Self-Hosted Applications

The selfhosted namespace contains productivity tools, dashboards, and utility services. All are deployed with the bjw-s app-template Helm chart and attach to envoy-external.

Application Catalog

AppDescriptionURLData
AtuinShell history sync serveratuin.wibrow.devPostgreSQL (shared)
CryptgeonEncrypted, view-once notes and filessecrets.wibrow.devDragonfly
Echo ServerHTTP request debuggingecho.wibrow.dev--
ExcalidrawCollaborative whiteboarddraw.wibrow.dev--
GlanceDashboard with feeds and widgetsglance.wibrow.dev--
HomepageKubernetes-aware application dashboardhome.wibrow.dev--
House HunterProperty search aggregatorhouse-hunter.wibrow.devPostgreSQL (shared)
IT ToolsDeveloper utilities in the browsertools.wibrow.dev--
MealieRecipe management and meal planningrecipes.wibrow.devPVC, kopiur backups
MinifluxMinimalist RSS/Atom readerminiflux.wibrow.devPostgreSQL (shared)
n8nWorkflow automationn8n.wibrow.devPVC, kopiur backups
RRDAREST API for DNS lookupsrrda.wibrow.dev--
WhoamiMinimal HTTP debugging endpointwhoami.wibrow.dev--

PostgreSQL apps are tenants on the shared CNPG cluster and use the cnpg-db-shared component; see Databases.


Application Details

Atuin

Atuin syncs encrypted shell history between machines.

  • Image: ghcr.io/atuinsh/atuin
  • Database: tenant atuin on the shared cluster
  • Access control: an Envoy Gateway SecurityPolicy on the atuin HTTPRoute checks an X-API-Key header against the atuin-apikeys Secret, since the CLI client cannot follow an OIDC redirect

Cryptgeon

Cryptgeon provides encrypted, self-destructing notes and file sharing. Messages are encrypted client-side.

  • Image: cupcakearmy/cryptgeon, plus a static-web-server container for custom branding
  • Storage: a Dragonfly instance (cryptgeon-dragonfly) managed by the Dragonfly operator

Echo Server

HTTP Echo Server returns request headers, body, and metadata. Useful for debugging gateway routing, TLS termination, and header injection.

  • Image: ghcr.io/mendhak/http-https-echo
  • Scale to zero: a KEDA ScaledObject (min 0, max 1) with an HTTP add-on InterceptorRoute starts it on demand

Excalidraw

Excalidraw is a collaborative whiteboard for sketching diagrams.

  • Image: docker.io/excalidraw/excalidraw:latest (digest pinned)
  • Storage: emptyDir only (stateless)

Glance

Glance is a dashboard with widgets for RSS feeds, weather, bookmarks, and monitoring.

  • Image: docker.io/glanceapp/glance
  • Configuration: ConfigMap mounted as the Glance config

Homepage

Homepage is a Kubernetes-aware application dashboard.

  • Image: ghcr.io/gethomepage/homepage
  • Configuration: ConfigMap with bookmarks, services, settings and widgets, plus custom.js, which loads the Rybbit tracking script
  • RBAC: ServiceAccount with cluster read permissions for service discovery

House Hunter

House Hunter is a custom property search aggregator.

  • Image: ghcr.io/swibrow/house-hunter:latest
  • Database: tenant house_hunter on the shared cluster

IT Tools

IT Tools is a collection of developer utilities (encoders, converters, generators).

  • Image: ghcr.io/sharevb/it-tools

Mealie

Mealie is a recipe manager and meal planner.

  • Image: ghcr.io/mealie-recipes/mealie
  • Storage: PVC mealie-data at /app/data via the pvc component, backed up by kopiur (mover runs as uid 911 to match the app)
  • Auth: OIDC client secret from Infisical

Miniflux

Miniflux is a minimalist RSS feed reader.

  • Image: ghcr.io/miniflux/miniflux (distroless)
  • Database: tenant miniflux on the shared cluster
  • Auth: OIDC via Kanidm (idm.wibrow.dev)
  • Polling: every 15 minutes using the entry frequency scheduler

n8n

n8n is a workflow automation platform with a visual editor.

  • Image: ghcr.io/n8n-io/n8n
  • Storage: PVC n8n at /home/node/.n8n via the pvc component, backed up by kopiur

RRDA

RRDA is a REST API for DNS record lookups.

  • Image: ghcr.io/cloudsnacks/rrda (built in cloudsnacks/containers)
  • Sidecar: adguard/dnsproxy forwarding to Cloudflare over DNS-over-HTTPS (1.1.1.1, 1.0.0.1)

Whoami

Whoami is a tiny HTTP server that returns connection and request information.

  • Image: docker.io/traefik/whoami