Kubernetes Namespaces¶
All workloads run on the mdapi-prod cluster (Harvester HCI / RKE2). Namespaces are organized by function.
About envuassu
"En Vuassu" is the name of the neighbourhood where multiple villas jointly own and manage a shared private space. The envuassu namespace hosts the services run for that small community of families (Nextcloud, Zammad ticketing, a dedicated Keycloak at login.envuassu.ch) — it is not an MDAPI-org service. It sits in the Web Hosting group below alongside the other independent web properties, and its identity is fully separate from the MDAPI Keycloak at idp.mdapi.ch.
One namespace is deliberately not listed
A dedicated hosting tenant — an independent party running their own workloads here — has its own namespace, Rancher project, resource quota and network-policy fence. That namespace is not named on this page.
Categories¶
Namespaces grouped by function. The Full Inventory table below lists every namespace with workloads, storage, and ingress.
Platform operators — kube-system (ingress-nginx), longhorn-system, rook-ceph (in-cluster Ceph), cephfs-kmod (DaemonSet compiling the ceph kernel module per kernel, with a cross-node Secret cache), cert-manager, cert-manager-infomaniak (Infomaniak DNS-01 webhook solver, for zones hosted at Infomaniak rather than self-hosted BIND9), metallb-system, external-secrets, external-dns, cnpg-system (CloudNativePG), volsync-system (Ceph PVC backups), keel, reloader (config-change rollouts), descheduler, fleet-*, gitlab-runner-builder (GitLab CI runner for the OpenWrt buildroot workspace), akeyless-pg-bridge (Akeyless↔Postgres secrets bridge), gitlab-agent (GitLab Agent for Kubernetes), etcd-priority (CPU-priority node-tuner DaemonSet, keeps etcd scheduling latency bounded under host load), falco (runtime detection — modern-eBPF DaemonSet, one pod per node, plus falcosidekick), kube-bench (CIS Kubernetes Benchmark, weekly CronJob, one pod per node), rancher-mgmt (in-cluster Rancher management — 3-VM KubeVirt/RKE2 HA trio on Leap Micro, active as primary since 2026-08-10; the external workstation instance it replaced was decommissioned in September 2026, so this is now the only management plane).
Identity & Auth (MDAPI org) — keycloak (idp.mdapi.ch), oauth2-proxy, openldap (LDAP + LAM), openfga (authorization backend for OpenObserve access control), plex-auth (Plex sign-in bridge for membership requests).
Ops / DevOps — bootstrap (GitLab EE), windmill (automation), backlog (beads issue tracker — Dolt SQL canonical DB, API + web UI at backlog.mdapi.ch), monitoring (VictoriaMetrics + Grafana + the alert plane), cattle-monitoring-system (node-exporter + kube-state-metrics remnants of rancher-monitoring), cattle-logging-system (fluent-bit + journald-aggregator DaemonSets, rancher-logging shell), cattle-dashboards (sidecar-provisioned Grafana dashboard ConfigMaps, rancher-monitoring shell), cribl (log streaming), openobserve (logs.mdapi.ch, indexed log search), zot (OCI registry), mirror (package mirror), squid (HTTP proxy), meshcentral (help.mdapi.ch, remote support for family devices), horizon (Evertrust Horizon CLM), horizon-discovery (network cert discovery, horizon-netscan CronJob), evertrust-mcp (Horizon/Stream MCP bridges), stream (Evertrust Stream internal PKI — see Certificates & PKI), ciphertrust (CipherTrust Manager VM, Akeyless customer fragment), openbao (secrets failover plane), paperless-kustodyan (RegData RPS data-protection engine, dedicated to Paperless) + kustodyan-mcp (its MCP bridge), k8s-mcp (Kubernetes MCP server), litellm (LLM API gateway — LiteLLM routing local-first model chains for the automation fleet, llm.mdapi.ch).
Networking / Infrastructure — ntppool (Chrony GPS stratum-1), ntppool-agent (NTP pool monitoring agent), nameserver (BIND9 public DNS), technitium (internal DNS + DHCP), split-horizon (in-cluster unbound split-horizon resolver), opennic (tier-2 resolver), jump (in-cluster jump seat on LB .62, ssh -p443 + mosh), honeypot (Trapeye), certspotter (CT monitor), ups (Network UPS Tools server), snowflake-proxy + webtunnel-bridge (donated-bandwidth Tor relays), transit (internal reverse-proxy layer exposing management UIs — Harvester, Rancher, NAS — through mdapi.ch/tillo.ch ingress), atlas (RIPE Atlas software probe, KubeVirt VM).
Collaboration & Comms — joplin (notes.mdapi.ch), paperless (documents.mdapi.ch, DMS), mail (full mail stack, 131 Gi), znc (IRC bouncer), mqtt (Mosquitto), openwebui (chat.mdapi.ch, household + friends chat UI over the in-cluster litellm gateway, self-hosted SearXNG for web search), bussola (bussola.mdapi.ch, personal budgeting application), formbricks-kustodyan (Formbricks survey platform with Cube analytics and an MCP bridge).
Domotics — home-assistant, appdaemon, esphome, frigate (NVR), scrypted (Nest → RTSP bridge for Frigate), wyoming (local voice pipeline for Home Assistant — Whisper speech-to-text, Piper text-to-speech, openWakeWord), findmy (Find My collector).
Media / TV — tv: 13-service stack (Plex, Sonarr, Radarr, Prowlarr, Bazarr, Tdarr, Autobrr, Seerr, Transmission + PIA, Threadfin, Flaresolverr, SFTPGo, rsync) on CephFS RWX volumes.
Portals — showcase (the public front door at mdapi.ch), portal (the members' portal + self-service marketplace at start.mdapi.ch — the marketplace itself is Windmill flows, not a separate namespace).
Labs — ctf (Kali Linux workstation VM for capture-the-flag practice), macos-vm (macOS VM, QEMU/OpenCore via docker-osx), dsf-lab (vendor-product evaluation VMs).
Web Hosting (independent properties) — spider3 (spider3.ch), coiffuredreams (coiffuredreams.ch), dellambrogio (dellambrogio.ch), ivodellambrogio (ivodellambrogio.ch), nextcloud (household file sync + Talk, cloud.mdapi.ch), envuassu (the En Vuassu neighbourhood community: Nextcloud + Zammad + Keycloak login.envuassu.ch), mdapiorg (permanent redirect: mdapi.org / *.mdapi.org → mdapi.ch), tillo (permanent redirect: tillo.ch / www.tillo.ch → author's LinkedIn profile).
Full Inventory¶
| Namespace | Key Workloads | Storage | Ingress / VIP |
|---|---|---|---|
akeyless-pg-bridge |
Akeyless↔Postgres secrets bridge | — | — |
appdaemon |
AppDaemon (Home Assistant automation engine) | 10Gi | — |
atlas |
RIPE Atlas software probe (KubeVirt VM) | 10Gi | — |
backlog |
beads issue tracker — Dolt sql-server (canonical DB) + bd API / web UI | 5Gi | backlog.mdapi.ch, 192.168.1.63 (SQL) |
bootstrap |
GitLab EE (webservice, sidekiq, toolbox, registry, kas) | Ceph RGW (S3) | gitlab.mdapi.ch |
bussola |
Bussola personal budgeting application (app + narrator service) | 12Gi + 2× 5Gi | bussola.mdapi.ch |
cattle-dashboards |
Sidecar-provisioned Grafana dashboard ConfigMaps (rancher-monitoring shell) | — | — |
cattle-logging-system |
fluent-bit + journald-aggregator DaemonSets (rancher-logging shell) | — | — |
cattle-monitoring-system |
node-exporter + kube-state-metrics (remnants of rancher-monitoring; its Harvester add-on is Fleet-managed) | — | — |
cephfs-kmod |
DaemonSet compiling the ceph kernel module per kernel (cross-node Secret cache) | — | — |
cert-manager |
cert-manager operator | — | — |
cert-manager-infomaniak |
infomaniak-webhook (cert-manager DNS-01 solver for Infomaniak-hosted zones) | — | — |
certspotter |
certspotter (CT log monitor) | 5Gi | — |
ciphertrust |
CipherTrust Manager (KubeVirt VM) — Akeyless customer fragment | 200Gi (RWX) | cm.mdapi.ch |
cnpg-system |
CloudNativePG operator | — | — |
coiffuredreams |
WordPress + MariaDB | 4Gi | coiffuredreams.ch |
cribl |
Cribl Stream | 50Gi | cribl.mdapi.ch |
ctf |
Kali Linux workstation (KubeVirt VM) for capture-the-flag practice | 100Gi | — |
democratic-csi |
NFS + iSCSI CSI drivers (namespace present, driver currently undeployed) | — | — |
descheduler |
Kubernetes descheduler | — | — |
dellambrogio |
WordPress (custom image) | — | dellambrogio.ch |
dsf-lab |
Vendor-product evaluation lab (2 KubeVirt VMs) | 2× 60Gi | — |
envuassu |
Nextcloud AIO + Zammad + Keycloak (neighbourhood community) | 200Gi data + more | cloud.envuassu.ch, suivi.envuassu.ch, login.envuassu.ch |
esphome |
ESPHome | 50Gi | esphome.mdapi.ch |
etcd-priority |
etcd-priority DaemonSet (CPU-priority node tuner, 1 pod/node) | — | — |
evertrust-mcp |
horizon-mcp + stream-mcp (Evertrust Horizon/Stream MCP bridges) | — | horizon-mcp.mdapi.ch, stream-mcp.mdapi.ch |
external-dns |
external-dns (RFC 2136 → Technitium) | — | — |
external-secrets |
External Secrets Operator | — | — |
falco |
Falco runtime detection DaemonSet (modern eBPF, 1 pod/node) + falcosidekick | — | — |
findmy |
Find My collector | 2× 1Gi | — |
formbricks-kustodyan |
Formbricks survey platform + Cube analytics + gateway / hub + MCP bridge | 1Gi + 5Gi | formbricks-kustodyan.mdapi.ch, formbricks-kustodyan-mcp.mdapi.ch |
frigate |
Frigate NVR | 31Gi | frigate.mdapi.ch |
gitlab-agent |
GitLab Agent for Kubernetes (kas) | — | — |
gitlab-runner-builder |
GitLab CI runner (OpenWrt buildroot workspace) | 60Gi | — |
home-assistant |
Home Assistant | PVCs + CNPG recorder (ha-recorder-pg, barman → Ceph RGW) |
home.mdapi.ch |
honeypot |
Trapeye | 20Gi | 192.168.1.45 |
horizon |
Evertrust Horizon (certificate lifecycle management) + MongoDB | 15Gi | horizon.mdapi.ch |
horizon-discovery |
horizon-netscan CronJob (network cert discovery) |
— | — |
horizon-issuer |
Horizon ClusterIssuer controller (cert-manager-style issuer sourced from Horizon) | — | — |
ivodellambrogio |
WordPress + MariaDB | 2Gi | ivodellambrogio.ch |
joplin |
Joplin Server + MCP bridge + Postgres | 5Gi | notes.mdapi.ch |
jump |
In-cluster jump seat (ssh -p443 + mosh) + Guacamole + CNPG Postgres | 8Gi + guac-pg | jump.mdapi.ch, 192.168.1.62 |
k8s-mcp |
Kubernetes MCP server | — | k8s-mcp.mdapi.ch |
keel |
Keel operator (poll every 4h) | — | — |
keycloak |
Keycloak + Postgres (MDAPI org SSO) | 5Gi | idp.mdapi.ch |
kube-bench |
CIS Kubernetes Benchmark CronJob (weekly, 1 pod/node) | — | — |
kube-system |
ingress-nginx | — | 192.168.1.191 |
kustodyan-mcp |
Kustodyan MCP server | — | kustodyan-mcp.mdapi.ch |
litellm |
LiteLLM LLM API gateway (local-first model routing for automations) | — | llm.mdapi.ch |
longhorn-system |
Longhorn controller + UI | — | — |
macos-vm |
macOS Monterey VM (QEMU/OpenCore via docker-osx) | 96Gi + 8Gi | — |
mail |
docker-mailserver + Roundcube + Rspamd + Autoconfig | 131Gi | webmail.mdapi.ch |
mdapiorg |
nginx ingress: permanent redirect mdapi.org/*.mdapi.org → mdapi.ch |
— | mdapi.org, *.mdapi.org |
meshcentral |
MeshCentral (NeDB on Longhorn, single replica) | 20Gi | help.mdapi.ch |
mirror |
Package mirror | 1Ti | mirror.mdapi.ch |
monitoring |
VictoriaMetrics (vmsingle + vmagent + vmalert) + Grafana + blackbox / Pushgateway / statuspage adapter | PVC (500Gi) | grafana.mdapi.ch |
mqtt |
Eclipse Mosquitto | 5Gi | 192.168.1.43 |
nameserver |
BIND9 + Webmin | 1Gi | ns.mdapi.ch, 192.168.1.53 |
nextcloud |
Nextcloud AIO (household file sync + Talk) | 700Gi data + more | cloud.mdapi.ch |
ntppool |
Chrony (GPS PPS, stratum-1) | — | 192.168.1.58 |
ntppool-agent |
NTP pool monitoring agent | 1Gi | — |
oauth2-proxy |
OAuth2 proxy | — | auth.mdapi.ch |
openbao |
OpenBao (secrets failover plane) | 5Gi | — |
openfga |
OpenFGA (OpenObserve access-control backend) + CNPG Postgres openfga-pg (2 instances) |
2Gi pg | — |
openldap |
OpenLDAP + LAM | 10Gi | lam.mdapi.ch, 192.168.1.52 |
opennic |
OpenNIC tier-2 resolver | — | 192.168.1.44 |
openobserve |
OpenObserve (indexed logs, traces, RUM) + OTel and database-monitoring collectors | Ceph RGW (Parquet) + PVC | logs.mdapi.ch |
openwebui |
Open WebUI (chat UI over litellm) + self-hosted SearXNG | PVC | chat.mdapi.ch |
paperless |
Paperless-NGX + CNPG Postgres + Valkey | 100Gi docs + 5Gi pg | documents.mdapi.ch |
paperless-kustodyan |
Kustodyan RPS engine + Valkey cache (dedicated to Paperless) | 10Gi | — |
plex-auth |
Plex sign-in bridge for the public request form | — | plex-auth.mdapi.ch |
portal |
Members' portal + marketplace engine (replaced Lowcoder) | — | start.mdapi.ch |
metallb-system |
MetalLB controller + speaker | — | — |
rancher-mgmt |
Rancher management (KubeVirt VM trio: rancher-mgmt-1/2/3) | 3× 64Gi RWX (leap-micro-62-1replica) |
rancher.mdapi.ch (via transit) |
reloader |
Stakater Reloader (rolls workloads on ConfigMap / Secret change) | — | — |
rook-ceph |
Rook operator + Ceph cluster (20 OSDs, mgr dashboard) | Ceph OSDs on P420i + FusionIO + bay-5 SSDs | ceph.mdapi.ch |
rum-assets |
Self-hosted browser RUM SDK for the public sites | ConfigMap (static) | rum.mdapi.ch |
scrypted |
Scrypted (Google Nest → RTSP bridge for Frigate) | 20Gi | scrypted.mdapi.ch |
showcase |
Static nginx public showcase | ConfigMap (static) | mdapi.ch, www.mdapi.ch |
snowflake-proxy |
Tor Snowflake proxy (donated bandwidth) | — | — |
spider3 |
Joomla + MariaDB | 52Gi | spider3.ch |
split-horizon |
unbound (split-horizon DNS resolver) | — | 192.168.1.1 |
squid |
Squid HTTP/S proxy | — | 192.168.1.50 |
stream |
Evertrust Stream (internal PKI: X.509 + SSH + TSA) + MongoDB | 5Gi | stream.mdapi.ch, crl.mdapi.ch |
technitium |
Technitium DNS + DHCP (primary + secondary) | 7Gi | 192.168.1.54 (DNS), 192.168.1.55 (DHCP) |
tillo |
nginx ingress: permanent redirect tillo.ch/www.tillo.ch → author's LinkedIn profile | — | tillo.ch, www.tillo.ch |
transit |
Reverse-proxy Service+Ingress set (Harvester, Rancher, NAS) | — | harvester.mdapi.ch, rancher.mdapi.ch, santillo.tillo.ch |
tv |
13-service media stack | CephFS RWX (ceph-filesystem) |
*.mdapi.ch per service |
ups |
NUT (Network UPS Tools) server | — | — |
volsync-system |
VolSync operator (Ceph PVC → restic, client-side encrypted to B2) | — | — |
webtunnel-bridge |
Tor WebTunnel bridge | 1Gi | — (unlisted by design) |
windmill |
Windmill + Postgres | 6Gi | windmill.mdapi.ch |
wyoming |
Wyoming voice pipeline for Home Assistant (Whisper, Piper, openWakeWord) | 5Gi | — |
znc |
ZNC IRC bouncer | 2Gi | 192.168.1.51 |
zot |
Zot OCI registry | Ceph RGW (zot-images object-bucket claim) |
zot.mdapi.ch |
TV Namespace — Media Stack¶
The tv namespace runs a full arr-stack for media acquisition and management, sharing ReadWriteMany (RWX) CephFS volumes (via Rook) across all services. The library was migrated off a Longhorn RWX volume onto CephFS.
Plex Live TV / EPG
Operational notes on the Threadfin → Plex XMLTV ingest path — channel mapping, xepg.json editing, and forcing a Plex EPG re-ingest — live on the Plex Live TV / Threadfin EPG page.
| Service | Image | Role |
|---|---|---|
| pms-docker | plexinc/pms-docker | Media server |
| sonarr | linuxserver/sonarr | TV show management |
| radarr | linuxserver/radarr | Movie management |
| prowlarr | linuxserver/prowlarr | Indexer management |
| bazarr | linuxserver/bazarr | Subtitle management |
| tdarr | haveagitgat/tdarr | Transcode automation |
| seerr | ghcr.io/seerr-team/seerr | Request management |
| transmission | transmission + PIA VPN sidecar | Download client |
| autobrr | ghcr.io/autobrr/autobrr | Torrent automation |
| threadfin | custom (registry.mdapi.ch) | IPTV proxy |
| flaresolverr | flaresolverr | Cloudflare bypass |
| sftpgo | drakkan/sftpgo | SFTP/FTP gateway (tv.files.mdapi.ch) |
| rsync | custom (registry.mdapi.ch) | rsync daemon for library transfers |
RWX storage
The media library's RWX volumes are provided by CephFS (the ceph-filesystem storage class, via Rook), which handles concurrent multi-pod access natively. The earlier Longhorn RWX class (harvester-longhorn-2replicas-notmigratable) pinned replicas to fixed nodes to avoid live-migration issues with large RWX volumes; it is no longer used for the media stack.