diff --git a/templates/kubernetes/volsync/README.md b/templates/kubernetes/volsync/README.md new file mode 100644 index 00000000..6225a481 --- /dev/null +++ b/templates/kubernetes/volsync/README.md @@ -0,0 +1,51 @@ +# VolSync Template + +## Flux Kustomization + +This requires `postBuild` configured on the Flux Kustomization + +```yaml +apiVersion: kustomize.toolkit.fluxcd.io/v1 +kind: Kustomization +metadata: + name: &app immich + namespace: flux-system +spec: + targetNamespace: default + path: ./kubernetes/apps/default/immich/app + prune: true + sourceRef: + kind: GitRepository + name: kubernetes + wait: false + interval: 30m + retryInterval: 1m + timeout: 5m + postBuild: + substitute: + APP: *app + VOLSYNC_CAPACITY: 1Gi + VOLSYNC_REPO_SECRET: immich-volsync +``` + +Then reference this template in the kustomization.yaml + +```yaml +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ./hr.yaml + - ./pvc.yaml + - ../../../../../templates/volsync +``` + +## Required `postBuild` vars: + +- `APP`: The application name +- `VOLSYNC_CAPACITY`: The PVC size +- `VOLSYNC_REPO_SECRET` + The name of the 1password entry holding the appropriate secret values: + - `RESTIC_REPOSITORY` + - `RESTIC_PASSWORD` + - `AWS_ACCESS_KEY_ID` + - `AWS_SECRET_ACCESS_KEY` diff --git a/templates/kubernetes/volsync/kustomization.yaml b/templates/kubernetes/volsync/kustomization.yaml new file mode 100644 index 00000000..37a7bb4b --- /dev/null +++ b/templates/kubernetes/volsync/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ./replication + - ./pvc.yaml diff --git a/templates/kubernetes/volsync/pvc.yaml b/templates/kubernetes/volsync/pvc.yaml new file mode 100644 index 00000000..0b4058a6 --- /dev/null +++ b/templates/kubernetes/volsync/pvc.yaml @@ -0,0 +1,16 @@ +--- +apiVersion: v1 +kind: PersistentVolumeClaim +metadata: + name: "${VOLSYNC_CLAIM:-${APP}}" +spec: + accessModes: + - "${VOLSYNC_ACCESSMODES:-ReadWriteOnce}" + dataSourceRef: + kind: ReplicationDestination + apiGroup: volsync.backube + name: "${APP}-bootstrap" + resources: + requests: + storage: "${VOLSYNC_CAPACITY:-1Gi}" + storageClassName: "zfs" diff --git a/templates/kubernetes/volsync/replication/externalsecret.yaml b/templates/kubernetes/volsync/replication/externalsecret.yaml new file mode 100644 index 00000000..63bd1345 --- /dev/null +++ b/templates/kubernetes/volsync/replication/externalsecret.yaml @@ -0,0 +1,6 @@ +apiVersion: onepassword.com/v1 +kind: OnePasswordItem +metadata: + name: "${VOLSYNC_REPO_SECRET}" +spec: + itemPath: "vaults/Kubernetes/items/${VOLSYNC_REPO_SECRET}" diff --git a/templates/kubernetes/volsync/replication/kustomization.yaml b/templates/kubernetes/volsync/replication/kustomization.yaml new file mode 100644 index 00000000..fb97a433 --- /dev/null +++ b/templates/kubernetes/volsync/replication/kustomization.yaml @@ -0,0 +1,7 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ./externalsecret.yaml + - ./replicationdestination.yaml + - ./replicationsource.yaml diff --git a/templates/kubernetes/volsync/replication/replicationdestination.yaml b/templates/kubernetes/volsync/replication/replicationdestination.yaml new file mode 100644 index 00000000..b0e89593 --- /dev/null +++ b/templates/kubernetes/volsync/replication/replicationdestination.yaml @@ -0,0 +1,19 @@ +--- +# yaml-language-server: $schema=https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/volsync.backube/replicationdestination_v1alpha1.json +apiVersion: volsync.backube/v1alpha1 +kind: ReplicationDestination +metadata: + name: "${APP}-bootstrap" +spec: + trigger: + manual: restore-once + restic: + copyMethod: Snapshot + repository: "${VOLSYNC_REPO_SECRET}" + cacheStorageClassName: "zfs" + cacheCapacity: "${VOLSYNC_CACHE_CAPACITY:-1Gi}" + storageClassName: "zfs" + volumeSnapshotClassName: "zfs" + accessModes: + - "${VOLSYNC_ACCESSMODES:-ReadWriteOnce}" + capacity: "${VOLSYNC_CAPACITY:-1Gi}" diff --git a/templates/kubernetes/volsync/replication/replicationsource.yaml b/templates/kubernetes/volsync/replication/replicationsource.yaml new file mode 100644 index 00000000..35f45e6f --- /dev/null +++ b/templates/kubernetes/volsync/replication/replicationsource.yaml @@ -0,0 +1,22 @@ +--- +# yaml-language-server: $schema=https://raw.githubusercontent.com/datreeio/CRDs-catalog/main/volsync.backube/replicationsource_v1alpha1.json +apiVersion: volsync.backube/v1alpha1 +kind: ReplicationSource +metadata: + name: ${APP} +spec: + sourcePVC: "${VOLSYNC_CLAIM:-${APP}}" + trigger: + schedule: "0 4 * * *" + restic: + copyMethod: Snapshot + repository: "${VOLSYNC_REPO_SECRET}" + cacheStorageClassName: "zfs" + cacheCapacity: "${VOLSYNC_CACHE_CAPACITY:-1Gi}" + storageClassName: "zfs" + volumeSnapshotClassName: "zfs" + pruneIntervalDays: 7 + retain: + hourly: 12 + daily: 7 + weekly: 4