Files
Scooby Husky 7990f1fa47 Add VPS warm-standby/backup site (Phase 0-1b)
Foundation for a DR/backup path using an always-on VPS as a second
ArgoCD-managed cluster, plus DB/backup standardization work that fell
out of it:

- vps-standby ArgoCD cluster destination + AppProject, MinIO backup
  receiver, VPS bootstrap script (k3s, Netbird, cert-manager)
- Dual-site DNS failover watcher + home-IP DDNS CronJob, Cloudflare
  token moved out of git into Vault+ExternalSecret
- Nextcloud migrated from ad-hoc MariaDB to CNPG + redis-operator
  (matches n8n/Authentik/GitLab's backup-native pattern)
- Authentik's CNPG manifests moved into the actual ArgoCD-synced
  manifests/ path (were present but never wired into the sync path)
- Vault raft-snapshot CronJob, CNPG barmanObjectStore backups
  (Authentik/n8n/Nextcloud), Nextcloud file-PVC restic sync - all
  targeting the new VPS MinIO receiver

See VPS Warm-Standby plan doc for full design rationale.
2026-08-17 14:59:26 -05:00

28 lines
795 B
YAML

---
# VPS MinIO credentials for CNPG's barmanObjectStore backup target, and reused
# by the Phase 1b PVC-content sync CronJob. Same Vault source as
# infrastructure/vault/manifests/raft-snapshot-cronjob.yaml
# (secret/vps-minio-credentials) - populated once, manually, after VPS bootstrap.
apiVersion: external-secrets.io/v1
kind: ExternalSecret
metadata:
name: vps-minio-credentials
namespace: nextcloud
spec:
refreshInterval: 1h
secretStoreRef:
kind: ClusterSecretStore
name: vault-backend
target:
name: vps-minio-secret
creationPolicy: Owner
data:
- secretKey: accesskey
remoteRef:
key: vps-minio-credentials
property: access-key
- secretKey: secretkey
remoteRef:
key: vps-minio-credentials
property: secret-key