Removes the full Nextcloud stack (PostgreSQL/CNPG, Valkey, Caddy sidecar) and replaces it with oCIS at drive.tr1ceracop.de. oCIS is self-contained (no external DB/cache needed) with S3ng storage backend on Hetzner Object Storage (bucket: ocis-tr1ceracop). Chart sourced from git via vendir since it is not published to a Helm repo. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
53 lines
1.1 KiB
YAML
53 lines
1.1 KiB
YAML
apiVersion: v1
|
|
data:
|
|
csp.yaml: |
|
|
---
|
|
directives:
|
|
child-src:
|
|
- '''self'''
|
|
connect-src:
|
|
- '''self'''
|
|
default-src:
|
|
- '''none'''
|
|
font-src:
|
|
- '''self'''
|
|
frame-ancestors:
|
|
- '''self'''
|
|
frame-src:
|
|
- '''self'''
|
|
- 'blob:'
|
|
img-src:
|
|
- '''self'''
|
|
- 'data:'
|
|
- 'blob:'
|
|
manifest-src:
|
|
- '''self'''
|
|
media-src:
|
|
- '''self'''
|
|
object-src:
|
|
- '''self'''
|
|
- 'blob:'
|
|
script-src:
|
|
- '''self'''
|
|
- '''unsafe-inline'''
|
|
style-src:
|
|
- '''self'''
|
|
- '''unsafe-inline'''
|
|
proxy.yaml: |
|
|
---
|
|
policy_selector:
|
|
static:
|
|
policy: ocis
|
|
kind: ConfigMap
|
|
metadata:
|
|
annotations:
|
|
a8r.io/repository: ssh://git@git.tr1ceracop.de:222/gitea_admin/k8s-and-chill.git
|
|
labels:
|
|
app.kubernetes.io/instance: ocis
|
|
app.kubernetes.io/managed-by: Helm
|
|
app.kubernetes.io/name: ocis
|
|
app.kubernetes.io/version: 7.1.4
|
|
helm.sh/chart: ocis-0.7.0
|
|
name: proxy-config
|
|
namespace: ocis
|