Scooby Husky and Claude Opus 4.6
5163403e24
Scale down non-critical replicas for homelab resource savings
...
Reduce replicas to 1 for workloads that don't need HA in a homelab:
- Prometheus 2→1, Alertmanager 2→1 (~4.4GB RAM saved)
- cert-manager 3→1
- GitLab: registry 2→1, kas 2→1, sidekiq 2→1, praefect 2→1,
pgbouncer-ro 3→1
- Guacamole + guacd 2→1
- Kiali 2→1, ArgoCD server 2→1
- Kyverno background-controller 2→1
- Scylla operator 2→1
- ext-authz-proxy 2→1, netbird-cluster-router 2→1
Kept multi-replica: coredns, envoy-gateway, kyverno admission,
vault, argocd-repo-server, gitlab-webservice, istiod, rook-ceph CSI.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 23:00:48 -05:00
Scooby Husky and Claude Opus 4.6
0c16785116
Fix Guacamole OIDC session persistence via Istio DestinationRule
...
Traffic goes through Istio (not Envoy Gateway), so cookie-based
consistent hashing must be on the Istio DestinationRule. Removes
the unused Envoy Gateway BackendTrafficPolicy.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 15:11:15 -05:00
Scooby Husky and Claude Opus 4.6
f71dbdb689
Add Envoy Gateway cookie-based session persistence for Guacamole OIDC
...
Fixes OIDC nonce validation failures with 2 replicas by using a
BackendTrafficPolicy with cookie-based consistent hashing instead of
Service-level ClientIP affinity (which doesn't work behind Envoy proxy).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 14:55:53 -05:00
Scooby Husky and Claude Opus 4.6
b9fd5a9461
Add session affinity to Guacamole service for OIDC flow
...
With 2 replicas, OIDC callbacks can hit a different pod than the
one that generated the state/nonce, causing auth failures. Session
affinity ensures the same client always reaches the same pod.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 14:47:25 -05:00
Scooby Husky and Claude Opus 4.6
e29eb9611b
Make Authentik the primary login method for Guacamole
...
Change EXTENSION_PRIORITY from "*,openid" to "openid,*" so
unauthenticated users are redirected to Authentik OIDC instead
of seeing the database login form.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 14:24:53 -05:00
Scooby Husky and Claude Opus 4.6
7eae427d1a
Scale services to 2+ replicas for HA
...
- ArgoCD: server and repo-server → 2 replicas
- GitLab: webservice, sidekiq, registry, KAS, praefect → min 2 replicas
- Guacamole: client and guacd → 2 replicas
- Kiali: 1 → 2 replicas
- Alertmanager: add 2 replicas
- TeslaMate CNPG: 1 → 2 instances
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 03:08:49 -05:00
Scooby Husky and Claude Opus 4.6
131cbca4a6
Fix ArgoCD ServerSideDiff permanent OutOfSync diffs
...
Add explicit CRD/API defaults to manifests that were causing ArgoCD's
SSA dry-run to produce results different from live state:
- HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs
- Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations
- Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults
- Gateway certificateRefs: add group="" default
- Guacamole Gateway: add group="" to certificateRefs
Add ignoreDifferences for resources that legitimately differ:
- Cilium cert Secrets (auto-generated, data always differs)
- Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates)
- Crowdsec LAPI Secrets (randomly generated)
- ServiceMonitor/PodMonitor relabeling action defaults
- StatefulSet volumeClaimTemplates apiVersion/kind defaults
Persist argocd-cm ignoreDifferences config in ArgoCD Helm values.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 17:32:59 -05:00
Scooby Husky
086a2bf406
Fix degraded apps: add nessus to project, remove duplicate guacamole route, update prometheus CRDs to v0.89.0
2026-03-09 22:32:15 -05:00
Scooby Husky
aacb8eebbe
Initial commit
2026-03-09 20:21:35 -05:00