stack.basicstack.de/apps
CTO Agent 0c1c05fc50 feat(monitoring): retire legacy backup-volumes CronJob + backup-storage PVC (DEV-489)
The restic pipeline (loki/grafana/k8s-resources) is proven end-to-end
after the DEV-488 restore drill, so the legacy rsync/tar pipeline into
the 100 Gi local-path `backup-storage` PVC is removed.

- Delete `apps/monitoring/backup-volumes-cronjob.yaml`.
- Remove the DEV-483 bridge `nodeSelector: k3s-worker-2` from
  `apps/monitoring/loki-deployment.yaml`. Loki's data protection now
  runs via `backup-loki-restic`, which follows the pod via podAffinity
  regardless of which node the RWO CSI volume attaches on. The
  `Recreate` rollout strategy stays — it is unrelated (avoids the
  attach-deadlock during a rollout). Resolves the RWO/nodeSelector
  attach race that was blocking DEV-478 weekly OS updates.
- Update `apps/monitoring/README.md` to drop the `backup-volumes`
  section, link the restic restore runbook, and record the pin
  removal.
- Clean stale coexistence comments in the restic/prometheus CronJob
  manifests now that the legacy job is gone.

Cluster-side (already applied out-of-band, since these manifests are
`kubectl apply`-based, not Argo-managed):
- `kubectl -n monitoring delete cronjob backup-volumes` -> NotFound.
- `kubectl -n monitoring delete pvc backup-storage` -> gone; local-path
  PV `pvc-d0db0ba9-8f89-4f66-9e65-d573ebe1085a` reclaimed automatically
  (Delete policy). Two stale pre-DEV-487 `backup-k8s-resources` job
  pods that still referenced the PVC were deleted to release the
  `pvc-protection` finalizer.
- `kubectl -n monitoring apply -f loki-deployment.yaml` -> Recreate
  rollout, new pod Ready in ~60s, no nodeSelector on the new spec.
- No `VolumeAttachment` for the retired PV.
- Restic CronJobs (`backup-loki-restic`, `backup-grafana-restic`,
  `backup-k8s-resources`, `prometheus-backup`) intact.

Pre-delete snapshots retained on k3s-cp-1 under
`/root/dev489-snapshots-20260816T155411Z/` for post-mortem.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-08-16 15:58:43 +00:00
..
argocd Add managed label to argocd sealed secrets 2026-07-12 16:32:34 +00:00
basicstack-org apps/basicstack-org/deployment.yaml aktualisiert 2026-07-18 17:42:30 +00:00
bookstack Document mysql-data-encrypted PVC as pre-existing, unmanaged resource 2026-07-12 17:13:26 +00:00
directus Add IgnoreExtraneous annotation to Directus sealed secrets 2026-07-25 14:57:27 +00:00
dozzle Add metrics.k8s.io permissions to Dozzle ClusterRole 2026-07-25 11:34:26 +00:00
forgejo fix(backups): Repair three broken CronJobs blocking weekly OS updates (DEV-464) 2026-08-09 16:51:30 +00:00
forgejo-runner fix: revert to Deployment with host Docker socket (dind approach abandoned) 2026-07-18 16:47:05 +00:00
harbor fix(harbor): set updateStrategy=Recreate for RWO PVC rollouts 2026-08-08 15:51:06 +00:00
headlamp apps/headlamp/deployment.yaml aktualisiert 2026-07-18 08:45:24 +00:00
monitoring feat(monitoring): retire legacy backup-volumes CronJob + backup-storage PVC (DEV-489) 2026-08-16 15:58:43 +00:00
opencloud apps/opencloud/init-job.yaml gelöscht 2026-08-01 08:46:46 +00:00
pangolin docs(pangolin): add apps/pangolin/README.md (DEV-461) 2026-08-08 16:49:22 +00:00
paperclip chore(paperclip): Remove legacy plain Ingress for paperclip.basicstack.de (DEV-456) 2026-08-08 14:56:06 +00:00
passbolt Fix Passbolt ArgoCD degraded status 2026-07-26 09:17:04 +00:00
pocket-id apps/pocket-id/README.md aktualisiert 2026-07-18 13:12:34 +00:00
stalwart feat(stalwart): switch config/data store from RocksDB to PostgreSQL (DEV-476) 2026-08-15 14:46:29 +00:00
app-argocd.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-basicstack-org.yaml feat: migrate basicstack.org deployment to stack repo 2026-07-18 17:13:31 +00:00
app-bookstack.yaml Enable auto-sync for bookstack application 2026-07-12 17:17:53 +00:00
app-directus.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-dozzle.yaml Add Dozzle container log viewer deployment 2026-07-19 13:25:08 +00:00
app-forgejo-runner.yaml Add Forgejo Actions runner deployment configuration 2026-07-18 14:21:57 +00:00
app-forgejo.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-harbor.yaml fix(harbor): enable automated selfHeal on harbor Application 2026-08-08 15:52:55 +00:00
app-headlamp.yaml Enable automated sync for Headlamp ArgoCD application 2026-07-18 07:38:58 +00:00
app-opencloud.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-pangolin.yaml Add Pangolin Kubernetes manifests 2026-07-26 12:09:07 +00:00
app-paperclip.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-passbolt.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-pocket-id.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-stalwart.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
ARGOCD-MIGRATION.md ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
README.md ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00

Applications

This directory contains deployment configurations for all applications running on the basicstack.de cluster.

ArgoCD Application Management

Each application has two types of files:

  1. app-<name>.yaml: ArgoCD Application manifest that tells ArgoCD to sync the app subdirectory
  2. <name>/: Application-specific Kubernetes manifests and configuration

The app-*.yaml files are synced by ArgoCD and create/manage the corresponding Application resources. Each application's manifests in its subdirectory are then synced by its Application resource.

Structure

Each application should have its own subdirectory containing:

  • Kubernetes manifests: Deployment, StatefulSet, Service, ConfigMap, Secret definitions
  • Helm values: If using Helm charts, include values.yaml files
  • Configuration files: Application-specific configs (TOML, JSON, YAML)
  • Documentation: README or guide specific to the application deployment
  • Patches: Any kubectl patches or modifications needed

Example: Stalwart

The stalwart/ directory serves as a reference implementation, containing:

  • Multiple deployment variants (basic, with OIDC, etc.)
  • Helm values files
  • Monitoring dashboard configurations
  • Backup/restore procedures
  • Operational documentation

Adding a New Application

  1. Create a new directory: apps/<application-name>/
  2. Add your Kubernetes manifests
  3. Include a README.md explaining:
    • What the application does
    • How to deploy it
    • Configuration options
    • Troubleshooting steps
  4. Test the deployment in a dev environment
  5. Commit with a descriptive message

Naming Conventions

  • Directory names: lowercase, hyphen-separated (e.g., my-app)
  • Manifest files: descriptive names indicating resource type (e.g., deployment.yaml, service.yaml)
  • Use consistent naming across applications