Services

What actually runs on the cluster, grouped by capability.

Here is everything the cluster runs today, grouped by what it provides. Hostnames use the opi5cluster.co.uk domain. Every group has an overview page, and every service has its own page with configuration and trade-offs. The Discord bots are listed here for completeness; their configuration stays private and they document themselves under Discord Bots.

How a service repo is laid out

Most services live in their own repo and follow the same shape, so once you have read one service you can read them all. A few are different on purpose: the media stack is a single umbrella chart, PostgreSQL vendors its upstream chart, and ArgoCD itself is configuration rather than an application.

{service-name}/
├── Chart.yaml                Chart Metadata and Version
├── values.yaml               Image tag, Database Name, Log level, Resources
├── .gitlab-ci.yml            Hadolint + Multi-arch buildx (linux/amd64, linux/arm64)
├── .helmignore
│
├── app/                      Python source (baked into the image or ConfigMap-injected)
│   ├── {component}/          API or UI or Bot or Any other
│   │   └── {files}.py        e.g. Handlers, background workers
│   └── {component}/          API or UI or Bot or any other
│       └── {files}.py        e.g. Discord commands, moderation rules
├── docker/                   Image build
│   ├── Dockerfile            Base image + uv (no pip) + apk upgrade + non-root uid 1000
│   └── {service}-image.sh    Buildx multi-arch push to registry.opi5cluster.co.uk/{service}:$VERSION + :latest
│
└── templates/                Helm chart (root-level: one Rollout per release)
    ├── rollout.yaml          Argo Rollout: replicas=1, canary 25/50/100 (unused but pinned)
    ├── external-secret.yaml  ESO -> Vault (cluster secret store) for the bot token
    ├── secret-postgres.yaml  ESO -> Vault, builds DATABASE_URL postgresql://...sslmode=require
    ├── service-account.yaml  {{ .Release.Namespace }}-sa
    └── {Other Manifest Files}

Platform & Infrastructure

The plumbing. Most of these exist so everything else can exist.

Service What it does
Cert-manager Issues and renews the wildcard TLS certificate using Cloudflare DNS-01
Cloudflared Publishes services to the internet through an outbound-only tunnel: zero open inbound ports
External Secrets Operator Pulls secrets out of Vault and lays them down as native Kubernetes secrets
Istio The front door and the mesh: Gateway API edge plus ambient mTLS between workloads
Longhorn Replicates block storage across nodes, so a lost disk is not a lost volume
MetalLB Hands out real LAN addresses to services in L2 mode, no cloud load balancer required
Reflector Copies secrets and config maps into the namespaces that need them
Vault Keeps every credential the cluster uses in one audited place
Velero Whole-cluster backups: nightly manifests and PVC data (Kopia) to RustFS running on backup-raspi3, kept 30 days
Zot Private container registry that scans images for known vulnerabilities

GitOps & Delivery

Nothing is deployed by hand. ArgoCD reconciles every application from Git.

Service What it does
ArgoCD Watches Git and keeps the cluster in sync, with health checks and a full sync history
ArgoCD Apps The catalog: one chart that registers every other service with ArgoCD
Argo Events Listens for events (webhooks, schedules, streams) and triggers workflows in response
Argo Rollouts Rolls out new versions gradually, canary or blue-green, instead of all at once
Argo Workflows Runs batch jobs and CI-style pipelines as containerised workflow steps

Observability & Dashboard

Metrics, logs, and one dashboard for everything above.

Service What it does
Homepage One pane of glass for every service in the lab
Loki + Alloy Collects logs from every container with Alloy and keeps them searchable for 14 days
Prometheus + Grafana Scrapes metrics from every workload and graphs them in Grafana, 30-day retention

Data & Streaming

State and streams. The data layer everything else reads and writes.

Service What it does
Apache Flink Processes event streams in real time with stateful, exactly-once pipelines
AutoMQ Kafka with logs on S3-compatible storage: the event backbone every producer and consumer shares
Metabase Query builder and dashboards over the cluster databases, no SQL knowledge required
PostgreSQL (CloudNativePG) PostgreSQL as a primary with replicas, backed up to object storage via the CNPG operator
RustFS S3-compatible object storage that backs Velero, AutoMQ, and the media pipeline

AI Stack

Local inference. No cloud API keys in the request path.

Service What it does
OpenVINO Model Server Self-hosted LLM, embedding, and image models behind an OpenAI-compatible API
Open WebUI ChatGPT-style interface over the local models, with per-user history and presets
Qdrant Vector database powering semantic search and grounding the local models with RAG

Media

A full self-hosted media pipeline, pinned to a single node with local SSD storage.

Service What it does
Bazarr Fetches and syncs subtitles for everything Sonarr and Radarr download
FlareSolverr Solves Cloudflare challenges so Prowlarr can reach protected indexers
Jellyfin Media server that streams the shared library to every screen in the house
Prowlarr Manages the torrent indexers and feeds them to Sonarr, Radarr, and qBittorrent
qBittorrent The download workhorse: pulls torrents to the media NAS and seeds them back
Radarr Watches for movie releases, grabs them, and hands them to the download stack
Seerr Where the household requests films and shows; approvals flow into Radarr and Sonarr
Sonarr Watches for new TV episodes, grabs them, and hands them to the download stack
Tdarr Transcodes and optimises the library so files play efficiently on every device
Whisper Turns audio into text with local speech-to-text models

Decommissioned Services

Services that have run on the cluster in the past. Kept for reference: their configuration is frozen as it last deployed.

Service What it does
Traefik The front door: every inbound HTTP and HTTPS route enters through it via the Gateway API

Discord Bots

Every Blocksensus bot runs on the cluster, deployed the same way as the services above. Bots do not get configuration pages here; each bot documents itself on its own product page instead.

Bot What it does
Beacon Beacon is a Discord events, polls, and notification scheduler. It delivers scheduled embeds, per-guild event boards, and timezone-aware reminders, so important announcements stop getting scrolled past.Polls are defined in simple YAML and can be pinned to any channel, and every delivery is logged and observable from the built-in dashboard.
Bouncer Bouncer is an onboarding and verification concierge. New members get a welcome, a simple reaction-based verification step, and the right roles from the moment they join.Optionally, Bouncer can walk new members through a short guided tour of the server via ephemeral messages. No clutter, no spam.Bouncer keeps per-guild concierge state in PostgreSQL, so a restart never loses track of who has been verified.
Meridian Meridian is a persistent world-clock board for Discord communities. It keeps an auto-refreshing embed in a channel showing the current time across every configured location.Working-hours indicators make it obvious who is awake, event-countdown boards keep launches and raids on schedule, and DST changes are handled automatically, with UTC kept as the central scheduling reference.
Muse Muse keeps a Discord community alive with conversation starters, brain teasers, party games, debates, trivia, and community events.Under the hood, Muse is a multi-tenant engagement engine with 8 Activity providers, plus ratings, badges, streaks, and a Hall of Fame to reward the members who show up.Muse is in private preview. It works, but it is not generally available yet.
Quote My Shizzle Quote My Shizzle turns Discord messages into funny, random, shareable artefacts: posters, headlines, wanted notices, magazine covers, and other chaotic creations.A YAML-template engine drives 10+ layouts with weighted-random selection, reactions are tracked, duplicates are suppressed via PostgreSQL-backed dedup, and servers get a daily digest of their best quotes.
Whistle Whistle delivers live sports updates to Discord, covering football, F1, MMA, NFL and more, from kickoff to the final whistle and beyond.Follow a team and Whistle pins it per server, opens a thread per game, and streams goals, points, and key events as they happen. The producer/consumer/bot pipeline runs on Kafka (AutoMQ) with Avro-encoded events for durability.
WoS-Assistant WoS-Assistant streamlines Whiteout Survival alliance management, automating the day-to-day so officers can focus on the game.It handles gift-code redemption, minister scheduling, SvS participation tracking, and player management. The three-service ecosystem (bot + API + web UI) communicates over Avro events on AutoMQ for durability.WoS-Assistant is private. It is built for a specific alliance.