This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/0xerr0r/blocky](https://redirect.github.com/0xERR0R/blocky) | minor | `a6d99f3` → `d9f15ed` | --- > [!WARNING] > Some dependencies could not be looked up. Check the [Dependency Dashboard](../issues/18710) for more information. Add the preset `:preserveSemverRanges` to your config if you don't want to pin your dependencies. --- ### Release Notes <details> <summary>0xERR0R/blocky (ghcr.io/0xerr0r/blocky)</summary> ### [`v0.30.0`](https://redirect.github.com/0xERR0R/blocky/releases/tag/v0.30.0) [Compare Source](https://redirect.github.com/0xERR0R/blocky/compare/v0.29.0...v0.30.0) #### Changelog ##### Features - [`0de3fac`](https://redirect.github.com/0xERR0R/blocky/commit/0de3fac101964aa85d6eb6ac43ed67d84d8116be): feat(sudn): handle resolver.arpa zone per RFC 9462 (DDR) ([#​2059](https://redirect.github.com/0xERR0R/blocky/issues/2059)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`c32863d`](https://redirect.github.com/0xERR0R/blocky/commit/c32863d342e4edaf949021bc21446ac8d5762e30): feat: add DNS-over-QUIC (DoQ) upstream support (RFC 9250) ([#​2013](https://redirect.github.com/0xERR0R/blocky/issues/2013)) ([@​elsbrock](https://redirect.github.com/elsbrock)) - [`22b0bdd`](https://redirect.github.com/0xERR0R/blocky/commit/22b0bdd3538e052b10660a3bfbcf1731d05b5b07): feat: add schedule-based blocking for deny/allowlist groups ([#​2037](https://redirect.github.com/0xERR0R/blocky/issues/2037)) ([@​alessandrocuzzocrea](https://redirect.github.com/alessandrocuzzocrea)) - [`842dda9`](https://redirect.github.com/0xERR0R/blocky/commit/842dda99a8ecbd489ee8755beea3ce6fe9fd49bf): feat: serve DoH over HTTP/3 (DoH3, RFC 9114) ([#​2060](https://redirect.github.com/0xERR0R/blocky/issues/2060)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`c95cfba`](https://redirect.github.com/0xERR0R/blocky/commit/c95cfba19b48c61b1f6dbdebe78fa4a29f221f9f): feat: validate allow/denylist references in ClientGroupsBlock ([#​2016](https://redirect.github.com/0xERR0R/blocky/issues/2016)) ([@​JenswBE](https://redirect.github.com/JenswBE)) ##### Bug fixes - [`10d6446`](https://redirect.github.com/0xERR0R/blocky/commit/10d644602db9a7b7ef93018de9f5a13eb5af8dbe): fix(api): keep /api/query response unobfuscated when log.privacy is on ([#​2058](https://redirect.github.com/0xERR0R/blocky/issues/2058)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`fb28513`](https://redirect.github.com/0xERR0R/blocky/commit/fb285134dec0503416161007d1f137700bade5de): fix: enhance DNS bootstrapping by utilizing IPs from DNS stamps ([#​1995](https://redirect.github.com/0xERR0R/blocky/issues/1995)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`2ffe18a`](https://redirect.github.com/0xERR0R/blocky/commit/2ffe18ae8908017555610920de08a013b0d33d1d): fix: use RFC 4034 canonical DNS name ordering for NSEC coverage check ([#​2017](https://redirect.github.com/0xERR0R/blocky/issues/2017)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) ##### Build and dependencies - [`a8015c8`](https://redirect.github.com/0xERR0R/blocky/commit/a8015c8a4d8d89c648f8d80da51ed8dc41b1bc9d): build(deps): bump codecov/codecov-action from 5 to 6 ([#​2029](https://redirect.github.com/0xERR0R/blocky/issues/2029)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`89aee54`](https://redirect.github.com/0xERR0R/blocky/commit/89aee541625fa4bc3ddfbf6d441d51cf1d09904f): build(deps): bump crazy-max/ghaction-docker-meta from 5 to 6 ([#​2005](https://redirect.github.com/0xERR0R/blocky/issues/2005)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`98f41c4`](https://redirect.github.com/0xERR0R/blocky/commit/98f41c4dedaa5630cb54ef0f97abf31ec02be12b): build(deps): bump dependabot/fetch-metadata from 2 to 3 ([#​2031](https://redirect.github.com/0xERR0R/blocky/issues/2031)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`83434c5`](https://redirect.github.com/0xERR0R/blocky/commit/83434c58456a612eb55dbd161ff13f39549f756e): build(deps): bump docker/build-push-action from 6 to 7 ([#​2004](https://redirect.github.com/0xERR0R/blocky/issues/2004)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`0c9e176`](https://redirect.github.com/0xERR0R/blocky/commit/0c9e176b314da2624aba23366c282a48ec98ab8f): build(deps): bump docker/login-action from 3 to 4 ([#​2003](https://redirect.github.com/0xERR0R/blocky/issues/2003)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`67dabab`](https://redirect.github.com/0xERR0R/blocky/commit/67dababac07d292533242a34ddfa5942ea8e813d): build(deps): bump docker/setup-buildx-action from 3 to 4 ([#​2006](https://redirect.github.com/0xERR0R/blocky/issues/2006)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`def8e95`](https://redirect.github.com/0xERR0R/blocky/commit/def8e95faa89e0810632565585e667de0627ab6c): build(deps): bump docker/setup-qemu-action from 3 to 4 ([#​2002](https://redirect.github.com/0xERR0R/blocky/issues/2002)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`733f21c`](https://redirect.github.com/0xERR0R/blocky/commit/733f21ce5b7f55c4da05013a358d644537b8e15e): build(deps): bump github.com/alicebob/miniredis/v2 from 2.37.0 to 2.38.0 ([#​2055](https://redirect.github.com/0xERR0R/blocky/issues/2055)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`5130c3e`](https://redirect.github.com/0xERR0R/blocky/commit/5130c3e2c11341dd5ccf637a86b8b45092a1c576): build(deps): bump github.com/breml/rootcerts from 0.3.4 to 0.3.5 ([#​2040](https://redirect.github.com/0xERR0R/blocky/issues/2040)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`08e53d7`](https://redirect.github.com/0xERR0R/blocky/commit/08e53d712aea9f11bccf3ea428da23e05781f4ab): build(deps): bump github.com/docker/go-connections from 0.6.0 to 0.7.0 ([#​2038](https://redirect.github.com/0xERR0R/blocky/issues/2038)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`95225f8`](https://redirect.github.com/0xERR0R/blocky/commit/95225f80f8334f28c75a5dbbebe6650fdc08be34): build(deps): bump github.com/jackc/pgx/v5 from 5.7.5 to 5.9.0 ([#​2039](https://redirect.github.com/0xERR0R/blocky/issues/2039)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`3274076`](https://redirect.github.com/0xERR0R/blocky/commit/3274076afdfffb8b64902954578ad12ec9fac41d): build(deps): bump github.com/jackc/pgx/v5 from 5.9.0 to 5.9.2 ([#​2041](https://redirect.github.com/0xERR0R/blocky/issues/2041)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`7a279fc`](https://redirect.github.com/0xERR0R/blocky/commit/7a279fcc89f7a3fcd1355698702cfe82647ef393): build(deps): bump github.com/moby/moby/api from 1.54.1 to 1.54.2 ([#​2050](https://redirect.github.com/0xERR0R/blocky/issues/2050)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`1a04f45`](https://redirect.github.com/0xERR0R/blocky/commit/1a04f458bd531920a28f7ab0d2fa80a373893984): build(deps): bump github.com/oapi-codegen/runtime from 1.1.2 to 1.2.0 ([#​1999](https://redirect.github.com/0xERR0R/blocky/issues/1999)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`076c880`](https://redirect.github.com/0xERR0R/blocky/commit/076c880c4e74177fb11600a4a7f28d36e1427a45): build(deps): bump github.com/oapi-codegen/runtime from 1.2.0 to 1.3.0 ([#​2021](https://redirect.github.com/0xERR0R/blocky/issues/2021)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`b7fddae`](https://redirect.github.com/0xERR0R/blocky/commit/b7fddae26631e24301ce58ad351b968ab32b04b7): build(deps): bump github.com/oapi-codegen/runtime from 1.3.0 to 1.3.1 ([#​2028](https://redirect.github.com/0xERR0R/blocky/issues/2028)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`9c8f11c`](https://redirect.github.com/0xERR0R/blocky/commit/9c8f11c7d9e82542879463b71a628c9257754486): build(deps): bump github.com/oapi-codegen/runtime from 1.3.1 to 1.4.0 ([#​2030](https://redirect.github.com/0xERR0R/blocky/issues/2030)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`62a7e4c`](https://redirect.github.com/0xERR0R/blocky/commit/62a7e4c5a6fe18821d4051fa525f75a22d63d66e): build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.1 to 2.28.2 ([#​2042](https://redirect.github.com/0xERR0R/blocky/issues/2042)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`56dfb1d`](https://redirect.github.com/0xERR0R/blocky/commit/56dfb1d19557f85e6ce9992b2b02f40ae33aef72): build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.2 to 2.28.3 ([#​2044](https://redirect.github.com/0xERR0R/blocky/issues/2044)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`adb9457`](https://redirect.github.com/0xERR0R/blocky/commit/adb9457c6d0a15bd1372be2c6ca3a7e84ddbce8b): build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.3 to 2.29.0 ([#​2057](https://redirect.github.com/0xERR0R/blocky/issues/2057)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`5d6da86`](https://redirect.github.com/0xERR0R/blocky/commit/5d6da8673e1f7d86b07314ae6e58eeb1b334a91b): build(deps): bump github.com/onsi/gomega from 1.39.1 to 1.40.0 ([#​2043](https://redirect.github.com/0xERR0R/blocky/issues/2043)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`6ac0c33`](https://redirect.github.com/0xERR0R/blocky/commit/6ac0c33f72306f6c4281196e8725ebb10c2904b1): build(deps): bump github.com/onsi/gomega from 1.40.0 to 1.41.0 ([#​2056](https://redirect.github.com/0xERR0R/blocky/issues/2056)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`14047f2`](https://redirect.github.com/0xERR0R/blocky/commit/14047f253168dbc19980909af858e186ebaaa423): build(deps): bump github.com/quic-go/quic-go from 0.59.0 to 0.59.1 ([#​2054](https://redirect.github.com/0xERR0R/blocky/issues/2054)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`670daf3`](https://redirect.github.com/0xERR0R/blocky/commit/670daf34dff8693b66486dec9bbccfef335a92be): build(deps): bump github.com/testcontainers/testcontainers-go/modules/mariadb from 0.40.0 to 0.41.0 ([#​2011](https://redirect.github.com/0xERR0R/blocky/issues/2011)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`ecd41d6`](https://redirect.github.com/0xERR0R/blocky/commit/ecd41d69cd7cb797b7437050a7bfd37853fcd939): build(deps): bump github.com/testcontainers/testcontainers-go/modules/postgres from 0.40.0 to 0.41.0 ([#​2012](https://redirect.github.com/0xERR0R/blocky/issues/2012)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`5c9df81`](https://redirect.github.com/0xERR0R/blocky/commit/5c9df8131316ccfc47e38ca20c38c609a3cd889f): build(deps): bump github.com/testcontainers/testcontainers-go/modules/redis from 0.40.0 to 0.41.0 ([#​2009](https://redirect.github.com/0xERR0R/blocky/issues/2009)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`0f1b3f3`](https://redirect.github.com/0xERR0R/blocky/commit/0f1b3f399bde6b30c4c47eb330119b9fa6b33599): build(deps): bump go.opentelemetry.io/otel/sdk from 1.35.0 to 1.40.0 ([#​2001](https://redirect.github.com/0xERR0R/blocky/issues/2001)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`6a06aa4`](https://redirect.github.com/0xERR0R/blocky/commit/6a06aa41098703014b743656a621ff7fcc205051): build(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.43.0 ([#​2047](https://redirect.github.com/0xERR0R/blocky/issues/2047)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`394a585`](https://redirect.github.com/0xERR0R/blocky/commit/394a58526110ad807fa75496ef2f05354cd48962): build(deps): bump golang.org/x/net from 0.51.0 to 0.52.0 ([#​2014](https://redirect.github.com/0xERR0R/blocky/issues/2014)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`f7718ae`](https://redirect.github.com/0xERR0R/blocky/commit/f7718ae5fe3dc98e9c32f4572e0089997873c390): build(deps): bump golang.org/x/net from 0.52.0 to 0.53.0 ([#​2036](https://redirect.github.com/0xERR0R/blocky/issues/2036)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`2ea2b65`](https://redirect.github.com/0xERR0R/blocky/commit/2ea2b653a872578add77e5147af147b4dd1536da): build(deps): bump golang.org/x/net from 0.53.0 to 0.54.0 ([#​2053](https://redirect.github.com/0xERR0R/blocky/issues/2053)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`2d36b56`](https://redirect.github.com/0xERR0R/blocky/commit/2d36b562f7ba4bf43f344f5b9cb95a01a58351be): build(deps): bump google.golang.org/grpc from 1.73.0 to 1.79.3 ([#​2020](https://redirect.github.com/0xERR0R/blocky/issues/2020)) ([@​dependabot](https://redirect.github.com/dependabot)\[bot]) - [`bdcd239`](https://redirect.github.com/0xERR0R/blocky/commit/bdcd239af4139d9417777b5d78f01ecdadb0caed): build(deps): bump testcontainers-go to v0.42.0 ([#​2046](https://redirect.github.com/0xERR0R/blocky/issues/2046)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`cb2ae25`](https://redirect.github.com/0xERR0R/blocky/commit/cb2ae25341b08be01d744159665d17dc0d434646): build: update golangci-lint ([#​2008](https://redirect.github.com/0xERR0R/blocky/issues/2008)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`fa8250c`](https://redirect.github.com/0xERR0R/blocky/commit/fa8250caf7cffb758ec77b106d650f83d53d2e60): build: update goreleaser action ([#​2024](https://redirect.github.com/0xERR0R/blocky/issues/2024)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) ##### Misc - [`1c43054`](https://redirect.github.com/0xERR0R/blocky/commit/1c43054e0eca29c6bd6a52dd607e484623c0530f): perf(blocking): keep time.Parse off the schedule hot path ([#​2049](https://redirect.github.com/0xERR0R/blocky/issues/2049)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`b4a1d54`](https://redirect.github.com/0xERR0R/blocky/commit/b4a1d54aa8456d721a585368f85a4a641e73948b): refactor(e2e): extend e2e tests ([#​2023](https://redirect.github.com/0xERR0R/blocky/issues/2023)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`667044b`](https://redirect.github.com/0xERR0R/blocky/commit/667044b07b4e887d0c5dfb1f22f6efe222e21beb): refactor: redis write through cache ([#​2025](https://redirect.github.com/0xERR0R/blocky/issues/2025)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`835e018`](https://redirect.github.com/0xERR0R/blocky/commit/835e0180a2d7390c684dbe77b41ae0bcedc978c4): refactor: small quick improvements ([#​2019](https://redirect.github.com/0xERR0R/blocky/issues/2019)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) - [`94e9212`](https://redirect.github.com/0xERR0R/blocky/commit/94e921242fc849fe270c1023e0849258f0f0a8c1): test(e2e): smoke-test schedule-based blocking ([#​2048](https://redirect.github.com/0xERR0R/blocky/issues/2048)) ([@​0xERR0R](https://redirect.github.com/0xERR0R)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://redirect.github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9ibG9ja3kiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
461 lines
12 KiB
YAML
461 lines
12 KiB
YAML
# yaml-language-server: $schema=./values.schema.json
|
|
image:
|
|
repository: ghcr.io/0xerr0r/blocky
|
|
tag: v0.30.0@sha256:d9f15eddffedded40797406349012cbd5966ef99c286b13321e7a76efddb9bdc
|
|
pullPolicy: IfNotPresent
|
|
k8sgatewayImage:
|
|
repository: ghcr.io/k8s-gateway/k8s_gateway
|
|
pullPolicy: IfNotPresent
|
|
tag: 1.8.0@sha256:e17ed387f48da00b4736fbeecc338238b11ea20478c3c9ad35876509eb65c022
|
|
|
|
workload:
|
|
main:
|
|
replicas: 2
|
|
strategy: RollingUpdate
|
|
podSpec:
|
|
containers:
|
|
main:
|
|
probes:
|
|
liveness:
|
|
enabled: false
|
|
type: exec
|
|
command:
|
|
- /app/blocky
|
|
- healthcheck
|
|
readiness:
|
|
enabled: false
|
|
type: exec
|
|
command:
|
|
- /app/blocky
|
|
- healthcheck
|
|
startup:
|
|
enabled: false
|
|
type: exec
|
|
command:
|
|
- /app/blocky
|
|
- healthcheck
|
|
# -- Blocky Config File content
|
|
blockyConfig: {}
|
|
# upstream:
|
|
# default:
|
|
# - 1.1.1.1
|
|
|
|
# -- some general blocky settings
|
|
blocky:
|
|
# -- Enable prometheus annotations
|
|
enablePrometheus: true
|
|
service:
|
|
main:
|
|
enabled: true
|
|
ports:
|
|
main:
|
|
enabled: true
|
|
port: 4000
|
|
protocol: http
|
|
targetPort: 4000
|
|
dns:
|
|
enabled: true
|
|
ports:
|
|
dns:
|
|
enabled: true
|
|
port: 53
|
|
protocol: udp
|
|
targetPort: 53
|
|
dnstcp:
|
|
enabled: true
|
|
protocol: tcp
|
|
port: "{{ .Values.service.dns.ports.dns.port }}"
|
|
targetPort: 53
|
|
dot:
|
|
enabled: true
|
|
ports:
|
|
dot:
|
|
enabled: true
|
|
port: 853
|
|
protocol: tcp
|
|
targetPort: 853
|
|
https:
|
|
enabled: true
|
|
ports:
|
|
https:
|
|
enabled: true
|
|
port: 4443
|
|
protocol: https
|
|
targetPort: 4443
|
|
k8sgateway:
|
|
enabled: true
|
|
ports:
|
|
k8sgateway:
|
|
enabled: true
|
|
port: 5353
|
|
protocol: udp
|
|
targetPort: 5353
|
|
|
|
# -- Path to cert and key file for SSL encryption. If not set, self-signed certificate will be generated
|
|
certFile: ""
|
|
keyFile: ""
|
|
|
|
# -- logging configuration
|
|
# Log level (one from trace, debug, info, warn, error)
|
|
logLevel: info
|
|
# Log format (text or json)
|
|
logFormat: text
|
|
# log timestamps (true or false)
|
|
logTimestamp: true
|
|
# Obfuscate log output (replace all alphanumeric characters with *) for user sensitive data like request domains or responses to increase privacy. (true or false)
|
|
logPrivacy: false
|
|
|
|
# -- Mininal TLS version that the DoH and DoT server will use
|
|
minTlsServeVersion: 1.2
|
|
|
|
# -- set the default DNS upstream servers
|
|
defaultUpstreams:
|
|
# Cloudflare
|
|
- 1.1.1.1
|
|
- 1.0.0.1
|
|
# Google
|
|
- 8.8.8.8
|
|
- 8.8.4.4
|
|
# Quad9
|
|
- 9.9.9.9
|
|
- 149.112.112.112
|
|
# OpenDNS
|
|
- 208.67.222.222
|
|
- 208.67.220.220
|
|
# ComodoSecure DNS
|
|
- 8.26.56.26
|
|
- 8.20.247.20
|
|
|
|
# -- set additional upstreams
|
|
upstreams:
|
|
# - name: group2
|
|
# dnsservers:
|
|
# - 1.1.1.1
|
|
|
|
# -- optional: timeout to query the upstream resolver. Default: 1s
|
|
upstreamTimeout: 1s
|
|
|
|
# -- set bootstrap dns (not needed)
|
|
# Ensures bootstrap encryption and ensure it doesn't use k8s dns
|
|
# When using an upstream specified by IP, and not by hostname, you can write only the upstream and skip ips.
|
|
bootstrapDns:
|
|
# -- Upstream
|
|
upstream: ""
|
|
# -- IP's linked to upstream DoT/DoH DNS name
|
|
ips: []
|
|
# -- set additional bootstrap dns (not needed, only used if bootstrapDns is set)
|
|
additionalBootstrapDns: []
|
|
# - upstream: ""
|
|
# ips: []
|
|
|
|
# -- Return empty answer for these queries
|
|
filtering:
|
|
# -- Ensures filtering by query type
|
|
queryTypes: []
|
|
|
|
# -- Set manual custom DNS resolution
|
|
customDNS:
|
|
customTTL: 1h
|
|
filterUnmappedTypes: true
|
|
rewrite: []
|
|
# - in: something.com
|
|
# out: somethingelse.com
|
|
mapping: []
|
|
# - domain: something.com
|
|
# dnsserver: 192.168.178.1
|
|
|
|
# -- Setup client-name lookup
|
|
clientLookup:
|
|
# -- upstream used for client-name lookup
|
|
upstream: ""
|
|
singleNameOrder: []
|
|
clients:
|
|
# - domain: laptop
|
|
# ips: []
|
|
|
|
# -- Configuration for caching of DNS responsesg
|
|
caching:
|
|
minTime: 15m
|
|
maxTime: 0m
|
|
maxItemsCount: 0
|
|
prefetching: true
|
|
prefetchExpires: 12h
|
|
prefetchThreshold: 5
|
|
prefetchMaxItemsCount: 0
|
|
cacheTimeNegative: 30m
|
|
|
|
# -- set conditional settings
|
|
conditional:
|
|
fallbackUpstream: false
|
|
rewrite: []
|
|
# - in: something.com
|
|
# out: somethingelse.com
|
|
mapping: []
|
|
# - domain: something.com
|
|
# dnsserver: 192.168.178.1
|
|
|
|
# -- set blocking settings using Lists
|
|
blocking:
|
|
# -- Sets the blocktype
|
|
blockType: nxDomain
|
|
# -- Sets the block ttl
|
|
blockTTL: 6h
|
|
# -- Sets the block refreshPeriod
|
|
refreshPeriod: 4h
|
|
# -- Sets the block download timeout
|
|
downloadTimeout: 60s
|
|
# -- timeout for list write to disk (each url)
|
|
writeTimeout: 60s
|
|
# -- timeout for reading the download (each url).
|
|
readTimeout: 60s
|
|
# -- timeout for reading request headers for the download (each url)
|
|
readHeaderTimeout: 60s
|
|
# -- Sets the block download attempt count
|
|
downloadAttempts: 3
|
|
# -- Sets the block download cooldown
|
|
downloadCooldown: 5s
|
|
# -- Sets how many list-groups can be processed at the same time
|
|
processingConcurrency: 8
|
|
# -- Set the start strategy (blocking | failOnError | fast)
|
|
startStrategy: fast
|
|
# -- Number of errors allowed in a list before it is considered invalid
|
|
maxErrorsPerSource: 5
|
|
|
|
# -- Add blocky whitelists
|
|
# `default` name is reservered for TrueCharts included default whitelist
|
|
# example shows the structure, though name should be changed when used
|
|
whitelist:
|
|
[]
|
|
# - name: default
|
|
# lists:
|
|
# - https://raw.githubusercontent.com/anudeepND/whitelist/master/domains/optional-list.txt
|
|
# - https://raw.githubusercontent.com/anudeepND/whitelist/master/domains/whitelist.txt
|
|
# - https://raw.githubusercontent.com/rahilpathan/pihole-whitelist/main/1.LowWL.txt
|
|
|
|
# -- Blocky blacklists
|
|
# `default` name is reservered for TrueCharts included default blacklist
|
|
# example shows the structure, though name should be changed when used
|
|
blacklist:
|
|
[]
|
|
# - name: default
|
|
# lists:
|
|
# - https://big.oisd.nl/domainswild
|
|
|
|
# -- Blocky clientGroupsBlock
|
|
clientGroupsBlock:
|
|
- name: default
|
|
groups:
|
|
- default
|
|
- default-ads
|
|
- default-tracking
|
|
- default-malicious
|
|
- default-suspicious
|
|
|
|
# -- configure using hostsfile for lookups
|
|
# Allows for using the hosts configured in kubernetes and such
|
|
hostsFile:
|
|
enabled: false
|
|
sources:
|
|
- /etc/hosts
|
|
- https://example.com/hosts
|
|
- |
|
|
# inline hosts
|
|
127.0.0.1 example.com
|
|
hostsTTL: 1h
|
|
filterLoopback: falsr
|
|
loading:
|
|
refreshPeriod: 4h
|
|
downloads:
|
|
timeout: 5s
|
|
attempts: 3
|
|
cooldown: 500ms
|
|
concurrency: 4
|
|
strategy: blocking
|
|
maxErrorsPerSource: 5
|
|
|
|
podOptions:
|
|
automountServiceAccountToken: true
|
|
|
|
serviceAccount:
|
|
main:
|
|
# -- Specifies whether a service account should be created
|
|
enabled: true
|
|
primary: true
|
|
|
|
# -- Create a ClusterRole and ClusterRoleBinding
|
|
# used by k8sgateway
|
|
rbac:
|
|
main:
|
|
# -- Enables or disables the ClusterRole and ClusterRoleBinding
|
|
enabled: true
|
|
primary: true
|
|
clusterWide: true
|
|
# -- Set Rules on the ClusterRole
|
|
rules:
|
|
# General CRDs
|
|
- apiGroups:
|
|
- apiextensions.k8s.io
|
|
resources:
|
|
- customresourcedefinitions
|
|
verbs:
|
|
- get
|
|
- list
|
|
- watch
|
|
# Ingress
|
|
- apiGroups:
|
|
- extensions
|
|
- networking.k8s.io
|
|
resources:
|
|
- ingresses
|
|
verbs:
|
|
- list
|
|
- watch
|
|
# Service
|
|
- apiGroups:
|
|
- ""
|
|
resources:
|
|
- services
|
|
- namespaces
|
|
verbs:
|
|
- list
|
|
- watch
|
|
# HTTPRoute, TLSRoute, GRPCRoute
|
|
- apiGroups:
|
|
- gateway.networking.k8s.io
|
|
resources:
|
|
- "*"
|
|
verbs:
|
|
- watch
|
|
- list
|
|
# DNSEndpoint
|
|
- apiGroups:
|
|
- externaldns.k8s.io
|
|
resources:
|
|
- dnsendpoints
|
|
verbs:
|
|
- get
|
|
- watch
|
|
- list
|
|
- apiGroups:
|
|
- externaldns.k8s.io
|
|
resources:
|
|
- dnsendpoints/status
|
|
verbs:
|
|
- "*"
|
|
|
|
k8sgateway:
|
|
enabled: true
|
|
# -- TTL for non-apex responses (in seconds)
|
|
ttl: 300
|
|
# -- Limit what kind of resources to watch, e.g. watchedResources: [ Ingress | Service | HTTPRoute | TLSRoute | GRPCRoute | DNSEndpoint ]
|
|
watchedResources:
|
|
- Ingress
|
|
- Service
|
|
- HTTPRoute
|
|
# -- Service name of a secondary DNS server (should be `serviceName.namespace`)
|
|
secondary: ""
|
|
# -- Override the default `serviceName.namespace` domain apex
|
|
apex: ""
|
|
# -- list of processed domains
|
|
domains: []
|
|
# -- Delegated domain
|
|
# - domain: "example.com"
|
|
# # -- Optional configuration option for DNS01 challenge that will redirect all acme
|
|
# # challenge requests to external cloud domain (e.g. managed by cert-manager)
|
|
# # See: https://cert-manager.io/docs/configuration/acme/dns01/
|
|
# dnsChallenge:
|
|
# enabled: false
|
|
# domain: dns01.clouddns.com
|
|
forward:
|
|
enabled: false
|
|
primary: tls://1.1.1.1
|
|
secondary: tls://1.0.0.1
|
|
options:
|
|
- name: tls_servername
|
|
value: cloudflare-dns.com
|
|
|
|
configmap:
|
|
dashboard:
|
|
enabled: true
|
|
labels:
|
|
grafana_dashboard: "1"
|
|
data:
|
|
blocky.json: >-
|
|
{{ .Files.Get "dashboard.json" | indent 8 }}
|
|
blockypostgres.json: >-
|
|
{{ .Files.Get "dashboardpsql.json" | indent 8 }}
|
|
datasource:
|
|
enabled: true
|
|
labels:
|
|
grafana_datasource: "1"
|
|
data:
|
|
datasourceblockypsql.yaml: |-
|
|
apiVersion: 1
|
|
datasources:
|
|
- name: BlockyPostgres
|
|
type: postgres
|
|
uid: blockypostgres
|
|
url: {{ printf "%s.%s:5432" (.Values.cnpg.main.creds.host | trimAll "\"") .Release.Namespace }}
|
|
access: proxy
|
|
user: {{ .Values.cnpg.main.user }}
|
|
secureJsonData:
|
|
password: {{ .Values.cnpg.main.creds.password | default "na" }}
|
|
jsonData:
|
|
database: {{ .Values.cnpg.main.database }}
|
|
sslmode: 'disable' # disable/require/verify-ca/verify-full
|
|
maxOpenConns: 100 # Grafana v5.4+
|
|
maxIdleConns: 100 # Grafana v5.4+
|
|
maxIdleConnsAuto: true # Grafana v9.5.1+
|
|
connMaxLifetime: 14400 # Grafana v5.4+
|
|
postgresVersion: 1500 # 903=9.3, 904=9.4, 905=9.5, 906=9.6, 1000=10
|
|
timescaledb: false
|
|
|
|
metrics:
|
|
main:
|
|
# -- Enable and configure a Prometheus serviceMonitor for the chart under this key.
|
|
# @default -- See values.yaml
|
|
enabled: true
|
|
type: "servicemonitor"
|
|
endpoints:
|
|
- port: main
|
|
path: /metrics
|
|
# -- Enable and configure Prometheus Rules for the chart under this key.
|
|
# @default -- See values.yaml
|
|
prometheusRule:
|
|
enabled: false
|
|
labels: {}
|
|
# -- Configure additionial rules for the chart under this key.
|
|
# @default -- See prometheusrules.yaml
|
|
rules: []
|
|
# - alert: UnifiPollerAbsent
|
|
# annotations:
|
|
# description: Unifi Poller has disappeared from Prometheus service discovery.
|
|
# summary: Unifi Poller is down.
|
|
# expr: |
|
|
# absent(up{job=~".*unifi-poller.*"} == 1)
|
|
# for: 5m
|
|
# labels:
|
|
# severity: critical
|
|
|
|
redis:
|
|
enabled: true
|
|
|
|
queryLog:
|
|
# optional one of: mysql, postgresql, csv, csv-client. If empty, log to console
|
|
type: "postgresql"
|
|
# directory (should be mounted as volume in docker) for csv, db connection string for mysql, ignored for included postgresql
|
|
# target: /var/log/something
|
|
# postgresql target: postgres://user:password@db_host_or_ip:5432/db_name
|
|
# if > 0, deletes log files which are older than ... days
|
|
logRetentionDays: 0
|
|
# optional: Max attempts to create specific query log writer, default: 3
|
|
creationAttempts: 3
|
|
# optional: Time between the creation attempts, default: 2s
|
|
creationCooldown: 2s
|
|
|
|
cnpg:
|
|
main:
|
|
enabled: true
|
|
user: blocky
|
|
database: blocky
|