835395f7ec
FIX(external-secrets): add ServerSideApply for CRD sync
...
- Fix CRD annotation size limit exceeded error
- ServerSideApply avoids last-applied-configuration annotation
2026-01-07 01:15:03 +09:00
384d73d1fa
REFACTOR(secrets): flatten Vault paths
...
- Change secret paths from <category>/<app> to <app>
- databases/postgresql → postgresql
- cluster-infrastructure/authelia → authelia
2026-01-06 16:53:10 +09:00
677214b848
REFACTOR(repo): move vault/ to manifests/
...
- Move ExternalSecret file from vault/ to manifests/secret.yaml
- Update kustomization.yaml references
- Remove vault/ folder
Apps: authelia
2026-01-06 16:43:38 +09:00
3c51bb3b5e
FIX(authelia): keep ingress in manifests
...
- Keep ingress in manifests/ due to chart schema complexity
- Authelia chart has complex ingress schema
2026-01-06 15:27:17 +09:00
52bc1b9d57
FIX(authelia): use rulesOverride for config
...
- Use rulesOverride for access control configuration
- Fix invalid Helm values properties
2026-01-06 15:26:24 +09:00
875dbbc42c
REFACTOR(authelia): integrate ingress in values
...
- Move config.yaml, middleware.yaml, rbac.yaml to manifests/
- Add ingress configuration to helm-values.yaml
- Remove separate ingress.yaml
2026-01-06 15:12:22 +09:00
6fbf2b16c2
REFACTOR(vault): move resources to manifests
...
- Move additional resources to manifests/ folder
- Separate from Helm chart configuration
2026-01-06 01:38:33 +09:00
321685822f
REFACTOR(repo): security repo structure
...
- Add application.yaml for ArgoCD app-of-apps
- Add kustomization.yaml with security components
- Add renovate.json for automated updates
- Update all component argocd.yaml repoURLs to security repo
Components: authelia, vault, external-secrets, falco, trivy
2026-01-05 00:40:26 +09:00
27ba06b750
REFACTOR(grafana): remove Falco and Traefik UI
...
- Use Grafana dashboards instead
- Delete falco-ui-secret ExternalSecret
- Delete traefik dashboard IngressRoute
2026-01-05 00:40:26 +09:00
c90574aee2
REFACTOR(grafana): remove Trivy UI
...
- Use Grafana dashboard instead
- Delete trivy-ui ArgoCD Application
- Delete trivy ingress.yaml
- Update kustomization.yaml
2026-01-05 00:40:26 +09:00
c51cca27d8
CHORE(falco): disable sidekick-ui and Redis
...
- Use Grafana dashboard instead
- Set webui.enabled: false (disables UI and Redis)
- Remove ingress.yaml for falco-ui
- Saves ~384Mi memory (Redis 256Mi + UI 128Mi)
2026-01-05 00:40:26 +09:00
c66801a166
FEAT(falco): add loki output to falcosidekick
...
- Send Falco events directly to Loki
- Enables viewing detailed events in Grafana with all fields
- Same data as Falco UI but queryable in Grafana
2026-01-05 00:40:26 +09:00
76c5fd8343
FIX(falco): use SM create instead of enabled
...
- Falco chart uses 'serviceMonitor.create' not 'enabled'
- Add release: prometheus label for Prometheus discovery
2026-01-05 00:40:26 +09:00
d4b84305a2
FIX(redis): use customConfig for maxmemory
...
- extraArgs was not being applied to Redis container
- Use customConfig which is the correct way to set Redis directives
- maxmemory 800mb with allkeys-lru policy
2026-01-05 00:40:26 +09:00
94dcb7d585
FEAT(falco): add 6h TTL to sidekick-ui
...
- to prevent Redis OOM
- Events older than 6 hours are auto-deleted
- Prevents linear memory growth in Redis
2026-01-05 00:40:26 +09:00
9822441e38
REFACTOR(repo): migrate repoURL to K3S-HOME
...
- Update repository URL to K3S-HOME organization
- Change from personal to organization repo
2026-01-05 00:40:26 +09:00
4e4be3109a
FIX(external-secrets): fix ESO CRD OutOfSync
...
- Add ignoreDifferences for CRD caBundle and spec/versions
- Add RespectIgnoreDifferences syncOption
- Prevents ArgoCD from detecting drift on CRD fields managed by webhook
2026-01-05 00:40:26 +09:00
168193845b
FIX(authelia): fix TOTP config for chart 0.10.x
...
- Change enabled to disable for TOTP configuration
- Fix chart compatibility
2026-01-05 00:40:26 +09:00
renovate[bot]
a6342a2fdd
CHORE(authelia): update authelia to 0.10.x
...
- Upgrade Authelia chart version
- Apply dependency updates
2026-01-05 00:40:26 +09:00
renovate[bot]
8fd3daa65f
CHORE(external-secrets): update ESO to v1.2.1
...
- Upgrade External Secrets Operator chart
- Apply dependency updates
2026-01-05 00:40:26 +09:00
fd31dc3c65
REFACTOR(authelia): remove redirect to Vault
...
- Remove redirect configuration to Vault
- Clean up authentication flow
2026-01-05 00:40:26 +09:00
1cd89f6bae
REFACTOR(falco): remove CPU limit
...
- Set cpu: null to override chart default (1 core)
- Prevents CPU throttling under high load
2026-01-05 00:40:26 +09:00
bce1bdf12b
FIX(trivy): fix Trivy resource limits
...
- Operator: add 512Mi memory limit
- Scan jobs: increase memory limit 500M -> 768Mi
- Reduce concurrent scan jobs 3 -> 2
2026-01-05 00:40:26 +09:00
c67b720ee4
FIX(falco): falco oom issues
...
- increase memory limits
- Falco: add 512Mi memory limit
- Falcosidekick: increase memory limit 256Mi -> 512Mi
- Redis: increase memory limit 512Mi -> 1Gi (was 84 restarts)
- Redis: increase maxmemory 400mb -> 800mb
2026-01-05 00:40:26 +09:00
a9a4ed1bf3
FIX(authelia): increase Authelia memory limit
...
- to 256Mi
OOMKilled with 128Mi limit. Increased to 256Mi for stability.
2026-01-05 00:40:26 +09:00
589b98a875
REFACTOR(trivy): remove Trivy scan job CPU limit
...
- Remove CPU limit to prevent throttling
- Optimize scan job performance
2026-01-05 00:40:26 +09:00
ede767498d
PERF(redis): increase Redis memory limit to 512Mi
...
- Increase memory limit to prevent OOM
- Optimize Redis configuration
2026-01-05 00:40:26 +09:00
a0e483a8c4
FEAT(trivy): add ignoreDiff for trivy-ui CPU limit
...
- Add ignoreDifferences for CPU limit field
- Prevent ArgoCD sync drift
2026-01-05 00:40:26 +09:00
59b834c250
REFACTOR(resources): use tilde for null CPU
...
- Use ~ (tilde) for null CPU limit values
- YAML best practice for null
2026-01-05 00:40:26 +09:00
e1ecf43096
REFACTOR(trivy): remove trivy-ui CPU limit
...
- Remove CPU limit to prevent throttling
- Optimize resource configuration
2026-01-05 00:40:26 +09:00
1a551b47ca
PERF(falco): optimize falco rules
...
- and add sidekick memory limit
- Add macros to exclude trivy, postgres, minio, vault from rules
- Disable Container Drift Detection (too noisy)
- Remove /etc/passwd from sensitive file access (normal lookups)
- Add 256Mi memory limit to falcosidekick (was using 1.1GB)
2026-01-05 00:40:26 +09:00
8d46ae9e49
FEAT(immich): add email to admin user for OAuth
...
- Add email field to admin user
- Required for Immich OAuth integration
2026-01-05 00:40:26 +09:00
04bc972466
FEAT(authelia): add Immich as OIDC client in Authelia
...
- Add Immich OIDC client configuration
- Enable OAuth authentication for Immich
2026-01-05 00:40:26 +09:00
ddc733d2d2
FEAT(authelia): add Vault as OIDC client in Authelia
...
- Add Vault OIDC client configuration
- Add VAULT_CLIENT_SECRET to ExternalSecret
- Mount VAULT_CLIENT_SECRET in pod
2026-01-05 00:40:26 +09:00
159e135ee8
FEAT(authelia): add OIDC admin ClusterRoleBinding
...
- Add ClusterRoleBinding for Authelia SSO
- Enable admin access via OIDC
2026-01-05 00:40:26 +09:00
0be0f4cb5a
FEAT(authelia): add jwks config for authelia oidc
...
- Mount jwks.pem from authelia-secrets
- Configure JWKS with RS256 algorithm
2026-01-05 00:40:26 +09:00
ef31735060
FIX(vault): fix OIDC HMAC secret key name
...
- Change key name from secret to key
- Fix Vault secret reference
2026-01-05 00:40:26 +09:00
e4fb804b3d
FEAT(headlamp): enable authelia oidc provider
...
- with headlamp client
- Add OIDC identity provider configuration
- Add Headlamp as OIDC client
- Update ExternalSecret for OIDC secrets (HMAC, JWKS, Headlamp client
secret)
2026-01-04 23:41:39 +09:00
4d4ecb13d6
FIX(falco): add NoExecute tolerations
...
- and enable Redis persistence
- Add NoExecute tolerations for master/control-plane nodes to run Falco
DaemonSet on all nodes
- Enable Redis storage to persist index data across pod restarts
2026-01-04 23:41:39 +09:00
d88cf75b95
FIX(authelia): fix Authelia secret key names
...
- Update key names to match chart expectations
- Fix ExternalSecret configuration
2026-01-04 23:41:39 +09:00
de5183469e
FEAT(authelia): add JWT_HMAC_KEY to ExternalSecret
...
- Add JWT_HMAC_KEY for password reset functionality
- Update ExternalSecret configuration
2026-01-04 23:41:39 +09:00
a4d9adc273
FIX(authelia): fix OIDC client_secret with plaintext prefix
...
- Use plaintext prefix for client secret
- Fix OIDC authentication
2026-01-04 23:41:39 +09:00
520261d36e
FEAT(authelia): enable Authelia OIDC provider with MinIO client
...
- Enable OIDC identity provider
- Add MinIO as OIDC client
- Configure secrets from Vault
2026-01-04 23:41:39 +09:00
7de57fc936
CHORE(authelia): disable falco-ui basic auth
...
- Use Authelia SSO instead
- Remove basic auth configuration
2026-01-04 23:41:39 +09:00
7abf679d5e
FEAT(goldilocks): add Authelia SSO
...
- Add Authelia SSO to goldilocks, karma, trivy ingress
- Enable single sign-on authentication
2026-01-04 23:41:39 +09:00
2a4d84a0bc
CHORE(deps): upgrade Falco to 0.40.0
...
- Upgrade for kernel 6.14 support
- Apply dependency updates
2026-01-04 23:41:39 +09:00
5f197a607b
FIX(falco): falco config errors
...
- Remove unsupported outputs_queue_capacity option
- Fix Container Drift Detection rule (remove undefined rename macro)
2026-01-04 23:41:39 +09:00
765104bb4e
REFACTOR(authelia): remove falco-ui-secret
...
- Use Authelia SSO instead
- Remove basic auth secret
2026-01-04 23:41:39 +09:00
b523935f3b
FIX(argocd): falco ArgoCD
...
- to use multiple sources for ingress deployment
- Change from single source to multiple sources
- Add kustomize path to deploy ingress.yaml
- Add Authelia middleware to ingress
2026-01-04 23:41:39 +09:00
2ce3a296ae
REFACTOR(authelia): remove OIDC config files
...
- Remove OIDC configuration files
- Clean up unused configurations
2026-01-04 23:41:39 +09:00