feat(supabase): add services and statefulset for database management

feat(synapse): update ingress to use traefik ingress class and bump version

feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress

feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration

fix(taiga): update liveness and readiness probes to use tcpSocket for health checks

fix(taiga): change PVC access mode to ReadWriteMany for media and static storage

feat(traefik): add icon and ignore rules for traefik service

docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments

feat(ushahidi): implement dedicated Redis deployment for Ushahidi

fix(vllm): update deployment strategy and readiness/liveness probes for improved stability

fix(writefreely): pin writefreely image version to v0.15.1 for consistency

docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
This commit is contained in:
2026-07-02 21:34:27 +00:00
parent 9f5057dff8
commit 4d983819c9
151 changed files with 3403 additions and 1303 deletions

25
cryptpad/notes.md Normal file
View File

@@ -0,0 +1,25 @@
# CryptPad — Notes
## Config directory requires emptyDir + initContainer
CryptPad's `/cryptpad/config/` directory is in the image overlay filesystem and is not writable
by the container process even when running as root.
**Fix**: mount an `emptyDir` at `/cryptpad/config` and use an initContainer to pre-seed
`config.example.js` from the image into the emptyDir:
```yaml
initContainers:
- name: seed-config
image: cryptpad/cryptpad:version-X.Y.Z
command: [sh, -c, "cp /cryptpad/config/config.example.js /config-dest/config.example.js"]
volumeMounts:
- name: cryptpad-config
mountPath: /config-dest
volumes:
- name: cryptpad-config
emptyDir: {}
```
Set `CPAD_CONF=/cryptpad/config/config.js` — the startup script copies `config.example.js` to
`config.js` on first run if `config.js` doesn't exist.

View File

@@ -22,7 +22,7 @@ spec:
type: RuntimeDefault
initContainers:
- name: seed-config
image: cryptpad/cryptpad:latest
image: cryptpad/cryptpad:version-2026.5.1
command:
- sh
- -c
@@ -33,9 +33,18 @@ spec:
volumeMounts:
- name: cryptpad-config
mountPath: /config-dest
securityContext:
runAsNonRoot: false
runAsUser: 0
allowPrivilegeEscalation: false
capabilities:
drop: [ALL]
readOnlyRootFilesystem: false
seccompProfile:
type: RuntimeDefault
containers:
- name: cryptpad
image: cryptpad/cryptpad:latest
image: cryptpad/cryptpad:version-2026.5.1
ports:
- name: http
containerPort: 3000
@@ -80,7 +89,14 @@ spec:
periodSeconds: 10
failureThreshold: 3
securityContext:
runAsNonRoot: false
runAsUser: 0
allowPrivilegeEscalation: false
capabilities:
drop: [ALL]
readOnlyRootFilesystem: false
seccompProfile:
type: RuntimeDefault
volumes:
- name: cryptpad-data
persistentVolumeClaim:

View File

@@ -1,4 +1,4 @@
version: 2024.x-1
version: 2026.5.1-2
defaultConfig:
namespace: cryptpad
externalDnsDomain: '{{ .cloud.domain }}'