--- # Exposes the VPS's pg-authentik primary (currently a read-only replica - # see cnpg-cluster.yaml's replica.enabled) to home over the Netbird mesh, # for the multi-site active-failover pilot. Same selector as CNPG's own # generated pg-authentik-rw ClusterIP Service, just NodePort instead. # # Unlike home's side of this (infrastructure/authentik/manifests/ # ha-postgres-nodeport.yaml), no UniFi port-forward or Kyverno # PolicyException needed here - the VPS's k3s has no NodePort # restriction, and home reaching OUT to the VPS already works today via # the netbird-egress DaemonSet's route (confirmed live all session, same # path used for MinIO/CrowdSec) - it's only the reverse direction # (external peers reaching INTO home) that needed the UniFi workaround. apiVersion: v1 kind: Service metadata: name: ha-authentik-postgres namespace: authentik spec: type: NodePort selector: cnpg.io/cluster: pg-authentik cnpg.io/instanceRole: primary ports: - port: 5432 targetPort: 5432 nodePort: 32433