{"repo":"brettinternet/homeops","free":true,"listed":false,"github":"https://github.com/brettinternet/homeops","clone":"git clone https://github.com/brettinternet/homeops.git","description":"devops resources in my self-hosted homelab","language":"Shell","stars":257,"topics":["homelab","mediaserver","proxmox","kubernetes","selfhosted","talos","k8s-at-home"],"license":null,"category":"self-hosted-apps","readme_excerpt":"HomeOps Features - Talos bare-metal K8s OS - Lots of self-hosted services - Flux GitOps with this repository (kubernetes directory) - Cilium container networking interface (CNI) and layer 4 loadbalancing - go-task shorthand for useful commands (Taskfile and taskfiles) for multiple clusters - SOPS secrets stored in Git - Renovate bot dependency updates - Cloudflared HTTP tunnel - K8s gateway for local DNS resolution to the cluster and NGINX ingress controller - Both internal & external services with a service gateway - OIDC authentication with LDAP - Automatic Cloudflare DNS updates with external-dns - CloudNative-PG with automatic failover - kube-prometheus-stack with various Grafana dashboards - Rook Ceph cluster storage This setup is inspired by this homelab gitops template. You can find similar setups with the k8s at home search. See also my homelab repo for how I provision machines in my home. Usage Setup Install go-task Provision the Talos nodes. Install flux. Verify the installation. DNS and Tunnel Setup a Cloudflare Tunnel. Add the tunnel's credentials.json to the value in cloudflared-secret and tunnel ID to cluster-secrets.sops.yaml . Add a Cloudflare API token with these permissions to the value in external-dns-secret . - Zone - DNS - Edit - Account - Cloudflare Tunnel - Read Github Webhook Setup a webook to reconcile flux when changes are pushed to Github. Note: this only works with Let's Encrypt Production certificates. Get webook path: Append to self-hosted domain","default_branch":null,"files":null,"tree":[],"storefront":"/r/brettinternet","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/brettinternet/homeops/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}