feat(supabase): add services and statefulset for database management

feat(synapse): update ingress to use traefik ingress class and bump version

feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress

feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration

fix(taiga): update liveness and readiness probes to use tcpSocket for health checks

fix(taiga): change PVC access mode to ReadWriteMany for media and static storage

feat(traefik): add icon and ignore rules for traefik service

docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments

feat(ushahidi): implement dedicated Redis deployment for Ushahidi

fix(vllm): update deployment strategy and readiness/liveness probes for improved stability

fix(writefreely): pin writefreely image version to v0.15.1 for consistency

docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
This commit is contained in:
2026-07-02 21:34:27 +00:00
parent 9f5057dff8
commit 4d983819c9
151 changed files with 3403 additions and 1303 deletions

28
zulip/notes.md Normal file
View File

@@ -0,0 +1,28 @@
# Zulip — Notes
## TLS-terminating reverse proxy configuration
Zulip's internal nginx redirects port 80 → HTTPS by default. When Traefik terminates TLS and
forwards plain HTTP internally, this causes an infinite redirect loop.
Set these two env vars in the deployment:
```yaml
- name: DISABLE_HTTPS
value: "true"
- name: LOADBALANCER_IPS
value: "10.244.0.0/16" # Kubernetes pod CIDR
```
- `DISABLE_HTTPS=true`: configures nginx in `http_only` mode, removing the 80 → HTTPS redirect.
- `LOADBALANCER_IPS`: trusts `X-Forwarded-Proto: https` from the pod CIDR so Zulip generates
`https://` links instead of `http://`. Set to the cluster's pod network CIDR (typically
`10.244.0.0/16` for Flannel).
Also update liveness/readiness probes from port 443 HTTPS to port 80 HTTP when
`DISABLE_HTTPS=true` is set.
## Root URL returns 404 — this is expected
Zulip's root URL (`/`) returns 404 "No organization found" — this is correct behavior.
The actual login page is at `/accounts/home/`.

View File

@@ -97,6 +97,11 @@ spec:
secretKeyRef:
name: zulip-secrets
key: smtp.password
# Reverse proxy configuration (Traefik terminates TLS)
- name: DISABLE_HTTPS
value: "true"
- name: LOADBALANCER_IPS
value: "10.244.0.0/16"
resources:
limits:
cpu: "2"
@@ -112,8 +117,7 @@ spec:
livenessProbe:
httpGet:
path: /accounts/home/
port: 443
scheme: HTTPS
port: 80
httpHeaders:
- name: Host
value: "{{ .domain }}"
@@ -124,8 +128,7 @@ spec:
readinessProbe:
httpGet:
path: /accounts/home/
port: 443
scheme: HTTPS
port: 80
httpHeaders:
- name: Host
value: "{{ .domain }}"