stack.basicstack.de/apps
CTO Agent 672387e678 fix(pangolin): Reconnect controller to fresh Postgres Pangolin, route via internal API port 3001
DEV-452. After the SQLite -> Postgres migration in DEV-451 the pangolin
initial setup was redone, so the controller's stale bearer token was
invalid. That was only half the problem: /api/v1/traefik-config is
served exclusively by Pangolin's internal API (port 3001), not the
external dashboard API (port 3000). Pointing a Bearer request at port
3000 always returned 401 because that path lives on the session-auth
router. This has been the underlying cause of the controller's
CrashLoopBackOff, not just the stale key.

Changes:
- pangolin-controller-api-key-sealed.yaml: reseal new bearer token
  (kubeseal against sealed-secrets-controller in kube-system, includes
  the Bearer prefix expected by the controller).
- pangolin-controller-config.yaml: CONFIG_ENDPOINT now targets
  http://pangolin.pangolin.svc.cluster.local:3001/api/v1/traefik-config.
- pangolin-deployment.yaml: Service now exposes port 3001 as the
  "internal" port so in-cluster clients (kube-controller) can reach it.
  Ingress still only routes / and /api to ports 3002/3000; port 3001
  is not published to the internet.
- pangolin-controller-deployment.yaml: replicas back to 1, dropped the
  temporary "scaled to 0" comment block.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-08-08 11:35:02 +00:00
..
argocd Add managed label to argocd sealed secrets 2026-07-12 16:32:34 +00:00
basicstack-org apps/basicstack-org/deployment.yaml aktualisiert 2026-07-18 17:42:30 +00:00
bookstack Document mysql-data-encrypted PVC as pre-existing, unmanaged resource 2026-07-12 17:13:26 +00:00
directus Add IgnoreExtraneous annotation to Directus sealed secrets 2026-07-25 14:57:27 +00:00
dozzle Add metrics.k8s.io permissions to Dozzle ClusterRole 2026-07-25 11:34:26 +00:00
forgejo Consolidate Forgejo backup into forgejo namespace 2026-07-26 09:35:31 +00:00
forgejo-runner fix: revert to Deployment with host Docker socket (dind approach abandoned) 2026-07-18 16:47:05 +00:00
harbor Fix Harbor ArgoCD degraded status by ignoring unsealed secret 2026-07-25 15:05:37 +00:00
headlamp apps/headlamp/deployment.yaml aktualisiert 2026-07-18 08:45:24 +00:00
opencloud apps/opencloud/init-job.yaml gelöscht 2026-08-01 08:46:46 +00:00
pangolin fix(pangolin): Reconnect controller to fresh Postgres Pangolin, route via internal API port 3001 2026-08-08 11:35:02 +00:00
paperclip Fix Paperclip storage and permissions 2026-07-26 11:10:21 +00:00
passbolt Fix Passbolt ArgoCD degraded status 2026-07-26 09:17:04 +00:00
platform-prod Convert all secrets to SealedSecrets for enhanced security 2026-07-01 18:38:27 +00:00
pocket-id apps/pocket-id/README.md aktualisiert 2026-07-18 13:12:34 +00:00
stalwart Document Hetzner Load Balancer architecture for Stalwart 2026-08-02 11:32:30 +00:00
app-argocd.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-basicstack-org.yaml feat: migrate basicstack.org deployment to stack repo 2026-07-18 17:13:31 +00:00
app-bookstack.yaml Enable auto-sync for bookstack application 2026-07-12 17:17:53 +00:00
app-directus.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-dozzle.yaml Add Dozzle container log viewer deployment 2026-07-19 13:25:08 +00:00
app-forgejo-runner.yaml Add Forgejo Actions runner deployment configuration 2026-07-18 14:21:57 +00:00
app-forgejo.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-harbor.yaml Refactor Harbor deployment to follow project structure pattern 2026-07-18 14:02:31 +00:00
app-headlamp.yaml Enable automated sync for Headlamp ArgoCD application 2026-07-18 07:38:58 +00:00
app-opencloud.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-pangolin.yaml Add Pangolin Kubernetes manifests 2026-07-26 12:09:07 +00:00
app-paperclip.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-passbolt.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-platform-prod.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-pocket-id.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
app-stalwart.yaml ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
ARGOCD-MIGRATION.md ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00
README.md ArgoCD: Replace complex stack sync with individual application syncs 2026-07-12 10:44:41 +00:00

Applications

This directory contains deployment configurations for all applications running on the basicstack.de cluster.

ArgoCD Application Management

Each application has two types of files:

  1. app-<name>.yaml: ArgoCD Application manifest that tells ArgoCD to sync the app subdirectory
  2. <name>/: Application-specific Kubernetes manifests and configuration

The app-*.yaml files are synced by ArgoCD and create/manage the corresponding Application resources. Each application's manifests in its subdirectory are then synced by its Application resource.

Structure

Each application should have its own subdirectory containing:

  • Kubernetes manifests: Deployment, StatefulSet, Service, ConfigMap, Secret definitions
  • Helm values: If using Helm charts, include values.yaml files
  • Configuration files: Application-specific configs (TOML, JSON, YAML)
  • Documentation: README or guide specific to the application deployment
  • Patches: Any kubectl patches or modifications needed

Example: Stalwart

The stalwart/ directory serves as a reference implementation, containing:

  • Multiple deployment variants (basic, with OIDC, etc.)
  • Helm values files
  • Monitoring dashboard configurations
  • Backup/restore procedures
  • Operational documentation

Adding a New Application

  1. Create a new directory: apps/<application-name>/
  2. Add your Kubernetes manifests
  3. Include a README.md explaining:
    • What the application does
    • How to deploy it
    • Configuration options
    • Troubleshooting steps
  4. Test the deployment in a dev environment
  5. Commit with a descriptive message

Naming Conventions

  • Directory names: lowercase, hyphen-separated (e.g., my-app)
  • Manifest files: descriptive names indicating resource type (e.g., deployment.yaml, service.yaml)
  • Use consistent naming across applications