Skip to content

Commit

Permalink
feat: add trusted CIDR vlan to no_auth
Browse files Browse the repository at this point in the history
  • Loading branch information
joryirving committed Jan 6, 2025
1 parent 74582a7 commit f08522a
Show file tree
Hide file tree
Showing 2 changed files with 30 additions and 28 deletions.
2 changes: 1 addition & 1 deletion kubernetes/main/apps/media/plex/app/helmrelease.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ spec:
env:
TZ: ${TIMEZONE}
PLEX_ADVERTISE_URL: https://plex.${SECRET_DOMAIN}:443,http://${SVC_PLEX_ADDR}:32400
PLEX_NO_AUTH_NETWORKS: ${NODE_CIDR}
PLEX_NO_AUTH_NETWORKS: ${NODE_CIDR},${TRUSTED_CIDR}
probes:
liveness: &probes
enabled: true
Expand Down
56 changes: 29 additions & 27 deletions kubernetes/shared/settings/cluster-secrets.sops.yaml
Original file line number Diff line number Diff line change
@@ -1,32 +1,34 @@
apiVersion: v1
kind: Secret
metadata:
name: cluster-secrets
namespace: flux-system
name: cluster-secrets
namespace: flux-system
stringData:
SECRET_ACME_EMAIL: ENC[AES256_GCM,data:umb7RbR4uWbgz98iHA==,iv:K9i/iq9Bc4PYoIpMfqaJTeexoxT1vbdfHUdOEe3GeR8=,tag:w6jcFxfq1xSyEMpfy/lhCg==,type:str]
BITWARDEN_ORG: ENC[AES256_GCM,data:desnaYiyd2wOun5XdG2sHAWDA4VHgXBdUQQv87i+BEy0Jywo,iv:aQm1ezWuP33vQizmE/efb3vWLZeeRUyhf1WbqTUHuCA=,tag:kuiZZIXGaA42tQXiA2Rn5g==,type:str]
BITWARDEN_PROJ: ENC[AES256_GCM,data:3xASPHhAzvxIh+n4h3pNGh8eUGRDlltTXAqkO5erghewmqGc,iv:DONQu8zQN4wMppg7NNG6klwSGjbb4C88Cqr3YyGdps0=,tag:S8oQebl4Q9xRvi4+LuEmPw==,type:str]
CLOUDFLARE_ACCOUNT_ID: ENC[AES256_GCM,data:kLP6M5Bb2BuNOarZ5i2SvE01QCk4sxgNtp7ZlXlIKt4=,iv:2SxTwsoMNJ4pEqA/og2Aewq7iO4EZC0EYxGd5P4DFyE=,tag:caSVj/2tKvlYJKC7J79egQ==,type:str]
SECRET_DOMAIN: ENC[AES256_GCM,data:4dlwtokraZ0=,iv:AyH/endMPGS/6iYDunUt1AqP0NIRqc2ZEVQe6JQRifw=,tag:IBhjr44MJu44hmc0UOLZEA==,type:str]
SVC_NUT_ADDR: ENC[AES256_GCM,data:YIz8zQ+sO21pOo0=,iv:8loreDYCo6YSf6yiYnTeUSd+DWIqdg/EcgALlIEVK8A=,tag:pQQJstkhBbbyo5Oa/WIypw==,type:str]
SECRET_ACME_EMAIL: ENC[AES256_GCM,data:umb7RbR4uWbgz98iHA==,iv:K9i/iq9Bc4PYoIpMfqaJTeexoxT1vbdfHUdOEe3GeR8=,tag:w6jcFxfq1xSyEMpfy/lhCg==,type:str]
BITWARDEN_ORG: ENC[AES256_GCM,data:desnaYiyd2wOun5XdG2sHAWDA4VHgXBdUQQv87i+BEy0Jywo,iv:aQm1ezWuP33vQizmE/efb3vWLZeeRUyhf1WbqTUHuCA=,tag:kuiZZIXGaA42tQXiA2Rn5g==,type:str]
BITWARDEN_PROJ: ENC[AES256_GCM,data:3xASPHhAzvxIh+n4h3pNGh8eUGRDlltTXAqkO5erghewmqGc,iv:DONQu8zQN4wMppg7NNG6klwSGjbb4C88Cqr3YyGdps0=,tag:S8oQebl4Q9xRvi4+LuEmPw==,type:str]
CLOUDFLARE_ACCOUNT_ID: ENC[AES256_GCM,data:kLP6M5Bb2BuNOarZ5i2SvE01QCk4sxgNtp7ZlXlIKt4=,iv:2SxTwsoMNJ4pEqA/og2Aewq7iO4EZC0EYxGd5P4DFyE=,tag:caSVj/2tKvlYJKC7J79egQ==,type:str]
SECRET_DOMAIN: ENC[AES256_GCM,data:4dlwtokraZ0=,iv:AyH/endMPGS/6iYDunUt1AqP0NIRqc2ZEVQe6JQRifw=,tag:IBhjr44MJu44hmc0UOLZEA==,type:str]
SVC_NUT_ADDR: ENC[AES256_GCM,data:YIz8zQ+sO21pOo0=,iv:8loreDYCo6YSf6yiYnTeUSd+DWIqdg/EcgALlIEVK8A=,tag:pQQJstkhBbbyo5Oa/WIypw==,type:str]
#ENC[AES256_GCM,data:27uZO6UzcTf5A9D6,iv:1OXUBE3M/TYquUyfFO9QK3rQsAsJ8t/dex6vg+d1bao=,tag:q5T/XEhCtRnBuiYkpR3Ltw==,type:comment]
TRUSTED_CIDR: ENC[AES256_GCM,data:WuEfwOvS3rNQZ5Kw/YqK,iv:VZB2mzK1QkkGbjknpklpH3UWqfu4+1TTM8rYiZ0uIko=,tag:ipPi1MPUmsR+n957QHpS8w==,type:str]
sops:
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age12v9uw8k6myrr49z9aq6jmcwa79aepu0p6p462nrv968qcae72pcspwldec
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBLaG00WmxPWjIvRjRVTTh3
V05uRFA2UmFXOFJIZmFnS3FvZVN0MkMvRVhjCmRqVnlQZDBOcUlzTzNTTDlvVnV4
ZTJ2RWd1M00yeWFTWEJVWUZITkYxU0EKLS0tIFlPcEtiN1E4SUlKckpyVm9ram5C
eG8vOG4zOXRQVW01K1hzNnNUdUxYNDQK2r6cmnIxsIDMUHfq8p0kOcr+E/KAea4z
tdtvD/HkOfTil0Qwld0NWRyA4DKC7AjhC0P8QlhYrNlfr5lqBqIFmQ==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2024-11-12T17:06:56Z"
mac: ENC[AES256_GCM,data:zZ7EasUlDiBltn+ktOogZ17k3xD4iF6uohs9frwlvDNAUxKsHSvAgUFrhA8YbIJUuJQGhpO9FtKMEVit62rw4wUjF+0BU/0od3jdkl/cbn+Z7R6YEBclIu66xCj+UU4TIYP0rkQQAKSPDeYrgyIRsGpYi6Fh546EDfSeq13mFq4=,iv:PBdOOVahiV3KdPYGg9aYeJ6Sj98H0haN0LIGwzGpA38=,tag:wjgHVy0F7BDxwDlIoF/vSg==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.9.1
kms: []
gcp_kms: []
azure_kv: []
hc_vault: []
age:
- recipient: age12v9uw8k6myrr49z9aq6jmcwa79aepu0p6p462nrv968qcae72pcspwldec
enc: |
-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBLaG00WmxPWjIvRjRVTTh3
V05uRFA2UmFXOFJIZmFnS3FvZVN0MkMvRVhjCmRqVnlQZDBOcUlzTzNTTDlvVnV4
ZTJ2RWd1M00yeWFTWEJVWUZITkYxU0EKLS0tIFlPcEtiN1E4SUlKckpyVm9ram5C
eG8vOG4zOXRQVW01K1hzNnNUdUxYNDQK2r6cmnIxsIDMUHfq8p0kOcr+E/KAea4z
tdtvD/HkOfTil0Qwld0NWRyA4DKC7AjhC0P8QlhYrNlfr5lqBqIFmQ==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2025-01-06T20:22:36Z"
mac: ENC[AES256_GCM,data:lp0JY1nGNfTHy+mJnx0v530kpjDtiLWCHXy5MzAJyWdwccDccOKRgozmcZMuXYHGbHkYjv784+qY/RBWM/NC32tHqq0zTsush/4zVud0B0qrJEs+nSsoEB1BAIscbBKFneSDznwkanA69sLS8Y+nI+12Rx4IrkglnaWtSoDU3Hg=,iv:/9McrbMBODU1SvHYWnhvOZXG6JdFsmA94u0ZQfe4NU0=,tag:H7B7myUYRzhVG7aCto+19w==,type:str]
pgp: []
encrypted_regex: ^(data|stringData)$
version: 3.9.2

0 comments on commit f08522a

Please sign in to comment.