03011a73e884a182a7e80bc943f844bda427bb09
Two initial Fornax distributed torrent workers, each a gluetun+qBittorrent+natpmpc-helper pod on a different ProtonVPN TX server with NAT-PMP enabled. VPN private keys stored in Vault at secret/fornax/worker-tx253 and secret/fornax/worker-tx34, surfaced via ExternalSecrets. Workers share the media-data PVC; each has its own config PVC. Services: fornax-worker-tx253:8080 and fornax-worker-tx34:8080 (ClusterIP, media ns)
infrastructure
Personal infrastructure-as-code for Legion (k3s home server) and supporting tooling.
| Doc | What it covers |
|---|---|
AGENTS.md |
Full reference: machines, secrets, services, domains, namespaces, common operations |
servers/legion/README.md |
What's running on Legion and how deployment works |
servers/legion/RUNBOOK.md |
Disaster recovery — full restore from scratch |
Quick start
cd servers/legion
direnv allow
terraform plan
terraform apply
Push to servers/ to deploy app changes via Argo CD.
Languages
HCL
78.4%
Shell
17.5%
Python
2.6%
Dockerfile
1.5%