Scooby Husky and Claude Opus 4.6
5163403e24
Scale down non-critical replicas for homelab resource savings
...
Reduce replicas to 1 for workloads that don't need HA in a homelab:
- Prometheus 2→1, Alertmanager 2→1 (~4.4GB RAM saved)
- cert-manager 3→1
- GitLab: registry 2→1, kas 2→1, sidekiq 2→1, praefect 2→1,
pgbouncer-ro 3→1
- Guacamole + guacd 2→1
- Kiali 2→1, ArgoCD server 2→1
- Kyverno background-controller 2→1
- Scylla operator 2→1
- ext-authz-proxy 2→1, netbird-cluster-router 2→1
Kept multi-replica: coredns, envoy-gateway, kyverno admission,
vault, argocd-repo-server, gitlab-webservice, istiod, rook-ceph CSI.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 23:00:48 -05:00
Scooby Husky and Claude Opus 4.6
7eae427d1a
Scale services to 2+ replicas for HA
...
- ArgoCD: server and repo-server → 2 replicas
- GitLab: webservice, sidekiq, registry, KAS, praefect → min 2 replicas
- Guacamole: client and guacd → 2 replicas
- Kiali: 1 → 2 replicas
- Alertmanager: add 2 replicas
- TeslaMate CNPG: 1 → 2 instances
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-15 03:08:49 -05:00
Scooby Husky and Claude Opus 4.6
c5e13377bd
Fix talos client key PEM header for nginx compatibility
...
ED25519 PRIVATE KEY header is not recognized by nginx's OpenSSL.
Convert to standard PKCS#8 PRIVATE KEY header (same DER content).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 20:31:31 -05:00
Scooby Husky and Claude Opus 4.6
6646943a98
Fix talos-client-cert secret namespace
...
Secret was in prometheus namespace but the talos-metrics-proxy
deployment referencing it runs in kube-system namespace.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 20:00:36 -05:00
Scooby Husky and Claude Opus 4.6
131cbca4a6
Fix ArgoCD ServerSideDiff permanent OutOfSync diffs
...
Add explicit CRD/API defaults to manifests that were causing ArgoCD's
SSA dry-run to produce results different from live state:
- HTTPRoutes: add group, kind, weight defaults to parentRefs/backendRefs
- Kyverno ClusterPolicies: add skipBackgroundRequests, allowExistingViolations
- Tetragon TracingPolicies: add return, maxData, resolve, returnCopy defaults
- Gateway certificateRefs: add group="" default
- Guacamole Gateway: add group="" to certificateRefs
Add ignoreDifferences for resources that legitimately differ:
- Cilium cert Secrets (auto-generated, data always differs)
- Istio ValidatingWebhookConfiguration failurePolicy (istiod mutates)
- Crowdsec LAPI Secrets (randomly generated)
- ServiceMonitor/PodMonitor relabeling action defaults
- StatefulSet volumeClaimTemplates apiVersion/kind defaults
Persist argocd-cm ignoreDifferences config in ArgoCD Helm values.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 17:32:59 -05:00
Scooby Husky and Claude Opus 4.6
ce23f9282c
Fix prometheus secret namespace and frigate capabilities
...
- Revert talos-client-cert secret to prometheus namespace (prometheus
pods mount this secret, not kube-system pods)
- Add CHOWN/DAC_OVERRIDE/SETUID/SETGID capabilities to frigate
(s6-overlay needs chown for log directories)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 05:59:23 -05:00
Scooby Husky and Claude Opus 4.6
aff4ce7441
Fix talos-client-cert secret namespace to match deployment (kube-system)
...
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-10 04:17:03 -05:00
Scooby Husky
aacb8eebbe
Initial commit
2026-03-09 20:21:35 -05:00