• Joined on 2026-02-19
davide pushed to main at davide/fleet-infra 2026-02-20 00:36:51 +00:00
779ed3d563 remove trivy-operator
davide pushed to main at davide/fleet-infra 2026-02-20 00:18:40 +00:00
b95a574d73 remove velero
davide pushed to main at davide/fleet-infra 2026-02-20 00:17:43 +00:00
5e55c0e277 encrypt crowdsec bouncer key with SOPS + variable substitution
davide pushed to main at davide/fleet-infra 2026-02-19 23:54:19 +00:00
75f8c6d5d8 fix: correct CrowdSec LAPI service name for bouncer
davide pushed to main at davide/fleet-infra 2026-02-19 23:53:02 +00:00
d19ede0559 feat: enable CrowdSec Traefik bouncer on all ingresses
davide pushed to main at davide/fleet-infra 2026-02-19 23:49:59 +00:00
d628dd2c67 fix: allow CrowdSec intra-namespace traffic (agent -> LAPI)
davide pushed to main at davide/fleet-infra 2026-02-19 23:45:15 +00:00
129efb39ad fix: revert to one_factor - 2FA needs SMTP notifier to work
davide pushed to main at davide/fleet-infra 2026-02-19 23:43:56 +00:00
133312a284 feat: replace Uptime Kuma with Gatus
davide pushed to main at davide/fleet-infra 2026-02-19 23:31:51 +00:00
dd74cc05fd fix: Velero kubectl image and AWS plugin version
davide pushed to main at davide/fleet-infra 2026-02-19 23:24:27 +00:00
08eb8255a8 sec: new Authelia password + enforce 2FA for all services
davide pushed to main at davide/fleet-infra 2026-02-19 23:21:00 +00:00
51bcdebca8 feat: add SOPS encrypted secrets and enable Flux decryption
davide pushed to main at davide/fleet-infra 2026-02-19 23:18:41 +00:00
914890b339 feat: protect Uptime Kuma and Weave GitOps with Authelia ForwardAuth
davide pushed to main at davide/fleet-infra 2026-02-19 23:13:34 +00:00
bc89216548 fix: allow ACME solver port 8089 in Authelia NetworkPolicy
davide pushed to main at davide/fleet-infra 2026-02-19 23:11:01 +00:00
a5c1772e4e fix: mount users_database.yml in Authelia pod
davide pushed to main at davide/fleet-infra 2026-02-19 23:06:27 +00:00
0d0fd95991 feat: deploy Wave 2 - CrowdSec + Velero
davide pushed to main at davide/fleet-infra 2026-02-19 22:58:30 +00:00
d59ac2a933 sec: disable Vaultwarden open signups, add admin token
davide pushed to main at davide/fleet-infra 2026-02-19 22:56:53 +00:00
b69cc16002 fix: remove Authelia default_redirection_url conflicting with authelia_url
davide pushed to main at davide/fleet-infra 2026-02-19 22:49:37 +00:00
98e073ad82 fix: correct Authelia and Trivy Operator chart values
davide pushed to main at davide/fleet-infra 2026-02-19 22:44:36 +00:00
c2a803d28b feat: deploy Wave 1 - Vaultwarden, Uptime Kuma, Trivy Operator, Authelia
davide pushed to main at davide/fleet-infra 2026-02-19 22:05:12 +00:00
232957ac4a Fix podinfo manifest - correct resource names