Files
truecharts/charts/stable/blocky/values.yaml
T
TrueCharts BotandGitHub 485e64cb7a feat(blocky): update image ghcr.io/0xerr0r/blocky v0.29.0 → v0.30.0 (#48338)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/0xerr0r/blocky](https://redirect.github.com/0xERR0R/blocky) |
minor | `a6d99f3` → `d9f15ed` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>0xERR0R/blocky (ghcr.io/0xerr0r/blocky)</summary>

###
[`v0.30.0`](https://redirect.github.com/0xERR0R/blocky/releases/tag/v0.30.0)

[Compare
Source](https://redirect.github.com/0xERR0R/blocky/compare/v0.29.0...v0.30.0)

#### Changelog

##### Features

-
[`0de3fac`](https://redirect.github.com/0xERR0R/blocky/commit/0de3fac101964aa85d6eb6ac43ed67d84d8116be):
feat(sudn): handle resolver.arpa zone per RFC 9462 (DDR)
([#&#8203;2059](https://redirect.github.com/0xERR0R/blocky/issues/2059))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`c32863d`](https://redirect.github.com/0xERR0R/blocky/commit/c32863d342e4edaf949021bc21446ac8d5762e30):
feat: add DNS-over-QUIC (DoQ) upstream support (RFC 9250)
([#&#8203;2013](https://redirect.github.com/0xERR0R/blocky/issues/2013))
([@&#8203;elsbrock](https://redirect.github.com/elsbrock))
-
[`22b0bdd`](https://redirect.github.com/0xERR0R/blocky/commit/22b0bdd3538e052b10660a3bfbcf1731d05b5b07):
feat: add schedule-based blocking for deny/allowlist groups
([#&#8203;2037](https://redirect.github.com/0xERR0R/blocky/issues/2037))
([@&#8203;alessandrocuzzocrea](https://redirect.github.com/alessandrocuzzocrea))
-
[`842dda9`](https://redirect.github.com/0xERR0R/blocky/commit/842dda99a8ecbd489ee8755beea3ce6fe9fd49bf):
feat: serve DoH over HTTP/3 (DoH3, RFC 9114)
([#&#8203;2060](https://redirect.github.com/0xERR0R/blocky/issues/2060))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`c95cfba`](https://redirect.github.com/0xERR0R/blocky/commit/c95cfba19b48c61b1f6dbdebe78fa4a29f221f9f):
feat: validate allow/denylist references in ClientGroupsBlock
([#&#8203;2016](https://redirect.github.com/0xERR0R/blocky/issues/2016))
([@&#8203;JenswBE](https://redirect.github.com/JenswBE))

##### Bug fixes

-
[`10d6446`](https://redirect.github.com/0xERR0R/blocky/commit/10d644602db9a7b7ef93018de9f5a13eb5af8dbe):
fix(api): keep /api/query response unobfuscated when log.privacy is on
([#&#8203;2058](https://redirect.github.com/0xERR0R/blocky/issues/2058))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`fb28513`](https://redirect.github.com/0xERR0R/blocky/commit/fb285134dec0503416161007d1f137700bade5de):
fix: enhance DNS bootstrapping by utilizing IPs from DNS stamps
([#&#8203;1995](https://redirect.github.com/0xERR0R/blocky/issues/1995))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`2ffe18a`](https://redirect.github.com/0xERR0R/blocky/commit/2ffe18ae8908017555610920de08a013b0d33d1d):
fix: use RFC 4034 canonical DNS name ordering for NSEC coverage check
([#&#8203;2017](https://redirect.github.com/0xERR0R/blocky/issues/2017))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))

##### Build and dependencies

-
[`a8015c8`](https://redirect.github.com/0xERR0R/blocky/commit/a8015c8a4d8d89c648f8d80da51ed8dc41b1bc9d):
build(deps): bump codecov/codecov-action from 5 to 6
([#&#8203;2029](https://redirect.github.com/0xERR0R/blocky/issues/2029))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`89aee54`](https://redirect.github.com/0xERR0R/blocky/commit/89aee541625fa4bc3ddfbf6d441d51cf1d09904f):
build(deps): bump crazy-max/ghaction-docker-meta from 5 to 6
([#&#8203;2005](https://redirect.github.com/0xERR0R/blocky/issues/2005))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`98f41c4`](https://redirect.github.com/0xERR0R/blocky/commit/98f41c4dedaa5630cb54ef0f97abf31ec02be12b):
build(deps): bump dependabot/fetch-metadata from 2 to 3
([#&#8203;2031](https://redirect.github.com/0xERR0R/blocky/issues/2031))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`83434c5`](https://redirect.github.com/0xERR0R/blocky/commit/83434c58456a612eb55dbd161ff13f39549f756e):
build(deps): bump docker/build-push-action from 6 to 7
([#&#8203;2004](https://redirect.github.com/0xERR0R/blocky/issues/2004))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`0c9e176`](https://redirect.github.com/0xERR0R/blocky/commit/0c9e176b314da2624aba23366c282a48ec98ab8f):
build(deps): bump docker/login-action from 3 to 4
([#&#8203;2003](https://redirect.github.com/0xERR0R/blocky/issues/2003))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`67dabab`](https://redirect.github.com/0xERR0R/blocky/commit/67dababac07d292533242a34ddfa5942ea8e813d):
build(deps): bump docker/setup-buildx-action from 3 to 4
([#&#8203;2006](https://redirect.github.com/0xERR0R/blocky/issues/2006))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`def8e95`](https://redirect.github.com/0xERR0R/blocky/commit/def8e95faa89e0810632565585e667de0627ab6c):
build(deps): bump docker/setup-qemu-action from 3 to 4
([#&#8203;2002](https://redirect.github.com/0xERR0R/blocky/issues/2002))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`733f21c`](https://redirect.github.com/0xERR0R/blocky/commit/733f21ce5b7f55c4da05013a358d644537b8e15e):
build(deps): bump github.com/alicebob/miniredis/v2 from 2.37.0 to 2.38.0
([#&#8203;2055](https://redirect.github.com/0xERR0R/blocky/issues/2055))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`5130c3e`](https://redirect.github.com/0xERR0R/blocky/commit/5130c3e2c11341dd5ccf637a86b8b45092a1c576):
build(deps): bump github.com/breml/rootcerts from 0.3.4 to 0.3.5
([#&#8203;2040](https://redirect.github.com/0xERR0R/blocky/issues/2040))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`08e53d7`](https://redirect.github.com/0xERR0R/blocky/commit/08e53d712aea9f11bccf3ea428da23e05781f4ab):
build(deps): bump github.com/docker/go-connections from 0.6.0 to 0.7.0
([#&#8203;2038](https://redirect.github.com/0xERR0R/blocky/issues/2038))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`95225f8`](https://redirect.github.com/0xERR0R/blocky/commit/95225f80f8334f28c75a5dbbebe6650fdc08be34):
build(deps): bump github.com/jackc/pgx/v5 from 5.7.5 to 5.9.0
([#&#8203;2039](https://redirect.github.com/0xERR0R/blocky/issues/2039))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`3274076`](https://redirect.github.com/0xERR0R/blocky/commit/3274076afdfffb8b64902954578ad12ec9fac41d):
build(deps): bump github.com/jackc/pgx/v5 from 5.9.0 to 5.9.2
([#&#8203;2041](https://redirect.github.com/0xERR0R/blocky/issues/2041))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`7a279fc`](https://redirect.github.com/0xERR0R/blocky/commit/7a279fcc89f7a3fcd1355698702cfe82647ef393):
build(deps): bump github.com/moby/moby/api from 1.54.1 to 1.54.2
([#&#8203;2050](https://redirect.github.com/0xERR0R/blocky/issues/2050))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`1a04f45`](https://redirect.github.com/0xERR0R/blocky/commit/1a04f458bd531920a28f7ab0d2fa80a373893984):
build(deps): bump github.com/oapi-codegen/runtime from 1.1.2 to 1.2.0
([#&#8203;1999](https://redirect.github.com/0xERR0R/blocky/issues/1999))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`076c880`](https://redirect.github.com/0xERR0R/blocky/commit/076c880c4e74177fb11600a4a7f28d36e1427a45):
build(deps): bump github.com/oapi-codegen/runtime from 1.2.0 to 1.3.0
([#&#8203;2021](https://redirect.github.com/0xERR0R/blocky/issues/2021))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`b7fddae`](https://redirect.github.com/0xERR0R/blocky/commit/b7fddae26631e24301ce58ad351b968ab32b04b7):
build(deps): bump github.com/oapi-codegen/runtime from 1.3.0 to 1.3.1
([#&#8203;2028](https://redirect.github.com/0xERR0R/blocky/issues/2028))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`9c8f11c`](https://redirect.github.com/0xERR0R/blocky/commit/9c8f11c7d9e82542879463b71a628c9257754486):
build(deps): bump github.com/oapi-codegen/runtime from 1.3.1 to 1.4.0
([#&#8203;2030](https://redirect.github.com/0xERR0R/blocky/issues/2030))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`62a7e4c`](https://redirect.github.com/0xERR0R/blocky/commit/62a7e4c5a6fe18821d4051fa525f75a22d63d66e):
build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.1 to 2.28.2
([#&#8203;2042](https://redirect.github.com/0xERR0R/blocky/issues/2042))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`56dfb1d`](https://redirect.github.com/0xERR0R/blocky/commit/56dfb1d19557f85e6ce9992b2b02f40ae33aef72):
build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.2 to 2.28.3
([#&#8203;2044](https://redirect.github.com/0xERR0R/blocky/issues/2044))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`adb9457`](https://redirect.github.com/0xERR0R/blocky/commit/adb9457c6d0a15bd1372be2c6ca3a7e84ddbce8b):
build(deps): bump github.com/onsi/ginkgo/v2 from 2.28.3 to 2.29.0
([#&#8203;2057](https://redirect.github.com/0xERR0R/blocky/issues/2057))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`5d6da86`](https://redirect.github.com/0xERR0R/blocky/commit/5d6da8673e1f7d86b07314ae6e58eeb1b334a91b):
build(deps): bump github.com/onsi/gomega from 1.39.1 to 1.40.0
([#&#8203;2043](https://redirect.github.com/0xERR0R/blocky/issues/2043))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`6ac0c33`](https://redirect.github.com/0xERR0R/blocky/commit/6ac0c33f72306f6c4281196e8725ebb10c2904b1):
build(deps): bump github.com/onsi/gomega from 1.40.0 to 1.41.0
([#&#8203;2056](https://redirect.github.com/0xERR0R/blocky/issues/2056))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`14047f2`](https://redirect.github.com/0xERR0R/blocky/commit/14047f253168dbc19980909af858e186ebaaa423):
build(deps): bump github.com/quic-go/quic-go from 0.59.0 to 0.59.1
([#&#8203;2054](https://redirect.github.com/0xERR0R/blocky/issues/2054))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`670daf3`](https://redirect.github.com/0xERR0R/blocky/commit/670daf34dff8693b66486dec9bbccfef335a92be):
build(deps): bump
github.com/testcontainers/testcontainers-go/modules/mariadb from 0.40.0
to 0.41.0
([#&#8203;2011](https://redirect.github.com/0xERR0R/blocky/issues/2011))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`ecd41d6`](https://redirect.github.com/0xERR0R/blocky/commit/ecd41d69cd7cb797b7437050a7bfd37853fcd939):
build(deps): bump
github.com/testcontainers/testcontainers-go/modules/postgres from 0.40.0
to 0.41.0
([#&#8203;2012](https://redirect.github.com/0xERR0R/blocky/issues/2012))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`5c9df81`](https://redirect.github.com/0xERR0R/blocky/commit/5c9df8131316ccfc47e38ca20c38c609a3cd889f):
build(deps): bump
github.com/testcontainers/testcontainers-go/modules/redis from 0.40.0 to
0.41.0
([#&#8203;2009](https://redirect.github.com/0xERR0R/blocky/issues/2009))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`0f1b3f3`](https://redirect.github.com/0xERR0R/blocky/commit/0f1b3f399bde6b30c4c47eb330119b9fa6b33599):
build(deps): bump go.opentelemetry.io/otel/sdk from 1.35.0 to 1.40.0
([#&#8203;2001](https://redirect.github.com/0xERR0R/blocky/issues/2001))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`6a06aa4`](https://redirect.github.com/0xERR0R/blocky/commit/6a06aa41098703014b743656a621ff7fcc205051):
build(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.43.0
([#&#8203;2047](https://redirect.github.com/0xERR0R/blocky/issues/2047))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`394a585`](https://redirect.github.com/0xERR0R/blocky/commit/394a58526110ad807fa75496ef2f05354cd48962):
build(deps): bump golang.org/x/net from 0.51.0 to 0.52.0
([#&#8203;2014](https://redirect.github.com/0xERR0R/blocky/issues/2014))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`f7718ae`](https://redirect.github.com/0xERR0R/blocky/commit/f7718ae5fe3dc98e9c32f4572e0089997873c390):
build(deps): bump golang.org/x/net from 0.52.0 to 0.53.0
([#&#8203;2036](https://redirect.github.com/0xERR0R/blocky/issues/2036))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`2ea2b65`](https://redirect.github.com/0xERR0R/blocky/commit/2ea2b653a872578add77e5147af147b4dd1536da):
build(deps): bump golang.org/x/net from 0.53.0 to 0.54.0
([#&#8203;2053](https://redirect.github.com/0xERR0R/blocky/issues/2053))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`2d36b56`](https://redirect.github.com/0xERR0R/blocky/commit/2d36b562f7ba4bf43f344f5b9cb95a01a58351be):
build(deps): bump google.golang.org/grpc from 1.73.0 to 1.79.3
([#&#8203;2020](https://redirect.github.com/0xERR0R/blocky/issues/2020))
([@&#8203;dependabot](https://redirect.github.com/dependabot)\[bot])
-
[`bdcd239`](https://redirect.github.com/0xERR0R/blocky/commit/bdcd239af4139d9417777b5d78f01ecdadb0caed):
build(deps): bump testcontainers-go to v0.42.0
([#&#8203;2046](https://redirect.github.com/0xERR0R/blocky/issues/2046))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`cb2ae25`](https://redirect.github.com/0xERR0R/blocky/commit/cb2ae25341b08be01d744159665d17dc0d434646):
build: update golangci-lint
([#&#8203;2008](https://redirect.github.com/0xERR0R/blocky/issues/2008))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`fa8250c`](https://redirect.github.com/0xERR0R/blocky/commit/fa8250caf7cffb758ec77b106d650f83d53d2e60):
build: update goreleaser action
([#&#8203;2024](https://redirect.github.com/0xERR0R/blocky/issues/2024))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))

##### Misc

-
[`1c43054`](https://redirect.github.com/0xERR0R/blocky/commit/1c43054e0eca29c6bd6a52dd607e484623c0530f):
perf(blocking): keep time.Parse off the schedule hot path
([#&#8203;2049](https://redirect.github.com/0xERR0R/blocky/issues/2049))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`b4a1d54`](https://redirect.github.com/0xERR0R/blocky/commit/b4a1d54aa8456d721a585368f85a4a641e73948b):
refactor(e2e): extend e2e tests
([#&#8203;2023](https://redirect.github.com/0xERR0R/blocky/issues/2023))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`667044b`](https://redirect.github.com/0xERR0R/blocky/commit/667044b07b4e887d0c5dfb1f22f6efe222e21beb):
refactor: redis write through cache
([#&#8203;2025](https://redirect.github.com/0xERR0R/blocky/issues/2025))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`835e018`](https://redirect.github.com/0xERR0R/blocky/commit/835e0180a2d7390c684dbe77b41ae0bcedc978c4):
refactor: small quick improvements
([#&#8203;2019](https://redirect.github.com/0xERR0R/blocky/issues/2019))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))
-
[`94e9212`](https://redirect.github.com/0xERR0R/blocky/commit/94e921242fc849fe270c1023e0849258f0f0a8c1):
test(e2e): smoke-test schedule-based blocking
([#&#8203;2048](https://redirect.github.com/0xERR0R/blocky/issues/2048))
([@&#8203;0xERR0R](https://redirect.github.com/0xERR0R))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMzAuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEzMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImFwcC9ibG9ja3kiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2026-05-19 01:28:59 +02:00

461 lines
12 KiB
YAML

# yaml-language-server: $schema=./values.schema.json
image:
repository: ghcr.io/0xerr0r/blocky
tag: v0.30.0@sha256:d9f15eddffedded40797406349012cbd5966ef99c286b13321e7a76efddb9bdc
pullPolicy: IfNotPresent
k8sgatewayImage:
repository: ghcr.io/k8s-gateway/k8s_gateway
pullPolicy: IfNotPresent
tag: 1.8.0@sha256:e17ed387f48da00b4736fbeecc338238b11ea20478c3c9ad35876509eb65c022
workload:
main:
replicas: 2
strategy: RollingUpdate
podSpec:
containers:
main:
probes:
liveness:
enabled: false
type: exec
command:
- /app/blocky
- healthcheck
readiness:
enabled: false
type: exec
command:
- /app/blocky
- healthcheck
startup:
enabled: false
type: exec
command:
- /app/blocky
- healthcheck
# -- Blocky Config File content
blockyConfig: {}
# upstream:
# default:
# - 1.1.1.1
# -- some general blocky settings
blocky:
# -- Enable prometheus annotations
enablePrometheus: true
service:
main:
enabled: true
ports:
main:
enabled: true
port: 4000
protocol: http
targetPort: 4000
dns:
enabled: true
ports:
dns:
enabled: true
port: 53
protocol: udp
targetPort: 53
dnstcp:
enabled: true
protocol: tcp
port: "{{ .Values.service.dns.ports.dns.port }}"
targetPort: 53
dot:
enabled: true
ports:
dot:
enabled: true
port: 853
protocol: tcp
targetPort: 853
https:
enabled: true
ports:
https:
enabled: true
port: 4443
protocol: https
targetPort: 4443
k8sgateway:
enabled: true
ports:
k8sgateway:
enabled: true
port: 5353
protocol: udp
targetPort: 5353
# -- Path to cert and key file for SSL encryption. If not set, self-signed certificate will be generated
certFile: ""
keyFile: ""
# -- logging configuration
# Log level (one from trace, debug, info, warn, error)
logLevel: info
# Log format (text or json)
logFormat: text
# log timestamps (true or false)
logTimestamp: true
# Obfuscate log output (replace all alphanumeric characters with *) for user sensitive data like request domains or responses to increase privacy. (true or false)
logPrivacy: false
# -- Mininal TLS version that the DoH and DoT server will use
minTlsServeVersion: 1.2
# -- set the default DNS upstream servers
defaultUpstreams:
# Cloudflare
- 1.1.1.1
- 1.0.0.1
# Google
- 8.8.8.8
- 8.8.4.4
# Quad9
- 9.9.9.9
- 149.112.112.112
# OpenDNS
- 208.67.222.222
- 208.67.220.220
# ComodoSecure DNS
- 8.26.56.26
- 8.20.247.20
# -- set additional upstreams
upstreams:
# - name: group2
# dnsservers:
# - 1.1.1.1
# -- optional: timeout to query the upstream resolver. Default: 1s
upstreamTimeout: 1s
# -- set bootstrap dns (not needed)
# Ensures bootstrap encryption and ensure it doesn't use k8s dns
# When using an upstream specified by IP, and not by hostname, you can write only the upstream and skip ips.
bootstrapDns:
# -- Upstream
upstream: ""
# -- IP's linked to upstream DoT/DoH DNS name
ips: []
# -- set additional bootstrap dns (not needed, only used if bootstrapDns is set)
additionalBootstrapDns: []
# - upstream: ""
# ips: []
# -- Return empty answer for these queries
filtering:
# -- Ensures filtering by query type
queryTypes: []
# -- Set manual custom DNS resolution
customDNS:
customTTL: 1h
filterUnmappedTypes: true
rewrite: []
# - in: something.com
# out: somethingelse.com
mapping: []
# - domain: something.com
# dnsserver: 192.168.178.1
# -- Setup client-name lookup
clientLookup:
# -- upstream used for client-name lookup
upstream: ""
singleNameOrder: []
clients:
# - domain: laptop
# ips: []
# -- Configuration for caching of DNS responsesg
caching:
minTime: 15m
maxTime: 0m
maxItemsCount: 0
prefetching: true
prefetchExpires: 12h
prefetchThreshold: 5
prefetchMaxItemsCount: 0
cacheTimeNegative: 30m
# -- set conditional settings
conditional:
fallbackUpstream: false
rewrite: []
# - in: something.com
# out: somethingelse.com
mapping: []
# - domain: something.com
# dnsserver: 192.168.178.1
# -- set blocking settings using Lists
blocking:
# -- Sets the blocktype
blockType: nxDomain
# -- Sets the block ttl
blockTTL: 6h
# -- Sets the block refreshPeriod
refreshPeriod: 4h
# -- Sets the block download timeout
downloadTimeout: 60s
# -- timeout for list write to disk (each url)
writeTimeout: 60s
# -- timeout for reading the download (each url).
readTimeout: 60s
# -- timeout for reading request headers for the download (each url)
readHeaderTimeout: 60s
# -- Sets the block download attempt count
downloadAttempts: 3
# -- Sets the block download cooldown
downloadCooldown: 5s
# -- Sets how many list-groups can be processed at the same time
processingConcurrency: 8
# -- Set the start strategy (blocking | failOnError | fast)
startStrategy: fast
# -- Number of errors allowed in a list before it is considered invalid
maxErrorsPerSource: 5
# -- Add blocky whitelists
# `default` name is reservered for TrueCharts included default whitelist
# example shows the structure, though name should be changed when used
whitelist:
[]
# - name: default
# lists:
# - https://raw.githubusercontent.com/anudeepND/whitelist/master/domains/optional-list.txt
# - https://raw.githubusercontent.com/anudeepND/whitelist/master/domains/whitelist.txt
# - https://raw.githubusercontent.com/rahilpathan/pihole-whitelist/main/1.LowWL.txt
# -- Blocky blacklists
# `default` name is reservered for TrueCharts included default blacklist
# example shows the structure, though name should be changed when used
blacklist:
[]
# - name: default
# lists:
# - https://big.oisd.nl/domainswild
# -- Blocky clientGroupsBlock
clientGroupsBlock:
- name: default
groups:
- default
- default-ads
- default-tracking
- default-malicious
- default-suspicious
# -- configure using hostsfile for lookups
# Allows for using the hosts configured in kubernetes and such
hostsFile:
enabled: false
sources:
- /etc/hosts
- https://example.com/hosts
- |
# inline hosts
127.0.0.1 example.com
hostsTTL: 1h
filterLoopback: falsr
loading:
refreshPeriod: 4h
downloads:
timeout: 5s
attempts: 3
cooldown: 500ms
concurrency: 4
strategy: blocking
maxErrorsPerSource: 5
podOptions:
automountServiceAccountToken: true
serviceAccount:
main:
# -- Specifies whether a service account should be created
enabled: true
primary: true
# -- Create a ClusterRole and ClusterRoleBinding
# used by k8sgateway
rbac:
main:
# -- Enables or disables the ClusterRole and ClusterRoleBinding
enabled: true
primary: true
clusterWide: true
# -- Set Rules on the ClusterRole
rules:
# General CRDs
- apiGroups:
- apiextensions.k8s.io
resources:
- customresourcedefinitions
verbs:
- get
- list
- watch
# Ingress
- apiGroups:
- extensions
- networking.k8s.io
resources:
- ingresses
verbs:
- list
- watch
# Service
- apiGroups:
- ""
resources:
- services
- namespaces
verbs:
- list
- watch
# HTTPRoute, TLSRoute, GRPCRoute
- apiGroups:
- gateway.networking.k8s.io
resources:
- "*"
verbs:
- watch
- list
# DNSEndpoint
- apiGroups:
- externaldns.k8s.io
resources:
- dnsendpoints
verbs:
- get
- watch
- list
- apiGroups:
- externaldns.k8s.io
resources:
- dnsendpoints/status
verbs:
- "*"
k8sgateway:
enabled: true
# -- TTL for non-apex responses (in seconds)
ttl: 300
# -- Limit what kind of resources to watch, e.g. watchedResources: [ Ingress | Service | HTTPRoute | TLSRoute | GRPCRoute | DNSEndpoint ]
watchedResources:
- Ingress
- Service
- HTTPRoute
# -- Service name of a secondary DNS server (should be `serviceName.namespace`)
secondary: ""
# -- Override the default `serviceName.namespace` domain apex
apex: ""
# -- list of processed domains
domains: []
# -- Delegated domain
# - domain: "example.com"
# # -- Optional configuration option for DNS01 challenge that will redirect all acme
# # challenge requests to external cloud domain (e.g. managed by cert-manager)
# # See: https://cert-manager.io/docs/configuration/acme/dns01/
# dnsChallenge:
# enabled: false
# domain: dns01.clouddns.com
forward:
enabled: false
primary: tls://1.1.1.1
secondary: tls://1.0.0.1
options:
- name: tls_servername
value: cloudflare-dns.com
configmap:
dashboard:
enabled: true
labels:
grafana_dashboard: "1"
data:
blocky.json: >-
{{ .Files.Get "dashboard.json" | indent 8 }}
blockypostgres.json: >-
{{ .Files.Get "dashboardpsql.json" | indent 8 }}
datasource:
enabled: true
labels:
grafana_datasource: "1"
data:
datasourceblockypsql.yaml: |-
apiVersion: 1
datasources:
- name: BlockyPostgres
type: postgres
uid: blockypostgres
url: {{ printf "%s.%s:5432" (.Values.cnpg.main.creds.host | trimAll "\"") .Release.Namespace }}
access: proxy
user: {{ .Values.cnpg.main.user }}
secureJsonData:
password: {{ .Values.cnpg.main.creds.password | default "na" }}
jsonData:
database: {{ .Values.cnpg.main.database }}
sslmode: 'disable' # disable/require/verify-ca/verify-full
maxOpenConns: 100 # Grafana v5.4+
maxIdleConns: 100 # Grafana v5.4+
maxIdleConnsAuto: true # Grafana v9.5.1+
connMaxLifetime: 14400 # Grafana v5.4+
postgresVersion: 1500 # 903=9.3, 904=9.4, 905=9.5, 906=9.6, 1000=10
timescaledb: false
metrics:
main:
# -- Enable and configure a Prometheus serviceMonitor for the chart under this key.
# @default -- See values.yaml
enabled: true
type: "servicemonitor"
endpoints:
- port: main
path: /metrics
# -- Enable and configure Prometheus Rules for the chart under this key.
# @default -- See values.yaml
prometheusRule:
enabled: false
labels: {}
# -- Configure additionial rules for the chart under this key.
# @default -- See prometheusrules.yaml
rules: []
# - alert: UnifiPollerAbsent
# annotations:
# description: Unifi Poller has disappeared from Prometheus service discovery.
# summary: Unifi Poller is down.
# expr: |
# absent(up{job=~".*unifi-poller.*"} == 1)
# for: 5m
# labels:
# severity: critical
redis:
enabled: true
queryLog:
# optional one of: mysql, postgresql, csv, csv-client. If empty, log to console
type: "postgresql"
# directory (should be mounted as volume in docker) for csv, db connection string for mysql, ignored for included postgresql
# target: /var/log/something
# postgresql target: postgres://user:password@db_host_or_ip:5432/db_name
# if > 0, deletes log files which are older than ... days
logRetentionDays: 0
# optional: Max attempts to create specific query log writer, default: 3
creationAttempts: 3
# optional: Time between the creation attempts, default: 2s
creationCooldown: 2s
cnpg:
main:
enabled: true
user: blocky
database: blocky