• 2 Posts
  • 14 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle
  • Sorry didn’t find the time until now to reply. Also in the process of migrating everything to my Kubernetes cluster, so this is not as up to date in regards to image versions as it should be.

    This is my current setup, with only qBittorrent and SABnzbd going through the Gluetun VPN container. Everything else just uses my regular home internet:

    ---
    [Unit]
    Description=Flaresolverr Container
    
    [Container]
    ContainerName=flaresolverr
    HostName=flaresolverr
    EnvironmentFile=global.env
    Image=ghcr.io/flaresolverr/flaresolverr:v3.4.6
    AutoUpdate=registry
    PublishPort=8091:8191
    Network=arr-stack.network
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=qBittorrent Container
    Wants=gluetun.service
    After=gluetun.service
    
    [Container]
    ContainerName=qbittorrent
    HostName=qbittorrent
    EnvironmentFile=global.env
    Environment=WEBUI_PORT=8080
    Image=lscr.io/linuxserver/qbittorrent:5.1.4
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Network=container:gluetun
    
    Volume=%h/container_volumes/qbittorrent/conf:/config:Z,U
    Volume=%h/Downloads/completed:/downloads:z,U
    Volume=%h/Downloads/incomplete:/incomplete:z,U
    Volume=%h/Downloads/torrents:/torrents:z,U
    
    Memory=1.5g
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Recyclarr TRaSH Guide Sync Container
    Wants=radarr.service sonarr.service
    After=radarr.service sonarr.service
    
    [Container]
    ContainerName=recyclarr
    HostName=recyclarr
    EnvironmentFile=global.env
    Image=ghcr.io/recyclarr/recyclarr:8
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Network=arr-stack.network
    
    Secret=sonarr_api_key,type=env,target=SONARR_API_KEY
    Secret=radarr_api_key,type=env,target=RADARR_API_KEY
    
    Volume=%h/container_volumes/recyclarr/conf:/config:Z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=SABnzbd Container
    Wants=gluetun.service
    After=gluetun.service
    
    [Container]
    ContainerName=sabnzbd
    HostName=sabnzbd
    Image=lscr.io/linuxserver/sabnzbd:4.5.5
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Network=container:gluetun
    EnvironmentFile=global.env
    
    Volume=%h/container_volumes/sabnzbd/conf:/config:Z,U
    Volume=%h/Downloads/sabnzbd/completed:/downloads:z,U
    Volume=%h/Downloads/sabnzbd/incomplete:/incomplete-downloads:z,U
    
    Memory=1.5g
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Sonarr Container
    After=gluetun.service prowlarr.service
    Wants=gluetun.service prowlarr.service
    
    [Container]
    ContainerName=sonarr
    HostName=sonarr
    EnvironmentFile=global.env
    Image=lscr.io/linuxserver/sonarr:4.0.17
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    PublishPort=8089:8989
    Network=arr-stack.network
    
    HealthCmd=["curl","--fail","http://127.0.0.1:8989/sonarr/ping"]
    HealthInterval=30s
    HealthRetries=10
    
    SecurityLabelDisable=true
    Volume=%h/container_volumes/sonarr/conf:/config:Z,U
    Volume=/mnt/eldanas/tv:/tv
    Volume=%h/Downloads/completed/sonarr:/downloads:z,U
    Volume=%h/Downloads/sabnzbd/completed/tv:/downloads-usenet:z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Prowlarr Container
    Wants=gluetun.service flaresolverr.service
    After=gluetun.service flaresolverr.service
    
    [Container]
    ContainerName=prowlarr
    HostName=prowlarr
    EnvironmentFile=global.env
    Image=lscr.io/linuxserver/prowlarr:2.3.5
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    PublishPort=8096:9696
    Network=arr-stack.network
    
    HealthCmd=["curl","--fail","http://127.0.0.1:9696/prowlarr/ping"]
    HealthInterval=30s
    HealthRetries=10
    
    Volume=%h/container_volumes/prowlarr/conf:/config:Z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Radarr Container
    After=gluetun.service prowlarr.service
    Wants=gluetun.service prowlarr.service
    
    [Container]
    ContainerName=radarr
    HostName=radarr
    EnvironmentFile=global.env
    Image=lscr.io/linuxserver/radarr:6.1.1
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    PublishPort=8078:7878
    Network=arr-stack.network
    
    HealthCmd=["curl","--fail","http://127.0.0.1:7878/radarr/ping"]
    HealthInterval=30s
    HealthRetries=10
    
    SecurityLabelDisable=true
    Volume=%h/container_volumes/radarr/conf:/config:Z,U
    Volume=/mnt/eldanas/movies:/movies
    Volume=%h/Downloads/completed/radarr:/downloads:z,U
    Volume=%h/Downloads/sabnzbd/completed/movies:/downloads-usenet:z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Gluetun Container
    
    [Container]
    ContainerName=gluetun
    HostName=gluetun
    EnvironmentFile=global.env
    EnvironmentFile=gluetun.env
    Environment=FIREWALL_INPUT_PORTS=8080
    Image=docker.io/qmcgaw/gluetun:v3.41.1
    AutoUpdate=registry
    PodmanArgs=--privileged
    AddCapability=NET_ADMIN
    AddDevice=/dev/net/tun:/dev/net/tun
    PublishPort=8080:8080
    # SABnzbd Port Mapping
    PublishPort=8085:8085
    # Gluetun Port Mapping
    PublishPort=8123:8000
    Network=arr-stack.network
    
    Volume=%h/container_volumes/gluetun/conf:/gluetun:Z,U
    
    Secret=proton_wireguard_private_key,type=env,target=WIREGUARD_PRIVATE_KEY
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Seerr Container
    After=gluetun.service
    Wants=gluetun.service
    
    [Container]
    ContainerName=seerr
    HostName=seerr
    EnvironmentFile=global.env
    Image=ghcr.io/seerr-team/seerr:v3.2.0
    UserNS=keep-id:uid=1000,gid=1000
    AutoUpdate=registry
    PublishPort=8055:5055
    Network=arr-stack.network
    
    Volume=%h/container_volumes/seerr/conf:/app/config:Z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    

    The global.env file only contains env variables like TZ or the PUID and PGID which are used in almost all my containers.


  • You can configure CoreDNS for what you are trying to do, there is usually a ConfigMap containing the CoreDNS config in the kube-system namespace. We did that as a quick hack on one of our clusters at work, but I wouldn’t recommend it tbh. Instead I would do what others already suggested and deploy a Pi-Hole or AdGuard Home, or even a second CoreDNS for this purpose.



  • I liked my Pi 3B+ for tinkering around and run some services like vaultwarden or a VPN node with PiVPN (first OpenVPN, later Wireguard). They are great for stuff like that and don’t use much power. Not sure it makes sense to add them as nodes though as 2GB is stretching it, although Talos OS has a minimal requirement for worker nodes of 1GB, so I might still try 😄

    As you can see I plan to use Talos as well, it sounds really promising what I read about it. For a CNI I plan to use Cilium and for distributed storage I might try Longhorn and see how it works. Apart from that I am still on the fence if I should run my nodes bare model or put a virt layer in between with Proxmox.





  • Oh wow okay, if I’d go down that route I would definitely do multiple VMs on that host. In my opinion, the whole clustering and self healing / HA aspect of Kubernetes is why I want to switch to it. I can do gitops with Podman/Docker as well, in fact I already do that including a renovate pipeline on my sel-hosted Forgejo instance. But having the redundancy of several nodes, if one goes down the service will still work or at least will be re-deployed within a couple of seconds, provided there is distributed storage (longhorn, ceph or even nfs cis) if its a stateful app.






  • Eldaroth@lemmy.worldtoSelfhosted@lemmy.worldDawarich 1.0
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 months ago

    Thanks for taking the time to reply.

    In the meantime I tried the app and it looks awesome! However, I noticed the app relies on google’s services location accuracy unfortunately. This is kind of a deal breaker for me to use the app for now. But I get that imlementing an F-Droid version is not your top priority, so I’ll follow the project and patiently wait for it :)




  • Eldaroth@lemmy.worldtoSelfhosted@lemmy.worldArr Podman Quadlets Setup
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    9 months ago

    Nice, did the move from docker to podman a couple of months ago myself. Now running the arr stack, nextcloud, immich and some other services as quadlets. File permission due to podmans rootless nature usually was the culprit if something was not working properly.

    I can share my quadlet systemd files I use for the arr stack. I deployed it as a pod:

    [Unit]
    Description=Arr-stack pod
    
    [Pod]
    PodName=arr-stack
    # Jellyseerr Port Mapping
    PublishPort=8055:5055
    # Sonarr Port Mapping
    PublishPort=8089:8989
    # Radarr Port Mapping
    PublishPort=8078:7878
    # Prowlarr Port Mapping
    PublishPort=8096:9696
    # Flaresolverr Port Mapping
    PublishPort=8091:8191
    # qBittorrent Port Mapping
    PublishPort=8080:8080
    ---
    [Unit]
    Description=Gluetun Container
    
    [Container]
    ContainerName=gluetun
    EnvironmentFile=global.env
    EnvironmentFile=gluetun.env
    Environment=FIREWALL_INPUT_PORTS=8080
    Image=docker.io/qmcgaw/gluetun:v3.40.0
    Pod=arr-stack.pod
    AutoUpdate=registry
    PodmanArgs=--privileged
    AddCapability=NET_ADMIN
    AddDevice=/dev/net/tun:/dev/net/tun
    
    Volume=%h/container_volumes/gluetun/conf:/gluetun:Z,U
    
    Secret=openvpn_user,type=env,target=OPENVPN_USER
    Secret=openvpn_password,type=env,target=OPENVPN_PASSWORD
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=qBittorrent Container
    Requires=gluetun.service
    After=gluetun.service
    
    [Container]
    ContainerName=qbittorrent
    EnvironmentFile=global.env
    Environment=WEBUI_PORT=8080
    Image=lscr.io/linuxserver/qbittorrent:5.1.2
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Pod=arr-stack.pod
    Network=container:gluetun
    
    Volume=%h/container_volumes/qbittorrent/conf:/config:Z,U
    Volume=%h/Downloads/completed:/downloads:z,U
    Volume=%h/Downloads/incomplete:/incomplete:z,U
    Volume=%h/Downloads/torrents:/torrents:z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Prowlarr Container
    Requires=gluetun.service
    After=gluetun.service
    
    [Container]
    ContainerName=prowlarr
    EnvironmentFile=global.env
    Image=lscr.io/linuxserver/prowlarr:2.0.5
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Pod=arr-stack.pod
    Network=container:gluetun
    
    HealthCmd=["curl","--fail","http://127.0.0.1:9696/prowlarr/ping"]
    HealthInterval=30s
    HealthRetries=10
    
    Volume=%h/container_volumes/prowlarr/conf:/config:Z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Flaresolverr Container
    
    [Container]
    ContainerName=flaresolverr
    EnvironmentFile=global.env
    Image=ghcr.io/flaresolverr/flaresolverr:v3.4.0
    AutoUpdate=registry
    Pod=arr-stack.pod
    Network=container:gluetun
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Radarr Container
    
    [Container]
    ContainerName=radarr
    EnvironmentFile=global.env
    Image=lscr.io/linuxserver/radarr:5.27.5
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Pod=arr-stack.pod
    Network=container:gluetun
    
    HealthCmd=["curl","--fail","http://127.0.0.1:7878/radarr/ping"]
    HealthInterval=30s
    HealthRetries=10
    
    # Disable SecurityLabels due to SMB share
    SecurityLabelDisable=true
    Volume=%h/container_volumes/radarr/conf:/config:Z,U
    Volume=/mnt/movies:/movies
    Volume=%h/Downloads/completed/radarr:/downloads:z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Sonarr Container
    
    [Container]
    ContainerName=sonarr
    EnvironmentFile=global.env
    Image=lscr.io/linuxserver/sonarr:4.0.15
    AutoUpdate=registry
    UserNS=keep-id:uid=1000,gid=1000
    Pod=arr-stack.pod
    Network=container:gluetun
    
    HealthCmd=["curl","--fail","http://127.0.0.1:8989/sonarr/ping"]
    HealthInterval=30s
    HealthRetries=10
    
    # Disable SecurityLabels due to SMB share
    SecurityLabelDisable=true
    Volume=%h/container_volumes/sonarr/conf:/config:Z,U
    Volume=/mnt/tv:/tv
    Volume=%h/Downloads/completed/sonarr:/downloads:z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    ---
    [Unit]
    Description=Jellyseerr Container
    
    [Container]
    ContainerName=jellyseerr
    EnvironmentFile=global.env
    Image=docker.io/fallenbagel/jellyseerr:2.7.3
    AutoUpdate=registry
    Pod=arr-stack.pod
    Network=container:gluetun
    
    Volume=%h/container_volumes/jellyseerr/conf:/app/config:Z,U
    
    [Service]
    Restart=always
    
    [Install]
    WantedBy=default.target
    

    I run my podman containers in a VM running Alma Linux. Works pretty great so far.

    Had the same issue when debugging systemctl errors, journalctl not being very helpful. At one point I just ran podman logs -f <container> in another terminal in a while loop just to catch the logs of the application. Not the most sophisticated approach, but it works 😄