UD-Q4_K_XL"
g26hmtp: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp:UD-Q4_K_XL"
g26hmnt: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp-nothink:UD-Q4_K_XL"
ge4qat: "unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL"
ge4qatnt: "unsloth/gemma-4-E4B-it-qat-GGUF-nothink:UD-Q4_K_XL"
ge2qat: "unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL"
ge2qatnt: "unsloth/gemma-4-E2B-it-qat-GGUF-nothink:UD-Q4_K_XL"
ge4mtp: "unsloth/gemma-4-E4B-it-qat-GGUF-mtp:UD-Q4_K_XL"
ge4mtpnt: "unsloth/gemma-4-E4B-it-qat-GGUF-mtp-nothink:UD-Q4_K_XL"
ge4ht: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M"
ge4hnt: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-nothink:Q4_K_M"
ge4hmtp: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp:Q4_K_M"
ge4hmnt: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp-nothink:Q4_K_M"
q36t: "unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL"
q36nt: "unsloth/Qwen3.6-35B-A3B-GGUF-nothink:UD-Q4_K_XL"
haut: "HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M"
haunt: "HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive-nothink:Q4_K_M"
mtpt: "unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M"
mtpnt: "unsloth/Qwen3.6-35B-A3B-MTP-GGUF-nothink:Q4_K_M"
evict_costs:
flux: 10 # large files, slow to reload
sets:
# any LLM can run alongside the small always-on model + STT + TTS (all CPU, no VRAM cost)
with_q8: "(coder | q35t | q35nt | q35ht | q35hnt | q4t | q4nt | q4ht | q4hnt | g26xl | g26xlnt | g26mtp | g26mtpnt | g26ht | g26hnt | g26hmtp | g26hmnt | ge4qat | ge4qatnt | ge2qat | ge2qatnt | ge4mtp | ge4mtpnt | ge4ht | ge4hnt | ge4hmtp | ge4hmnt | q36t | q36nt | haut | haunt | mtpt | mtpnt) & q8 & stt"
# FLUX runs alone — evicts everything including q8, but keeps STT for voice during image gen
image_gen: "flux & stt"
models:
"Qwen3-Coder-Next-GGUF:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3-Coder-Next-GGUF:Q4_K_M
--ctx-size 65536
--predict 8192
--temp 1.0
--min-p 0.01
--top-p 0.95
--top-k 40
--repeat-penalty 1.0
-ctk q4_0 -ctv q4_0
${common_args}
"Qwen3.5-35B-A3B-GGUF:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3.5-35B-A3B-GGUF:Q4_K_M
${ctx_256k}
${qwen35_think_args}
${common_args}
"Qwen3.5-35B-A3B-GGUF-nothink:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3.5-35B-A3B-GGUF:Q4_K_M
${ctx_256k}
${qwen35_nothink_args}
${common_args}
# The "heretic" version does not provide the mmproj
# so providing url to the one from the non-heretic version.
"Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M":
cmd: |
llama-server
-hf mradermacher/Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M
${qwen35_35b_heretic_mmproj}
${ctx_256k}
${qwen35_think_args}
${common_args}
"Qwen3.5-35B-A3B-heretic-GGUF-nothink:Q4_K_M":
cmd: |
llama-server
-hf mradermacher/Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M
${qwen35_35b_heretic_mmproj}
${ctx_256k}
${qwen35_nothink_args}
${common_args}
"Qwen3.5-0.8B-GGUF-nothink:Q4_K_XL":
cmd: |
llama-server
-hf unsloth/Qwen3.5-0.8B-GGUF:Q4_K_XL
--ctx-size 4096
${qwen35_nothink_args}
${base_args}
"Qwen3.5-4B-GGUF:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3.5-4B-GGUF:Q4_K_M
${ctx_128k}
${qwen35_think_args}
${common_args}
"Qwen3.5-4B-GGUF-nothink:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3.5-4B-GGUF:Q4_K_M
${ctx_128k}
${qwen35_nothink_args}
${common_args}
"Qwen3.5-4B-heretic-GGUF:Q4_K_M":
cmd: |
llama-server
-hf mradermacher/Qwen3.5-4B-heretic-GGUF:Q4_K_M
${qwen35_4b_heretic_mmproj}
${ctx_128k}
${qwen35_think_args}
${common_args}
"Qwen3.5-4B-heretic-GGUF-nothink:Q4_K_M":
cmd: |
llama-server
-hf mradermacher/Qwen3.5-4B-heretic-GGUF:Q4_K_M
${qwen35_4b_heretic_mmproj}
${ctx_128k}
${qwen35_nothink_args}
${common_args}
"gemma-4-26B-A4B-it-qat:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
${ctx_256k}
${gemma4_sampling}
${common_args}
"gemma-4-26B-A4B-it-qat-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
${ctx_256k}
${gemma4_nothink_sampling}
${common_args}
"gemma-4-26B-A4B-it-qat-mtp:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_256k}
${gemma4_sampling}
${common_args}
"gemma-4-26B-A4B-it-qat-mtp-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_256k}
${gemma4_nothink_sampling}
${common_args}
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL":
cmd: |
llama-server
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
${ctx_256k}
${gemma4_sampling}
${common_args}
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
${ctx_256k}
${gemma4_nothink_sampling}
${common_args}
# The heretic QAT repo does not ship an MTP drafter,
# so borrow the one from the non-heretic unsloth QAT repo.
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp:UD-Q4_K_XL":
cmd: |
llama-server
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_256k}
${gemma4_sampling}
${common_args}
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_256k}
${gemma4_nothink_sampling}
${common_args}
"unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
${ctx_128k}
${gemma4_sampling}
${common_args}
"unsloth/gemma-4-E4B-it-qat-GGUF-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
${ctx_128k}
${gemma4_nothink_sampling}
${common_args}
"unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL \
${ctx_128k}
${gemma4_sampling}
${common_args}
"unsloth/gemma-4-E2B-it-qat-GGUF-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL \
${ctx_128k}
${gemma4_nothink_sampling}
${common_args}
"unsloth/gemma-4-E4B-it-qat-GGUF-mtp:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_128k}
${gemma4_sampling}
${common_args}
"unsloth/gemma-4-E4B-it-qat-GGUF-mtp-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_128k}
${gemma4_nothink_sampling}
${common_args}
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M":
cmd: |
llama-server
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
${ctx_128k}
${gemma4_sampling}
${common_args}
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-nothink:Q4_K_M":
cmd: |
llama-server
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
${ctx_128k}
${gemma4_nothink_sampling}
${common_args}
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp:Q4_K_M":
cmd: |
llama-server
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_128k}
${gemma4_sampling}
${common_args}
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp-nothink:Q4_K_M":
cmd: |
llama-server
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
--spec-type draft-mtp
--spec-draft-n-max 1
--swa-full
--kv-unified
--parallel 1
${ctx_128k}
${gemma4_nothink_sampling}
${common_args}
"unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL
${ctx_256k}
${qwen35_think_args}
${common_args}
"unsloth/Qwen3.6-35B-A3B-GGUF-nothink:UD-Q4_K_XL":
cmd: |
llama-server
-hf unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL
${ctx_256k}
${qwen35_nothink_args}
${common_args}
"HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M":
cmd: |
llama-server
-hf HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M
${ctx_256k}
${qwen35_think_args}
${common_args}
"HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive-nothink:Q4_K_M":
cmd: |
llama-server
-hf HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M
${ctx_256k}
${qwen35_nothink_args}
${common_args}
"unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M
${ctx_256k}
${qwen35_think_args}
--spec-type draft-mtp --spec-draft-n-max 1
--parallel 1
${common_args}
"unsloth/Qwen3.6-35B-A3B-MTP-GGUF-nothink:Q4_K_M":
cmd: |
llama-server
-hf unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M
${ctx_256k}
${qwen35_nothink_args}
--spec-type draft-mtp --spec-draft-n-max 1
--parallel 1
${common_args}
# STT via parakeet-server (parakeet.cpp OpenAI-compatible server, CPU, always loaded)
# Model downloaded on first start and cached under /root/.cache/parakeet.cpp/models
# parakeet-proxy.py sits in front to convert any audio format to WAV via ffmpeg,
# since parakeet-server only accepts real WAV but browsers send Ogg/Opus.
"parakeet-tdt_ctc-1.1b":
checkEndpoint: none
cmd: |
env PROXY_PORT=${PORT} FFMPEG_BIN=/root/.cache/ffmpeg/ffmpeg python3 /config/parakeet-proxy.py
# Image generation via stable-diffusion.cpp (sd-server)
# Models must be pre-downloaded to /root/.cache/sd/
# FLUX.2-klein-4B: fast unified text-to-image and image editing model (Apache 2.0)
# Download: uv run --with huggingface_hub hf download unsloth/FLUX.2-klein-4B-GGUF flux-2-klein-4b-Q4_K_M.gguf --local-dir /root/.cache/sd
# Download VAE: uv run --with huggingface_hub hf download Comfy-Org/flux2-klein-4B split_files/vae/flux2-vae.safetensors --local-dir /root/.cache/sd/flux2-klein && cp /root/.cache/sd/flux2-klein/split_files/vae/flux2-vae.safetensors /root/.cache/sd/
# Download LLM: uv run --with huggingface_hub hf download ponpoke/flux2-klein-4b-uncensored-text-encoder flux2-klein-4b-uncensored-q4_k_m.gguf --local-dir /root/.cache/sd
"flux2-klein-4b:Q4_K_M":
checkEndpoint: "/"
cmd: |
sd-server
--listen-port ${PORT}
--diffusion-model /root/.cache/sd/flux-2-klein-4b-Q4_K_M.gguf
--vae /root/.cache/sd/flux2-vae.safetensors
--llm /root/.cache/sd/flux2-klein-4b-uncensored-q4_k_m.gguf
--cfg-scale 1.0
--sampling-method euler
--steps 4
--diffusion-fa
--offload-to-cpu
-227
View File
@@ -1,227 +0,0 @@
#!/usr/bin/env python3
"""
Thin reverse proxy for parakeet-server.
Accepts POST /v1/audio/transcriptions with any audio format,
converts the audio to 16 kHz mono WAV via ffmpeg, then forwards
the converted file to the real parakeet-server running on PARAKEET_PORT.
Also proxies GET /health straight through.
Usage:
PROXY_PORT=<port> PARAKEET_PORT=<upstream> python3 parakeet-proxy.py
"""
import http.server
import io
import os
import subprocess
import sys
import tempfile
import urllib.request
import urllib.error
PROXY_PORT = int(os.environ.get("PROXY_PORT", "8080"))
PARAKEET_PORT = PROXY_PORT + 1
FFMPEG = os.environ.get("FFMPEG_BIN", "ffmpeg")
MODEL = os.environ.get("PARAKEET_MODEL", "tdt_ctc-1.1b-q4_k.gguf")
CACHE_DIR = os.environ.get("PARAKEET_CACHE_DIR", "/root/.cache/parakeet.cpp/models")
def convert_to_wav(data: bytes) -> bytes:
"""Convert any audio bytes to 16 kHz mono PCM WAV via ffmpeg."""
with tempfile.NamedTemporaryFile(suffix=".input", delete=False) as inf:
inf.write(data)
inf_path = inf.name
out_path = inf_path + ".wav"
try:
subprocess.run(
[
FFMPEG, "-y",
"-i", inf_path,
"-ar", "16000",
"-ac", "1",
"-f", "wav",
out_path,
],
check=True,
stdout=subprocess.DEVNULL,
stderr=subprocess.DEVNULL,
)
with open(out_path, "rb") as f:
return f.read()
finally:
os.unlink(inf_path)
if os.path.exists(out_path):
os.unlink(out_path)
def parse_multipart(content_type: str, body: bytes):
"""
Parse a multipart/form-data body.
Returns a dict of field_name -> (filename_or_None, content_type, data).
"""
import email
from email import policy as email_policy
# email.parser needs the full MIME headers to parse multipart
raw = b"Content-Type: " + content_type.encode() + b"\r\n\r\n" + body
msg = email.message_from_bytes(raw, policy=email_policy.compat32)
parts = {}
for part in msg.get_payload():
cd = part.get("Content-Disposition", "")
name = None
filename = None
for item in cd.split(";"):
item = item.strip()
if item.startswith('name='):
name = item[5:].strip('"')
elif item.startswith('filename='):
filename = item[9:].strip('"')
if name is not None:
parts[name] = (filename, part.get_content_type(), part.get_payload(decode=True))
return parts
def build_multipart(fields: dict) -> tuple[bytes, str]:
"""
Build a multipart/form-data body from fields dict:
field_name -> (filename_or_None, content_type, data_bytes)
Returns (body_bytes, content_type_header_value).
"""
boundary = b"----ParakeetProxyBoundary0xDEADBEEF"
body = b""
for name, (filename, ct, data) in fields.items():
body += b"--" + boundary + b"\r\n"
if filename:
body += (
f'Content-Disposition: form-data; name="{name}"; filename="{filename}"\r\n'
).encode()
else:
body += f'Content-Disposition: form-data; name="{name}"\r\n'.encode()
body += f"Content-Type: {ct}\r\n\r\n".encode()
body += data + b"\r\n"
body += b"--" + boundary + b"--\r\n"
return body, f"multipart/form-data; boundary={boundary.decode()}"
class ProxyHandler(http.server.BaseHTTPRequestHandler):
def log_message(self, fmt, *args):
print(f"[parakeet-proxy] {self.address_string()} - {fmt % args}", flush=True)
def do_GET(self):
if self.path == "/health":
self._forward_get("/health")
else:
self.send_response(404)
self.end_headers()
def do_POST(self):
if self.path.rstrip("/") == "/v1/audio/transcriptions":
self._handle_transcription()
else:
self.send_response(404)
self.end_headers()
def _forward_get(self, path):
try:
url = f"http://127.0.0.1:{PARAKEET_PORT}{path}"
with urllib.request.urlopen(url, timeout=5) as resp:
body = resp.read()
self.send_response(resp.status)
self.send_header("Content-Type", resp.headers.get("Content-Type", "application/json"))
self.end_headers()
self.wfile.write(body)
except Exception as e:
self.send_response(502)
self.end_headers()
self.wfile.write(str(e).encode())
def _handle_transcription(self):
length = int(self.headers.get("Content-Length", 0))
body = self.rfile.read(length)
ct = self.headers.get("Content-Type", "")
try:
fields = parse_multipart(ct, body)
except Exception as e:
self._error(400, f"failed to parse multipart: {e}")
return
if "file" not in fields:
self._error(400, "missing required field 'file'")
return
filename, file_ct, audio_data = fields["file"]
# Convert to WAV regardless of what we received
try:
wav_data = convert_to_wav(audio_data)
except subprocess.CalledProcessError:
self._error(400, "ffmpeg could not decode audio")
return
except Exception as e:
self._error(500, f"conversion error: {e}")
return
# Rebuild multipart with converted WAV, preserve other fields
new_fields = {}
for name, (fn, fct, data) in fields.items():
if name == "file":
new_fields[name] = ("recording.wav", "audio/wav", wav_data)
else:
new_fields[name] = (fn, fct, data)
new_body, new_ct = build_multipart(new_fields)
# Forward to parakeet-server
try:
url = f"http://127.0.0.1:{PARAKEET_PORT}/v1/audio/transcriptions"
req = urllib.request.Request(
url,
data=new_body,
headers={"Content-Type": new_ct},
method="POST",
)
with urllib.request.urlopen(req, timeout=300) as resp:
resp_body = resp.read()
self.send_response(resp.status)
self.send_header("Content-Type", resp.headers.get("Content-Type", "application/json"))
self.end_headers()
self.wfile.write(resp_body)
except urllib.error.HTTPError as e:
resp_body = e.read()
self.send_response(e.code)
self.send_header("Content-Type", e.headers.get("Content-Type", "application/json"))
self.end_headers()
self.wfile.write(resp_body)
except Exception as e:
self._error(502, f"upstream error: {e}")
def _error(self, code: int, msg: str):
body = f'{{"error":{{"message":"{msg}","type":"proxy_error"}}}}'.encode()
self.send_response(code)
self.send_header("Content-Type", "application/json")
self.end_headers()
self.wfile.write(body)
if __name__ == "__main__":
proc = subprocess.Popen([
"parakeet-server",
"--host", "127.0.0.1",
"--port", str(PARAKEET_PORT),
"--model", MODEL,
"--cache-dir", CACHE_DIR,
])
print(f"[parakeet-proxy] started parakeet-server pid={proc.pid} on :{PARAKEET_PORT}", flush=True)
server = http.server.HTTPServer(("0.0.0.0", PROXY_PORT), ProxyHandler)
print(f"[parakeet-proxy] listening on :{PROXY_PORT}", flush=True)
try:
server.serve_forever()
except KeyboardInterrupt:
pass
finally:
proc.terminate()
proc.wait()
+7 -50
View File
@@ -2,7 +2,7 @@
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: llama-swap name: supervisord
namespace: llama namespace: llama
spec: spec:
replicas: 1 replicas: 1
@@ -16,64 +16,24 @@ spec:
labels: labels:
app: llama-swap app: llama-swap
spec: spec:
initContainers:
- name: download-whisper
image: gitea.lumpiasty.xyz/lumpiasty/llama-swap:unified-vulkan-parakeet-2026-06-12
command:
- sh
- -c
- |
mkdir -p /root/.cache/whisper
if [ ! -f /root/.cache/whisper/ggml-small.bin ]; then
echo "Downloading whisper-small model..."
curl -L -o /root/.cache/whisper/ggml-small.bin \
https://huggingface.co/ggerganov/whisper.cpp/resolve/main/ggml-small.bin
else
echo "whisper-small model already present, skipping download"
fi
if [ ! -f /root/.cache/ffmpeg/ffmpeg ]; then
echo "Downloading static ffmpeg..."
mkdir -p /root/.cache/ffmpeg
apt-get update -qq && apt-get install -y --no-install-recommends xz-utils
curl -L -o /root/.cache/ffmpeg/ffmpeg.tar.xz \
https://github.com/BtbN/FFmpeg-Builds/releases/download/latest/ffmpeg-master-latest-linux64-gpl.tar.xz
tar -xJf /root/.cache/ffmpeg/ffmpeg.tar.xz -C /root/.cache/ffmpeg --wildcards '*/ffmpeg' --strip-components=2
rm /root/.cache/ffmpeg/ffmpeg.tar.xz
chmod +x /root/.cache/ffmpeg/ffmpeg
else
echo "ffmpeg already present, skipping download"
fi
volumeMounts:
- name: models
mountPath: /root/.cache
containers: containers:
- name: llama-swap - name: supervisord
image: gitea.lumpiasty.xyz/lumpiasty/llama-swap:unified-vulkan-parakeet-2026-06-12 image: gitea.lumpiasty.xyz/lumpiasty/supervisord:latest@sha256:2676d13df2a0833b27ab8ec441da78c6c43d3f7bf75837d35723eefb40a82ce1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
command:
- llama-swap
args:
- --config=/config/config.yaml
- --watch-config
env:
- name: RADV_EXPERIMENTAL
value: transfer_queue
ports: ports:
- containerPort: 8080 - containerPort: 8080
name: http name: http
protocol: TCP protocol: TCP
env:
- name: WORKSPACE
value: /root
volumeMounts: volumeMounts:
- name: models - name: models
mountPath: /root/.cache mountPath: /root
- name: models
mountPath: /usr/local/bin/ffmpeg
subPath: ffmpeg/ffmpeg
- mountPath: /dev/kfd - mountPath: /dev/kfd
name: kfd name: kfd
- mountPath: /dev/dri - mountPath: /dev/dri
name: dri name: dri
- mountPath: /config
name: config
securityContext: securityContext:
privileged: true privileged: true
volumes: volumes:
@@ -88,9 +48,6 @@ spec:
hostPath: hostPath:
path: /dev/dri path: /dev/dri
type: Directory type: Directory
- name: config
configMap:
name: llama-swap
--- ---
apiVersion: v1 apiVersion: v1
kind: Service kind: Service
+1 -1
View File
@@ -21,7 +21,7 @@ spec:
# OpenAI-compatible Kokoro-FastAPI TTS server, CPU PyTorch backend. # OpenAI-compatible Kokoro-FastAPI TTS server, CPU PyTorch backend.
# Models baked into the image (no PVC needed). # Models baked into the image (no PVC needed).
# v0.3.0 includes fix for per-request voice tensor memory leak (#459). # v0.3.0 includes fix for per-request voice tensor memory leak (#459).
image: ghcr.io/remsky/kokoro-fastapi-cpu:v0.5.0 image: ghcr.io/remsky/kokoro-fastapi-cpu:v0.9.0
ports: ports:
- containerPort: 8880 - containerPort: 8880
name: http name: http
-6
View File
@@ -8,9 +8,3 @@ resources:
- pvc-ssd.yaml - pvc-ssd.yaml
- deployment.yaml - deployment.yaml
- kokoro.yaml - kokoro.yaml
configMapGenerator:
- name: llama-swap
namespace: llama
files:
- config.yaml=configs/config.yaml
- parakeet-proxy.py=configs/parakeet-proxy.py
+1 -1
View File
@@ -15,7 +15,7 @@ spec:
spec: spec:
initContainers: initContainers:
- name: prepare-home - name: prepare-home
image: alpine:3.24.0 image: alpine:3.24.1
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
command: command:
- /bin/sh - /bin/sh
+1 -1
View File
@@ -18,7 +18,7 @@ spec:
chart: chart:
spec: spec:
chart: open-webui chart: open-webui
version: 14.8.0 version: 16.5.0
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: open-webui name: open-webui
+1 -1
View File
@@ -18,7 +18,7 @@ spec:
chart: chart:
spec: spec:
chart: woodpecker chart: woodpecker
version: 3.6.4 version: 3.7.3
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: woodpecker name: woodpecker
File diff suppressed because it is too large Load Diff
@@ -1,5 +1,5 @@
# Stage 1: build CoreDNS with minimal plugin set # Stage 1: build CoreDNS with minimal plugin set
FROM golang:1.25-alpine AS build FROM golang:1.27-alpine AS build
RUN apk add --no-cache git make bash RUN apk add --no-cache git make bash
+15
View File
@@ -0,0 +1,15 @@
FROM debian:13.6
ENV DEBIAN_FRONTEND=noninteractive
RUN apt update && apt install -y --no-install-recommends\
curl wget vim \
ca-certificates \
build-essential cmake libvulkan-dev glslc spirv-headers libssl-dev git \
mesa-utils mesa-vulkan-drivers \
supervisor \
&& rm -rf /var/lib/apt/lists/*
ADD --chmod=755 entrypoint.sh /
ENTRYPOINT ["/entrypoint.sh"]
+8
View File
@@ -0,0 +1,8 @@
#!/usr/bin/env bash
WORKSPACE="${WORKSPACE:-/workspace}"
CONF=$WORKSPACE/supervisord.conf
[[ -f "$CONF" ]] || (echo_supervisord_conf > $CONF )
exec supervisord -n -c $CONF "$@"
+19 -7
View File
@@ -84,9 +84,10 @@ subnets would fail routing lookup with "net unreachable" without it.
| Destination | Source | Distance | Active when | | Destination | Source | Distance | Active when |
|---|---|---|---| |---|---|---|---|
| `0.0.0.0/0` | static via `pppoe-gpon` | 1 | GPON up | | `1.0.0.1/32`, `8.8.4.4/32` | static via `pppoe-gpon` | 1 | always |
| `0.0.0.0/0` | static via `1.0.0.1`, `8.8.4.4` (recursive) | 1, 2 | GPON ping check succeeds |
| `0.0.0.0/0` | BGP from D-Link via `192.168.6.2` | 200 | wwan up on D-Link | | `0.0.0.0/0` | BGP from D-Link via `192.168.6.2` | 200 | wwan up on D-Link |
| `2000::/3` | static via `sit1` (HE tunnel) | 1 | sit1 active (HE tunnel works) | | `2000::/3` | static via `2001:470:70:dd::1` (HE tunnel) | 1 | HE tunnel ping check succeeds |
| `2000::/3` | BGP from D-Link via `2001:470:61a3:600::2` | 200 | wwan up on D-Link | | `2000::/3` | BGP from D-Link via `2001:470:61a3:600::2` | 200 | wwan up on D-Link |
RouterOS distance comparison is straightforward: distance 1 always wins RouterOS distance comparison is straightforward: distance 1 always wins
@@ -136,11 +137,12 @@ preferred route for D-Link's own traffic.
- **wwan modem goes down** → BIRD2 device protocol detects wwan0 down → - **wwan modem goes down** → BIRD2 device protocol detects wwan0 down →
static `lte_default` / `lte_default6` become unreachable → BGP withdraws static `lte_default` / `lte_default6` become unreachable → BGP withdraws
announcements → CRS removes BGP-learned default announcements → CRS removes BGP-learned default
- **GPON drops** → `pppoe-gpon` interface down → CRS distance-1 default - **GPON drops or blackholes** → recursive ping checks (1.0.0.1, 8.8.4.4) over `pppoe-gpon`
route inactive → distance-200 BGP route activates → CRS withdraws its fail (takes ~20s: 10s ping interval + 10s timeout) → CRS distance-1/2 default routes inactive → distance-200 BGP route
default-originate announcement to D-Link (since no default is installed activates → CRS withdraws its default-originate announcement to D-Link (loop
any more) → D-Link's kernel default-via-CRS is removed → D-Link uses prevention prevents reflecting D-Link's own route) → D-Link's kernel
wwan kernel default → traffic flows from CRS via vlan6 → D-Link → wwan default-via-CRS is removed → D-Link uses wwan kernel default → traffic flows
from CRS via vlan6 → D-Link → wwan
All transitions are automatic and driven by interface state. No active All transitions are automatic and driven by interface state. No active
probing (Netwatch / mwan3), no scripts toggling routes. probing (Netwatch / mwan3), no scripts toggling routes.
@@ -241,6 +243,16 @@ QMI initialization within ~1 second.
Full investigation: see [wwan-bm806c-qmi-workaround.md](./wwan-bm806c-qmi-workaround.md). Full investigation: see [wwan-bm806c-qmi-workaround.md](./wwan-bm806c-qmi-workaround.md).
## Multi-WAN Stale Connection Tracking
When the routing table fails over from GPON to LTE (or vice versa), RouterOS does not automatically clear existing connection tracking entries. If an established TCP/UDP connection is routed out the new WAN interface, it retains the NAT translation state (source IP) of the old WAN interface. The packet is sent to the ISP with the wrong source IP and is silently dropped, causing clients (like Tailscale) to hang for minutes until their internal sockets time out.
To solve this purely declaratively without scripts or blanket connection flushes, the `forward` chain is configured to "fast-fail" these shifted connections:
1. Connections are marked with their egress WAN upon establishment (`wan-gpon` or `wan-lte`) via the `mangle` table.
2. If an established connection with a `wan-gpon` mark attempts to route out `vlan6` (LTE), or a `wan-lte` mark routes out `pppoe-gpon`, it is explicitly rejected (`tcp-reset` for TCP, `icmp-network-unreachable` for UDP) before reaching the NAT table.
3. This rejection immediately signals the client OS that the route is dead, forcing the application (Tailscale, SIP clients, etc.) to instantly close the socket and establish a new one, which successfully binds to the new WAN interface and NAT state.
## Implementation files ## Implementation files
| File | Role | | File | Role |
+1 -1
View File
@@ -50,7 +50,7 @@ Network is divided to multiple VLANs to enforce strict access control rules usin
Internet access only<br> Internet access only<br>
IP: 192.168.5.0/24 / 2001:470:61a3:a::/64<br> IP: 192.168.5.0/24 / 2001:470:61a3:a::/64<br>
Gateway: 192.168.5.1 / 2001:470:61a3:a:ffff:ffff:ffff:ffff<br> Gateway: 192.168.5.1 / 2001:470:61a3:a:ffff:ffff:ffff:ffff<br>
DHCP / SLAAC, accessible via separate WiFi network "szafa" from D-Link for absolutely untrusted Tuya and like devices DHCP / SLAAC, accessible via separate, hidden WiFi network "szafa" from D-Link with strict MAC filtering for absolutely untrusted Tuya and like devices
- 6: Internet access for OpenWRT<br> - 6: Internet access for OpenWRT<br>
Internet access only<br> Internet access only<br>
IP: 192.168.6.0/24 / 2001:470:61a3:600::/64<br> IP: 192.168.6.0/24 / 2001:470:61a3:600::/64<br>
+1
View File
@@ -56,6 +56,7 @@ spec:
addresses: addresses:
# Not advertising ClusterIP - kubeproxyreplacement should? translate them directly to pod ips # Not advertising ClusterIP - kubeproxyreplacement should? translate them directly to pod ips
# Not advertising ExternalIP - they should be reachable via static config # Not advertising ExternalIP - they should be reachable via static config
- ClusterIP
- LoadBalancerIP - LoadBalancerIP
selector: selector:
matchExpressions: matchExpressions:
@@ -18,7 +18,7 @@ spec:
chart: chart:
spec: spec:
chart: cert-manager-webhook-ovh chart: cert-manager-webhook-ovh
version: 0.9.13 version: 0.9.16
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: cert-manager-webhook-ovh name: cert-manager-webhook-ovh
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: cert-manager chart: cert-manager
version: v1.20.2 version: v1.21.1
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: cert-manager name: cert-manager
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: cilium chart: cilium
version: 1.19.4 version: 1.20.1
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: cilium name: cilium
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: cloudnative-pg chart: cloudnative-pg
version: 0.28.3 version: 0.29.0
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: cnpg name: cnpg
+1 -1
View File
@@ -110,7 +110,7 @@ spec:
kubernetes.io/os: linux kubernetes.io/os: linux
containers: containers:
- name: coredns - name: coredns
image: registry.k8s.io/coredns/coredns:v1.14.3 image: registry.k8s.io/coredns/coredns:v1.14.7
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
args: ["-conf", "/etc/coredns/Corefile"] args: ["-conf", "/etc/coredns/Corefile"]
ports: ports:
+1 -1
View File
@@ -97,7 +97,7 @@ spec:
env: env:
- name: GOMEMLIMIT - name: GOMEMLIMIT
value: 161MiB value: 161MiB
image: registry.k8s.io/coredns/coredns:v1.14.3 image: registry.k8s.io/coredns/coredns:v1.14.7
imagePullPolicy: IfNotPresent imagePullPolicy: IfNotPresent
livenessProbe: livenessProbe:
failureThreshold: 5 failureThreshold: 5
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: k8up chart: k8up
version: 4.9.0 version: 4.10.0
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: k8up-io name: k8up-io
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: openbao chart: openbao
version: 0.28.3 version: 0.29.4
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: openbao name: openbao
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: openebs chart: openebs
version: 4.5.0 version: 4.5.1
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: openebs name: openebs
@@ -23,7 +23,7 @@ spec:
chart: chart:
spec: spec:
chart: vault-secrets-operator chart: vault-secrets-operator
version: 1.4.0 version: 1.5.1
sourceRef: sourceRef:
kind: HelmRepository kind: HelmRepository
name: hashicorp name: hashicorp
+13 -1
View File
@@ -11,6 +11,18 @@
] ]
}, },
"prHourlyLimit": 9, "prHourlyLimit": 9,
"customManagers": [
{
"customType": "regex",
"fileMatch": [
"apps/.+\\.yaml$"
],
"matchStrings": [
"tag:\\s*[\"']?(?<currentValue>[^\"' \\n]+)[\"']?\\s*#\\s*renovate:\\s*(?:datasource=(?<datasource>[^\\s]+)\\s+)?depName=(?<depName>[^\\s]+)(?:\\s+registryUrl=(?<registryUrl>[^\\s]+))?"
],
"datasourceTemplate": "{{#if datasource}}{{{datasource}}}{{else}}docker{{/if}}"
}
],
"packageRules": [ "packageRules": [
{ {
"matchPackageNames": ["usekaneo/kaneo", "ghcr.io/usekaneo/kaneo"], "matchPackageNames": ["usekaneo/kaneo", "ghcr.io/usekaneo/kaneo"],
@@ -25,7 +37,7 @@
"platformAutomerge": true "platformAutomerge": true
}, },
{ {
"matchUpdateTypes": ["patch"], "matchUpdateTypes": ["patch", "digest"],
"automerge": true, "automerge": true,
"automergeType": "pr", "automergeType": "pr",
"platformAutomerge": true "platformAutomerge": true
@@ -28,3 +28,4 @@ machine:
# arrives too late. Work around using kernel args: # arrives too late. Work around using kernel args:
extraKernelArgs: extraKernelArgs:
- amdgpu.runpm=1 - amdgpu.runpm=1
- amdgpu.lockup_timeout=0,120000,0,0
+4
View File
@@ -1,3 +1,7 @@
path "secret/data/authentik/kaneo" { path "secret/data/authentik/kaneo" {
capabilities = ["read"] capabilities = ["read"]
} }
path "secret/data/kaneo" {
capabilities = ["read"]
}