feat: add Authelia OIDC provider (lldap backend, Immich client)#4
Merged
Conversation
swares
added a commit
that referenced
this pull request
Jul 22, 2026
* docs: add SSO.md — OIDC status, notes, and patterns for all lab services * docs: apply audit corrections - CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles - ARCHITECTURE.md: add Reloader and Zot to services table - HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker) - WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry - services.md: add Reloader and Zot entries - STANDUP.md: remove Proxmox API token ref; archive Phase 5 - LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented)
swares
added a commit
that referenced
this pull request
Jul 22, 2026
* docs: add SSO.md — OIDC status, notes, and patterns for all lab services * docs: apply audit corrections - CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles - ARCHITECTURE.md: add Reloader and Zot to services table - HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker) - WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry - services.md: add Reloader and Zot entries - STANDUP.md: remove Proxmox API token ref; archive Phase 5 - LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented) * fix(authelia): remove orphaned authelia-data PVC The PVC was never mounted by the Deployment (only config and secrets volumes are used). It has been Pending for 3 days as local-path waits for a consumer that never arrives, causing ArgoCD to report the app as Progressing indefinitely. No data loss risk: the PVC was never bound.
swares
added a commit
that referenced
this pull request
Jul 22, 2026
…nostics (#273) * docs: add SSO.md — OIDC status, notes, and patterns for all lab services * docs: apply audit corrections - CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles - ARCHITECTURE.md: add Reloader and Zot to services table - HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker) - WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry - services.md: add Reloader and Zot entries - STANDUP.md: remove Proxmox API token ref; archive Phase 5 - LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented) * fix(authelia): remove orphaned authelia-data PVC The PVC was never mounted by the Deployment (only config and secrets volumes are used). It has been Pending for 3 days as local-path waits for a consumer that never arrives, causing ArgoCD to report the app as Progressing indefinitely. No data loss risk: the PVC was never bound. * docs: update GITOPS-STUDY-GUIDE with Reloader, orphaned PVC, and ArgoCD health diagnostics - Add Reloader section (Section 4): explains Stakater Reloader annotation and which deployments carry it (Authelia, Semaphore, Zot) - Expand ArgoCD Progressing diagnostic: add jq resource-health query and app controller log command before the hard refresh step - Expand PVC Pending cause: distinguish orphaned PVC (no consumer, stays Pending forever with WaitForFirstConsumer) from provisioner errors; document the fix (delete manifest, ArgoCD prune cleans it up)
swares
added a commit
that referenced
this pull request
Jul 22, 2026
…#274) * docs: add SSO.md — OIDC status, notes, and patterns for all lab services * docs: apply audit corrections - CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles - ARCHITECTURE.md: add Reloader and Zot to services table - HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker) - WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry - services.md: add Reloader and Zot entries - STANDUP.md: remove Proxmox API token ref; archive Phase 5 - LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented) * fix(authelia): remove orphaned authelia-data PVC The PVC was never mounted by the Deployment (only config and secrets volumes are used). It has been Pending for 3 days as local-path waits for a consumer that never arrives, causing ArgoCD to report the app as Progressing indefinitely. No data loss risk: the PVC was never bound. * docs: update GITOPS-STUDY-GUIDE with Reloader, orphaned PVC, and ArgoCD health diagnostics - Add Reloader section (Section 4): explains Stakater Reloader annotation and which deployments carry it (Authelia, Semaphore, Zot) - Expand ArgoCD Progressing diagnostic: add jq resource-health query and app controller log command before the hard refresh step - Expand PVC Pending cause: distinguish orphaned PVC (no consumer, stays Pending forever with WaitForFirstConsumer) from provisioner errors; document the fix (delete manifest, ArgoCD prune cleans it up) * feat(backup): add daily cloud backup of critical cluster state to R2 Installs backup-cloud.service + timer on H4 (runs 03:00 UTC daily). What gets backed up offsite (Cloudflare R2, free 10GB tier): - k3s etcd snapshots - lldap DB snapshots - Vault raft snapshots (if present) - Postgres dumps: Authelia, Immich, Semaphore (via kubectl exec) Total estimated size: well under 2GB. Restic retention: 7 daily, 4 weekly, 3 monthly. Credentials read from Vault at secret/lab/cloudflare-r2. Closes the single-location gap for cluster state — NAS media stays on the two cold-tier RAID disks (Track 2 decision pending).
swares
added a commit
that referenced
this pull request
Jul 22, 2026
* docs: add SSO.md — OIDC status, notes, and patterns for all lab services * docs: apply audit corrections - CLAUDE.md: clarify RPi 4B / opi-zero2w-1 DNS roles - ARCHITECTURE.md: add Reloader and Zot to services table - HARDWARE.md: fix OPi Zero 2W #4 role (MQTT secondary broker) - WORKFLOWS.md: note that standard workloads don't need gitops/apps/ entry - services.md: add Reloader and Zot entries - STANDUP.md: remove Proxmox API token ref; archive Phase 5 - LAB-DESIGN.md: add design-proposal disclaimer (Proxmox not implemented) * fix(authelia): remove orphaned authelia-data PVC The PVC was never mounted by the Deployment (only config and secrets volumes are used). It has been Pending for 3 days as local-path waits for a consumer that never arrives, causing ArgoCD to report the app as Progressing indefinitely. No data loss risk: the PVC was never bound. * docs: update GITOPS-STUDY-GUIDE with Reloader, orphaned PVC, and ArgoCD health diagnostics - Add Reloader section (Section 4): explains Stakater Reloader annotation and which deployments carry it (Authelia, Semaphore, Zot) - Expand ArgoCD Progressing diagnostic: add jq resource-health query and app controller log command before the hard refresh step - Expand PVC Pending cause: distinguish orphaned PVC (no consumer, stays Pending forever with WaitForFirstConsumer) from provisioner errors; document the fix (delete manifest, ArgoCD prune cleans it up) * feat(backup): add daily cloud backup of critical cluster state to R2 Installs backup-cloud.service + timer on H4 (runs 03:00 UTC daily). What gets backed up offsite (Cloudflare R2, free 10GB tier): - k3s etcd snapshots - lldap DB snapshots - Vault raft snapshots (if present) - Postgres dumps: Authelia, Immich, Semaphore (via kubectl exec) Total estimated size: well under 2GB. Restic retention: 7 daily, 4 weekly, 3 monthly. Credentials read from Vault at secret/lab/cloudflare-r2. Closes the single-location gap for cluster state — NAS media stays on the two cold-tier RAID disks (Track 2 decision pending). * fix(backup): escape bash array syntax that conflicts with Jinja2 comment tags
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
go