blumeops/argocd/manifests
Erich Blume cb4f4085c2 C1: bake shower wheel into image; wire borgmatic; refine NFS docs
Three follow-ups on the shower deployment branch:

1. containers/shower/default.nix now uses buildPythonPackage to install
   the adelaide-baby-shower-app wheel + its deps at nix build time. The
   wheel comes from the forge PyPI index with a pinned SRI hash. The
   entrypoint no longer does pip-at-boot — it just runs migrations,
   collectstatic, and execs gunicorn.

2. ansible/roles/borgmatic/defaults/main.yml:
   - Adds shower to borgmatic_k8s_sqlite_dumps (context k3s-ringtail)
     so /app/data/db.sqlite3 is dumped via kubectl exec on every run.
   - Adds /Volumes/shower (sifaka SMB mount on indri) to
     borgmatic_source_directories so prize-photo media gets archived.

3. NFS share docs corrected to match the real on-sifaka pattern:
   exports allowlist 192.168.1.0/24 + 100.64.0.0/10 with all_squash to
   admin (matching frigate/paperless/etc.), not "Squash=No mapping".
   The pod's runAsUser doesn't need to match an on-disk uid because
   all_squash rewrites every write to admin:users.

Also adds a missing service-versions entry for the tailscale container
introduced in PR #347 — pre-existing gap surfaced by the
container-version-check hook on this commit.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-11 08:37:12 -07:00
..
1password-connect
alloy-k8s C0: alloy — bump kustomization tags to main-branch SHA 2026-05-01 08:31:27 -07:00
alloy-ringtail C0: alloy — bump kustomization tags to main-branch SHA 2026-05-01 08:31:27 -07:00
alloy-tracing-ringtail C0: alloy — bump kustomization tags to main-branch SHA 2026-05-01 08:31:27 -07:00
argocd
authentik
cloudnative-pg
databases
external-secrets
forgejo-runner
frigate
grafana
grafana-config C1: deploy adelaide-baby-shower-app to ringtail k3s 2026-05-11 08:14:12 -07:00
homepage C0: bump homepage image to fixed-perms build (v1.11.0-678f26b-nix) 2026-05-10 21:16:34 -07:00
immich C0: valkey — bump kustomization tags to main-branch SHA 2026-05-01 17:47:16 -07:00
kingfisher
kiwix
kube-state-metrics
kube-state-metrics-ringtail
loki
mealie
miniflux
navidrome
ntfy
nvidia-device-plugin
ollama
paperless C0: valkey — bump kustomization tags to main-branch SHA 2026-05-01 17:47:16 -07:00
prometheus
prowler
shower C1: bake shower wheel into image; wire borgmatic; refine NFS docs 2026-05-11 08:37:12 -07:00
tailscale-operator
tailscale-operator-base
tailscale-operator-ringtail C0: tailscale main-SHA rebuild for ringtail proxyclass 2026-05-06 06:52:39 -07:00
tempo
teslamate
torrent
unpoller