mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 21:27:48 +08:00
1.9 KiB
1.9 KiB
Kubernetes
This folder holds the kubernetes GitOps configuration for the maintainers' dedicated server. It manages services such as the demo instance and preview environments.
Bootstrap
- Boot the Hetzner server into the recovery image and connect via SSH
- Install debian 12 through https://github.com/terem42/zfs-hetzner-vm (note this issue comment)
- Ssh into the new install
- Install k3s with this command:
curl -sfL https://get.k3s.io | sh -s - --disable-cloud-controller --disable-helm-controller --disable=traefik,local-storage,servicelb --tls-san 'mich.immich.cloud'
- Grab the kubeconfig file:
scp mich:/etc/rancher/k3s/k3s.yaml ~/.kube/mich.kubeconfig - Enter the user credentials from the kubeconfig into 1password.
- Bootstrap the onepassword operator (See secrets bootstrapping)
- Bootstrap flux:
kubectl apply --kustomize ./bootstrap - Apply the cluster config:
kubectl apply --kustomize ./flux/config
Secrets bootstrapping
This cluster uses the 1password operator for secrets management. To bootstrap:
- Download the 1password-credentials.json file from 1password to a temporary folder
- Copy the 1password connect access token from the vault
- Beware sneaky trailing newlines in the access token, they will ruin your life.
- Create the namespace and secret:
kubectl create namespace secrets
kubectl create secret generic -n secrets onepassword-api --from-literal=session="$(base64 1password-credentials.json)" --from-literal=token="<ACCESSTOKEN>"
rm 1password-credentials.json
Manual setup
The following things have been set up manually on the debian host.
Installed packages:
- unattended-upgrades
Commands:
- Created zfs volumes for kubernetes storage
zfs create rpool/k8s zfs create rpool/k8s/volumes zfs create rpool/k8s/snapshots