Homelab Applications¶
The applications the homelab cluster exists to run. The cluster itself — Flatcar, Kubeadm, Cilium, Rook-Ceph, ArgoCD and everything under them — is a separate repository with its own documentation; this site covers only what runs on top.
Applications¶
| Application | URL | Storage | Database | Authentication |
|---|---|---|---|---|
| Home Assistant | home.k8s.wlkr.ch | 5Gi for /config |
CloudNativePG, for the recorder | Authentik proxy, in front of its own login |
| Nextcloud | cloud.k8s.wlkr.ch | 50Gi for files | CloudNativePG | Authentik OIDC |
| Trivy Operator | — | 5Gi for the vulnerability database | None — findings are CRDs | None; it has no interface |
Trivy Operator has no UI and nothing to log into. It lives here rather than in the platform repository because it is a workload on the cluster: nothing the platform brings up depends on it.
How a directory becomes an application¶
The apps ApplicationSet in the platform repository watches this one and
generates an ArgoCD Application from every */application.yaml it finds.
Pushing a directory deploys an application; there is no list to register it in.
homelab (platform) homelab-apps (this repository)
Application argocd
└── ApplicationSet platform
└── Application workloads ──▶ ApplicationSet apps
(stage 12-workloads) └── one Application per directory
The apps ApplicationSet is created in the platform's last rollout stage, so
nothing here deploys until the whole platform beneath it is healthy. The
platform references this repository exactly once, as a repoURL, and never
reads what is in it.
These Applications are not under the platform's RollingSync strategy, so they
keep selfHeal: a hand-edited Deployment is reverted within minutes. Why the
split exists is in
GitOps Strategy.
What they have in common¶
Conventions is the full list. The short version:
- A namespace they own, with explicit Pod Security Admission labels.
- A
CiliumNetworkPolicydenying ingress by default. - A CloudNativePG
Cluster, never a chart's bundled database. - Proxy configuration for the
apps-gateway, which terminates TLS and forwards from inside the pod CIDR. - Authentik, not their own accounts, as far as each is capable of it.
Authentication¶
Both user-facing applications go through
Authentik, in the shape each one
supports. Nextcloud speaks OIDC, so it is real single sign-on
with the local login hidden. Home Assistant ships no OIDC
provider, so the Authentik outpost sits in front of its own login and browser
users authenticate twice. Both use auth.k8s.wlkr.ch, never the auth.infra
name, which resolves only on the local network — see
Two hostnames.
Adding one¶
Read Conventions first; it is short. The step-by-step version is Adding a Workload in the platform documentation.