qbittorrentvpn.yaml 9.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336
  1. ---
  2. apiVersion: apps/v1
  3. kind: Deployment
  4. metadata:
  5. name: qbittorrentvpn
  6. namespace: plex
  7. spec:
  8. strategy:
  9. type: Recreate
  10. selector:
  11. matchLabels:
  12. app: qbittorrentvpn
  13. replicas: 1
  14. template:
  15. metadata:
  16. labels:
  17. app: qbittorrentvpn
  18. annotations:
  19. backup.velero.io/backup-volumes-excludes: seedbox,media,media2,data-ec,scratch
  20. spec:
  21. affinity:
  22. nodeAffinity:
  23. requiredDuringSchedulingIgnoredDuringExecution:
  24. nodeSelectorTerms:
  25. - matchExpressions:
  26. - key: seedbox
  27. operator: In
  28. values:
  29. - "true"
  30. containers:
  31. - name: qbittorrentvpn
  32. image: binhex/arch-qbittorrentvpn:5.1.4-1-01
  33. ports:
  34. - containerPort: 8080
  35. name: http-web-svc
  36. securityContext:
  37. privileged: true
  38. envFrom:
  39. - secretRef:
  40. name: qbittorrentvpn-secret
  41. livenessProbe:
  42. exec:
  43. command: ["curl", "--fail", "localhost:8080"]
  44. volumeMounts:
  45. - mountPath: "/media"
  46. name: media
  47. - mountPath: "/media2"
  48. name: media2
  49. - mountPath: "/dataec"
  50. name: data-ec
  51. - mountPath: "/config"
  52. name: config
  53. - mountPath: "/scratch"
  54. name: seedbox
  55. volumes:
  56. - name: media
  57. persistentVolumeClaim:
  58. claimName: plex-pvc
  59. - name: media2
  60. persistentVolumeClaim:
  61. claimName: media2-pvc
  62. - name: data-ec
  63. persistentVolumeClaim:
  64. claimName: data-ec-pvc
  65. - name: config
  66. persistentVolumeClaim:
  67. claimName: qbittorrentvpn-pvc
  68. - name: seedbox
  69. hostPath:
  70. path: /seedbox/torrents
  71. type: Directory
  72. ---
  73. apiVersion: apps/v1
  74. kind: Deployment
  75. metadata:
  76. name: qbittorrentvpn-exporter
  77. namespace: plex
  78. spec:
  79. strategy:
  80. type: Recreate
  81. selector:
  82. matchLabels:
  83. app: qbittorrentvpn-exporter
  84. replicas: 1
  85. template:
  86. metadata:
  87. labels:
  88. app: qbittorrentvpn-exporter
  89. spec:
  90. containers:
  91. - name: qbittorrentvpn-exporter
  92. image: ghcr.io/esanchezm/prometheus-qbittorrent-exporter:latest
  93. ports:
  94. - containerPort: 8000
  95. name: metrics
  96. envFrom:
  97. - secretRef:
  98. name: qbittorrentvpn-exporter-secret
  99. livenessProbe:
  100. exec:
  101. command:
  102. - "/bin/sh"
  103. - "-c"
  104. - 'wget -O - 0.0.0.0:8000 | grep -E "qbittorrent_up\{.* 1.0"'
  105. initialDelaySeconds: 3
  106. timeoutSeconds: 5
  107. periodSeconds: 3
  108. failureThreshold: 15
  109. resources:
  110. requests:
  111. memory: "0"
  112. limits:
  113. memory: "256Mi"
  114. ---
  115. apiVersion: v1
  116. kind: Service
  117. metadata:
  118. name: qbittorrentvpn-service
  119. namespace: plex
  120. spec:
  121. selector:
  122. app: qbittorrentvpn
  123. type: ClusterIP
  124. ports:
  125. - name: qbittorrentvpn-web-port
  126. protocol: TCP
  127. port: 8080
  128. targetPort: http-web-svc
  129. ---
  130. apiVersion: v1
  131. kind: Service
  132. metadata:
  133. name: qbittorrentvpn-exporter-service
  134. namespace: plex
  135. labels:
  136. app: qbittorrentvpn-exporter
  137. spec:
  138. selector:
  139. app: qbittorrentvpn-exporter
  140. type: ClusterIP
  141. ports:
  142. - name: metrics
  143. protocol: TCP
  144. port: 8000
  145. targetPort: metrics
  146. ---
  147. apiVersion: networking.k8s.io/v1
  148. kind: Ingress
  149. metadata:
  150. name: qbittorrentvpn
  151. namespace: plex
  152. annotations:
  153. traefik.ingress.kubernetes.io/router.entrypoints: websecure
  154. traefik.ingress.kubernetes.io/router.middlewares: kube-system-lanonly@kubernetescrd
  155. spec:
  156. rules:
  157. - host: qbittorrentvpn.lan.jibby.org
  158. http:
  159. paths:
  160. - path: /
  161. pathType: Prefix
  162. backend:
  163. service:
  164. name: qbittorrentvpn-service
  165. port:
  166. number: 8080
  167. ---
  168. apiVersion: monitoring.coreos.com/v1
  169. kind: PrometheusRule
  170. metadata:
  171. labels:
  172. prometheus: qbittorrent
  173. role: alert-rules
  174. name: prometheus-qbittorrent-rules
  175. namespace: plex
  176. spec:
  177. groups:
  178. - name: ./qbittorrent.rules
  179. rules:
  180. - alert: QbittorrentErroredTorrents
  181. expr: sum(qbittorrent_torrents_count{status="error"}) > 0
  182. # Restart the above deployment reguarly. Sometimes VPN throughput slows down & a restart helps.
  183. ---
  184. apiVersion: batch/v1
  185. kind: CronJob
  186. metadata:
  187. name: qbittorrentvpn-restart
  188. namespace: plex
  189. spec:
  190. schedule: "*/30 * * * *"
  191. successfulJobsHistoryLimit: 1
  192. failedJobsHistoryLimit: 1
  193. concurrencyPolicy: Forbid
  194. jobTemplate:
  195. spec:
  196. template:
  197. metadata:
  198. labels:
  199. app: qbittorrentvpn-restart
  200. spec:
  201. serviceAccountName: qbittorrentvpn-restart-serviceaccount
  202. securityContext:
  203. runAsUser: 1000
  204. runAsGroup: 1000
  205. restartPolicy: OnFailure
  206. containers:
  207. - name: qbittorrentvpn-restart
  208. image: python:3.14
  209. command:
  210. - python3
  211. - -c
  212. - |
  213. import subprocess
  214. import json
  215. import pprint
  216. import urllib.parse
  217. import sys
  218. import datetime
  219. # Vars to configure
  220. namespace = 'plex'
  221. qparams = {'labelSelector': 'app=qbittorrentvpn'}
  222. max_runtime = datetime.timedelta(days=3)
  223. # serviceaccount/k8s specific vars. Likely don't need to edit these.
  224. serviceaccount_dir = '/var/run/secrets/kubernetes.io/serviceaccount'
  225. apiserver = 'https://kubernetes.default.svc'
  226. token = open(f'{serviceaccount_dir}/token').read()
  227. result = subprocess.run([
  228. 'curl',
  229. '--cacert', f'{serviceaccount_dir}/ca.crt',
  230. '--header', f'Authorization: Bearer {token}',
  231. '-X', 'GET',
  232. f'{apiserver}/api/v1/namespaces/{namespace}/pods?{urllib.parse.urlencode(qparams)}'
  233. ],
  234. capture_output=True,
  235. check=True,
  236. )
  237. pod_list = json.loads(result.stdout)
  238. items = pod_list.get('items')
  239. if items is None or len(items) < 1:
  240. print(f'No pod found? Exiting. {pod_list=}')
  241. sys.exit(1)
  242. if len(items) > 1:
  243. print(f'>1 pod? Exiting. {items=}, {len(items)=}')
  244. sys.exit(1)
  245. pod = items[0]
  246. container_statuses = pod['status']['containerStatuses']
  247. if len(container_statuses) != 1:
  248. print(f'len(containerStatuses) != 1? Exiting. {container_statuses=}')
  249. sys.exit(1)
  250. running = container_statuses[0]['state'].get('running')
  251. if not running:
  252. print(f'Pod not running? Exiting. {container_statuses["state"]=}')
  253. started_at = datetime.datetime.fromisoformat(running["startedAt"])
  254. runtime = datetime.datetime.now(tz=datetime.UTC) - started_at
  255. print(f'{runtime=} > {max_runtime=} ? {runtime > max_runtime}')
  256. if runtime > max_runtime:
  257. pod_name = pod['metadata']['name']
  258. print(f'Deleting pod {pod_name}')
  259. result = subprocess.run([
  260. 'curl',
  261. '--cacert', f'{serviceaccount_dir}/ca.crt',
  262. '--header', f'Authorization: Bearer {token}',
  263. '-X', 'DELETE',
  264. f'{apiserver}/api/v1/namespaces/{namespace}/pods/{pod_name}'
  265. ],
  266. capture_output=True,
  267. check=True,
  268. )
  269. ---
  270. apiVersion: v1
  271. kind: ServiceAccount
  272. metadata:
  273. name: qbittorrentvpn-restart-serviceaccount
  274. namespace: plex
  275. ---
  276. apiVersion: rbac.authorization.k8s.io/v1
  277. kind: RoleBinding
  278. metadata:
  279. name: qbittorrentvpn-restart-serviceaccount-edit
  280. namespace: plex
  281. roleRef:
  282. apiGroup: rbac.authorization.k8s.io
  283. kind: ClusterRole
  284. name: edit
  285. subjects:
  286. - kind: ServiceAccount
  287. name: qbittorrentvpn-restart-serviceaccount
  288. namespace: plex
  289. # qbit_manage to auto-tag by tracker URL
  290. ---
  291. apiVersion: batch/v1
  292. kind: CronJob
  293. metadata:
  294. name: qbittorrentvpn-manage
  295. namespace: plex
  296. spec:
  297. schedule: "*/10 * * * *"
  298. successfulJobsHistoryLimit: 1
  299. failedJobsHistoryLimit: 1
  300. concurrencyPolicy: Forbid
  301. jobTemplate:
  302. spec:
  303. activeDeadlineSeconds: 60
  304. template:
  305. metadata:
  306. labels:
  307. app: qbittorrentvpn-manage
  308. spec:
  309. restartPolicy: OnFailure
  310. containers:
  311. - name: qbittorrentvpn-manage
  312. image: ghcr.io/stuffanthings/qbit_manage:v4.6.5
  313. command:
  314. - python3
  315. - qbit_manage.py
  316. - "--run"
  317. volumeMounts:
  318. - name: config
  319. mountPath: /config/config.yml
  320. subPath: config.yml
  321. volumes:
  322. - name: config
  323. configMap:
  324. name: qbittorrentvpn-manage-config
  325. configMap:
  326. items:
  327. - key: config.yml
  328. path: config.yml