Note
This is a sanitized, public fork of a private GitOps repository hosted on an on-prem Git remote. Secrets, internal hostnames/IPs, and environment-specific values have been scrubbed or replaced with placeholders. Some history/commits may be squashed or redacted - I'm also unlikely to update it frequently.
A GitOps-based home infrastructure management system using K3s, ArgoCD, and Docker Compose.
This repository contains configuration and deployment code for managing home infrastructure services. Services are deployed using:
- Kubernetes (K3s): Lightweight Kubernetes for containerized services
- MetalLB: LoadBalancer implementation for bare-metal Kubernetes
- ArgoCD: GitOps-based continuous deployment
- Longhorn: Optional distributed block storage
- 1Password Connect: Secrets sourced from 1Password instead of committed to Git
- Docker Compose: For simpler services that don't need Kubernetes
home-gitops/
├── docs/ # Detailed documentation
├── infrastructure/ # Core infrastructure setup
│ ├── k3s/ # K3s cluster installation
│ ├── metallb/ # MetalLB LoadBalancer
│ ├── argocd/ # ArgoCD installation
│ ├── longhorn/ # Optional distributed storage
│ ├── storage/ # NFS/storage class configs
│ ├── 1password/ # 1Password Connect for secrets
│ ├── traefik-extra/ # Extra Traefik IngressRoutes
│ └── rockchip-npu-device-plugin/ # NPU device plugin (RK1/rockchip nodes)
├── kubernetes/
│ ├── apps/ # Helm charts for all services
│ ├── argocd-apps/ # ArgoCD Application definitions
│ └── resources/ # Shared cluster resources (namespaces, etc.)
├── docker/ # Docker Compose services
├── images/ # Custom Docker images
├── scripts/ # Automation scripts
├── skills/ # Agent/automation skill definitions (e.g. scaffolding new apps)
├── utility/ # One-off tooling, migration helpers, test manifests
└── to_port/ # Manifests staged for migration into kubernetes/apps
- Linux server (Ubuntu 20.04+ recommended)
- Minimum 4GB RAM, 2 CPU cores
- 50GB+ storage
- sudo/root access
-
Clone this repository:
git clone <your-repo-url> cd home-gitops
-
Run the setup script:
sudo ./scripts/setup-cluster.sh
Optional: Install with Longhorn distributed storage:
sudo ./scripts/setup-cluster.sh --with-longhorn
-
This will:
- Install K3s
- Install MetalLB for LoadBalancer services
- Optionally install Longhorn distributed storage
- Deploy ArgoCD
- Create all Kubernetes applications
-
Access ArgoCD to monitor deployments:
kubectl port-forward svc/argocd-server -n argocd 8080:443
Visit https://localhost:8080
-
Configure environment files:
cp docker/emby/.env.example docker/emby/.env # Edit .env files as needed -
Deploy services:
./scripts/deploy-docker-services.sh
Each service is a Helm chart deployed via an ArgoCD Application (kubernetes/argocd-apps/).
| Category | Services |
|---|---|
| Networking / Ingress | adguard-home, adguard-home-sync, nginx-proxy-manager, nginx-test, cloudflared-tunnel, error-pages |
| Media | audiobookshelf, tronbyt-server, emby-exporter, qbittorrent-exporter |
| Home / Personal | home-assistant, homepage, homelable, actual-budget, mealie |
| AI / LLM | openwebui, anythingllm, litellm, firecrawl, camofox, searxng, rk-llama.cpp-server, rockllama |
| Dev Tooling | onedev, jenkins, docker-registry |
| Documents / Productivity | paperless-ngx, stirling-pdf, overleaf |
| Monitoring / Observability | app-monitoring (Prometheus + Grafana), gatus |
| Games | minecraft |
| Service | Description |
|---|---|
| emby | Media server |
| paperless-ngx | Document management (compose-only variant) |
| mealie | Recipe manager (compose-only variant) |
| scanner-pi | Document scanning helper running on a Raspberry Pi |
| Component | Path | Purpose |
|---|---|---|
| K3s | infrastructure/k3s/ |
Lightweight Kubernetes distribution |
| MetalLB | infrastructure/metallb/ |
Bare-metal LoadBalancer |
| ArgoCD | infrastructure/argocd/ |
GitOps continuous deployment |
| Longhorn | infrastructure/longhorn/ |
Optional distributed block storage |
| Storage | infrastructure/storage/ |
NFS and StorageClass configuration |
| 1Password Connect | infrastructure/1password/ |
Secrets management integration |
| Traefik Extra | infrastructure/traefik-extra/ |
Additional IngressRoutes for the built-in Traefik |
| Rockchip NPU Device Plugin | infrastructure/rockchip-npu-device-plugin/ |
Exposes RK1/rockchip NPU hardware to Kubernetes |
- Edit the Helm chart values in
kubernetes/apps/<service>/values.yaml - Commit and push changes
- ArgoCD will automatically sync (or sync manually via UI)
- Create Helm chart in
kubernetes/apps/<service>/ - Create ArgoCD Application in
kubernetes/argocd-apps/<service>.yaml - Commit and push
- Apply the Application:
kubectl apply -f kubernetes/argocd-apps/<service>.yaml
See skills/new-k8s-app/SKILL.md for a guided scaffold of the chart + Application boilerplate.
Secrets are sourced from 1Password via the Connect server in infrastructure/1password/ rather than committed to Git. See individual service documentation for specific secret requirements.
Services use different storage backends:
- HostPath: Local storage on cluster nodes (
/mnt/data/) - NFS: Network storage (
nas-alpha.example.net) - Longhorn (optional): Distributed block storage with replication and snapshots
For high availability and advanced features, install Longhorn:
# During cluster setup
sudo ./scripts/setup-cluster.sh --with-longhorn
# Or install separately
cd infrastructure/longhorn
./install.shBenefits:
- Automatic data replication across nodes
- Volume snapshots and backups
- Web UI for management
- Dynamic volume provisioning
Access Longhorn UI:
kubectl port-forward -n longhorn-system svc/longhorn-frontend 8000:80Visit: http://localhost:8000
See infrastructure/longhorn/README.md for detailed documentation.
Configure storage paths in each service's values.yaml.
Backup configurations and secrets:
./scripts/backup-configs.shBackups are saved to backups/<timestamp>/
Services are automatically updated by ArgoCD when you push changes to git.
Manual sync:
argocd app sync <service-name>Kubernetes services:
kubectl logs -n <namespace> -l app=<service> -fDocker services:
docker compose -f docker/<service>/docker-compose.yaml logs -fkubectl get nodes
kubectl get pods --all-namespaces
kubectl get applications -n argocdutility/— one-off migration helpers, test manifests, and scratch tooling not part of the steady-state GitOps flow (e.g.pvc-copy/,rk1dev/,1password-test/).to_port/— manifests for services awaiting conversion into proper Helm charts underkubernetes/apps/.
- Setup Guide - Detailed setup instructions
- Services - Service-specific documentation
- Architecture - System architecture overview
- Migration Guide - Notes on the move to the GitOps layout
- Changelog - Notable changes to this repository
Custom Docker images are built from images/:
cd images/minecraft-mscs
./build.sh
docker push nmcglo/minecraft-mscs:v0.1When making changes:
- Test locally first
- Update documentation if needed
- Commit with clear messages
- Push to trigger ArgoCD sync
Personal home infrastructure - use at your own risk.