Skip to content

feat(uptime-kuma): add outbound availability checks with Discord alerts - #73

Merged
PragalvaXFREZ merged 1 commit into
mainfrom
feat/uptime-kuma
Sep 6, 2026
Merged

PragalvaXFREZ merged 1 commit into
mainfrom
feat/uptime-kuma

Conversation

@PragalvaXFREZ

Copy link
Copy Markdown
Owner

What

Adds Uptime Kuma to devata as a workload Application in namespace uptime.

  • Chart uptime-kuma 4.2.0 (app 2.5.0) from helm.irsigler.cloud, values in kubernetes/apps/uptime-kuma/values.yaml. Renovate covers the pin through the existing Argo CD manager patterns.
  • 1Gi Longhorn PVC declared in the repo and passed to the chart as existingClaim, so class and labels stay under Git.
  • Recreate strategy, because a single replica with a ReadWriteOnce volume cannot roll.
  • Pinned to talos-lqv-w4u by hostname (most memory headroom). Requests 50m/128Mi, memory limit 256Mi, no CPU limit.
  • Security context: seccomp RuntimeDefault, no privilege escalation, drop ALL, add NET_RAW for ping monitors. Image is root; baseline PSA permits it.
  • CiliumNetworkPolicy: egress to kube-dns, TCP 80/443 to world, ICMP echo to world. Ingress only from the ingress entity (LAN Gateway Envoy). Chart's generic NetworkPolicy disabled.
  • Component README with safety model, verification, rollback, and limitations. Root README map gains the new app directory.

What this deliberately does not do

  • No Velero Schedule. kubernetes/infra/storage/velero/README.md records a no-unattended-schedule contract against the 1 GB R2 ceiling. The README points at the on-demand path instead.
  • No public exposure. A LAN Gateway route for kuma.lab.pragalva.me follows in a separate PR.

Validation

  • helm template with the repo values renders cleanly.
  • kubeconform -strict passes on the Application, PVC, CiliumNetworkPolicy, and the rendered chart output.
  • python3 scripts/check-docs.py passes.

After merge

  1. kubectl -n uptime get deploy,pod,pvc,cnp and confirm the pod is on talos-lqv-w4u with a Bound Longhorn volume and two healthy replicas.
  2. Port-forward, create the admin account, add the Discord webhook, add one HTTP monitor.
  3. Add a TCP monitor on a port outside 80/443 and confirm it stays red. That proves the policy is enforced.

Install the uptime-kuma chart as a workload Application with a
repository-owned 1Gi Longhorn claim, a Recreate strategy for the single
ReadWriteOnce volume, a pin to the Nitro worker for memory headroom, a
256Mi memory limit, and a reduced-privilege security context.

A CiliumNetworkPolicy allows DNS, TCP 80 and 443, and ICMP echo out, and
accepts inbound only from the Cilium ingress identity so the LAN Gateway
can front it. No Velero schedule is added: the R2 target keeps its
documented on-demand-only contract.

Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant