Commit Graph
989 Commits
Author SHA1 Message Date
Junv (via Hermes) c72f12ad8e ci: trigger workflow to bump PLACEHOLDER image 2026-06-14 12:17:22 +10:00
Junv (via Hermes) 89ccee86bd fix(demo-service): move imagePullSecrets to pod-level
K8s ignores imagePullSecrets at container-level; it must be at pod spec level.
This is why the pull was failing with 401.
2026-06-14 12:13:37 +10:00
github-actions[bot] 15248b4ca2 ci(demo-service): bump image to git-cbb50ac 2026-06-14 02:11:06 +00:00
Junv (via Hermes) cbb50ac941 ci(demo-service): move manifest to home-apps/ root for ArgoCD
- ArgoCD 'home-apps' app tracks the home-apps/ directory at root level only
- Move k8s-manifest.yaml to home-apps/demo-service.yaml (sibling of other apps)
- Keep source code (Dockerfile, service.py, etc.) in home-apps/demo-service/ subdirectory
- Update workflow to update the new path
- Also fix imagePullSecrets placement (pod-level not container-level)
2026-06-14 12:10:22 +10:00
github-actions[bot] b12bc67b17 ci(demo-service): bump image to git-49703c4 2026-06-14 02:02:47 +00:00
Junv (via Hermes) 49703c4c8f ci(demo-service): fix sed regex to match both old and new image references 2026-06-14 12:02:10 +10:00
Junv (via Hermes) 425955b921 ci(demo-service): GitHub Actions workflow for ghcr.io build
- .github/workflows/build-demo-service.yml builds on push when home-apps/demo-service/**
- Pushes to ghcr.io/wahyd4/demo-manager with git SHA tag + :latest
- Updates k8s-manifest.yaml with new image tag
- ArgoCD picks up the new image on next sync

k8s-manifest changes:
- image: ghcr.io/wahyd4/demo-manager (was docker.io/library/demo-manager)
- imagePullPolicy: Always
- imagePullSecrets: github-image-pull-secret (auth for ghcr.io)
2026-06-14 11:59:52 +10:00
Junv (via Hermes) 031f39bae6 fix(demo-service): force inline Content-Disposition to prevent download
- All responses (HTML, CSS, JS, images) now have Content-Disposition: inline
- Add Cache-Control: no-store to bust any cached attachment response
- 401/404 error pages: inline, text/html, no-store
2026-06-14 11:49:52 +10:00
Junv (via Hermes) cc0fe77749 fix(demo-service): render HTML inline instead of download
- FileResponse sets Content-Disposition: attachment by default
- Switch to HTMLResponse for .html files to render in browser
2026-06-14 11:45:34 +10:00
Junv (via Hermes) c76e3f86a8 fix(demo-service): drafts accessible when authenticated
- New /site-content endpoint serves files with visibility+auth check
- All paths proxied through API (not Caddy file_server)
- Drafts: 401 canvas page (no auth) or 200 content (with auth)
- Nonexistent: 404 canvas page
- Preserves proper HTTP status codes
2026-06-14 11:43:33 +10:00
Junv (via Hermes) a8a09c6675 fix(demo-service): restore admin UI, add canvas error page for 401/403/404
- admin-ui.html extracted from git history
- Caddy handle_errors serves canvas page for all HTML errors
- Error page served directly by Caddy (correct status code preserved)
- Republished hermes-stats and my-awesome-demo
- Modular file structure: _config.py, _loaders.py, admin-ui.html, error-page.html
2026-06-14 11:36:04 +10:00
Junv (via Hermes) 10a055d37c feat(demo-service): canvas particle animation error page
- Chill canvas animation with floating particles + connections
- 'This page isnt available right now' friendly message
- Modular file structure: _config.py + _loaders.py for env vars and HTML
- No login method exposed on error page
2026-06-14 11:29:42 +10:00
Junv (via Hermes) 0dfb2eaa36 feat(demo-service): minimal SVG-animated access-restricted page
- Replaces login page with pure SVG animation (no login buttons)
- Animated lock icon, pulsing dots, orbiting ring, breathing circles
- Lightweight — zero dependencies, pure CSS/SVG
2026-06-14 11:22:09 +10:00
Junv (via Hermes) ad75449e0d feat(demo-service): beautiful login-required page for /admin
- Replaces 401 JSON with styled HTML error page
- Glassmorphism card with Pocket ID SSO sign-in button
- New sites default to draft (published: false)
2026-06-14 11:20:30 +10:00
Junv (via Hermes) b694a317d4 fix(demo-service): site title opens new tab unless disabled 2026-06-14 11:15:29 +10:00
Junv (via Hermes) 7edfe2cfa4 fix(demo-service): always render site name as clickable link
- Published sites: link to public URL
- Draft sites: link with dashed underline → opens preview modal
2026-06-14 11:11:36 +10:00
Junv (via Hermes) 4dce2be3d4 feat(demo-service): add publish/unpublish draft system with preview
- Sites now start as drafts (published: false) — hidden from public
- Publish endpoint makes site live at demo.junv.cc/<name>
- Unpublish hides it back to draft
- Preview endpoint serves draft HTML to authenticated users
- Caddy blocks .draft/.bak files (defense-in-depth)
- Backward compatible: existing sites default to published
- sync_visibility() handles all state transitions
2026-06-14 11:10:25 +10:00
Junv (via Hermes) 3e36501eba fix: Caddy routing for /admin without trailing slash 2026-06-14 10:59:14 +10:00
Junv (via Hermes) d4484e6750 feat: add Demo Service — Caddy + FastAPI for hosting demo sites at demo.junv.cc
- Caddy as static file server + reverse proxy
- FastAPI management API with Pocket ID SSO
- Web UI at demo.junv.cc/admin
- Agent API with Bearer token auth
- Demo sites accessible at demo.junv.cc/<folder-name>
- NFS PVC for persistent storage
- Enable/disable per-site
2026-06-14 10:57:36 +10:00
Junv (via Hermes) 3a860bb486 remove: K8s security-audit cronjob (path not available on node, switching to Hermes cron) 2026-06-13 15:26:14 +10:00
Junv (via Hermes) e99ec79ae5 add: cronjob for weekly security audit (Sat 7:50 AM) 2026-06-13 15:20:38 +10:00
junv e6f3892b02 Add security script 2026-06-13 15:16:10 +10:00
junv fccba836df Whitelist VPN IPs in CrowdSec sync 2026-06-13 09:40:46 +10:00
junv b579775729 Update token refresh 2026-06-13 09:34:27 +10:00
junv c23b15946e Update n8n 2026-06-13 07:59:06 +10:00
junvandGitHub 7b9f5e5c18 Merge pull request #3 from wahyd4/upgrade-docker-images-2026-06
 chore: upgrade Docker images batch — June 2026
2026-06-01 16:57:31 +10:00
Junv (via Hermes) a8b6890a99 chore: upgrade Docker images batch — June 2026
Updates 7 Docker images across the infrastructure manifests (PG14 kept as-is):

  media/jackett.yaml
    linuxserver/jackett: 0.24.1124 → 0.24.1985 (patch)

  media/media.yaml
    linuxserver/qbittorrent: version-5.1.2-r4 → version-5.2.1_v2.0.12 (major 5.1→5.2)

  home-apps/n8n.yaml
    n8nio/n8n: 2.15.0 → 2.23.1 (minor)

  db/qdrant.yaml
    qdrant/qdrant: v1.16-unprivileged → v1.18.1-unprivileged (minor)

  kube-vip/daemonset.yaml
    kube-vip/kube-vip: v0.4.4 → v0.9.2 (conservative, stayed within v0.x)

  on-demand/once-etcd-job.yaml
    etcd: 3.5.1-0 → 3.5.30-0 (patch)

  adhoc-config/oauth2-proxy.yaml
    oauth2-proxy/oauth2-proxy: v7.6.0 → v7.15.2 (minor)

Note: postgres:14 kept unchanged per PR review feedback.
kube-vip kept at v0.9.2 (latest v0.x) instead of v1.2.0 to avoid
v0→v1 breaking changes.
2026-06-01 16:52:51 +10:00
junv b6d13bed5a Enhance security level of postgres and redis 2026-05-24 10:18:43 +10:00
junv fe85c6ab8f Update argo 2026-05-16 08:58:10 +10:00
junv 2346303132 Update terraform modules 2026-05-16 08:48:04 +10:00
junvandCopilot e41ff70182 Update k3s
Co-authored-by: Copilot <copilot@github.com>
2026-05-03 15:28:58 +10:00
junv 4a5168c332 Update 2026-04-14 11:50:27 +10:00
junv 5b50b27752 Correct hermes dashboard! 2026-04-14 11:41:58 +10:00
小黑 (AI Bot) b0c19a6a2e Grant ai-bot full admin ownership of home-apps namespace 2026-04-14 11:27:47 +10:00
小黑 (AI Bot) 37052f3971 Add RBAC for ai-bot to manage EndpointSlices in home-apps namespace 2026-04-14 11:21:53 +10:00
小黑 (AI Bot) bf1bf4d9b9 Add hermes-dashboard service + ingress with OAuth2 SSO for bot.junv.cc 2026-04-14 11:08:56 +10:00
junv 9115ee61cc update home apps 2026-04-08 11:55:03 +10:00
junv 0f22882fe2 Update media 2026-04-08 09:20:19 +10:00
junv 42d5a3be83 Add logseq 2026-04-07 11:25:21 +10:00
junv 5ba95185fc Update n8n 2026-04-07 09:31:42 +10:00
junv a27a8362dc Update 2026-04-01 20:01:53 +11:00
junv 5c6786231f Update auto ban 2026-04-01 19:54:01 +11:00
junv 7ae2616308 Add crowdsec auto ban 2026-04-01 19:51:16 +11:00
junv f540312aa9 Apply links role binding 2026-04-01 19:36:04 +11:00
junv ffad3b8c3c Expose redis to k8s 2026-03-29 10:09:27 +11:00
junv 9e49328e7e Update n8n 2026-03-21 14:10:48 +11:00
junv a892c26ca6 Add k3s Skills.md 2026-03-17 10:27:32 +11:00
junv e271d82abe Update 2026-03-14 08:22:43 +11:00
junv 1bc86938da Update n8n 2026-02-24 10:38:28 +11:00
junv cc29275c68 Update image 2026-02-23 19:14:15 +11:00