Applications

The cluster runs a wide range of self-hosted applications, organized by category under kubernetes/apps/pitower/<category>/<app>/. Each category is a namespace and each app directory is an ArgoCD Application named pitower-<category>-<app>. Most applications are deployed with the bjw-s app-template Helm chart (5.2.1) and are reached through one of two Envoy Gateways via Gateway API HTTPRoute resources.

Application Categories

CategoryAppsDescription
Media Stack (media)8Jellyfin, Immich, *arr apps, autobrr, and download clients
Home Automation (home-automation)2Frigate NVR, plus an ingress route to Home Assistant OS running outside the cluster
Self-Hosted (selfhosted)13Dashboards, productivity tools, and debugging utilities
Databases (database)7CloudNative-PG operator, clusters and tenants, Dragonfly and ClickHouse operators
ai17Open WebUI, ComfyUI, LLMKube, agentgateway, ToolHive MCP servers, SearXNG, memini, MLflow, browser-use, and more
analytics1Rybbit web analytics (backend, client, ClickHouse)
banking5Actual, Firefly III and its importer, Ghostfolio, Paperless
dev4Forgejo, dev-desktop, herdr, propagit
second-brain2AFFiNE and CouchDB (Obsidian sync)
kubevirt / vms2 / 3KubeVirt and CDI, and the VMs they run (dev, omarchy, debian-test)
workflows3Argo Workflows, Argo Events, agentgateway model sync
workshop1Bambuddy (Bambu Lab printer management)
arc2GitHub Actions Runner Controller and runner scale sets
renovate1renovate-operator
Platformcert-manager, kopiur-system, kube-system, monitoring, networking, openebs, rook-ceph, security, system
ProjectsSingle-app categories for personal projects: flickerd, garrison, goat, pantry-system, rackrat, trade-ops, trade-ops-dev

Gateway Routing Pattern

Applications expose their web interfaces through HTTPRoute resources attached to one of two Envoy Gateways in the networking namespace:

GatewayLoadBalancer IPDNS targetUse Case
envoy-external10.20.10.239external.wibrow.devPublic services, reached through the towonel tunnel
envoy-internal10.20.10.238internal.wibrow.devLAN and Tailscale only
Typical HTTPRoute attachment
route:
  app:
    hostnames:
      - app-name.wibrow.dev
    parentRefs:
      - name: envoy-external  # or envoy-internal
        namespace: networking
        sectionName: https

The ai namespace also runs its own agentgateway Gateway for LLM and MCP traffic.

Common Patterns

Stakater Reloader

Controllers that consume Secrets or ConfigMaps carry reloader.stakater.com/auto: "true", which restarts pods when those objects change.

Single Sign-On

Apps that support OIDC authenticate against Kanidm at idm.wibrow.dev.

Persistent Data and Backups

App data PVCs are declared with the pvc kustomize component and backed up hourly to Garage S3 by the kopiur component. See Development > Adding Apps.

NFS Media Storage

The *arr apps, the download clients, Jellyfin and Frigate mount the Synology NAS over NFS (server data):

yaml
persistence:
  media:
    type: nfs
    server: data
    path: /volume1/media
    globalMounts:
      - path: /data/nas-media

External Secrets

Secrets come from ExternalSecret resources backed by the infisical ClusterSecretStore (paths /<category>/<app>/<SECRET_NAME>). Database credentials come from the cnpg-secrets-database ClusterSecretStore, usually through the cnpg-db-shared component.