Collection of the Shivering-Isles infrastructure.
  • Earthly 31.2%
  • Go Template 21.6%
  • HCL 17%
  • Shell 15%
  • Dockerfile 9.2%
  • Other 6%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Renovate Bot 3ab406e389
All checks were successful
gitops-pr-validation Pipeline completed successfully
build-upload-gitops-docs Pipeline completed successfully
build-upload-runbooks Pipeline completed successfully
helm-chart-pipeline Pipeline completed successfully
gitops-images Pipeline completed successfully
chore(deps): update helm release hcloud-exporter to v4.25.0
2026-08-18 06:24:55 +00:00
.chglog chore(chglog): Style removal entires in changelog 2024-01-07 01:45:40 +01:00
.vale docs(vale): Add linting step to documentation 2024-01-01 19:39:00 +01:00
apps chore(deps): update helm release hcloud-exporter to v4.25.0 2026-08-18 06:24:55 +00:00
bin feat(images): Migrate dovecot and postfix 2026-08-16 23:15:15 +02:00
bootstrap chore(deps): update helm release tigera-operator to v3.32.1 2026-07-17 06:19:09 +00:00
charts chore(deps): update docker.io/library/nextcloud docker tag to v34.0.3 2026-08-15 06:08:24 +00:00
clusters/k8s01 chore(deps): update dependency fluxcd/flux2 to v2.9.4 2026-08-08 06:05:21 +00:00
docs docs(iamges): Remove dropped images from the docs 2026-08-16 23:59:07 +02:00
images Merge remote-tracking branch 'origin/renovate/getsops-sops-3.x' 2026-08-18 02:28:26 +02:00
infrastructure feat(vpa): Upgrade to version 1.7.1 2026-08-13 01:53:06 +02:00
shared feat(images): Migrate dovecot and postfix 2026-08-16 23:15:15 +02:00
talos feat(images): Replace tools setup with Earthly by using Taskfile 2026-08-16 23:15:11 +02:00
tekton chore(deps): update ghcr.io/renovatebot/renovate docker tag to v44.31.0 2026-08-17 06:12:08 +00:00
terraform chore(deps): update terraform hcloud to v1.68.0 2026-08-06 07:26:25 +00:00
views chore(views): Remove test line from view-file 2022-01-30 00:21:24 +01:00
.gitignore terraform: Initial commit! 2021-10-05 03:35:01 +02:00
.gitleaksignore ci(gitleaks): Update ignore file 2026-07-16 12:43:28 +02:00
.sops.yaml fix(nas): Switch to probe for external service 2024-11-26 03:01:04 +01:00
.vale.ini docs(vale): Add linting step to documentation 2024-01-01 19:39:00 +01:00
Earthfile feat(images): Replace tools setup with Earthly by using Taskfile 2026-08-16 23:15:11 +02:00
README.md feat(fluxcd): Adjust webhook for forgejo 2026-07-12 13:29:56 +02:00
renovate.json feat(images): Migrate dovecot and postfix 2026-08-16 23:15:15 +02:00
Taskfile.yml feat(images): Replace tools setup with Earthly by using Taskfile 2026-08-16 23:15:11 +02:00

Shivering-Isles GitOps Infrastructure

This repository has become the centre of Shivering-Isles Infrastructure. It homes basically all deployments of software, various custom container images, various self-maintained helm charts and more.

Usage

For SI-GitLab this would look like this:

export GITLAB_TOKEN=<project access token able to write the API and repository>
flux bootstrap gitlab \
  --hostname=git.shivering-isles.com \
  --ssh-hostname=git.shivering-isles.com:2222 \
  --ssh-key-algorithm ed25519 \
  --owner=<your user / team> \
  --repository=<your repository name> \
  --path=clusters/<your cluster name>

Ideas & ToDo's

This toolchain is still under development. Before it will be used in production there are still some things left to do:

  • Buy hardware for the project.
  • Provide CLI container that contains all tools.
  • Automate overlay network deployment (calico)
  • Use encrypted overlay network (calico+wireguard)
  • Automate cluster monitoring deployment (kube-prometheus)
  • Automate ingress-controller deployment (ingress-nginx)
  • Automate policy enforcement (kyverno) deployment
  • Encrypt root filesystems for all nodes (LUKS + clevis)
  • Enforce SELinux on the deployed machines
  • Automate system upgrades using Kubernetes (system-upgrade-controller)
  • Automate system configuration using Kubernetes (system-upgrade-controller)
  • Provide an fully encrypted (handled on host level) storage class (longhorn)
  • Deploy cert-manager
  • Deploy credentials for cert-manager
  • Automate ingress-controller default certificate deployment
  • Add encrypted deployment instructions (SOPS + fluxcd)
  • Integrate Renovatebot with this repository to manage updates.
  • Automate Kubernetes upgrades
  • Automate ingress-controller configuration for proxy-protocol
  • Migrate apps to GitOps and Kubernetes
  • Deploy kubelet with proper certificates
  • Centralised logging (using loki/greylog/ELK/…)
  • Add secure runtime class (gVisor/kata-container/…) for exposed containers
  • Move to immutable base-system
  • Set Priority classes for workloads (on namespace level it's done, but helm releases still need adjustment)
  • Migrate to Forgejo
    • Kubernetes
      • fluxcd source
      • fluxcd webhook
      • renovate
      • Tekton
    • Restore SI-GitLab repositories
      • infrastructure-gitops
      • infrastructure
      • hcloud-dynfw
      • blog
    • Restore helm releases and alike
  • Harden egress NetworkPolicies keycloak, forecastle, matrix
  • Backup essential volumes using mc and client-side encryption and Object Locks
  • Migrate S3 from Minio to VersityGw
    • Mastodon
    • Hedgedoc
    • gitops-docs
    • runbooks
    • postgres-operator logical backup
    • postgres-operator WAL/Base backup
    • longhorn backup
    • blog-archive
    • gitlab-runner-cache
    • shelly-firmware
    • togehter