gatus: replace uptime-kuma with declarative config-as-code monitoring #23
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/gatus-replaces-kuma"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Replaces Uptime Kuma with Gatus, which keeps all monitoring config in version control — the whole reason for the swap: kuma stored every monitor in its SQLite DB via the web UI, unreviewable and unreproducible from the flake.
What's in the new
webservices/gatusaspectin.freun.devinternal ones, and the alderaan.space *arr stack), conditions[STATUS] < 500+[CERTIFICATE_EXPIRATION] > 48h, 1m interval.heartbeat.interval = 26h— dead man switches for:automatic-upgrade-<host>for apu/freun-dev/radish/turny/pumpkin (replaces the kuma push tokens;auto-upgradenow pushessuccess=true/falseto/api/v1/endpoints/jobs_automatic-upgrade-<host>/externalwith a per-host bearer token),backupfor radish's borg job (replacesUPTIME_KUMA_TOKENwithGATUS_TOKEN_BACKUP).modules.smtp), reusing grafana'ssmtp_passwordsops key — no duplicate credential. Default alert: failure-threshold 2, send-on-resolved.security.basicwith usernamejokke, bcrypt hash served from sops via env interpolation so it never enters the store. The push API (/api/v1/endpoints/*/external) sits outside basic auth upstream and is token-authenticated.services.webserveron the same vhost as before (status.freun.dev, port 3007).Verified
nix eval ...toplevel.drvPathsucceeds for freun-dev, apu, turny, pumpkin (radish's eval failure — privatetree_huggergithub input — is pre-existing onmain).nix build ...toplevelsucceeds for freun-dev with stubbed secrets; the generatedgatus.yamland unit were inspected (env files attached, tokens interpolated from sops env).⚠ Required before merge (sops rekey, needs your yubikey)
secrets/auto-upgrade.yaml: rename key treekuma-push/<host>→token/upgrade/<host>(same per-host values), and addtoken/backup(copy the value currently insecrets/backup.yamlasUPTIME_KUMA_TOKEN— the backup heartbeat token can literally be the same secret, kuma tokens were just opaque strings).secrets/backup.yaml: replaceUPTIME_KUMA_TOKENwithGATUS_TOKEN_BACKUP(same value is fine).secrets/gatus.yamlwith keybasic_auth_bcrypt: a bcrypt hash (cost ≥ 9) of the dashboard password, base64-encoded after hashing, e.g.: (the fallback creation rule already coverssecrets/gatus.yaml— yubikey + freun-dev age key; add other hosts only if they'll ever need to read it, they don't).Until those land, hosts will fail activation on
sops-install-secrets(verified: missing keys are the only remaining failure).Reverting
Single revert commit restores kuma; the old kuma SQLite state dir (
/var/lib/uptime-kuma) is untouched by this PR, so no monitor data is lost either way.c7a9e60e37f54fe60342f54fe603420a9cf23c4a0a9cf23c4a8bb372ad918bb372ad91e6db2174eaView command line instructions
Checkout
From your project repository, check out a new branch and test the changes.