feat(supabase): add services and statefulset for database management

feat(synapse): update ingress to use traefik ingress class and bump version

feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress

feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration

fix(taiga): update liveness and readiness probes to use tcpSocket for health checks

fix(taiga): change PVC access mode to ReadWriteMany for media and static storage

feat(traefik): add icon and ignore rules for traefik service

docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments

feat(ushahidi): implement dedicated Redis deployment for Ushahidi

fix(vllm): update deployment strategy and readiness/liveness probes for improved stability

fix(writefreely): pin writefreely image version to v0.15.1 for consistency

docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
This commit is contained in:
2026-07-02 21:34:27 +00:00
parent 9f5057dff8
commit 4d983819c9
151 changed files with 3403 additions and 1303 deletions

35
syncthing-relay/README.md Normal file
View File

@@ -0,0 +1,35 @@
# Syncthing Relay Server
strelaysrv relays encrypted Syncthing traffic between devices that cannot connect directly (e.g. both behind NAT).
## Bandwidth warning
Unlike the discovery server, the relay **proxies all sync traffic**. Every byte synced between clients who cannot connect directly flows through your Wild Central device and your internet connection. On a home or community internet connection, heavy use by multiple members syncing large files can saturate your upstream bandwidth.
Deploy this only if you know your members need relay support and your connection can handle it. If members can connect directly, the relay is never used.
## Network setup
Port **22067** (TCP) must be forwarded on your router to the relay's LoadBalancer IP. Check the assigned IP with:
```bash
kubectl get svc -n syncthing-relay syncthing-relay
```
Set `externalAddress` in your app config to `your-domain-or-ip:22067` so the relay advertises the correct public address.
## Privacy
This relay is configured as private (not registered with the Syncthing global relay pool). Only Syncthing clients that explicitly add your relay URL will use it. The relay operator can see which device IDs are connecting and data volumes, but not file contents — traffic is end-to-end encrypted between Syncthing clients.
## Syncthing client configuration
Add the relay URI in Syncthing settings under **Settings → Connections → Relays**:
```
relay://your-domain:22067
```
## Status
The relay status page is available at `https://{{ domain }}/status`.

6
syncthing-relay/app.yaml Normal file
View File

@@ -0,0 +1,6 @@
name: syncthing-relay
is: syncthing-relay
description: Syncthing Relay Server (strelaysrv) relays encrypted Syncthing traffic between devices that cannot connect directly due to NAT or firewall restrictions.
category: services
icon: https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/syncthing.svg
latest: "1"

View File

@@ -0,0 +1,69 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: syncthing-relay
namespace: {{ .namespace }}
spec:
replicas: 1
strategy:
type: Recreate
selector:
matchLabels:
component: server
template:
metadata:
labels:
component: server
spec:
securityContext:
runAsNonRoot: false
runAsUser: 0
seccompProfile:
type: RuntimeDefault
containers:
- name: strelaysrv
image: syncthing/relaysrv:2.1.1
args:
- --listen=:22067
- --status-srv=:22068
- --keys=/var/strelaysrv
- --pools=
- --ext-address={{ .externalAddress }}
ports:
- name: relay
containerPort: 22067
protocol: TCP
- name: status
containerPort: 22068
protocol: TCP
resources:
limits:
cpu: 500m
memory: 128Mi
requests:
cpu: 25m
memory: 32Mi
volumeMounts:
- name: relay-data
mountPath: /var/strelaysrv
livenessProbe:
httpGet:
path: /status
port: 22068
initialDelaySeconds: 10
periodSeconds: 30
failureThreshold: 3
readinessProbe:
httpGet:
path: /status
port: 22068
initialDelaySeconds: 5
periodSeconds: 10
failureThreshold: 3
securityContext:
readOnlyRootFilesystem: false
volumes:
- name: relay-data
persistentVolumeClaim:
claimName: syncthing-relay-data
restartPolicy: Always

View File

@@ -0,0 +1,26 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: syncthing-relay
namespace: {{ .namespace }}
annotations:
external-dns.alpha.kubernetes.io/target: {{ .externalDnsDomain }}
external-dns.alpha.kubernetes.io/cloudflare-proxied: "false"
external-dns.alpha.kubernetes.io/ttl: "60"
spec:
ingressClassName: traefik
rules:
- host: {{ .domain }}
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: syncthing-relay-status
port:
number: 80
tls:
- hosts:
- {{ .domain }}
secretName: {{ .tlsSecretName }}

View File

@@ -0,0 +1,15 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: {{ .namespace }}
labels:
- includeSelectors: true
pairs:
app: syncthing-relay
managedBy: kustomize
partOf: wild-cloud
resources:
- namespace.yaml
- pvc.yaml
- deployment.yaml
- service.yaml
- ingress.yaml

View File

@@ -0,0 +1,8 @@
version: 2.1.1
defaultConfig:
namespace: syncthing-relay
domain: relay.{{ .cloud.domain }}
externalDnsDomain: "{{ .cloud.domain }}"
tlsSecretName: wildcard-wild-cloud-tls
externalAddress: "{{ .cloud.domain }}:22067"
storage: 100Mi

View File

@@ -0,0 +1,4 @@
apiVersion: v1
kind: Namespace
metadata:
name: "{{ .namespace }}"

View File

@@ -0,0 +1,11 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: syncthing-relay-data
namespace: {{ .namespace }}
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: {{ .storage }}

View File

@@ -0,0 +1,29 @@
apiVersion: v1
kind: Service
metadata:
name: syncthing-relay
namespace: {{ .namespace }}
spec:
type: LoadBalancer
selector:
component: server
ports:
- name: relay
port: 22067
targetPort: 22067
protocol: TCP
---
apiVersion: v1
kind: Service
metadata:
name: syncthing-relay-status
namespace: {{ .namespace }}
spec:
type: ClusterIP
selector:
component: server
ports:
- name: status
port: 80
targetPort: 22068
protocol: TCP