Homelab GitOps apps for Argo CD (Uptime Kuma, migrations to K3s). Source of truth mirrored to Forgejo.
Find a file
Еркин Даниил Артурович f9995e19cc fix comment
2026-09-11 14:37:08 +03:00
applications выпилили телепрокси 2026-09-03 18:03:14 +03:00
apps fix comment 2026-09-11 14:37:08 +03:00
bootstrap Document dual-push to GitLab and Forgejo dan4eg. 2026-08-12 00:02:25 +03:00
.gitignore Initial gitops-apps: Argo app-of-apps and Uptime Kuma. 2026-08-11 04:28:40 +10:00
README.md выпилили телепрокси 2026-09-03 18:03:14 +03:00

gitops-apps

Манифесты приложений для Argo CD на homelab K3s (VIE).

Инфраструктура (K3s, Argo CD, Forgejo, cert-manager) — в репозитории ansible.
Сюда кладём только apps.

Источники Git

Роль URL
Fetch / история на ноуте https://kurrrwa.ddns.net/dan4eg/gitops-apps.git (GitLab :443)
Always-on source для Argo https://git.yorkin.online/dan4eg/gitops-apps.git (Forgejo)

Один apps-репо: dan4eg/gitops-apps. Репы под forgejo_admin в схеме нет.

Argo CD смотрит только на Forgejo (с VIE до GitLab на ноуте нет стабильного пути).

Dual-push (локальный origin)

Один git push origin уезжает и в GitLab, и в Forgejo — оба по HTTPS:

cd /Users/daniil/projects/gitops-apps

git remote remove origin 2>/dev/null || true
git remote add origin https://kurrrwa.ddns.net/dan4eg/gitops-apps.git
git remote set-url --add --push origin https://kurrrwa.ddns.net/dan4eg/gitops-apps.git
git remote set-url --add --push origin https://git.yorkin.online/dan4eg/gitops-apps.git

# опционально: пуш только в Forgejo
git remote add forgejo https://git.yorkin.online/dan4eg/gitops-apps.git

git remote -v
git push origin main

Auth: macOS Keychain (git credential-osxkeychain). Для GitLab нужен token с write_repository (не readonly migrate-token).

Pull mirror / GitLab→Forgejo mirror не нужны.

Дерево

bootstrap/
  root.yaml                 # App-of-apps (один раз применить в argocd)
applications/
  monitoring.yaml           # Application → apps/monitoring
  telemt.yaml               # Application → apps/telemt (WEB MTProto)
  tg-cursor-bridge.yaml     # Application → apps/tg-cursor-bridge
  vikunja.yaml              # Application → apps/vikunja
apps/
  monitoring/               # Uptime Kuma + reconciler
  telemt/                   # Telemt WEB за Traefik Ingress (kurrrwa.yorkin.online)
  tg-cursor-bridge/         # Telegram → Cursor webhook bridge
  vikunja/                  # Vikunja + Postgres (бывший docker-compose на FIN)
  migrations/               # место под перенос docker-compose apps в K3s

Bootstrap Argo CD

Credentials репо в Argo → Forgejo dan4eg/gitops-apps, затем:

kubectl apply -n argocd -f bootstrap/root.yaml

Root Application следит за applications/ и создаёт дочерние apps (auto-sync).

Monitoring: Uptime Kuma

  • UI: https://uptime.yorkin.online (DNS A → IP VIE 152.53.95.181)
  • TLS: cert-manager letsencrypt-prod + Traefik
  • Namespace: monitoring

VoiceCounter (Push Monitor)

У бота нет HTTP endpoint — мониторим через Push в Uptime Kuma:

  1. В UI Kuma: Add Monitor → Push → interval (например 60s).
  2. Скопировать Push URL вида https://uptime.yorkin.online/api/push/<token>.
  3. На хосте VoiceCounter (FIN) периодически дергать URL (cron / sidecar / в самом боте):
curl -fsS -o /dev/null "https://uptime.yorkin.online/api/push/<token>?status=up&msg=OK&ping="

Секрет push-токена не хранить в этом репо.

tg-cursor-bridge

Telegram Bot webhook → Cursor Automation. Namespace: tg-cursor-bridge.

  • URL: https://tg.yorkin.online (DNS A → IP VIE 152.53.95.181)
  • TLS: cert-manager letsencrypt-prod + Traefik
  • Image: git.yorkin.online/dan4eg/tg-cursor-bridge:0.1.1
  • Секреты не в git. Создать на кластере до (или сразу после) sync:
kubectl create namespace tg-cursor-bridge --dry-run=client -o yaml | kubectl apply -f -

kubectl -n tg-cursor-bridge create secret generic tg-cursor-bridge \
  --from-literal=TELEGRAM_BOT_TOKEN='...' \
  --from-literal=TELEGRAM_SECRET_TOKEN='...' \
  --from-literal=TELEGRAM_CHAT_ID='...' \
  --from-literal=CURSOR_WEBHOOK_URL='...' \
  --from-literal=CURSOR_WEBHOOK_TOKEN='...' \
  --from-literal=CURSOR_ROUTES='[]'

kubectl -n tg-cursor-bridge create secret docker-registry forgejo-registry \
  --docker-server=git.yorkin.online \
  --docker-username='...' \
  --docker-password='...'

CURSOR_ROUTES можно опустить, если достаточно дефолтной пары URL/token. Без tg-cursor-bridge под не стартует; без forgejo-registry не стянет образ.

Telegram webhook:

curl -X POST "https://api.telegram.org/bot${TELEGRAM_BOT_TOKEN}/setWebhook" \
  -d "url=https://tg.yorkin.online/telegram" \
  -d "secret_token=${TELEGRAM_SECRET_TOKEN}"

Vikunja

  • UI/API: https://yorkin.online (DNS A → IP VIE 152.53.95.181)
  • TLS: cert-manager letsencrypt-prod + Traefik
  • Namespace: vikunja
  • Image: vikunja/vikunja:2.3.0 + postgres:16-alpine
  • Секреты не в git. Создать на кластере до sync:
kubectl create namespace vikunja --dry-run=client -o yaml | kubectl apply -f -

kubectl -n vikunja create secret generic vikunja \
  --from-literal=POSTGRES_PASSWORD='...' \
  --from-literal=VIKUNJA_DATABASE_PASSWORD='...' \
  --from-literal=VIKUNJA_SERVICE_JWTSECRET='...'

Без Secret под Postgres не стартует. JWT и пароль БД — те же, что были на FIN (/opt/vikunja). Данные: PVC vikunja-postgres и vikunja-files (local-path).

DNS (осталось для публичного HTTPS): в Cloudflare A yorkin.online → 152.53.95.181, прокси выключить (DNS only, как git.yorkin.online), AAAA на apex убрать. После этого cert-manager выпустит vikunja-tls.

После cutover ansible-плейбук deploy_vikunja.yml на FIN не гонять — он снова поднимет compose на :80/:443.

Telemt (MTProto WEB)

Не FakeTLS и не hostPort :443. Traefik по-прежнему терминирует TLS на 443; Telemt слушает только ClusterIP HTTP/1.1 :18080. Контракт: Telemt WEB_PROXY.

  • Image: ghcr.io/telemt/telemt:3.5.5
  • Namespace: teleproxy (историческое имя; Secret teleproxy / SECRET)
  • Публичный vhost: kurrrwa.yorkin.online (весь Host, не path-split)
  • public_addr: 152.53.95.181:443
  • Decoy: статическая страница
  • Carrier: https (fallback) + negotiation https-lanes / websocket
  • Секрет в ссылке: dd + 32 hex. Префикс ee в WEB не поддерживается

DNS не в этом репо: Cloudflare A kurrrwa.yorkin.online → 152.53.95.181, DNS only, без AAAA. Без записи cert-manager не выпустит сертификат.

Клиент: Telegram Desktop 7.1.1+, тип прокси WEB. Ссылка без порта:

tg://webproxy?server=kurrrwa.yorkin.online&secret=dd<32 hex>

Старая tg://proxy?server=152.53.95.181&port=443&secret=ee…yorkin.online к этому режиму не относится.

32 hex — тот же ключ, что в Secret (без ee и без hex-домена). Если Secret ещё нет:

kubectl -n teleproxy create secret generic teleproxy \
  --from-literal=SECRET='<32 hex>'

Миграции в K3s

Каталог apps/migrations/ — для следующих сервисов (VoiceCounter и т.д.).
Паттерн: манифесты/kustomize под apps/<name>/ + applications/<name>.yaml.