infra/stacks/platform/modules
Viktor Barzin 850ab5277f migrate consuming stacks to ESO + remove k8s-dashboard static token
Phase 9: ExternalSecret migration across 26 stacks:

Fully migrated (vault data source removed, ESO delivers secrets):
- speedtest, shadowsocks, wealthfolio, plotting-book, f1-stream, tandoor
- n8n, dawarich, diun, netbox, onlyoffice, tuya-bridge
- hackmd (ESO template for DB URL), health (ESO template for DB URL)
- trading-bot (ESO template for DATABASE_URL + 7 secret env vars)
- forgejo (removed unused vault data source)

Partially migrated (vault kept for plan-time, ESO added for runtime):
- immich, linkwarden, nextcloud, paperless-ngx (jsondecode for homepage)
- claude-memory, rybbit, url, webhook_handler (plan-time in locals/jobs)
- woodpecker, openclaw, resume (plan-time in helm values/jobs/modules)

17 stacks unchanged (all plan-time: homepage annotations, configmaps,
module inputs) — vault data source works with OIDC auth.

Phase 17a: Remove k8s-dashboard static admin token secret.
Users now get tokens via: vault write kubernetes/creds/dashboard-admin
2026-03-18 08:04:02 +00:00
..
authentik mitigate cluster instability during terraform applies 2026-03-18 08:04:02 +00:00
cloudflared equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
cnpg equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
crowdsec equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
dbaas fix: MySQL memory overcommit + shlink OOMKill 2026-03-18 08:04:01 +00:00
headscale equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
infra-maintenance etcd defrag cronjob: add --command-timeout=60s 2026-03-18 08:04:02 +00:00
iscsi-csi right-size cluster memory: reduce overprovisioned, fix under-provisioned services 2026-03-18 08:04:01 +00:00
k8s-portal equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
kyverno migrate consuming stacks to ESO + remove k8s-dashboard static token 2026-03-18 08:04:02 +00:00
mailserver equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
metallb [ci skip] Move Terraform modules into stack directories 2026-02-22 14:38:14 +00:00
metrics-server equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
monitoring mitigate cluster instability during terraform applies 2026-03-18 08:04:02 +00:00
nfs-csi equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
nvidia fix immich TF drift from Kyverno ndots injection, right-size nvidia GPU operator 2026-03-18 08:04:01 +00:00
rbac add vaultwarden daily backup CronJob to NFS 2026-03-18 08:04:00 +00:00
redis equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
reverse_proxy Remove all CPU limits cluster-wide to eliminate CFS throttling 2026-03-18 08:03:58 +00:00
sealed-secrets equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
technitium equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
traefik mitigate cluster instability during terraform applies 2026-03-18 08:04:02 +00:00
uptime-kuma Remove all CPU limits cluster-wide to eliminate CFS throttling 2026-03-18 08:03:58 +00:00
vaultwarden vaultwarden: upgrade to 1.35.4, use Recreate strategy 2026-03-18 08:04:01 +00:00
vpa equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
wireguard equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00
xray equalize memory req=lim across 70+ containers using Prometheus 7d max data 2026-03-18 08:04:00 +00:00