{ kubernetes.resources = { secrets.database.stringData.databasePassword = "ref+sops://secrets/kubernetes.yaml#/nextcloud/databasePassword"; deployments = { server.spec = { selector.matchLabels = { app = "nextcloud"; component = "server"; }; strategy = { type = "RollingUpdate"; rollingUpdate = { maxSurge = 0; maxUnavailable = 1; }; }; template = { metadata.labels = { app = "nextcloud"; component = "server"; }; spec = { volumes.data.persistentVolumeClaim.claimName = "data"; containers.nextcloud = { image = "nextcloud:28"; ports.web.containerPort = 80; env = { POSTGRES_USER.value = "nextcloud"; POSTGRES_DB.value = "nextcloud"; POSTGRES_HOST.value = "lewis.dmz"; POSTGRES_PASSWORD.valueFrom.secretKeyRef = { name = "database"; key = "databasePassword"; }; }; volumeMounts = [{ name = "data"; mountPath = "/var/www/html"; }]; }; securityContext = { fsGroup = 33; fsGroupChangePolicy = "OnRootMismatch"; }; affinity.nodeAffinity.preferredDuringSchedulingIgnoredDuringExecution = [{ weight = 1; preference.matchExpressions = [{ key = "storageType"; operator = "In"; values = [ "fast" ]; }]; }]; }; }; }; database.spec = { selector.matchLabels = { app = "nextcloud"; component = "database"; }; template = { metadata.labels = { app = "nextcloud"; component = "database"; }; spec = { containers.postgres = { image = "postgres:15"; imagePullPolicy = "IfNotPresent"; ports.postgres.containerPort = 5432; env = { POSTGRES_DB.value = "nextcloud"; POSTGRES_USER.value = "nextcloud"; PGDATA.value = "/pgdata/data"; POSTGRES_PASSWORD.valueFrom.secretKeyRef = { name = "database"; key = "databasePassword"; }; }; volumeMounts = [{ name = "database"; mountPath = "/pgdata"; }]; }; volumes.database.persistentVolumeClaim.claimName = "database"; }; }; }; }; services = { server.spec = { selector = { app = "nextcloud"; component = "server"; }; ports.web = { port = 80; targetPort = "web"; }; }; database.spec = { selector = { app = "nextcloud"; component = "database"; }; ports.postgres = { port = 5432; targetPort = "postgres"; }; }; }; }; lab = { ingresses.web = { host = "cloud.kun.is"; service = { name = "server"; portName = "web"; }; }; longhorn.persistentVolumeClaim = { data = { volumeName = "nextcloud"; storage = "50Gi"; }; database = { volumeName = "nextcloud-db"; storage = "400Mi"; }; }; }; }