Compare commits
207
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
874dc11927 | ||
|
|
e9c8100f53 | ||
|
|
00082171a3 | ||
|
|
aa681fc963 | ||
|
|
32b71be47a | ||
|
|
76da17f808 | ||
|
|
5eeab70a99 | ||
|
|
4f5de9294c | ||
|
|
2e18084008 | ||
|
|
ee9e7f1905 | ||
|
|
6ebfdeb989 | ||
|
|
923b37e171 | ||
|
|
ef2e7987f0 | ||
|
|
9ce13dc207 | ||
|
|
9985851e82 | ||
|
|
598330097f | ||
|
|
d4293e4e29 | ||
|
|
a800b218c4 | ||
|
|
056d762dc9 | ||
|
|
e3dfba7170 | ||
|
|
928f3d1005 | ||
|
|
0d81ee473f | ||
|
|
4fb53636f1 | ||
|
|
6241b81f02 | ||
|
|
5b8833325d | ||
|
|
ed3da857d5 | ||
|
|
f3cc1f3688 | ||
|
|
de8bb69cdc | ||
|
|
ea29623106 | ||
|
|
b0cbe885a5 | ||
|
|
2ade45b3dc | ||
|
|
4af96d3c5d | ||
|
|
0f557f8c09
|
||
|
|
6ff0796946 | ||
|
|
851a2096e3 | ||
|
|
e1ef81db71 | ||
|
|
c64e6e73f9 | ||
|
|
cf021a776d | ||
|
|
29d9cfbcbf | ||
|
|
255b29fb6c | ||
|
|
7d0ece3fb1 | ||
|
|
bb391b641f | ||
|
|
0990af576e | ||
|
|
7d3d036912 | ||
|
|
d31e792530 | ||
|
|
96ef9a9925 | ||
|
|
1b6b8eee16
|
||
|
|
aa7842a5d5 | ||
|
|
7d6158af20 | ||
|
|
fd2afb45f5 | ||
|
|
1073ee27e1 | ||
|
|
29f1f31bd0 | ||
|
|
304235ccd6 | ||
|
|
9705084504 | ||
|
|
2c3db3c0a2 | ||
|
|
fe391afe1a
|
||
|
|
e69f3ce4ae | ||
|
|
39cb9626fe
|
||
|
|
c1eadb29d1 | ||
|
|
9d8cda8228
|
||
|
|
ba90001ec8
|
||
|
|
ece05f6119 | ||
|
|
129279192a | ||
|
|
a703b8ef4c | ||
|
|
33d30a1f6a | ||
|
|
d3e794233b | ||
|
|
3f2e7bff23 | ||
|
|
1f6e7f6d06 | ||
|
|
27a07fb5d9 | ||
|
|
0790de0fdf | ||
|
|
0261f900d7 | ||
|
|
b3135998f6 | ||
|
|
aff867b774
|
||
|
|
4c31107f8c | ||
|
|
6b15082274 | ||
|
|
94d7817a07
|
||
|
|
63e502735c | ||
|
|
2b687712cb | ||
|
|
c7ceb45ba1 | ||
|
|
bd33268bc0 | ||
|
|
c4143d95fc | ||
|
|
146a251669 | ||
|
|
3400bcc421 | ||
|
|
45365dd01f | ||
|
|
8e84550bfb | ||
|
|
ed4e59dac1 | ||
|
|
2aca37a14c | ||
|
|
d86ad8e56a | ||
|
|
81518b132a | ||
|
|
0ba8aa2889 | ||
|
|
c2cde1836c | ||
|
|
3b957ca449 | ||
|
|
c748950996 | ||
|
|
7fecb4e456 | ||
|
|
c0729a67bd | ||
|
|
b423498c41 | ||
|
|
26585e64ae | ||
|
|
41147dc02f | ||
|
|
d4931833f0 | ||
|
|
6524a14745
|
||
|
|
858e121c55 | ||
|
|
edd56e84d7 | ||
|
|
87b6003b23
|
||
|
|
ef3b8a271e | ||
|
|
f7b8cbb9aa | ||
|
|
4c21fcb5ff | ||
|
|
3a7d2fbd10 | ||
|
|
9bdc88061f | ||
|
|
d6747ca3d5 | ||
|
|
fffb888676 | ||
|
|
b4880ad3ff | ||
|
|
fbde3d9faf | ||
|
|
a8db4f4e4b | ||
|
|
eae60867b8 | ||
|
|
98a7c15e50 | ||
|
|
ff5b4655b9 | ||
|
|
ac7e12ec4e | ||
|
|
91e36289e6 | ||
|
|
68ab235d06 | ||
|
|
dfb1a5f8d2 | ||
|
|
7489a0900a | ||
|
|
e32beb1002 | ||
|
|
2755d5e406 | ||
|
|
5f50a177a0 | ||
|
|
847d7bfca7
|
||
|
|
cd59a087c7
|
||
|
|
0bee3a3ca7 | ||
|
|
de0170ce8c | ||
|
|
524c27a3ed | ||
|
|
bcf3dbd63b | ||
|
|
0db6c52c1b | ||
|
|
381ba41c0f | ||
|
|
cf5eeccdae
|
||
|
|
d8de1ec47b
|
||
|
|
714d83eb86
|
||
|
|
bb7e358b25
|
||
|
|
806a6f38d4
|
||
|
|
89d610886f
|
||
|
|
5e566bd6b7
|
||
|
|
dfbd89d4cf
|
||
|
|
ea888c57fb
|
||
|
|
2d980550eb
|
||
|
|
ef6a2d4b46
|
||
|
|
23c5b8e51a
|
||
|
|
0cb5e02099 | ||
|
|
5fe2bb7e06 | ||
|
|
c5f9a0b2e2 | ||
|
|
4b702f5323 | ||
|
|
1b2ec339f3 | ||
|
|
af47861ff0 | ||
|
|
c02b794091 | ||
|
|
ad7fe9fa2a | ||
|
|
d660175bf3 | ||
|
|
bf6b3361ea | ||
|
|
ff0f6143db | ||
|
|
1bed69e6cf | ||
|
|
82a5f98c0f
|
||
|
|
c7b9f37fe0
|
||
|
|
1390e482d2 | ||
|
|
f2643ef8a2 | ||
|
|
0a9c5825db | ||
|
|
e5ad95bbff | ||
|
|
4e56905d13 | ||
|
|
4cdd24c700 | ||
|
|
4fd0f59dac
|
||
|
|
da023b5b13 | ||
|
|
ad7dbcf267 | ||
|
|
961dfd5e03
|
||
|
|
1680761f1f | ||
|
|
ae5917e7ee
|
||
|
|
56d74c84b1 | ||
|
|
116f2fc8e2 | ||
|
|
13765f7c2c | ||
|
|
0bc71af19e | ||
|
|
bb84765e5e | ||
|
|
0371891ba4 | ||
|
|
040358a169 | ||
|
|
39f675c5c9 | ||
|
|
4891e8151d | ||
|
|
14163d3b06 | ||
|
|
2e69373417 | ||
|
|
6738932ed4 | ||
|
|
f50a4baa9a | ||
|
|
706966fca7 | ||
|
|
e3f11537a4
|
||
|
|
b336866044
|
||
|
|
a5464cf7a4
|
||
|
|
6cec5c234b | ||
|
|
cdee1a0798 | ||
|
|
4034628449
|
||
|
|
1e86dc5e2b
|
||
|
|
dbb1aeb62e | ||
|
|
b1751ec427 | ||
|
|
b9458c46bd | ||
|
|
6f73511e2b | ||
|
|
de1a31f98b | ||
|
|
319f1c3009 | ||
|
|
c513c575d2 | ||
|
|
6f7c4c91b4 | ||
|
|
4df35f496f | ||
|
|
8214677d03 | ||
|
|
a01ec90b06 | ||
|
|
d10c3efe68
|
||
|
|
ae7f58240c | ||
|
|
9f5d45d515 | ||
|
|
de10cba76c | ||
|
|
60ba0cfe90 |
@@ -2,11 +2,12 @@ when:
|
|||||||
- event: push
|
- event: push
|
||||||
path:
|
path:
|
||||||
include:
|
include:
|
||||||
- mikrotik/coredns/**
|
- docker/**
|
||||||
|
- .woodpecker/build-images.yaml
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Get registry creds from OpenBao
|
- name: Get registry creds from OpenBao
|
||||||
image: quay.io/openbao/openbao:2.5.4
|
image: quay.io/openbao/openbao:2.6.2
|
||||||
environment:
|
environment:
|
||||||
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
||||||
ROLE_ID:
|
ROLE_ID:
|
||||||
@@ -21,8 +22,8 @@ steps:
|
|||||||
- 'printf "PLUGIN_USERNAME=%s\n" "$(bao kv get -mount secret -field REGISTRY_USERNAME container-registry)" > /woodpecker/registry.env'
|
- 'printf "PLUGIN_USERNAME=%s\n" "$(bao kv get -mount secret -field REGISTRY_USERNAME container-registry)" > /woodpecker/registry.env'
|
||||||
- 'printf "PLUGIN_PASSWORD=%s\n" "$(bao kv get -mount secret -field REGISTRY_PASSWORD container-registry)" >> /woodpecker/registry.env'
|
- 'printf "PLUGIN_PASSWORD=%s\n" "$(bao kv get -mount secret -field REGISTRY_PASSWORD container-registry)" >> /woodpecker/registry.env'
|
||||||
|
|
||||||
- name: Build and push
|
- name: Build and push mikrotik coredns
|
||||||
image: woodpeckerci/plugin-docker-buildx:6.1.0
|
image: woodpeckerci/plugin-docker-buildx:6.1.1
|
||||||
privileged: true
|
privileged: true
|
||||||
settings:
|
settings:
|
||||||
registry: gitea.lumpiasty.xyz
|
registry: gitea.lumpiasty.xyz
|
||||||
@@ -31,12 +32,32 @@ steps:
|
|||||||
tags:
|
tags:
|
||||||
- latest
|
- latest
|
||||||
- ${CI_COMMIT_SHA:0:8}
|
- ${CI_COMMIT_SHA:0:8}
|
||||||
dockerfile: mikrotik/coredns/Dockerfile
|
dockerfile: docker/coredns/Dockerfile
|
||||||
context: mikrotik/coredns/
|
context: docker/coredns/
|
||||||
env_file: /woodpecker/registry.env
|
env_file: /woodpecker/registry.env
|
||||||
|
cache_images:
|
||||||
|
- gitea.lumpiasty.xyz/lumpiasty/coredns-mikrotik:buildcache
|
||||||
|
depends_on: ["Get registry creds from OpenBao"]
|
||||||
|
|
||||||
|
- name: Build and push supervisord
|
||||||
|
image: woodpeckerci/plugin-docker-buildx:6.1.1
|
||||||
|
privileged: true
|
||||||
|
settings:
|
||||||
|
registry: gitea.lumpiasty.xyz
|
||||||
|
repo: gitea.lumpiasty.xyz/lumpiasty/supervisord
|
||||||
|
platforms: linux/amd64
|
||||||
|
tags:
|
||||||
|
- latest
|
||||||
|
- ${CI_COMMIT_SHA:0:8}
|
||||||
|
dockerfile: docker/supervisord/Dockerfile
|
||||||
|
context: docker/supervisord/
|
||||||
|
env_file: /woodpecker/registry.env
|
||||||
|
cache_images:
|
||||||
|
- gitea.lumpiasty.xyz/lumpiasty/supervisord:buildcache
|
||||||
|
depends_on: ["Get registry creds from OpenBao"]
|
||||||
|
|
||||||
- name: Invalidate OpenBao token
|
- name: Invalidate OpenBao token
|
||||||
image: quay.io/openbao/openbao:2.5.4
|
image: quay.io/openbao/openbao:2.6.2
|
||||||
environment:
|
environment:
|
||||||
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
||||||
commands:
|
commands:
|
||||||
@@ -44,3 +65,6 @@ steps:
|
|||||||
- bao write -f auth/token/revoke-self
|
- bao write -f auth/token/revoke-self
|
||||||
when:
|
when:
|
||||||
- status: [success, failure]
|
- status: [success, failure]
|
||||||
|
depends_on:
|
||||||
|
- Build and push mikrotik coredns
|
||||||
|
- Build and push supervisord
|
||||||
@@ -6,7 +6,7 @@ skip_clone: true
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Get kubernetes access from OpenBao
|
- name: Get kubernetes access from OpenBao
|
||||||
image: quay.io/openbao/openbao:2.5.4
|
image: quay.io/openbao/openbao:2.6.2
|
||||||
environment:
|
environment:
|
||||||
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
||||||
ROLE_ID:
|
ROLE_ID:
|
||||||
@@ -35,13 +35,13 @@ steps:
|
|||||||
--namespace flux-system
|
--namespace flux-system
|
||||||
- kubectl config use-context cluster
|
- kubectl config use-context cluster
|
||||||
- name: Reconcile git source
|
- name: Reconcile git source
|
||||||
image: ghcr.io/fluxcd/flux-cli:v2.8.8
|
image: ghcr.io/fluxcd/flux-cli:v2.9.5
|
||||||
environment:
|
environment:
|
||||||
KUBECONFIG: /woodpecker/kubeconfig
|
KUBECONFIG: /woodpecker/kubeconfig
|
||||||
commands:
|
commands:
|
||||||
- flux reconcile source git flux-system
|
- flux reconcile source git flux-system
|
||||||
- name: Invalidate OpenBao token
|
- name: Invalidate OpenBao token
|
||||||
image: quay.io/openbao/openbao:2.5.4
|
image: quay.io/openbao/openbao:2.6.2
|
||||||
environment:
|
environment:
|
||||||
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
||||||
commands:
|
commands:
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ skip_clone: true
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Get renovate token from OpenBao
|
- name: Get renovate token from OpenBao
|
||||||
image: quay.io/openbao/openbao:2.5.4
|
image: quay.io/openbao/openbao:2.6.2
|
||||||
environment:
|
environment:
|
||||||
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
||||||
ROLE_ID:
|
ROLE_ID:
|
||||||
@@ -21,7 +21,8 @@ steps:
|
|||||||
- bao kv get -mount secret -field RENOVATE_TOKEN renovate > /woodpecker/renovate_token
|
- bao kv get -mount secret -field RENOVATE_TOKEN renovate > /woodpecker/renovate_token
|
||||||
- bao kv get -mount secret -field GITHUB_COM_TOKEN renovate > /woodpecker/github_com_token
|
- bao kv get -mount secret -field GITHUB_COM_TOKEN renovate > /woodpecker/github_com_token
|
||||||
- name: Run Renovate
|
- name: Run Renovate
|
||||||
image: renovate/renovate:43.220.0
|
image: renovate/renovate:44
|
||||||
|
pull: true
|
||||||
environment:
|
environment:
|
||||||
RENOVATE_AUTODISCOVER: "true"
|
RENOVATE_AUTODISCOVER: "true"
|
||||||
RENOVATE_ENDPOINT: https://gitea.lumpiasty.xyz/api/v1
|
RENOVATE_ENDPOINT: https://gitea.lumpiasty.xyz/api/v1
|
||||||
@@ -34,7 +35,7 @@ steps:
|
|||||||
- export GITHUB_COM_TOKEN=$(cat /woodpecker/github_com_token)
|
- export GITHUB_COM_TOKEN=$(cat /woodpecker/github_com_token)
|
||||||
- /usr/local/sbin/renovate-entrypoint.sh renovate
|
- /usr/local/sbin/renovate-entrypoint.sh renovate
|
||||||
- name: Invalidate OpenBao token
|
- name: Invalidate OpenBao token
|
||||||
image: quay.io/openbao/openbao:2.5.4
|
image: quay.io/openbao/openbao:2.6.2
|
||||||
environment:
|
environment:
|
||||||
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
VAULT_ADDR: https://openbao.lumpiasty.xyz:8200
|
||||||
commands:
|
commands:
|
||||||
|
|||||||
@@ -25,6 +25,12 @@
|
|||||||
network: iot
|
network: iot
|
||||||
mode: ap
|
mode: ap
|
||||||
ssid: szafa
|
ssid: szafa
|
||||||
|
hidden: '1' # Stop broadcasting SSID
|
||||||
|
macfilter: allow # Apply MAC filter allowing only specific addresses
|
||||||
|
maclist:
|
||||||
|
- 80:64:7c:99:21:20 # Thermomether
|
||||||
|
- C0:F8:53:89:E5:EF # Smart plug
|
||||||
|
- C0:F8:53:89:E3:42 # smart plug
|
||||||
encryption: psk2
|
encryption: psk2
|
||||||
key: "{{ openwrt_iot_wifi_password }}"
|
key: "{{ openwrt_iot_wifi_password }}"
|
||||||
disabled: '0'
|
disabled: '0'
|
||||||
|
|||||||
@@ -1,8 +1,56 @@
|
|||||||
---
|
---
|
||||||
|
- name: Configure WAN connection marking
|
||||||
|
community.routeros.api_modify:
|
||||||
|
path: ip firewall mangle
|
||||||
|
data:
|
||||||
|
- action: mark-connection
|
||||||
|
chain: forward
|
||||||
|
connection-state: new
|
||||||
|
new-connection-mark: wan-gpon
|
||||||
|
out-interface: pppoe-gpon
|
||||||
|
passthrough: true
|
||||||
|
comment: Mark connections going out GPON
|
||||||
|
- action: mark-connection
|
||||||
|
chain: forward
|
||||||
|
connection-state: new
|
||||||
|
new-connection-mark: wan-lte
|
||||||
|
out-interface: vlan6
|
||||||
|
passthrough: true
|
||||||
|
comment: Mark connections going out LTE
|
||||||
|
handle_absent_entries: remove
|
||||||
|
handle_entries_content: remove_as_much_as_possible
|
||||||
|
ensure_order: true
|
||||||
|
|
||||||
- name: Configure IPv4 firewall filter rules
|
- name: Configure IPv4 firewall filter rules
|
||||||
community.routeros.api_modify:
|
community.routeros.api_modify:
|
||||||
path: ip firewall filter
|
path: ip firewall filter
|
||||||
data:
|
data:
|
||||||
|
- action: reject
|
||||||
|
chain: forward
|
||||||
|
connection-mark: wan-gpon
|
||||||
|
out-interface: vlan6
|
||||||
|
protocol: tcp
|
||||||
|
reject-with: tcp-reset
|
||||||
|
comment: Fast-fail TCP connections that shifted from GPON to LTE
|
||||||
|
- action: reject
|
||||||
|
chain: forward
|
||||||
|
connection-mark: wan-gpon
|
||||||
|
out-interface: vlan6
|
||||||
|
reject-with: icmp-network-unreachable
|
||||||
|
comment: Fast-fail non-TCP connections that shifted from GPON to LTE
|
||||||
|
- action: reject
|
||||||
|
chain: forward
|
||||||
|
connection-mark: wan-lte
|
||||||
|
out-interface: pppoe-gpon
|
||||||
|
protocol: tcp
|
||||||
|
reject-with: tcp-reset
|
||||||
|
comment: Fast-fail TCP connections that shifted from LTE to GPON
|
||||||
|
- action: reject
|
||||||
|
chain: forward
|
||||||
|
connection-mark: wan-lte
|
||||||
|
out-interface: pppoe-gpon
|
||||||
|
reject-with: icmp-network-unreachable
|
||||||
|
comment: Fast-fail non-TCP connections that shifted from LTE to GPON
|
||||||
- action: fasttrack-connection
|
- action: fasttrack-connection
|
||||||
chain: forward
|
chain: forward
|
||||||
connection-state: established,related
|
connection-state: established,related
|
||||||
@@ -208,6 +256,11 @@
|
|||||||
dst-port: 30033
|
dst-port: 30033
|
||||||
out-interface: vlan4
|
out-interface: vlan4
|
||||||
protocol: tcp
|
protocol: tcp
|
||||||
|
- action: accept
|
||||||
|
chain: allow-ports
|
||||||
|
dst-port: 10011
|
||||||
|
out-interface: vlan4
|
||||||
|
protocol: tcp
|
||||||
- action: accept
|
- action: accept
|
||||||
chain: allow-ports
|
chain: allow-ports
|
||||||
comment: Allow HTTP
|
comment: Allow HTTP
|
||||||
@@ -267,6 +320,12 @@
|
|||||||
dst-port: 30033
|
dst-port: 30033
|
||||||
protocol: tcp
|
protocol: tcp
|
||||||
to-addresses: 10.44.0.0
|
to-addresses: 10.44.0.0
|
||||||
|
- action: dst-nat
|
||||||
|
chain: dstnat
|
||||||
|
dst-address: 139.28.40.212
|
||||||
|
dst-port: 10011
|
||||||
|
protocol: tcp
|
||||||
|
to-addresses: 10.44.0.0
|
||||||
- action: src-nat
|
- action: src-nat
|
||||||
chain: srcnat
|
chain: srcnat
|
||||||
comment: src-nat from LAN to TS3 to some Greenland address
|
comment: src-nat from LAN to TS3 to some Greenland address
|
||||||
|
|||||||
@@ -12,15 +12,44 @@
|
|||||||
scope: 30
|
scope: 30
|
||||||
suppress-hw-offload: false
|
suppress-hw-offload: false
|
||||||
target-scope: 10
|
target-scope: 10
|
||||||
- disabled: false
|
- comment: GPON Monitor 1
|
||||||
|
disabled: false
|
||||||
|
distance: 1
|
||||||
|
dst-address: 1.0.0.1/32
|
||||||
|
gateway: pppoe-gpon
|
||||||
|
routing-table: main
|
||||||
|
scope: 10
|
||||||
|
suppress-hw-offload: false
|
||||||
|
target-scope: 10
|
||||||
|
- comment: GPON Monitor 2
|
||||||
|
disabled: false
|
||||||
|
distance: 1
|
||||||
|
dst-address: 8.8.4.4/32
|
||||||
|
gateway: pppoe-gpon
|
||||||
|
routing-table: main
|
||||||
|
scope: 10
|
||||||
|
suppress-hw-offload: false
|
||||||
|
target-scope: 10
|
||||||
|
- comment: GPON Default 1
|
||||||
|
disabled: false
|
||||||
distance: 1
|
distance: 1
|
||||||
dst-address: 0.0.0.0/0
|
dst-address: 0.0.0.0/0
|
||||||
gateway: pppoe-gpon
|
gateway: 1.0.0.1
|
||||||
|
check-gateway: ping
|
||||||
routing-table: main
|
routing-table: main
|
||||||
scope: 30
|
scope: 30
|
||||||
suppress-hw-offload: false
|
suppress-hw-offload: false
|
||||||
target-scope: 10
|
target-scope: 11
|
||||||
vrf-interface: pppoe-gpon
|
- comment: GPON Default 2
|
||||||
|
disabled: false
|
||||||
|
distance: 2
|
||||||
|
dst-address: 0.0.0.0/0
|
||||||
|
gateway: 8.8.4.4
|
||||||
|
check-gateway: ping
|
||||||
|
routing-table: main
|
||||||
|
scope: 30
|
||||||
|
suppress-hw-offload: false
|
||||||
|
target-scope: 11
|
||||||
handle_absent_entries: remove
|
handle_absent_entries: remove
|
||||||
handle_entries_content: remove_as_much_as_possible
|
handle_entries_content: remove_as_much_as_possible
|
||||||
|
|
||||||
@@ -32,6 +61,7 @@
|
|||||||
distance: 1
|
distance: 1
|
||||||
dst-address: 2000::/3
|
dst-address: 2000::/3
|
||||||
gateway: 2001:470:70:dd::1
|
gateway: 2001:470:70:dd::1
|
||||||
|
check-gateway: ping
|
||||||
scope: 30
|
scope: 30
|
||||||
target-scope: 10
|
target-scope: 10
|
||||||
- comment: Tailnet
|
- comment: Tailnet
|
||||||
|
|||||||
@@ -10,6 +10,7 @@
|
|||||||
password: "{{ routeros_pppoe_password }}"
|
password: "{{ routeros_pppoe_password }}"
|
||||||
# Using CoreDNS container with DNS64
|
# Using CoreDNS container with DNS64
|
||||||
use-peer-dns: false
|
use-peer-dns: false
|
||||||
|
add-default-route: false
|
||||||
user: "{{ routeros_pppoe_username }}"
|
user: "{{ routeros_pppoe_username }}"
|
||||||
handle_absent_entries: remove
|
handle_absent_entries: remove
|
||||||
handle_entries_content: remove_as_much_as_possible
|
handle_entries_content: remove_as_much_as_possible
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: authentik
|
chart: authentik
|
||||||
version: 2026.5.3
|
version: 2026.8.1
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: authentik
|
name: authentik
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ metadata:
|
|||||||
name: gitea-shared-storage-lvmhdd
|
name: gitea-shared-storage-lvmhdd
|
||||||
namespace: openebs
|
namespace: openebs
|
||||||
spec:
|
spec:
|
||||||
capacity: 10Gi
|
capacity: "21474836480"
|
||||||
ownerNodeID: anapistula-delrosalae
|
ownerNodeID: anapistula-delrosalae
|
||||||
shared: "yes"
|
shared: "yes"
|
||||||
thinProvision: "no"
|
thinProvision: "no"
|
||||||
@@ -20,7 +20,7 @@ metadata:
|
|||||||
name: gitea-shared-storage-lvmhdd
|
name: gitea-shared-storage-lvmhdd
|
||||||
spec:
|
spec:
|
||||||
capacity:
|
capacity:
|
||||||
storage: 10Gi
|
storage: 20Gi
|
||||||
accessModes:
|
accessModes:
|
||||||
- ReadWriteOnce
|
- ReadWriteOnce
|
||||||
persistentVolumeReclaimPolicy: Retain
|
persistentVolumeReclaimPolicy: Retain
|
||||||
@@ -41,6 +41,6 @@ spec:
|
|||||||
- ReadWriteOnce
|
- ReadWriteOnce
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
storage: 10Gi
|
storage: 20Gi
|
||||||
storageClassName: hdd-lvmpv
|
storageClassName: hdd-lvmpv
|
||||||
volumeName: gitea-shared-storage-lvmhdd
|
volumeName: gitea-shared-storage-lvmhdd
|
||||||
|
|||||||
@@ -17,13 +17,15 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: gitea
|
chart: gitea
|
||||||
version: 12.6.0
|
version: 12.7.0
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: gitea-charts
|
name: gitea-charts
|
||||||
namespace: gitea
|
namespace: gitea
|
||||||
interval: 12h
|
interval: 12h
|
||||||
values:
|
values:
|
||||||
|
image:
|
||||||
|
tag: 1.27.2 # REMOVE ME after new helm chart version includes this update
|
||||||
postgresql-ha:
|
postgresql-ha:
|
||||||
enabled: false
|
enabled: false
|
||||||
|
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ metadata:
|
|||||||
name: gitea-valkey-primary-lvmhdd-0
|
name: gitea-valkey-primary-lvmhdd-0
|
||||||
namespace: openebs
|
namespace: openebs
|
||||||
spec:
|
spec:
|
||||||
capacity: 1Gi
|
capacity: "4294967296"
|
||||||
ownerNodeID: anapistula-delrosalae
|
ownerNodeID: anapistula-delrosalae
|
||||||
shared: "yes"
|
shared: "yes"
|
||||||
thinProvision: "no"
|
thinProvision: "no"
|
||||||
@@ -20,7 +20,7 @@ metadata:
|
|||||||
name: gitea-valkey-primary-lvmhdd-0
|
name: gitea-valkey-primary-lvmhdd-0
|
||||||
spec:
|
spec:
|
||||||
capacity:
|
capacity:
|
||||||
storage: 1Gi
|
storage: 4Gi
|
||||||
accessModes:
|
accessModes:
|
||||||
- ReadWriteOnce
|
- ReadWriteOnce
|
||||||
persistentVolumeReclaimPolicy: Retain
|
persistentVolumeReclaimPolicy: Retain
|
||||||
@@ -41,6 +41,6 @@ spec:
|
|||||||
- ReadWriteOnce
|
- ReadWriteOnce
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
storage: 1Gi
|
storage: 4Gi
|
||||||
storageClassName: hdd-lvmpv
|
storageClassName: hdd-lvmpv
|
||||||
volumeName: gitea-valkey-primary-lvmhdd-0
|
volumeName: gitea-valkey-primary-lvmhdd-0
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: valkey
|
chart: valkey
|
||||||
version: 0.9.4
|
version: 0.11.0
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: valkey
|
name: valkey
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: immich
|
chart: immich
|
||||||
version: 1.2.6
|
version: 2.0.3
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: secustor
|
name: secustor
|
||||||
|
|||||||
@@ -15,6 +15,10 @@ spec:
|
|||||||
protocol: TCP
|
protocol: TCP
|
||||||
port: 30033
|
port: 30033
|
||||||
targetPort: 30033
|
targetPort: 30033
|
||||||
|
- name: rawquery
|
||||||
|
protocol: TCP
|
||||||
|
port: 10011
|
||||||
|
targetPort: 10011
|
||||||
type: LoadBalancer
|
type: LoadBalancer
|
||||||
externalTrafficPolicy: Local
|
externalTrafficPolicy: Local
|
||||||
ipFamilyPolicy: PreferDualStack
|
ipFamilyPolicy: PreferDualStack
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
---
|
||||||
|
apiVersion: secrets.hashicorp.com/v1beta1
|
||||||
|
kind: VaultStaticSecret
|
||||||
|
metadata:
|
||||||
|
name: kaneo-app-secret
|
||||||
|
namespace: kaneo
|
||||||
|
spec:
|
||||||
|
type: kv-v2
|
||||||
|
|
||||||
|
mount: secret
|
||||||
|
path: kaneo
|
||||||
|
|
||||||
|
destination:
|
||||||
|
create: true
|
||||||
|
name: kaneo-app-secret
|
||||||
|
type: Opaque
|
||||||
|
transformation:
|
||||||
|
excludeRaw: true
|
||||||
|
templates:
|
||||||
|
auth_secret:
|
||||||
|
text: '{{ get .Secrets "auth_secret" }}'
|
||||||
|
|
||||||
|
vaultAuthRef: kaneo
|
||||||
@@ -2,6 +2,7 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
|
- app-secret.yaml
|
||||||
- oauth-secret.yaml
|
- oauth-secret.yaml
|
||||||
- postgres-volume.yaml
|
- postgres-volume.yaml
|
||||||
- postgres-cluster.yaml
|
- postgres-cluster.yaml
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ spec:
|
|||||||
interval: 24h
|
interval: 24h
|
||||||
url: https://github.com/usekaneo/kaneo.git
|
url: https://github.com/usekaneo/kaneo.git
|
||||||
ref:
|
ref:
|
||||||
tag: v2.7.7
|
tag: v2.22.0
|
||||||
ignore: |
|
ignore: |
|
||||||
# exclude all
|
# exclude all
|
||||||
/*
|
/*
|
||||||
@@ -53,11 +53,13 @@ spec:
|
|||||||
enabled: false
|
enabled: false
|
||||||
|
|
||||||
kaneo:
|
kaneo:
|
||||||
image:
|
|
||||||
tag: "2.7.3" # renovate: depName=ghcr.io/usekaneo/kaneo registryUrl=https://ghcr.io
|
|
||||||
env:
|
env:
|
||||||
clientUrl: "https://kaneo.lumpiasty.xyz"
|
clientUrl: "https://kaneo.lumpiasty.xyz"
|
||||||
disablePasswordRegistration: true
|
disablePasswordRegistration: true
|
||||||
|
existingSecret:
|
||||||
|
enabled: true
|
||||||
|
name: kaneo-app-secret
|
||||||
|
key: auth_secret
|
||||||
database:
|
database:
|
||||||
external:
|
external:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|||||||
@@ -1,444 +0,0 @@
|
|||||||
# yaml-language-server: $schema=https://raw.githubusercontent.com/mostlygeek/llama-swap/refs/heads/main/config-schema.json
|
|
||||||
healthCheckTimeout: 600
|
|
||||||
logToStdout: "both" # proxy and upstream
|
|
||||||
|
|
||||||
macros:
|
|
||||||
base_args: "--no-warmup --port ${PORT} --mlock --no-mmap"
|
|
||||||
common_args: "--fit-target 256 --no-warmup --port ${PORT} --no-mmap -tb 12 -t 6"
|
|
||||||
cpu_args: "--no-warmup --port ${PORT} -ngl 0"
|
|
||||||
ctx_64k: "--ctx-size 65536"
|
|
||||||
ctx_128k: "--ctx-size 131072"
|
|
||||||
ctx_256k: "--ctx-size 131072"
|
|
||||||
qwen35_think_args: "--temp 1.0 --top-p 0.95 --top-k 20 --min-p 0.00 -ctk q4_0 -ctv q4_0 --presence_penalty 1.5 --reasoning on"
|
|
||||||
qwen35_nothink_args: "--temp 0.7 --top-p 0.80 --top-k 20 --min-p 0.00 -ctk q4_0 -ctv q4_0 --presence_penalty 1.5 --reasoning off"
|
|
||||||
qwen35_35b_heretic_mmproj: "--mmproj-url https://huggingface.co/unsloth/Qwen3.5-35B-A3B-GGUF/resolve/main/mmproj-F16.gguf --mmproj /root/.cache/llama.cpp/unsloth_Qwen3.5-35B-A3B-GGUF_mmproj-F16.gguf"
|
|
||||||
qwen35_4b_heretic_mmproj: "--mmproj-url https://huggingface.co/unsloth/Qwen3.5-4B-GGUF/resolve/main/mmproj-F16.gguf --mmproj /root/.cache/llama.cpp/unsloth_Qwen3.5-4B-GGUF_mmproj-F16.gguf"
|
|
||||||
gemma4_sampling: "--temp 1.0 --top-p 0.95 --top-k 64 -ctk q4_0 -ctv q4_0"
|
|
||||||
gemma4_nothink_sampling: "--temp 1.0 --top-p 0.95 --top-k 64 -ctk q4_0 -ctv q4_0 --reasoning off"
|
|
||||||
|
|
||||||
hooks:
|
|
||||||
on_startup:
|
|
||||||
preload:
|
|
||||||
- "Qwen3.5-0.8B-GGUF-nothink:Q4_K_XL"
|
|
||||||
- "parakeet-tdt_ctc-1.1b"
|
|
||||||
|
|
||||||
# matrix replaces groups (they are mutually exclusive).
|
|
||||||
# The small 0.8B model runs alongside any LLM.
|
|
||||||
# FLUX runs alone — it needs all available VRAM and will evict the 0.8B first.
|
|
||||||
matrix:
|
|
||||||
vars:
|
|
||||||
q8: "Qwen3.5-0.8B-GGUF-nothink:Q4_K_XL"
|
|
||||||
stt: "parakeet-tdt_ctc-1.1b"
|
|
||||||
flux: "flux2-klein-4b:Q4_K_M"
|
|
||||||
coder: "Qwen3-Coder-Next-GGUF:Q4_K_M"
|
|
||||||
q35t: "Qwen3.5-35B-A3B-GGUF:Q4_K_M"
|
|
||||||
q35nt: "Qwen3.5-35B-A3B-GGUF-nothink:Q4_K_M"
|
|
||||||
q35ht: "Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M"
|
|
||||||
q35hnt: "Qwen3.5-35B-A3B-heretic-GGUF-nothink:Q4_K_M"
|
|
||||||
q4t: "Qwen3.5-4B-GGUF:Q4_K_M"
|
|
||||||
q4nt: "Qwen3.5-4B-GGUF-nothink:Q4_K_M"
|
|
||||||
q4ht: "Qwen3.5-4B-heretic-GGUF:Q4_K_M"
|
|
||||||
q4hnt: "Qwen3.5-4B-heretic-GGUF-nothink:Q4_K_M"
|
|
||||||
g26xl: "gemma-4-26B-A4B-it-qat:UD-Q4_K_XL"
|
|
||||||
g26xlnt: "gemma-4-26B-A4B-it-qat-nothink:UD-Q4_K_XL"
|
|
||||||
g26mtp: "gemma-4-26B-A4B-it-qat-mtp:UD-Q4_K_XL"
|
|
||||||
g26mtpnt: "gemma-4-26B-A4B-it-qat-mtp-nothink:UD-Q4_K_XL"
|
|
||||||
g26ht: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL"
|
|
||||||
g26hnt: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-nothink:UD-Q4_K_XL"
|
|
||||||
g26hmtp: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp:UD-Q4_K_XL"
|
|
||||||
g26hmnt: "SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp-nothink:UD-Q4_K_XL"
|
|
||||||
ge4qat: "unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL"
|
|
||||||
ge4qatnt: "unsloth/gemma-4-E4B-it-qat-GGUF-nothink:UD-Q4_K_XL"
|
|
||||||
ge2qat: "unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL"
|
|
||||||
ge2qatnt: "unsloth/gemma-4-E2B-it-qat-GGUF-nothink:UD-Q4_K_XL"
|
|
||||||
ge4mtp: "unsloth/gemma-4-E4B-it-qat-GGUF-mtp:UD-Q4_K_XL"
|
|
||||||
ge4mtpnt: "unsloth/gemma-4-E4B-it-qat-GGUF-mtp-nothink:UD-Q4_K_XL"
|
|
||||||
ge4ht: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M"
|
|
||||||
ge4hnt: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-nothink:Q4_K_M"
|
|
||||||
ge4hmtp: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp:Q4_K_M"
|
|
||||||
ge4hmnt: "llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp-nothink:Q4_K_M"
|
|
||||||
q36t: "unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL"
|
|
||||||
q36nt: "unsloth/Qwen3.6-35B-A3B-GGUF-nothink:UD-Q4_K_XL"
|
|
||||||
haut: "HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M"
|
|
||||||
haunt: "HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive-nothink:Q4_K_M"
|
|
||||||
mtpt: "unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M"
|
|
||||||
mtpnt: "unsloth/Qwen3.6-35B-A3B-MTP-GGUF-nothink:Q4_K_M"
|
|
||||||
|
|
||||||
evict_costs:
|
|
||||||
flux: 10 # large files, slow to reload
|
|
||||||
|
|
||||||
sets:
|
|
||||||
# any LLM can run alongside the small always-on model + STT + TTS (all CPU, no VRAM cost)
|
|
||||||
with_q8: "(coder | q35t | q35nt | q35ht | q35hnt | q4t | q4nt | q4ht | q4hnt | g26xl | g26xlnt | g26mtp | g26mtpnt | g26ht | g26hnt | g26hmtp | g26hmnt | ge4qat | ge4qatnt | ge2qat | ge2qatnt | ge4mtp | ge4mtpnt | ge4ht | ge4hnt | ge4hmtp | ge4hmnt | q36t | q36nt | haut | haunt | mtpt | mtpnt) & q8 & stt"
|
|
||||||
# FLUX runs alone — evicts everything including q8, but keeps STT for voice during image gen
|
|
||||||
image_gen: "flux & stt"
|
|
||||||
|
|
||||||
|
|
||||||
models:
|
|
||||||
"Qwen3-Coder-Next-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3-Coder-Next-GGUF:Q4_K_M
|
|
||||||
--ctx-size 65536
|
|
||||||
--predict 8192
|
|
||||||
--temp 1.0
|
|
||||||
--min-p 0.01
|
|
||||||
--top-p 0.95
|
|
||||||
--top-k 40
|
|
||||||
--repeat-penalty 1.0
|
|
||||||
-ctk q4_0 -ctv q4_0
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-35B-A3B-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.5-35B-A3B-GGUF:Q4_K_M
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-35B-A3B-GGUF-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.5-35B-A3B-GGUF:Q4_K_M
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
# The "heretic" version does not provide the mmproj
|
|
||||||
# so providing url to the one from the non-heretic version.
|
|
||||||
"Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf mradermacher/Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M
|
|
||||||
${qwen35_35b_heretic_mmproj}
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-35B-A3B-heretic-GGUF-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf mradermacher/Qwen3.5-35B-A3B-heretic-GGUF:Q4_K_M
|
|
||||||
${qwen35_35b_heretic_mmproj}
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-0.8B-GGUF-nothink:Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.5-0.8B-GGUF:Q4_K_XL
|
|
||||||
--ctx-size 4096
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${base_args}
|
|
||||||
|
|
||||||
"Qwen3.5-4B-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.5-4B-GGUF:Q4_K_M
|
|
||||||
${ctx_128k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-4B-GGUF-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.5-4B-GGUF:Q4_K_M
|
|
||||||
${ctx_128k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-4B-heretic-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf mradermacher/Qwen3.5-4B-heretic-GGUF:Q4_K_M
|
|
||||||
${qwen35_4b_heretic_mmproj}
|
|
||||||
${ctx_128k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"Qwen3.5-4B-heretic-GGUF-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf mradermacher/Qwen3.5-4B-heretic-GGUF:Q4_K_M
|
|
||||||
${qwen35_4b_heretic_mmproj}
|
|
||||||
${ctx_128k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"gemma-4-26B-A4B-it-qat:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"gemma-4-26B-A4B-it-qat-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"gemma-4-26B-A4B-it-qat-mtp:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"gemma-4-26B-A4B-it-qat-mtp-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
# The heretic QAT repo does not ship an MTP drafter,
|
|
||||||
# so borrow the one from the non-heretic unsloth QAT repo.
|
|
||||||
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF-mtp-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf SC117/gemma-4-26B-A4B-it-qat-heretic-GGUF:UD-Q4_K_XL \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-26B-A4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_256k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/gemma-4-E4B-it-qat-GGUF-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/gemma-4-E2B-it-qat-GGUF-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-E2B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/gemma-4-E4B-it-qat-GGUF-mtp:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/gemma-4-E4B-it-qat-GGUF-mtp-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/gemma-4-E4B-it-qat-GGUF:UD-Q4_K_XL \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF-mtp-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf llmfan46/gemma-4-E4B-it-ultra-uncensored-heretic-GGUF:Q4_K_M \
|
|
||||||
--spec-draft-hf unsloth/gemma-4-E4B-it-qat-GGUF:Q8_0-MTP \
|
|
||||||
--spec-type draft-mtp
|
|
||||||
--spec-draft-n-max 1
|
|
||||||
--swa-full
|
|
||||||
--kv-unified
|
|
||||||
--parallel 1
|
|
||||||
${ctx_128k}
|
|
||||||
${gemma4_nothink_sampling}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/Qwen3.6-35B-A3B-GGUF-nothink:UD-Q4_K_XL":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.6-35B-A3B-GGUF:UD-Q4_K_XL
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf HauhauCS/Qwen3.6-35B-A3B-Uncensored-HauhauCS-Aggressive:Q4_K_M
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_think_args}
|
|
||||||
--spec-type draft-mtp --spec-draft-n-max 1
|
|
||||||
--parallel 1
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
"unsloth/Qwen3.6-35B-A3B-MTP-GGUF-nothink:Q4_K_M":
|
|
||||||
cmd: |
|
|
||||||
llama-server
|
|
||||||
-hf unsloth/Qwen3.6-35B-A3B-MTP-GGUF:Q4_K_M
|
|
||||||
${ctx_256k}
|
|
||||||
${qwen35_nothink_args}
|
|
||||||
--spec-type draft-mtp --spec-draft-n-max 1
|
|
||||||
--parallel 1
|
|
||||||
${common_args}
|
|
||||||
|
|
||||||
# STT via parakeet-server (parakeet.cpp OpenAI-compatible server, CPU, always loaded)
|
|
||||||
# Model downloaded on first start and cached under /root/.cache/parakeet.cpp/models
|
|
||||||
# parakeet-proxy.py sits in front to convert any audio format to WAV via ffmpeg,
|
|
||||||
# since parakeet-server only accepts real WAV but browsers send Ogg/Opus.
|
|
||||||
"parakeet-tdt_ctc-1.1b":
|
|
||||||
checkEndpoint: none
|
|
||||||
cmd: |
|
|
||||||
env PROXY_PORT=${PORT} FFMPEG_BIN=/root/.cache/ffmpeg/ffmpeg python3 /config/parakeet-proxy.py
|
|
||||||
|
|
||||||
|
|
||||||
# Image generation via stable-diffusion.cpp (sd-server)
|
|
||||||
# Models must be pre-downloaded to /root/.cache/sd/
|
|
||||||
# FLUX.2-klein-4B: fast unified text-to-image and image editing model (Apache 2.0)
|
|
||||||
# Download: uv run --with huggingface_hub hf download unsloth/FLUX.2-klein-4B-GGUF flux-2-klein-4b-Q4_K_M.gguf --local-dir /root/.cache/sd
|
|
||||||
# Download VAE: uv run --with huggingface_hub hf download Comfy-Org/flux2-klein-4B split_files/vae/flux2-vae.safetensors --local-dir /root/.cache/sd/flux2-klein && cp /root/.cache/sd/flux2-klein/split_files/vae/flux2-vae.safetensors /root/.cache/sd/
|
|
||||||
# Download LLM: uv run --with huggingface_hub hf download ponpoke/flux2-klein-4b-uncensored-text-encoder flux2-klein-4b-uncensored-q4_k_m.gguf --local-dir /root/.cache/sd
|
|
||||||
"flux2-klein-4b:Q4_K_M":
|
|
||||||
checkEndpoint: "/"
|
|
||||||
cmd: |
|
|
||||||
sd-server
|
|
||||||
--listen-port ${PORT}
|
|
||||||
--diffusion-model /root/.cache/sd/flux-2-klein-4b-Q4_K_M.gguf
|
|
||||||
--vae /root/.cache/sd/flux2-vae.safetensors
|
|
||||||
--llm /root/.cache/sd/flux2-klein-4b-uncensored-q4_k_m.gguf
|
|
||||||
--cfg-scale 1.0
|
|
||||||
--sampling-method euler
|
|
||||||
--steps 4
|
|
||||||
--diffusion-fa
|
|
||||||
--offload-to-cpu
|
|
||||||
@@ -1,227 +0,0 @@
|
|||||||
#!/usr/bin/env python3
|
|
||||||
"""
|
|
||||||
Thin reverse proxy for parakeet-server.
|
|
||||||
|
|
||||||
Accepts POST /v1/audio/transcriptions with any audio format,
|
|
||||||
converts the audio to 16 kHz mono WAV via ffmpeg, then forwards
|
|
||||||
the converted file to the real parakeet-server running on PARAKEET_PORT.
|
|
||||||
|
|
||||||
Also proxies GET /health straight through.
|
|
||||||
|
|
||||||
Usage:
|
|
||||||
PROXY_PORT=<port> PARAKEET_PORT=<upstream> python3 parakeet-proxy.py
|
|
||||||
"""
|
|
||||||
|
|
||||||
import http.server
|
|
||||||
import io
|
|
||||||
import os
|
|
||||||
import subprocess
|
|
||||||
import sys
|
|
||||||
import tempfile
|
|
||||||
import urllib.request
|
|
||||||
import urllib.error
|
|
||||||
|
|
||||||
PROXY_PORT = int(os.environ.get("PROXY_PORT", "8080"))
|
|
||||||
PARAKEET_PORT = PROXY_PORT + 1
|
|
||||||
FFMPEG = os.environ.get("FFMPEG_BIN", "ffmpeg")
|
|
||||||
MODEL = os.environ.get("PARAKEET_MODEL", "tdt_ctc-1.1b-q4_k.gguf")
|
|
||||||
CACHE_DIR = os.environ.get("PARAKEET_CACHE_DIR", "/root/.cache/parakeet.cpp/models")
|
|
||||||
|
|
||||||
|
|
||||||
def convert_to_wav(data: bytes) -> bytes:
|
|
||||||
"""Convert any audio bytes to 16 kHz mono PCM WAV via ffmpeg."""
|
|
||||||
with tempfile.NamedTemporaryFile(suffix=".input", delete=False) as inf:
|
|
||||||
inf.write(data)
|
|
||||||
inf_path = inf.name
|
|
||||||
out_path = inf_path + ".wav"
|
|
||||||
try:
|
|
||||||
subprocess.run(
|
|
||||||
[
|
|
||||||
FFMPEG, "-y",
|
|
||||||
"-i", inf_path,
|
|
||||||
"-ar", "16000",
|
|
||||||
"-ac", "1",
|
|
||||||
"-f", "wav",
|
|
||||||
out_path,
|
|
||||||
],
|
|
||||||
check=True,
|
|
||||||
stdout=subprocess.DEVNULL,
|
|
||||||
stderr=subprocess.DEVNULL,
|
|
||||||
)
|
|
||||||
with open(out_path, "rb") as f:
|
|
||||||
return f.read()
|
|
||||||
finally:
|
|
||||||
os.unlink(inf_path)
|
|
||||||
if os.path.exists(out_path):
|
|
||||||
os.unlink(out_path)
|
|
||||||
|
|
||||||
|
|
||||||
def parse_multipart(content_type: str, body: bytes):
|
|
||||||
"""
|
|
||||||
Parse a multipart/form-data body.
|
|
||||||
Returns a dict of field_name -> (filename_or_None, content_type, data).
|
|
||||||
"""
|
|
||||||
import email
|
|
||||||
from email import policy as email_policy
|
|
||||||
|
|
||||||
# email.parser needs the full MIME headers to parse multipart
|
|
||||||
raw = b"Content-Type: " + content_type.encode() + b"\r\n\r\n" + body
|
|
||||||
msg = email.message_from_bytes(raw, policy=email_policy.compat32)
|
|
||||||
parts = {}
|
|
||||||
for part in msg.get_payload():
|
|
||||||
cd = part.get("Content-Disposition", "")
|
|
||||||
name = None
|
|
||||||
filename = None
|
|
||||||
for item in cd.split(";"):
|
|
||||||
item = item.strip()
|
|
||||||
if item.startswith('name='):
|
|
||||||
name = item[5:].strip('"')
|
|
||||||
elif item.startswith('filename='):
|
|
||||||
filename = item[9:].strip('"')
|
|
||||||
if name is not None:
|
|
||||||
parts[name] = (filename, part.get_content_type(), part.get_payload(decode=True))
|
|
||||||
return parts
|
|
||||||
|
|
||||||
|
|
||||||
def build_multipart(fields: dict) -> tuple[bytes, str]:
|
|
||||||
"""
|
|
||||||
Build a multipart/form-data body from fields dict:
|
|
||||||
field_name -> (filename_or_None, content_type, data_bytes)
|
|
||||||
Returns (body_bytes, content_type_header_value).
|
|
||||||
"""
|
|
||||||
boundary = b"----ParakeetProxyBoundary0xDEADBEEF"
|
|
||||||
body = b""
|
|
||||||
for name, (filename, ct, data) in fields.items():
|
|
||||||
body += b"--" + boundary + b"\r\n"
|
|
||||||
if filename:
|
|
||||||
body += (
|
|
||||||
f'Content-Disposition: form-data; name="{name}"; filename="{filename}"\r\n'
|
|
||||||
).encode()
|
|
||||||
else:
|
|
||||||
body += f'Content-Disposition: form-data; name="{name}"\r\n'.encode()
|
|
||||||
body += f"Content-Type: {ct}\r\n\r\n".encode()
|
|
||||||
body += data + b"\r\n"
|
|
||||||
body += b"--" + boundary + b"--\r\n"
|
|
||||||
return body, f"multipart/form-data; boundary={boundary.decode()}"
|
|
||||||
|
|
||||||
|
|
||||||
class ProxyHandler(http.server.BaseHTTPRequestHandler):
|
|
||||||
def log_message(self, fmt, *args):
|
|
||||||
print(f"[parakeet-proxy] {self.address_string()} - {fmt % args}", flush=True)
|
|
||||||
|
|
||||||
def do_GET(self):
|
|
||||||
if self.path == "/health":
|
|
||||||
self._forward_get("/health")
|
|
||||||
else:
|
|
||||||
self.send_response(404)
|
|
||||||
self.end_headers()
|
|
||||||
|
|
||||||
def do_POST(self):
|
|
||||||
if self.path.rstrip("/") == "/v1/audio/transcriptions":
|
|
||||||
self._handle_transcription()
|
|
||||||
else:
|
|
||||||
self.send_response(404)
|
|
||||||
self.end_headers()
|
|
||||||
|
|
||||||
def _forward_get(self, path):
|
|
||||||
try:
|
|
||||||
url = f"http://127.0.0.1:{PARAKEET_PORT}{path}"
|
|
||||||
with urllib.request.urlopen(url, timeout=5) as resp:
|
|
||||||
body = resp.read()
|
|
||||||
self.send_response(resp.status)
|
|
||||||
self.send_header("Content-Type", resp.headers.get("Content-Type", "application/json"))
|
|
||||||
self.end_headers()
|
|
||||||
self.wfile.write(body)
|
|
||||||
except Exception as e:
|
|
||||||
self.send_response(502)
|
|
||||||
self.end_headers()
|
|
||||||
self.wfile.write(str(e).encode())
|
|
||||||
|
|
||||||
def _handle_transcription(self):
|
|
||||||
length = int(self.headers.get("Content-Length", 0))
|
|
||||||
body = self.rfile.read(length)
|
|
||||||
ct = self.headers.get("Content-Type", "")
|
|
||||||
|
|
||||||
try:
|
|
||||||
fields = parse_multipart(ct, body)
|
|
||||||
except Exception as e:
|
|
||||||
self._error(400, f"failed to parse multipart: {e}")
|
|
||||||
return
|
|
||||||
|
|
||||||
if "file" not in fields:
|
|
||||||
self._error(400, "missing required field 'file'")
|
|
||||||
return
|
|
||||||
|
|
||||||
filename, file_ct, audio_data = fields["file"]
|
|
||||||
|
|
||||||
# Convert to WAV regardless of what we received
|
|
||||||
try:
|
|
||||||
wav_data = convert_to_wav(audio_data)
|
|
||||||
except subprocess.CalledProcessError:
|
|
||||||
self._error(400, "ffmpeg could not decode audio")
|
|
||||||
return
|
|
||||||
except Exception as e:
|
|
||||||
self._error(500, f"conversion error: {e}")
|
|
||||||
return
|
|
||||||
|
|
||||||
# Rebuild multipart with converted WAV, preserve other fields
|
|
||||||
new_fields = {}
|
|
||||||
for name, (fn, fct, data) in fields.items():
|
|
||||||
if name == "file":
|
|
||||||
new_fields[name] = ("recording.wav", "audio/wav", wav_data)
|
|
||||||
else:
|
|
||||||
new_fields[name] = (fn, fct, data)
|
|
||||||
|
|
||||||
new_body, new_ct = build_multipart(new_fields)
|
|
||||||
|
|
||||||
# Forward to parakeet-server
|
|
||||||
try:
|
|
||||||
url = f"http://127.0.0.1:{PARAKEET_PORT}/v1/audio/transcriptions"
|
|
||||||
req = urllib.request.Request(
|
|
||||||
url,
|
|
||||||
data=new_body,
|
|
||||||
headers={"Content-Type": new_ct},
|
|
||||||
method="POST",
|
|
||||||
)
|
|
||||||
with urllib.request.urlopen(req, timeout=300) as resp:
|
|
||||||
resp_body = resp.read()
|
|
||||||
self.send_response(resp.status)
|
|
||||||
self.send_header("Content-Type", resp.headers.get("Content-Type", "application/json"))
|
|
||||||
self.end_headers()
|
|
||||||
self.wfile.write(resp_body)
|
|
||||||
except urllib.error.HTTPError as e:
|
|
||||||
resp_body = e.read()
|
|
||||||
self.send_response(e.code)
|
|
||||||
self.send_header("Content-Type", e.headers.get("Content-Type", "application/json"))
|
|
||||||
self.end_headers()
|
|
||||||
self.wfile.write(resp_body)
|
|
||||||
except Exception as e:
|
|
||||||
self._error(502, f"upstream error: {e}")
|
|
||||||
|
|
||||||
def _error(self, code: int, msg: str):
|
|
||||||
body = f'{{"error":{{"message":"{msg}","type":"proxy_error"}}}}'.encode()
|
|
||||||
self.send_response(code)
|
|
||||||
self.send_header("Content-Type", "application/json")
|
|
||||||
self.end_headers()
|
|
||||||
self.wfile.write(body)
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
proc = subprocess.Popen([
|
|
||||||
"parakeet-server",
|
|
||||||
"--host", "127.0.0.1",
|
|
||||||
"--port", str(PARAKEET_PORT),
|
|
||||||
"--model", MODEL,
|
|
||||||
"--cache-dir", CACHE_DIR,
|
|
||||||
])
|
|
||||||
print(f"[parakeet-proxy] started parakeet-server pid={proc.pid} on :{PARAKEET_PORT}", flush=True)
|
|
||||||
|
|
||||||
server = http.server.HTTPServer(("0.0.0.0", PROXY_PORT), ProxyHandler)
|
|
||||||
print(f"[parakeet-proxy] listening on :{PROXY_PORT}", flush=True)
|
|
||||||
try:
|
|
||||||
server.serve_forever()
|
|
||||||
except KeyboardInterrupt:
|
|
||||||
pass
|
|
||||||
finally:
|
|
||||||
proc.terminate()
|
|
||||||
proc.wait()
|
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: Deployment
|
kind: Deployment
|
||||||
metadata:
|
metadata:
|
||||||
name: llama-swap
|
name: supervisord
|
||||||
namespace: llama
|
namespace: llama
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
replicas: 1
|
||||||
@@ -16,64 +16,24 @@ spec:
|
|||||||
labels:
|
labels:
|
||||||
app: llama-swap
|
app: llama-swap
|
||||||
spec:
|
spec:
|
||||||
initContainers:
|
|
||||||
- name: download-whisper
|
|
||||||
image: gitea.lumpiasty.xyz/lumpiasty/llama-swap:unified-vulkan-parakeet-2026-06-12
|
|
||||||
command:
|
|
||||||
- sh
|
|
||||||
- -c
|
|
||||||
- |
|
|
||||||
mkdir -p /root/.cache/whisper
|
|
||||||
if [ ! -f /root/.cache/whisper/ggml-small.bin ]; then
|
|
||||||
echo "Downloading whisper-small model..."
|
|
||||||
curl -L -o /root/.cache/whisper/ggml-small.bin \
|
|
||||||
https://huggingface.co/ggerganov/whisper.cpp/resolve/main/ggml-small.bin
|
|
||||||
else
|
|
||||||
echo "whisper-small model already present, skipping download"
|
|
||||||
fi
|
|
||||||
if [ ! -f /root/.cache/ffmpeg/ffmpeg ]; then
|
|
||||||
echo "Downloading static ffmpeg..."
|
|
||||||
mkdir -p /root/.cache/ffmpeg
|
|
||||||
apt-get update -qq && apt-get install -y --no-install-recommends xz-utils
|
|
||||||
curl -L -o /root/.cache/ffmpeg/ffmpeg.tar.xz \
|
|
||||||
https://github.com/BtbN/FFmpeg-Builds/releases/download/latest/ffmpeg-master-latest-linux64-gpl.tar.xz
|
|
||||||
tar -xJf /root/.cache/ffmpeg/ffmpeg.tar.xz -C /root/.cache/ffmpeg --wildcards '*/ffmpeg' --strip-components=2
|
|
||||||
rm /root/.cache/ffmpeg/ffmpeg.tar.xz
|
|
||||||
chmod +x /root/.cache/ffmpeg/ffmpeg
|
|
||||||
else
|
|
||||||
echo "ffmpeg already present, skipping download"
|
|
||||||
fi
|
|
||||||
volumeMounts:
|
|
||||||
- name: models
|
|
||||||
mountPath: /root/.cache
|
|
||||||
containers:
|
containers:
|
||||||
- name: llama-swap
|
- name: supervisord
|
||||||
image: gitea.lumpiasty.xyz/lumpiasty/llama-swap:unified-vulkan-parakeet-2026-06-12
|
image: gitea.lumpiasty.xyz/lumpiasty/supervisord:latest@sha256:2676d13df2a0833b27ab8ec441da78c6c43d3f7bf75837d35723eefb40a82ce1
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
command:
|
|
||||||
- llama-swap
|
|
||||||
args:
|
|
||||||
- --config=/config/config.yaml
|
|
||||||
- --watch-config
|
|
||||||
env:
|
|
||||||
- name: RADV_EXPERIMENTAL
|
|
||||||
value: transfer_queue
|
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8080
|
- containerPort: 8080
|
||||||
name: http
|
name: http
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
|
env:
|
||||||
|
- name: WORKSPACE
|
||||||
|
value: /root
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: models
|
- name: models
|
||||||
mountPath: /root/.cache
|
mountPath: /root
|
||||||
- name: models
|
|
||||||
mountPath: /usr/local/bin/ffmpeg
|
|
||||||
subPath: ffmpeg/ffmpeg
|
|
||||||
- mountPath: /dev/kfd
|
- mountPath: /dev/kfd
|
||||||
name: kfd
|
name: kfd
|
||||||
- mountPath: /dev/dri
|
- mountPath: /dev/dri
|
||||||
name: dri
|
name: dri
|
||||||
- mountPath: /config
|
|
||||||
name: config
|
|
||||||
securityContext:
|
securityContext:
|
||||||
privileged: true
|
privileged: true
|
||||||
volumes:
|
volumes:
|
||||||
@@ -88,9 +48,6 @@ spec:
|
|||||||
hostPath:
|
hostPath:
|
||||||
path: /dev/dri
|
path: /dev/dri
|
||||||
type: Directory
|
type: Directory
|
||||||
- name: config
|
|
||||||
configMap:
|
|
||||||
name: llama-swap
|
|
||||||
---
|
---
|
||||||
apiVersion: v1
|
apiVersion: v1
|
||||||
kind: Service
|
kind: Service
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ spec:
|
|||||||
# OpenAI-compatible Kokoro-FastAPI TTS server, CPU PyTorch backend.
|
# OpenAI-compatible Kokoro-FastAPI TTS server, CPU PyTorch backend.
|
||||||
# Models baked into the image (no PVC needed).
|
# Models baked into the image (no PVC needed).
|
||||||
# v0.3.0 includes fix for per-request voice tensor memory leak (#459).
|
# v0.3.0 includes fix for per-request voice tensor memory leak (#459).
|
||||||
image: ghcr.io/remsky/kokoro-fastapi-cpu:v0.5.0
|
image: ghcr.io/remsky/kokoro-fastapi-cpu:v0.9.0
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8880
|
- containerPort: 8880
|
||||||
name: http
|
name: http
|
||||||
|
|||||||
@@ -8,9 +8,3 @@ resources:
|
|||||||
- pvc-ssd.yaml
|
- pvc-ssd.yaml
|
||||||
- deployment.yaml
|
- deployment.yaml
|
||||||
- kokoro.yaml
|
- kokoro.yaml
|
||||||
configMapGenerator:
|
|
||||||
- name: llama-swap
|
|
||||||
namespace: llama
|
|
||||||
files:
|
|
||||||
- config.yaml=configs/config.yaml
|
|
||||||
- parakeet-proxy.py=configs/parakeet-proxy.py
|
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ spec:
|
|||||||
spec:
|
spec:
|
||||||
initContainers:
|
initContainers:
|
||||||
- name: prepare-home
|
- name: prepare-home
|
||||||
image: alpine:3.24.0
|
image: alpine:3.24.1
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
command:
|
command:
|
||||||
- /bin/sh
|
- /bin/sh
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: open-webui
|
chart: open-webui
|
||||||
version: 14.8.0
|
version: 16.5.0
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: open-webui
|
name: open-webui
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: woodpecker
|
chart: woodpecker
|
||||||
version: 3.6.4
|
version: 3.7.3
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: woodpecker
|
name: woodpecker
|
||||||
|
|||||||
File diff suppressed because it is too large
Load Diff
@@ -1,5 +1,5 @@
|
|||||||
# Stage 1: build CoreDNS with minimal plugin set
|
# Stage 1: build CoreDNS with minimal plugin set
|
||||||
FROM golang:1.25-alpine AS build
|
FROM golang:1.27-alpine AS build
|
||||||
|
|
||||||
RUN apk add --no-cache git make bash
|
RUN apk add --no-cache git make bash
|
||||||
|
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
FROM debian:13.6
|
||||||
|
|
||||||
|
ENV DEBIAN_FRONTEND=noninteractive
|
||||||
|
|
||||||
|
RUN apt update && apt install -y --no-install-recommends\
|
||||||
|
curl wget vim \
|
||||||
|
ca-certificates \
|
||||||
|
build-essential cmake libvulkan-dev glslc spirv-headers libssl-dev git \
|
||||||
|
mesa-utils mesa-vulkan-drivers \
|
||||||
|
supervisor \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
ADD --chmod=755 entrypoint.sh /
|
||||||
|
|
||||||
|
ENTRYPOINT ["/entrypoint.sh"]
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
WORKSPACE="${WORKSPACE:-/workspace}"
|
||||||
|
CONF=$WORKSPACE/supervisord.conf
|
||||||
|
|
||||||
|
[[ -f "$CONF" ]] || (echo_supervisord_conf > $CONF )
|
||||||
|
|
||||||
|
exec supervisord -n -c $CONF "$@"
|
||||||
@@ -84,9 +84,10 @@ subnets would fail routing lookup with "net unreachable" without it.
|
|||||||
|
|
||||||
| Destination | Source | Distance | Active when |
|
| Destination | Source | Distance | Active when |
|
||||||
|---|---|---|---|
|
|---|---|---|---|
|
||||||
| `0.0.0.0/0` | static via `pppoe-gpon` | 1 | GPON up |
|
| `1.0.0.1/32`, `8.8.4.4/32` | static via `pppoe-gpon` | 1 | always |
|
||||||
|
| `0.0.0.0/0` | static via `1.0.0.1`, `8.8.4.4` (recursive) | 1, 2 | GPON ping check succeeds |
|
||||||
| `0.0.0.0/0` | BGP from D-Link via `192.168.6.2` | 200 | wwan up on D-Link |
|
| `0.0.0.0/0` | BGP from D-Link via `192.168.6.2` | 200 | wwan up on D-Link |
|
||||||
| `2000::/3` | static via `sit1` (HE tunnel) | 1 | sit1 active (HE tunnel works) |
|
| `2000::/3` | static via `2001:470:70:dd::1` (HE tunnel) | 1 | HE tunnel ping check succeeds |
|
||||||
| `2000::/3` | BGP from D-Link via `2001:470:61a3:600::2` | 200 | wwan up on D-Link |
|
| `2000::/3` | BGP from D-Link via `2001:470:61a3:600::2` | 200 | wwan up on D-Link |
|
||||||
|
|
||||||
RouterOS distance comparison is straightforward: distance 1 always wins
|
RouterOS distance comparison is straightforward: distance 1 always wins
|
||||||
@@ -136,11 +137,12 @@ preferred route for D-Link's own traffic.
|
|||||||
- **wwan modem goes down** → BIRD2 device protocol detects wwan0 down →
|
- **wwan modem goes down** → BIRD2 device protocol detects wwan0 down →
|
||||||
static `lte_default` / `lte_default6` become unreachable → BGP withdraws
|
static `lte_default` / `lte_default6` become unreachable → BGP withdraws
|
||||||
announcements → CRS removes BGP-learned default
|
announcements → CRS removes BGP-learned default
|
||||||
- **GPON drops** → `pppoe-gpon` interface down → CRS distance-1 default
|
- **GPON drops or blackholes** → recursive ping checks (1.0.0.1, 8.8.4.4) over `pppoe-gpon`
|
||||||
route inactive → distance-200 BGP route activates → CRS withdraws its
|
fail (takes ~20s: 10s ping interval + 10s timeout) → CRS distance-1/2 default routes inactive → distance-200 BGP route
|
||||||
default-originate announcement to D-Link (since no default is installed
|
activates → CRS withdraws its default-originate announcement to D-Link (loop
|
||||||
any more) → D-Link's kernel default-via-CRS is removed → D-Link uses
|
prevention prevents reflecting D-Link's own route) → D-Link's kernel
|
||||||
wwan kernel default → traffic flows from CRS via vlan6 → D-Link → wwan
|
default-via-CRS is removed → D-Link uses wwan kernel default → traffic flows
|
||||||
|
from CRS via vlan6 → D-Link → wwan
|
||||||
|
|
||||||
All transitions are automatic and driven by interface state. No active
|
All transitions are automatic and driven by interface state. No active
|
||||||
probing (Netwatch / mwan3), no scripts toggling routes.
|
probing (Netwatch / mwan3), no scripts toggling routes.
|
||||||
@@ -241,6 +243,16 @@ QMI initialization within ~1 second.
|
|||||||
|
|
||||||
Full investigation: see [wwan-bm806c-qmi-workaround.md](./wwan-bm806c-qmi-workaround.md).
|
Full investigation: see [wwan-bm806c-qmi-workaround.md](./wwan-bm806c-qmi-workaround.md).
|
||||||
|
|
||||||
|
## Multi-WAN Stale Connection Tracking
|
||||||
|
|
||||||
|
When the routing table fails over from GPON to LTE (or vice versa), RouterOS does not automatically clear existing connection tracking entries. If an established TCP/UDP connection is routed out the new WAN interface, it retains the NAT translation state (source IP) of the old WAN interface. The packet is sent to the ISP with the wrong source IP and is silently dropped, causing clients (like Tailscale) to hang for minutes until their internal sockets time out.
|
||||||
|
|
||||||
|
To solve this purely declaratively without scripts or blanket connection flushes, the `forward` chain is configured to "fast-fail" these shifted connections:
|
||||||
|
|
||||||
|
1. Connections are marked with their egress WAN upon establishment (`wan-gpon` or `wan-lte`) via the `mangle` table.
|
||||||
|
2. If an established connection with a `wan-gpon` mark attempts to route out `vlan6` (LTE), or a `wan-lte` mark routes out `pppoe-gpon`, it is explicitly rejected (`tcp-reset` for TCP, `icmp-network-unreachable` for UDP) before reaching the NAT table.
|
||||||
|
3. This rejection immediately signals the client OS that the route is dead, forcing the application (Tailscale, SIP clients, etc.) to instantly close the socket and establish a new one, which successfully binds to the new WAN interface and NAT state.
|
||||||
|
|
||||||
## Implementation files
|
## Implementation files
|
||||||
|
|
||||||
| File | Role |
|
| File | Role |
|
||||||
|
|||||||
+1
-1
@@ -50,7 +50,7 @@ Network is divided to multiple VLANs to enforce strict access control rules usin
|
|||||||
Internet access only<br>
|
Internet access only<br>
|
||||||
IP: 192.168.5.0/24 / 2001:470:61a3:a::/64<br>
|
IP: 192.168.5.0/24 / 2001:470:61a3:a::/64<br>
|
||||||
Gateway: 192.168.5.1 / 2001:470:61a3:a:ffff:ffff:ffff:ffff<br>
|
Gateway: 192.168.5.1 / 2001:470:61a3:a:ffff:ffff:ffff:ffff<br>
|
||||||
DHCP / SLAAC, accessible via separate WiFi network "szafa" from D-Link for absolutely untrusted Tuya and like devices
|
DHCP / SLAAC, accessible via separate, hidden WiFi network "szafa" from D-Link with strict MAC filtering for absolutely untrusted Tuya and like devices
|
||||||
- 6: Internet access for OpenWRT<br>
|
- 6: Internet access for OpenWRT<br>
|
||||||
Internet access only<br>
|
Internet access only<br>
|
||||||
IP: 192.168.6.0/24 / 2001:470:61a3:600::/64<br>
|
IP: 192.168.6.0/24 / 2001:470:61a3:600::/64<br>
|
||||||
|
|||||||
@@ -56,6 +56,7 @@ spec:
|
|||||||
addresses:
|
addresses:
|
||||||
# Not advertising ClusterIP - kubeproxyreplacement should? translate them directly to pod ips
|
# Not advertising ClusterIP - kubeproxyreplacement should? translate them directly to pod ips
|
||||||
# Not advertising ExternalIP - they should be reachable via static config
|
# Not advertising ExternalIP - they should be reachable via static config
|
||||||
|
- ClusterIP
|
||||||
- LoadBalancerIP
|
- LoadBalancerIP
|
||||||
selector:
|
selector:
|
||||||
matchExpressions:
|
matchExpressions:
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: cert-manager-webhook-ovh
|
chart: cert-manager-webhook-ovh
|
||||||
version: 0.9.13
|
version: 0.9.16
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: cert-manager-webhook-ovh
|
name: cert-manager-webhook-ovh
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: cert-manager
|
chart: cert-manager
|
||||||
version: v1.20.2
|
version: v1.21.1
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: cert-manager
|
name: cert-manager
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: cilium
|
chart: cilium
|
||||||
version: 1.19.4
|
version: 1.20.1
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: cilium
|
name: cilium
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: cloudnative-pg
|
chart: cloudnative-pg
|
||||||
version: 0.28.3
|
version: 0.29.0
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: cnpg
|
name: cnpg
|
||||||
|
|||||||
@@ -110,7 +110,7 @@ spec:
|
|||||||
kubernetes.io/os: linux
|
kubernetes.io/os: linux
|
||||||
containers:
|
containers:
|
||||||
- name: coredns
|
- name: coredns
|
||||||
image: registry.k8s.io/coredns/coredns:v1.14.3
|
image: registry.k8s.io/coredns/coredns:v1.14.7
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
args: ["-conf", "/etc/coredns/Corefile"]
|
args: ["-conf", "/etc/coredns/Corefile"]
|
||||||
ports:
|
ports:
|
||||||
|
|||||||
@@ -97,7 +97,7 @@ spec:
|
|||||||
env:
|
env:
|
||||||
- name: GOMEMLIMIT
|
- name: GOMEMLIMIT
|
||||||
value: 161MiB
|
value: 161MiB
|
||||||
image: registry.k8s.io/coredns/coredns:v1.14.3
|
image: registry.k8s.io/coredns/coredns:v1.14.7
|
||||||
imagePullPolicy: IfNotPresent
|
imagePullPolicy: IfNotPresent
|
||||||
livenessProbe:
|
livenessProbe:
|
||||||
failureThreshold: 5
|
failureThreshold: 5
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: k8up
|
chart: k8up
|
||||||
version: 4.9.0
|
version: 4.10.0
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: k8up-io
|
name: k8up-io
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: openbao
|
chart: openbao
|
||||||
version: 0.28.3
|
version: 0.29.4
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: openbao
|
name: openbao
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: openebs
|
chart: openebs
|
||||||
version: 4.5.0
|
version: 4.5.1
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: openebs
|
name: openebs
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ spec:
|
|||||||
chart:
|
chart:
|
||||||
spec:
|
spec:
|
||||||
chart: vault-secrets-operator
|
chart: vault-secrets-operator
|
||||||
version: 1.4.0
|
version: 1.5.1
|
||||||
sourceRef:
|
sourceRef:
|
||||||
kind: HelmRepository
|
kind: HelmRepository
|
||||||
name: hashicorp
|
name: hashicorp
|
||||||
|
|||||||
+13
-1
@@ -11,6 +11,18 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"prHourlyLimit": 9,
|
"prHourlyLimit": 9,
|
||||||
|
"customManagers": [
|
||||||
|
{
|
||||||
|
"customType": "regex",
|
||||||
|
"fileMatch": [
|
||||||
|
"apps/.+\\.yaml$"
|
||||||
|
],
|
||||||
|
"matchStrings": [
|
||||||
|
"tag:\\s*[\"']?(?<currentValue>[^\"' \\n]+)[\"']?\\s*#\\s*renovate:\\s*(?:datasource=(?<datasource>[^\\s]+)\\s+)?depName=(?<depName>[^\\s]+)(?:\\s+registryUrl=(?<registryUrl>[^\\s]+))?"
|
||||||
|
],
|
||||||
|
"datasourceTemplate": "{{#if datasource}}{{{datasource}}}{{else}}docker{{/if}}"
|
||||||
|
}
|
||||||
|
],
|
||||||
"packageRules": [
|
"packageRules": [
|
||||||
{
|
{
|
||||||
"matchPackageNames": ["usekaneo/kaneo", "ghcr.io/usekaneo/kaneo"],
|
"matchPackageNames": ["usekaneo/kaneo", "ghcr.io/usekaneo/kaneo"],
|
||||||
@@ -25,7 +37,7 @@
|
|||||||
"platformAutomerge": true
|
"platformAutomerge": true
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"matchUpdateTypes": ["patch"],
|
"matchUpdateTypes": ["patch", "digest"],
|
||||||
"automerge": true,
|
"automerge": true,
|
||||||
"automergeType": "pr",
|
"automergeType": "pr",
|
||||||
"platformAutomerge": true
|
"platformAutomerge": true
|
||||||
|
|||||||
@@ -28,3 +28,4 @@ machine:
|
|||||||
# arrives too late. Work around using kernel args:
|
# arrives too late. Work around using kernel args:
|
||||||
extraKernelArgs:
|
extraKernelArgs:
|
||||||
- amdgpu.runpm=1
|
- amdgpu.runpm=1
|
||||||
|
- amdgpu.lockup_timeout=0,120000,0,0
|
||||||
|
|||||||
@@ -1,3 +1,7 @@
|
|||||||
path "secret/data/authentik/kaneo" {
|
path "secret/data/authentik/kaneo" {
|
||||||
capabilities = ["read"]
|
capabilities = ["read"]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
path "secret/data/kaneo" {
|
||||||
|
capabilities = ["read"]
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user