# MinIO on the VPS - shared backup-receiver bucket for the vps-standby site. # Standalone mode: single node, single VPS disk, no erasure coding needed here - # this is a backup *copy*, not itself something requiring HA. # # Root credentials come from a pre-existing Secret created manually on the # VPS cluster (kubectl, not git - matches how other VPS bootstrap secrets # are handled, since this cluster has no Vault/ESO of its own to source an # ExternalSecret from): # kubectl -n minio create secret generic vps-minio-root-secret \ # --from-literal=rootUser= --from-literal=rootPassword= # # Originally left rootUser/rootPassword unset entirely, relying on the # chart's auto-generation - broke in a way that took a while to trace: # ArgoCD renders Helm charts via `helm template`, which does NOT support # the `lookup` function charts normally use to preserve an existing # auto-generated secret across upgrades (that only works with real `helm # upgrade`). Every ArgoCD sync (selfHeal: true, so this means constantly) # re-rendered a BRAND NEW random root password, immediately invalidating # whatever credentials were stored in the home cluster's Vault for the # backup/CronJob consumers (vault-raft-snapshot, CNPG barmanObjectStore # x3, nextcloud-pvc-sync) - confirmed live 2026-08-18, all of them failing # with "Access Key Id does not exist" despite having just been fixed. mode: standalone existingSecret: vps-minio-root-secret persistence: enabled: true storageClass: local-path size: 150Gi # budget out of the VPS's 360GB disk; leaves room for Phase 2 standby PVCs resources: requests: cpu: 50m memory: 256Mi limits: cpu: 500m memory: 1Gi # Buckets used by the backup/standby plumbing (Phase 1b / Phase 2). Created on # first deploy; safe to append to as later phases land. buckets: - name: vault-raft-snapshots policy: none purge: false - name: cnpg-backups policy: none purge: false - name: nextcloud-files policy: none purge: false # No ingress here - MinIO is reached over Netbird (while home is up) or from # workloads inside the vps-standby cluster itself. It never needs to be public. ingress: enabled: false # NodePort so home-cluster CronJobs (vault raft snapshots, CNPG barman backups, # Nextcloud PVC sync) can reach this over the Netbird tunnel at # :30900 - single-node cluster, so NodePort is simplest here. # Verify the exact key path against `helm show values minio/minio` for the # deployed chart version (5.4.0) before applying - not confirmed live. service: type: NodePort nodePort: 30900 metrics: serviceMonitor: enabled: false # no Prometheus on the VPS cluster (out of scope for this build)