Skip to content

feat: add Authelia OIDC provider (lldap backend, Immich client)#4

Merged
swares merged 1 commit into
mainfrom
feat/authelia
Jun 28, 2026
Merged

feat: add Authelia OIDC provider (lldap backend, Immich client)#4
swares merged 1 commit into
mainfrom
feat/authelia

Conversation

@swares

@swares swares commented Jun 28, 2026

Copy link
Copy Markdown
Owner

go

@swares
swares merged commit d065af7 into main Jun 28, 2026
2 checks passed
swares added a commit that referenced this pull request Jul 22, 2026
* docs: add SSO.md — OIDC status, notes, and patterns for all lab services

* docs: apply audit corrections

- CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles
- ARCHITECTURE.md: add Reloader and Zot to services table
- HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker)
- WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry
- services.md: add Reloader and Zot entries
- STANDUP.md: remove Proxmox API token ref; archive Phase 5
- LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented)
swares added a commit that referenced this pull request Jul 22, 2026
* docs: add SSO.md — OIDC status, notes, and patterns for all lab services

* docs: apply audit corrections

- CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles
- ARCHITECTURE.md: add Reloader and Zot to services table
- HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker)
- WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry
- services.md: add Reloader and Zot entries
- STANDUP.md: remove Proxmox API token ref; archive Phase 5
- LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented)

* fix(authelia): remove orphaned authelia-data PVC

The PVC was never mounted by the Deployment (only config and secrets
volumes are used). It has been Pending for 3 days as local-path waits
for a consumer that never arrives, causing ArgoCD to report the app as
Progressing indefinitely.

No data loss risk: the PVC was never bound.
swares added a commit that referenced this pull request Jul 22, 2026
…nostics (#273)

* docs: add SSO.md — OIDC status, notes, and patterns for all lab services

* docs: apply audit corrections

- CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles
- ARCHITECTURE.md: add Reloader and Zot to services table
- HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker)
- WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry
- services.md: add Reloader and Zot entries
- STANDUP.md: remove Proxmox API token ref; archive Phase 5
- LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented)

* fix(authelia): remove orphaned authelia-data PVC

The PVC was never mounted by the Deployment (only config and secrets
volumes are used). It has been Pending for 3 days as local-path waits
for a consumer that never arrives, causing ArgoCD to report the app as
Progressing indefinitely.

No data loss risk: the PVC was never bound.

* docs: update GITOPS-STUDY-GUIDE with Reloader, orphaned PVC, and ArgoCD health diagnostics

- Add Reloader section (Section 4): explains Stakater Reloader annotation and
  which deployments carry it (Authelia, Semaphore, Zot)
- Expand ArgoCD Progressing diagnostic: add jq resource-health query and
  app controller log command before the hard refresh step
- Expand PVC Pending cause: distinguish orphaned PVC (no consumer, stays
  Pending forever with WaitForFirstConsumer) from provisioner errors;
  document the fix (delete manifest, ArgoCD prune cleans it up)
swares added a commit that referenced this pull request Jul 22, 2026
…#274)

* docs: add SSO.md — OIDC status, notes, and patterns for all lab services

* docs: apply audit corrections

- CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles
- ARCHITECTURE.md: add Reloader and Zot to services table
- HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker)
- WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry
- services.md: add Reloader and Zot entries
- STANDUP.md: remove Proxmox API token ref; archive Phase 5
- LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented)

* fix(authelia): remove orphaned authelia-data PVC

The PVC was never mounted by the Deployment (only config and secrets
volumes are used). It has been Pending for 3 days as local-path waits
for a consumer that never arrives, causing ArgoCD to report the app as
Progressing indefinitely.

No data loss risk: the PVC was never bound.

* docs: update GITOPS-STUDY-GUIDE with Reloader, orphaned PVC, and ArgoCD health diagnostics

- Add Reloader section (Section 4): explains Stakater Reloader annotation and
  which deployments carry it (Authelia, Semaphore, Zot)
- Expand ArgoCD Progressing diagnostic: add jq resource-health query and
  app controller log command before the hard refresh step
- Expand PVC Pending cause: distinguish orphaned PVC (no consumer, stays
  Pending forever with WaitForFirstConsumer) from provisioner errors;
  document the fix (delete manifest, ArgoCD prune cleans it up)

* feat(backup): add daily cloud backup of critical cluster state to R2

Installs backup-cloud.service + timer on H4 (runs 03:00 UTC daily).

What gets backed up offsite (Cloudflare R2, free 10GB tier):
  - k3s etcd snapshots
  - lldap DB snapshots
  - Vault raft snapshots (if present)
  - Postgres dumps: Authelia, Immich, Semaphore (via kubectl exec)

Total estimated size: well under 2GB. Restic retention: 7 daily,
4 weekly, 3 monthly. Credentials read from Vault at secret/lab/cloudflare-r2.

Closes the single-location gap for cluster state — NAS media stays
on the two cold-tier RAID disks (Track 2 decision pending).
swares added a commit that referenced this pull request Jul 22, 2026
* docs: add SSO.md — OIDC status, notes, and patterns for all lab services

* docs: apply audit corrections

- CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles
- ARCHITECTURE.md: add Reloader and Zot to services table
- HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker)
- WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry
- services.md: add Reloader and Zot entries
- STANDUP.md: remove Proxmox API token ref; archive Phase 5
- LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented)

* fix(authelia): remove orphaned authelia-data PVC

The PVC was never mounted by the Deployment (only config and secrets
volumes are used). It has been Pending for 3 days as local-path waits
for a consumer that never arrives, causing ArgoCD to report the app as
Progressing indefinitely.

No data loss risk: the PVC was never bound.

* docs: update GITOPS-STUDY-GUIDE with Reloader, orphaned PVC, and ArgoCD health diagnostics

- Add Reloader section (Section 4): explains Stakater Reloader annotation and
  which deployments carry it (Authelia, Semaphore, Zot)
- Expand ArgoCD Progressing diagnostic: add jq resource-health query and
  app controller log command before the hard refresh step
- Expand PVC Pending cause: distinguish orphaned PVC (no consumer, stays
  Pending forever with WaitForFirstConsumer) from provisioner errors;
  document the fix (delete manifest, ArgoCD prune cleans it up)

* feat(backup): add daily cloud backup of critical cluster state to R2

Installs backup-cloud.service + timer on H4 (runs 03:00 UTC daily).

What gets backed up offsite (Cloudflare R2, free 10GB tier):
  - k3s etcd snapshots
  - lldap DB snapshots
  - Vault raft snapshots (if present)
  - Postgres dumps: Authelia, Immich, Semaphore (via kubectl exec)

Total estimated size: well under 2GB. Restic retention: 7 daily,
4 weekly, 3 monthly. Credentials read from Vault at secret/lab/cloudflare-r2.

Closes the single-location gap for cluster state — NAS media stays
on the two cold-tier RAID disks (Track 2 decision pending).

* fix(backup): escape bash array syntax that conflicts with Jinja2 comment tags
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant