A collection of Argo CD Applications and ApplicationSets to deploy common FOSS building blocks and web applications. Many are in a "smol-app" format and heavily used in smol-k8s-lab.
  • Go Template 57.4%
  • CSS 37.3%
  • Shell 5.3%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-30 21:03:58 +02:00
.forgejo clean up renovate 2026-08-16 14:57:57 +02:00
alloy Merge pull request 'Update Helm release kube-state-metrics to v8.5.0' (#79) from renovate/kube-state-metrics-8.x into main 2026-09-20 20:19:06 +00:00
argocd Update Helm release argo-cd to v10.9.2 2026-09-21 12:56:17 +00:00
autoscaler use master branch instead of main :( 2026-06-28 12:04:19 +02:00
cert-manager Update Helm release cert-manager to v1.21.2 2026-09-12 12:55:54 +00:00
cilium Update Helm release cilium to v1.20.2 2026-09-16 12:55:56 +00:00
collabora_online Update Helm release collabora-online to v1.3.5 2026-09-25 12:56:18 +00:00
coturn cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
crowdsec add crowdsec jobs 2026-09-30 21:03:58 +02:00
demo Update ghcr.io/element-hq/ess-helm/matrix-stack Docker tag to v26.9.4 2026-09-30 12:56:19 +00:00
external-secrets-operator Update Helm release external-secrets to v2.11.0 2026-09-22 12:56:35 +00:00
forgejo Update code.forgejo.org/forgejo-helm/forgejo Docker tag to v17.1.7 2026-09-18 12:58:34 +00:00
funkwhale Update Helm release funkwhale to v0.18.2 2026-09-26 12:56:48 +00:00
generic-app Update Helm release generic-app to v0.2.0 2026-06-24 08:03:05 +00:00
generic-device-plugin cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
ghost Update Helm release ghost to v2.28.0 2026-09-15 12:56:05 +00:00
gotosocial don't need to link existing groups anymore 2026-09-28 17:21:31 +02:00
grafana_stack Update ghcr.io/grafana-community/helm-charts/grafana Docker tag to v13.2.7 2026-09-29 12:56:20 +00:00
harbor Merge pull request 'Update Helm release valkey to v0.12.0' (#69) from renovate/valkey-0.x into main 2026-09-13 16:34:39 +00:00
headscale Update Helm release headscale to v0.5.4 2026-09-25 12:56:24 +00:00
home-assistant Update Helm release home-assistant to v2.7.3 2026-09-26 12:56:54 +00:00
ingress-nginx cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
invoice-ninja Update Helm release valkey to v0.12.0 2026-09-08 08:20:51 +00:00
jellyfin even less default backups 2026-09-29 09:52:34 +02:00
k8tz cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
k8up Update Helm release k8up to v4.10.0 2026-07-21 12:56:39 +00:00
k8up_backups_helm_chart update all helm docs and clean up home assitant namespace stuff 2026-06-11 10:25:16 +02:00
kubevirt bump kubevirt stack version 2026-09-05 20:31:19 +00:00
kyverno Update Helm release kyverno to v3.9.1 2026-09-10 12:56:12 +00:00
libretranslate update libretranslate limits 2026-09-20 15:10:37 +02:00
longhorn cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
mastodon Update Helm release mastodon to v14 2026-09-22 13:04:02 +00:00
matrix Update Helm release cnpg-cluster-certs to v2.1.0 2026-09-08 09:06:52 +00:00
metallb Merge pull request 'Update Helm release metallb to v0.16.1' (#8) from renovate/metallb-0.x into main 2026-09-13 16:32:45 +00:00
mysql/operators cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
nextcloud fix which stuff we update 2026-09-30 10:56:02 +02:00
nvidia_device_plugin Update Helm release nvidia-device-plugin to v0.20.1 2026-09-27 12:56:23 +00:00
openbao Update Helm release openbao to v0.29.5 2026-09-21 12:56:20 +00:00
peertube Update Helm release peertube to v3 2026-09-22 13:04:02 +00:00
postgres Update ghcr.io/cloudnative-pg/charts/cloudnative-pg Docker tag to v0.29.1 2026-09-24 12:56:27 +00:00
renovate Update Helm release renovate to v46.311.3 2026-09-21 12:56:47 +00:00
s3-httproutes update all the helm-docs and add openbao.probes for openbao smol-app 2026-07-21 11:29:12 +02:00
s3_bucket_ingresses don't hardcode s3 ingresses to peertube 2025-01-17 22:36:30 +01:00
s3_persistence_and_backups clean up values 2026-01-30 21:33:16 +01:00
scripts remove more ./ from scripts 2024-12-15 17:44:11 +01:00
seaweedfs Update Helm release seaweedfs-csi-driver to v0.2.38 2026-09-15 12:55:47 +00:00
slink cleaning up more new org and repos 2026-09-08 10:55:26 +02:00
snapshot-controller/smol-app Update Helm release snapshot-controller to v5.3.0 2026-09-22 12:56:42 +00:00
traefik update crowdsec toggle 2026-09-29 13:08:44 +02:00
valkey update valkey directory again 2026-09-08 14:37:23 +02:00
velero Update Helm release velero to v12.2.0 2026-09-22 12:56:46 +00:00
writefreely clean up writefreely labels and seaweedfs naming 2026-08-22 11:26:20 +02:00
zitadel Fix zitadel backup bucket name 2026-09-13 12:47:22 +00:00
.gitignore update gitignore 2024-03-23 10:45:54 +01:00
AI_POLICY.md fix funkwhale docs and ai policy 2026-08-25 16:05:41 +02:00
badargoart_small.png add bad argocd art directly to repo 2024-07-07 14:26:06 +02:00
CODEOWNERS Update CODEOWNERS - add valkey for cloudymax 2024-07-25 20:24:53 +02:00
CONTRIBUTING.md update more github.com to codeberg.org 2026-06-24 08:53:59 +02:00
LICENSE initial recommit 2023-07-01 14:35:38 +02:00
README.md update valkey directory again 2026-09-08 14:37:23 +02:00
renovate.json update renovate config to match new suggestions from renovate 2026-06-21 11:05:16 +02:00

Shared Argo CD templates for self hosted infra

A collection of Argo CD templates for deploying helm apps or directories of Kubernetes (k8s) manifests as Argo CD apps. We're still working on full stability, but please feel free to ask questions or make suggestions 🧡

These Argo CD apps were originally designed to be compatible with smol-k8s-lab, but they can be used anywhere :)

Note

This repo is also mirrored to https://codeberg.org/open-engineering/argocd-apps

Core Tenants

Here's some quick guidelines, but you if you'd like to contribute, please read the full contributing guidelines here 😃!

  • Follow a base schema for all our files and directories so that we can easily make more of them faster.

  • Make secure as we go to avoid the dreaded all-at-once security pass (but we may have missed something, in which case, please let us know).

  • Be kind and if something doesn't work as it should, try to fix the upstream repo before introducing a good-enough fix here.

  • NEVER FORGET THE BACKUPS. DO YOU REMEMBER WHAT HAPPENED LAST TIME WE DIDN'T HAVE THIS RULE? 😭

All Apps

Continuous Deployment

App Directory Description
argocd The one, the only, Argo CD is used for declarative continuous delivery to Kubernetes with a fully-loaded UI. This actually deploys all the other apps and manages itself too :3

Chat

App Directory Description
coturn TURN/STUN server for connecting VoIP peers
matrix matrix is a selfhosted chat server that plugs into a bunch of other chat apps

Experimental

App Directory Description
element server suite community edition ESS is the official Element HQ maintained matrix stack, but it's a little behind on things like support for gateway API, so we don't recommend it at this time.

Backups

App Directory Description
k8up K8up is a k8s native backups done via restic, so you can sync your persistent volumes to external s3 compliant storage
velero Verlo is a k8s native backups done via restic, so you can sync your persistent volumes (and volumeSnapshots) to external s3 compliant storage

Database and Key Value Stores

MySQL

App Directory Description
mysql-operator MySQL database management operator to spin up MySQL clusters, and create backups
percona-pxc-operator MySQL database management operator to spin up MySQL clusters, and create backups

PostgreSQL

App Directory Description
cloud-native-postgres PostgreSQL database management operator to spin up postgres instances, collect metrics, and create backups

Valkey

App Directory Description
Valkey Bitnami Valkey helm chart on k8s. Valkey is a more FOSS alternative to Redis.
Valkey Cluster Bitnami Valkey Cluster helm chart on k8s. Valkey is a more FOSS alternative to Redis Cluster.
Valkey Operator Valkey Operator helm chart on k8s. Valkey is a more FOSS alternative to Redis Cluster.

File Storage

App Directory Description
Collabora Online Collabora Online is a powerful online document editing suite
harbor Container Registry and OCI artifact store with built-in vulernability scanning via Trivy
nextcloud Nextcloud is a self hosted file storage cloud solution. Replaces something like google drive/photos/notes/meets/calendar - mostly stable
Volume Snapshot Controller Volume Snapshot Controller for taking snapshots of PVCs

Multi-media

App Directory Description
funkwhale Funkwhale is kind of like a self hosted spotify. It specializes in audio.
jellyfin Jellyfin is a home media storage and viewing web app. It specializes in video.

S3 Compatible

App Directory Description
SeaweedFS SeaweedFS is a secure and very fast self hosted S3 compatible Object Store specialized for either many files or large files

Experimental

App Directory Description
garage Garage is a self hosted S3 compatible Object Store
longhorn Longhorn is a lightweight, reliable and easy-to-use distributed block storage system for Kubernetes. (not currently actively in development)

Identity Providers and SSO

App Directory Description
zitadel helm chart for Zitadel, an Identity Access Management tool with built in OpenIDConnect for authenticating to self hosted apps. Recommended over keycloak.

Experimental

App Directory Description
keycloak helm chart for Keycloak, an Identity Access Management tool with built in OpenIDConnect for authenticating to self hosted apps
oauth2-proxy Oauth2 proxy that works with Google, however we're testing a keycloak provider right now
vouch-proxy helm chart for Vouch, an OAuth2 proxy that allows you to use ingress-nginx annotations to connect to a third party identity provider, giving you proper auth on websites that don't have auth. Currently works with the zitadel provider in this template, but also known to work with keycloak, google, and github. Deprecated as we don't use ingress-nginx anymore.

Monitoring

The main thing we deploy is the Grafana Stack which includes:

  • Mimir
  • Loki
  • Tempo
  • Grafana

We also offer optional Tempo for telemetry.

App Directory Description
grafana_stack Alloy, Mimir, Loki, Grafana for collecting metrics for monitoring/alerting, and dashboards/charts
prometheus-push-gateway Installs the Prometheus Push Gateway which enables pushing metrics from jobs that would be difficult or impossible to scrape

Experimental

App Directory Description
kepler helm chart for Kepler, (Kubernetes-based Efficient Power Level Exporter), which uses eBPF to probe performance counters and other system stats, use ML models to estimate workload energy consumption based on these stats, and exports them as Prometheus metrics.
tempo Tempo for collecting telemetry and exposing it through Grafana. Useful for supporting developers who make heavy use of tracing.

Networking

App Directory Description
metallb A helm chart for metallb which will let you manager your own ip address pool for use with ingress

Ingress

App Directory Description
cert-manager helm chart for cert-manager, for providing TLS certificates based on nginx ingress annotations
cilium A helm chart for cilium, for transparently securing network connectivity/loadbalancing b/w app workloads such as app containers or processes
ingress-nginx helm chart for ingress-nginx, an nginx ingress controller to allow external traffic to the cluster (now Deprecated and slowly being phased out in favor of traefik)
traefik helm chart for traefik, an ingress controller to allow external traffic to the cluster

VPN

App Directory Description
headscale VPN, there isn't an official helm chart, so we're still working on this
wireguard A helm chart for wg-access-server which uses Wireguard®️ for a VPN

Other

Other useful tools that don't fit neatly into any one category.

Experimental

App Directory Description
k8tz A helm chart for k8tz, to inject timezone info into cronjob pods
LibreTranslate A helm chart for LibreTranslate, to self host a translation tool

Security

App Directory Description
kyverno Kubernetes-native policy management

Experimental

App Directory Description
opa Open Policy Agent Gatekeeper

Secrets Management

App Directory Description
external-secrets-operator ESO (External Secrets Operator) used for sourcing k8s secrets from an external provider
bitwarden-external-secrets ESO Bitwarden SecretStore, for using secrets directly from bitwarden items. This is slowly being deprecated as Bitwarden changes their business model.
openbao OpenBao is an open source secrets management solution forked from Vault and supported by the Linux Foundation. It works great with ESO.

Experimental

App Directory Description
infisical Infisical is an open source secrets management solution and it has a k8s secrets operator.

Social Media

App Directory Description
ghost Ghost is a selfhosted blogging platform.
gotosocial GoToSocial is a selfhosted social media site, includes postgresql. Advertised as lighter weight in requirements than Mastodon.
mastodon Mastodon is a selfhosted social media site, includes postgresql, elastic search (for full text searching), and valkey (in memory caching)
peertube PeerTube is a selfhosted video hosting website that acts a replacement for YouTube. This app of apps includes postgresql, valkey, and S3 (via SeaweedFS).
writefreely WriteFreely is a slim selfhosted blogging platform.

Virtual Machines

App Directory Description
kubevirt KubeVirt is a virtual machine management add-on for Kubernetes.

Experimental

App Directory Description
Nvidia GPU Operator The GPU Operator allows administrators of Kubernetes clusters to manage GPU nodes

Troubleshooting Tips

  • Namespace stuck in terminating state

    kubectl get namespace "<NAMESPACE>" -o json   | tr -d "\n" | sed "s/\"finalizers\": \[[^]]\+\]/\"finalizers\": []/"   | kubectl replace --raw /api/v1/<NAMESPACE>/cdi/finalize -f -
    
  • Find all items in a namespace

    kubectl api-resources --verbs=list --namespaced -o name   | xargs -n 1 kubectl get --show-kind --ignore-not-found -n <NAMESPACE>
    
  • be sure to check for and remove Mutatingwebhookconfiguration and Validatingwebhookconfiguration

  • Patching a resource you found via the Xargs search

    kubectl patch <CLASS>/<NAME>-p '{"metadata":{"finalizers":[]}}' --type=merge -n <NAMESPACE>