carr.pub live: cert-manager, hello site, DDNS; monitoring + loadtest committed

This commit is contained in:
Adam Carr
2026-09-19 20:57:04 -07:00
parent 8451333c3a
commit a1ee870f67
3 changed files with 171 additions and 0 deletions

View File

@@ -0,0 +1,14 @@
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-prod
spec:
acme:
server: https://acme-v02.api.letsencrypt.org/directory
email: adam.carr@hey.com
privateKeySecretRef:
name: letsencrypt-prod-account-key
solvers:
- http01:
ingress:
class: traefik

View File

@@ -0,0 +1,69 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: ddns-script
namespace: monitoring
data:
ddns.sh: |
#!/bin/sh
# Keeps the carr.pub apex A record pointing at this network's public IP.
RECORD_ID=84723206
ZONE="carr.pub"
ACCOUNT=6300
API="https://api.dnsimple.com/v2"
AUTH="Authorization: Bearer ${DNSIMPLE_TOKEN}"
IP=$(curl -s -m 15 https://ifconfig.me)
case "$IP" in
*.*.*.*) : ;;
*) echo "no valid public ip: '$IP'"; exit 0 ;;
esac
CUR=$(curl -s -m 15 -H "$AUTH" "$API/$ACCOUNT/zones/$ZONE/records/$RECORD_ID" \
| sed -n 's/.*"content":"\([^"]*\)".*/\1/p')
if [ "$IP" = "$CUR" ]; then
echo "$(date -Is) up to date ($IP)"
exit 0
fi
RES=$(curl -s -m 15 -X PATCH -H "$AUTH" -H "Content-Type: application/json" \
"$API/$ACCOUNT/zones/$ZONE/records/$RECORD_ID" \
-d "{\"content\":\"$IP\"}")
echo "$(date -Is) updated carr.pub -> $IP"
case "$RES" in
*'"id"'*) exit 0 ;;
*) echo "API error: $RES"; exit 1 ;;
esac
---
apiVersion: batch/v1
kind: CronJob
metadata:
name: ddns-carr-pub
namespace: monitoring
spec:
schedule: "*/5 * * * *"
concurrencyPolicy: Forbid
successfulJobsHistoryLimit: 1
failedJobsHistoryLimit: 3
jobTemplate:
spec:
backoffLimit: 1
template:
spec:
restartPolicy: Never
containers:
- name: ddns
image: curlimages/curl:8.11.1
command: ["/bin/sh", "/scripts/ddns.sh"]
env:
- name: DNSIMPLE_TOKEN
valueFrom:
secretKeyRef: {name: dnsimple-token, key: token}
resources:
requests: {cpu: 10m, memory: 16Mi}
limits: {memory: 32Mi}
volumeMounts:
- {name: scripts, mountPath: /scripts}
volumes:
- name: scripts
configMap: {name: ddns-script, defaultMode: 0744}

View File

@@ -0,0 +1,88 @@
apiVersion: v1
kind: Namespace
metadata:
name: web
---
apiVersion: v1
kind: ConfigMap
metadata:
name: hello-index
namespace: web
data:
index.html: |
<!doctype html>
<html>
<head><meta charset="utf-8"><title>carr.pub</title>
<style>
body { font-family: system-ui, sans-serif; background: #111; color: #eee;
display: grid; place-items: center; height: 100vh; margin: 0; }
h1 { font-size: 3rem; margin: 0 0 .5rem; }
p { color: #888; font-size: 1.2rem; }
</style>
</head>
<body>
<div style="text-align:center">
<h1>carr.pub</h1>
<p>Served by the planck cluster — 20 Raspberry Pis that finally earn their rack space.</p>
</div>
</body>
</html>
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: hello-web
namespace: web
spec:
replicas: 6
selector:
matchLabels: {app: hello-web}
template:
metadata:
labels: {app: hello-web}
spec:
containers:
- name: web
image: nginx:1.29-alpine
ports: [{containerPort: 80}]
resources:
requests: {cpu: 10m, memory: 16Mi}
limits: {memory: 64Mi}
volumeMounts:
- {name: html, mountPath: /usr/share/nginx/html}
volumes:
- name: html
configMap: {name: hello-index}
---
apiVersion: v1
kind: Service
metadata:
name: hello-web
namespace: web
spec:
selector: {app: hello-web}
ports:
- port: 80
targetPort: 80
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: carr-pub
namespace: web
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
spec:
tls:
- hosts: [carr.pub]
secretName: carr-pub-tls
rules:
- host: carr.pub
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: hello-web
port: {number: 80}