Commit Graph

28 Commits

Author SHA1 Message Date
Will Anderson 214afed0a2 Set DNS_UPSTREAM_RESOLVER_TYPE=plain to actually disable DoT in gluetun
DOT=off alone does not override DNS_UPSTREAM_RESOLVER_TYPE in this version
of gluetun — it defaults to DoT regardless, causing DNS failures through
ProtonVPN (port 853 connection reset). Setting the resolver type directly
fixes plain DNS routing to k8s CoreDNS.
2026-04-14 22:04:36 -05:00
Will Anderson 41ab2eaf0e Fix DNS_UPSTREAM_PLAIN_ADDRESSES format: requires ip:port not bare ip 2026-04-14 22:01:50 -05:00
Will Anderson 10dd561ec0 Fix gluetun healthcheck targets and DNS env var on fornax workers
Change HEALTH_TARGET_ADDRESS to ProtonVPN API endpoints so TLS startup
check doesn't fail against cloudflare.com/github.com (rejected from
ProtonVPN exit IPs). Rename deprecated DNS_ADDRESS to
DNS_UPSTREAM_PLAIN_ADDRESSES in fornax-workers.yaml.
2026-04-14 21:58:52 -05:00
Will Anderson a1623eda39 Fix gluetun DNS: disable DoT, use k8s coredns as plaintext resolver
DoT (port 853) to 1.1.1.1 through ProtonVPN VPN tunnel gets TCP RST,
causing gluetun healthcheck to fail (can't resolve github.com /
cloudflare.com). k8s coredns at 10.43.0.10 is reachable via eth0
within FIREWALL_OUTBOUND_SUBNETS, bypassing the VPN for DNS while
letting all other traffic tunnel correctly.

Also rename VPN_ENDPOINT_IP/PORT to WIREGUARD_ENDPOINT_IP/PORT to
suppress gluetun deprecation warnings.
2026-04-14 21:32:57 -05:00
Will Anderson 741191a7e6 Switch workers to custom WireGuard provider with correct endpoint IPs
gluetun's bundled protonvpn server list has stale IPs for US-TX#179
(37.19.200.26) and US-TX#220 (95.173.217.2). The WIREGUARD_ENDPOINT_IP
env var is a filter not an override, so there's no way to redirect
protonvpn provider to a new IP.

Switch to custom WireGuard provider with hardcoded endpoint IPs from
fresh ProtonVPN configs (95.173.217.29 / 146.70.58.130). Add
DNS_KEEP_NAMESERVER=on so gluetun leaves k8s DNS intact instead of
routing DNS through its own proxy (which breaks in-cluster).

Port forwarding is not available with custom provider; will restore
once gluetun releases an updated server list image.
2026-04-14 21:29:29 -05:00
Will Anderson 0688700ebc Fix gluetun endpoint env var: use WIREGUARD_ENDPOINT_IP, drop port
gluetun rejects VPN_ENDPOINT_PORT when SERVER_NAMES is used (server
selection mode), and warns that VPN_ENDPOINT_IP is deprecated in
favour of WIREGUARD_ENDPOINT_IP. Use only WIREGUARD_ENDPOINT_IP;
port 51820 is ProtonVPN's default and doesn't need to be set.
2026-04-14 21:25:55 -05:00
Will Anderson 87934e9284 Override stale gluetun endpoint IPs for ProtonVPN servers
ProtonVPN migrated US-TX#179 (37.19.200.26 → 95.173.217.29) and
US-TX#220 (95.173.217.2 → 146.70.58.130). gluetun's bundled server
list still has the old dead IPs. Override via VPN_ENDPOINT_IP and
VPN_ENDPOINT_PORT so gluetun uses the correct endpoints while keeping
the protonvpn provider (and port forwarding) intact.
2026-04-14 21:24:19 -05:00
Will Anderson 008df2b584 Fix server names: US-TX#179 for tx253, US-TX#220 for tx34 (gluetun protonvpn format) 2026-04-14 21:19:02 -05:00
Will Anderson a2239ab89e Switch back to protonvpn provider with US-TX#253 and US-TX#34 2026-04-14 21:17:20 -05:00
Will Anderson 88c4d795e7 Switch DNS to 8.8.8.8 — ProtonVPN internal DNS returning errors 2026-04-14 21:12:33 -05:00
Will Anderson 027667e7f7 Remove custom health target — use ProtonVPN internal DNS for resolution 2026-04-14 21:10:42 -05:00
Will Anderson e6d1350ca8 Use ProtonVPN internal DNS and direct IP healthcheck to diagnose VPN 2026-04-14 21:08:55 -05:00
Will Anderson 0c238e9e7e Update worker VPN endpoints: tx253→US-TX#253, tx34→US-TX#34 2026-04-14 21:04:37 -05:00
Will Anderson 7893fdc1d3 Remove VPN_PORT_FORWARDING from tx34 — not supported with custom provider 2026-04-14 20:27:16 -05:00
Will Anderson 59f551663b Switch gluetun to custom provider — use explicit WireGuard config for US-IL#267
Avoids gluetun's ProtonVPN server name lookup entirely. All WireGuard
parameters (endpoint, peer key, client address, keepalive) come directly
from the downloaded ProtonVPN config.
2026-04-14 20:22:31 -05:00
Will Anderson 9a523da831 Use SERVER_COUNTRIES=US with explicit endpoint — gluetun has no US-IL naming 2026-04-14 20:20:47 -05:00
Will Anderson c283110e70 Switch workers to US-IL#267 with explicit WireGuard endpoint and peer key
US-TX#179 and US-TX#220 were failing — WireGuard handshake completing
but no traffic passing (silent drop). Switching both workers to US-IL#267
and pinning the endpoint IP and peer public key directly to avoid relying
on gluetun's built-in server list lookup.
2026-04-14 20:18:57 -05:00
Will Anderson b5f481d9a4 Fix qbt-config-patch for Python 3.14: use lambda in re.sub replacements
Python 3.14 raises PatternError for backslash sequences like \P in
re.sub replacement strings. Switch to lambda replacements which bypass
that interpretation. Also pin to python:3.13-alpine to avoid future
surprises from pulling :3-alpine.
2026-04-14 20:00:24 -05:00
Will Anderson 4ef625ef3d qbittorrent: bake performance settings into initContainer
Switch qbt-config-patch from busybox/sed to python:3-alpine so we can
cleanly handle INI keys with backslashes. Now seeds both password hash
and high-throughput defaults (3000 max connections, 50 active downloads,
unlimited rate) on fresh PVC deployments. Existing configs are updated
in-place; API-applied values are preserved on restart.
2026-04-11 12:24:16 -05:00
Will Anderson c4cd91920a Fix qBittorrent auth: stamp known password hash via initContainer
LocalhostAuthEnabled=false isn't honored in this qBT version. Instead, initContainer
stamps the PBKDF2 hash for admin:adminadmin before startup so all three pods have
consistent credentials. portforward-helper and coordinator restored to cookie-based
SID auth.
2026-04-11 11:14:23 -05:00
Will Anderson 531df76a90 Patch qBittorrent config via initContainer before startup
Adds qbt-config-patch initContainer that sets WebUI\LocalhostAuthEnabled=false
in qBittorrent.conf before the main containers start. Prevents qBittorrent from
overwriting the setting (previously edited at runtime, lost on pod restart).
2026-04-11 11:11:23 -05:00
Will Anderson 854ccd1344 Disable qBittorrent localhost auth; remove credentials from helpers
LocalhostAuthEnabled=false set in all three qbt configs. portforward-helper and
coordinator now call the API directly without auth — no more ban risk from failed
login attempts.
2026-04-11 11:08:54 -05:00
Will Anderson ffd3068f78 Fix port forwarding: read file instead of HTTP API, fix server names
- portforward-helper now reads /tmp/gluetun/forwarded_port via shared emptyDir
  volume instead of polling gluetun HTTP API (which returned Unauthorized)
- Main qbt: SERVER_NAMES=US-IL#1 (valid entry in gluetun server list)
- Both manifests cleaned up
2026-04-11 10:12:19 -05:00
Will Anderson 69976ca172 Fix main qbt server selection; bump portforward-helper memory limit
- Main qbt: switch from pinned US-IL#149 (no PF) to SERVER_REGIONS=Illinois so
  gluetun picks any IL server with port forwarding enabled
- Fornax workers: portforward-helper 32Mi→96Mi to stop OOMKill
2026-04-11 10:03:52 -05:00
Will Anderson cce8c0a0d4 Fix server names to match gluetun's ProtonVPN server list
US-TX#253 and US-TX#34 aren't in gluetun's built-in list. Switching to:
- Main qbt: US-IL#149 (was US-IL#267)
- Fornax TX253: US-TX#179
- Fornax TX34: US-TX#220
Private keys are per-account and work with any ProtonVPN WireGuard server.
2026-04-11 09:59:23 -05:00
Will Anderson e1996d4396 Switch to gluetun native ProtonVPN port forwarding (VPN_PORT_FORWARDING=on)
Replaces DIY natpmpc sidecar with gluetun's built-in NAT-PMP handling for the protonvpn
provider. The natpmpc UDP response was being dropped by gluetun's firewall since conntrack
doesn't track stateless UDP from the gateway. With VPN_PORT_FORWARDING=on, gluetun handles
the NAT-PMP exchange internally and exposes the port at :8000/v1/openvpn/portforwarded.
Helper sidecar now just polls that endpoint.
2026-04-11 09:57:07 -05:00
Will Anderson 24e308202b Allow NAT-PMP response port through gluetun firewall (FIREWALL_INPUT_PORTS=5351) 2026-04-11 09:50:55 -05:00
Will Anderson 03011a73e8 Add Fornax worker pods — US-TX#253 and US-TX#34
Two initial Fornax distributed torrent workers, each a gluetun+qBittorrent+natpmpc-helper
pod on a different ProtonVPN TX server with NAT-PMP enabled. VPN private keys stored in
Vault at secret/fornax/worker-tx253 and secret/fornax/worker-tx34, surfaced via
ExternalSecrets. Workers share the media-data PVC; each has its own config PVC.

Services: fornax-worker-tx253:8080 and fornax-worker-tx34:8080 (ClusterIP, media ns)
2026-04-11 09:46:18 -05:00