Add VPS warm-standby/backup site (Phase 0-1b)

Foundation for a DR/backup path using an always-on VPS as a second
ArgoCD-managed cluster, plus DB/backup standardization work that fell
out of it:

- vps-standby ArgoCD cluster destination + AppProject, MinIO backup
  receiver, VPS bootstrap script (k3s, Netbird, cert-manager)
- Dual-site DNS failover watcher + home-IP DDNS CronJob, Cloudflare
  token moved out of git into Vault+ExternalSecret
- Nextcloud migrated from ad-hoc MariaDB to CNPG + redis-operator
  (matches n8n/Authentik/GitLab's backup-native pattern)
- Authentik's CNPG manifests moved into the actual ArgoCD-synced
  manifests/ path (were present but never wired into the sync path)
- Vault raft-snapshot CronJob, CNPG barmanObjectStore backups
  (Authentik/n8n/Nextcloud), Nextcloud file-PVC restic sync - all
  targeting the new VPS MinIO receiver

See VPS Warm-Standby plan doc for full design rationale.
This commit is contained in:
Scooby Husky
2026-08-17 14:59:26 -05:00
parent 5163403e24
commit 7990f1fa47
25 changed files with 1161 additions and 139 deletions
+26 -6
View File
@@ -73,16 +73,27 @@ nextcloud:
externalDatabase:
enabled: true
type: mysql
host: mariadb-nextcloud
port: 3306
# Moved from MariaDB to CNPG-backed Postgres (apps/nextcloud/manifests/cnpg-cluster.yaml)
# for backup/DR consistency with the rest of the stack (n8n, Authentik, GitLab
# all use CNPG's native barmanObjectStore backup - MariaDB needed a bespoke
# mysqldump job instead). pg-nextcloud-rw is CNPG's generated read-write
# Service name for the "pg-nextcloud" Cluster.
#
# IMPORTANT: switching type here does NOT migrate existing data. Nextcloud
# requires an explicit `occ db:convert-type pgsql ...` run before cutover if
# there's real data in the old MariaDB instance. usernameKey/passwordKey below
# match CNPG's generated app-secret keys (confirmed against the existing,
# already-working infrastructure/authentik/values.yaml pg-authentik-app usage).
type: postgresql
host: pg-nextcloud-rw
port: 5432
user: nextcloud
database: nextcloud
existingSecret:
enabled: true
secretName: mariadb-nextcloud
secretName: pg-nextcloud-app
passwordKey: password
usernameKey: user
usernameKey: username # matches CNPG's generated app-secret key, confirmed against infrastructure/authentik/values.yaml's existing pg-authentik-app usage
persistence:
enabled: true
@@ -99,7 +110,16 @@ resources:
memory: 2Gi
redis:
enabled: false
# Was disabled; now points at the standalone Redis CR (redis-operator) in
# apps/nextcloud/manifests/redis-cr.yaml instead of the chart's bundled
# subchart - fixes Nextcloud's file-locking/caching as a side benefit of
# this migration. Verify these key names against `helm show values
# nextcloud/nextcloud` for the deployed chart version before applying.
enabled: true
host: redis-nextcloud
port: 6379
existingSecret: redis-nextcloud-secret
existingSecretPasswordKey: password
metrics:
enabled: false