Initial commit

This commit is contained in:
2026-07-22 01:23:40 -04:00
commit de9b3c0c1e
8 changed files with 348 additions and 0 deletions
+257
View File
@@ -0,0 +1,257 @@
#SPDX-License-Identifier: MIT-0
---
# tasks file for ansible-role-peertube
- name: add peertube repo
kubernetes.core.helm_repository:
name: peertube
repo_url: https://dl.peertube.com/charts/
register: repo_update
- name: update repos
command: helm repo update
when: repo_update.changed
- name: deploy peertube
kubernetes.core.helm:
name: peertube
chart_ref: peertube/peertube
release_namespace: peertube
create_namespace: true
values:
image:
repository: chocobozzz/peertube
pullPolicy: IfNotPresent
config:
serverName: peertube.eom.dev
webadminConfig: true
secret: "{{ peertube_secret }}"
admin:
email: eric@eom.dev
mail:
transport: smtp
# sendmail:
hostname: postfix.eom.dev
port: 587
username: peertube
fromAddress: peertube@eom.dev
password: "{{ peertube_admin_password }}"
## Data storage on S3 - will still require persistence even if enabled.
objectStorage:
enabled: true
endpoint: minio.eom.dev
region: us-east-1
# uploadACL: public-read
# uploadACLPrivate: private
# maxUploadPart: 2GB
accessKey: "{{ peertube_minio_access_key }}""
secretKey: "{{ peertube_minio_secret_key }}"
streaming:
bucket_name: peertube
prefix: streaming/
# base_url:
videos:
bucket_name: peertube
prefix: videos/
# base_url:
exports:
bucket_name: peertube
prefix: exports/
# base_url:
originals:
bucket_name: peertube
prefix: originals/
# base_url:
captions:
bucket_name: peertube
prefix: captions/
# base_url:
## Main persistent storage, will be used for uploads, processing, plugins, etc
persistence:
enabled: true
size: 2Ti
storageClass: "nfs-client"
extraConfig:
## It's recommended to limit this to only your internal cluster network
trust_proxy:
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/24
- fc00::/7
# - loopback
instance:
description: "PeerTube on eom.dev"
## Extra environment variables to set on Peertube
##
extraEnv:
- name: PT_INITIAL_ROOT_PASSWORD
value: "{{ peertube_admin_password }}"
# - name: TZ
# value: Europe/Stockholm
extraSecret: {}
# PEERTUBE_INSTANCE_TERMS: "These are some very secret terms-of-service"
## Extra values to set on the pod spec.
## Can be used for setting things like host aliases, overhead, custom schedulers, etc
##
extraPodSpec: {}
# Additional volumes of the peertube pod.
extraVolumes: []
# - name: my-config
# configMap:
# name: my-config
# Additional volume mounts of the peertube container.
extraVolumeMounts: []
# - name: my-config
# mountPath: /my-path/
# subPath: my-file
## Self-deployed PostgreSQL database
## See: https://github.com/bitnami/charts/tree/master/bitnami/postgresql
##
postgresql:
enabled: true
auth:
database: peertube
username: peertube
# existingSecret:
# secretKeys:
# userPasswordKey: password
persistence:
enabled: true
## Externally managed PostgreSQL, required if postgresql.enabled=false
##
externalPostgresql:
host:
# port: 5432
database: peertube
username: peertube
# password:
# ssl: true
# existingSecret:
# existingSecretKey: postgres-password
## Self-deployed Redis database
## See: https://github.com/bitnami/charts/tree/master/bitnami/redis
##
redis:
enabled: true
architecture: standalone
auth:
enabled: true
# password: peertube
# existingSecret: redis-secret
# existingSecretPasswordKey: redis-password
master:
kind: Deployment
persistence:
enabled: true
## Externally managed Redis, required if redis.enabled=false
##
externalRedis:
host:
# port: 6379
# db: 0
# password:
# existingSecret:
# existingSecretKey: redis-password
## Default probes, using ping API to avoid excessive echo
##
livenessProbe:
httpGet:
path: /api/v1/ping
port: http
readinessProbe:
httpGet:
path: /api/v1/ping
port: http
startupProbe:
httpGet:
path: /api/v1/ping
port: http
serviceAccount:
## Specifies whether a service account should be created
create: true
## Annotations to add to the service account
annotations: {}
## The name of the service account to use.
## If not set and create is true, a name is generated using the fullname template
# name:
podAnnotations: {}
podSecurityContext:
fsGroup: 999
securityContext:
readOnlyRootFilesystem: true
runAsNonRoot: true
runAsUser: 999
# capabilities:
# drop:
# - ALL
service:
type: ClusterIP
port: 80
rtmpPort: 1935
ingress:
enabled: true
className: ""
annotations: {}
# kubernetes.io/ingress.class: nginx
# kubernetes.io/tls-acme: "true"
paths:
- path: /
pathType: ImplementationSpecific
tls: []
- secretName: peertube-tls
hosts:
- peertube.eom.dev
resources: {}
# limits:
# cpu: 100m
# memory: 128Mi
# requests:
# cpu: 100m
# memory: 128Mi
autoscaling:
enabled: false
minReplicas: 1
maxReplicas: 3
targetCPUUtilizationPercentage: 80
# targetMemoryUtilizationPercentage: 80
nodeSelector: {}
tolerations: []
affinity: {}