Services
What actually runs on the cluster, grouped by capability.
Here is everything the cluster runs today, grouped by what it provides.
Hostnames use the opi5cluster.co.uk domain. Every group has an
overview page, and every service has its own page with configuration and trade-offs.
The Discord bots are listed here for completeness; their configuration stays
private and they document themselves under Discord Bots.
How a service repo is laid out
Most services live in their own repo and follow the same shape, so once you have read one service you can read them all. A few are different on purpose: the media stack is a single umbrella chart, PostgreSQL vendors its upstream chart, and ArgoCD itself is configuration rather than an application.
{service-name}/
├── Chart.yaml Chart Metadata and Version
├── values.yaml Image tag, Database Name, Log level, Resources
├── .gitlab-ci.yml Hadolint + Multi-arch buildx (linux/amd64, linux/arm64)
├── .helmignore
│
├── app/ Python source (baked into the image or ConfigMap-injected)
│ ├── {component}/ API or UI or Bot or Any other
│ │ └── {files}.py e.g. Handlers, background workers
│ └── {component}/ API or UI or Bot or any other
│ └── {files}.py e.g. Discord commands, moderation rules
├── docker/ Image build
│ ├── Dockerfile Base image + uv (no pip) + apk upgrade + non-root uid 1000
│ └── {service}-image.sh Buildx multi-arch push to registry.opi5cluster.co.uk/{service}:$VERSION + :latest
│
└── templates/ Helm chart (root-level: one Rollout per release)
├── rollout.yaml Argo Rollout: replicas=1, canary 25/50/100 (unused but pinned)
├── external-secret.yaml ESO -> Vault (cluster secret store) for the bot token
├── secret-postgres.yaml ESO -> Vault, builds DATABASE_URL postgresql://...sslmode=require
├── service-account.yaml {{ .Release.Namespace }}-sa
└── {Other Manifest Files} Platform & Infrastructure
The plumbing. Most of these exist so everything else can exist.
| Service | What it does |
|---|---|
| Cert-manager | Issues and renews the wildcard TLS certificate using Cloudflare DNS-01 |
| Cloudflared | Publishes services to the internet through an outbound-only tunnel: zero open inbound ports |
| External Secrets Operator | Pulls secrets out of Vault and lays them down as native Kubernetes secrets |
| Istio | The front door and the mesh: Gateway API edge plus ambient mTLS between workloads |
| Longhorn | Replicates block storage across nodes, so a lost disk is not a lost volume |
| MetalLB | Hands out real LAN addresses to services in L2 mode, no cloud load balancer required |
| Reflector | Copies secrets and config maps into the namespaces that need them |
| Vault | Keeps every credential the cluster uses in one audited place |
| Velero | Whole-cluster backups: nightly manifests and PVC data (Kopia) to RustFS running on backup-raspi3, kept 30 days |
| Zot | Private container registry that scans images for known vulnerabilities |
GitOps & Delivery
Nothing is deployed by hand. ArgoCD reconciles every application from Git.
| Service | What it does |
|---|---|
| ArgoCD | Watches Git and keeps the cluster in sync, with health checks and a full sync history |
| ArgoCD Apps | The catalog: one chart that registers every other service with ArgoCD |
| Argo Events | Listens for events (webhooks, schedules, streams) and triggers workflows in response |
| Argo Rollouts | Rolls out new versions gradually, canary or blue-green, instead of all at once |
| Argo Workflows | Runs batch jobs and CI-style pipelines as containerised workflow steps |
Observability & Dashboard
Metrics, logs, and one dashboard for everything above.
| Service | What it does |
|---|---|
| Homepage | One pane of glass for every service in the lab |
| Loki + Alloy | Collects logs from every container with Alloy and keeps them searchable for 14 days |
| Prometheus + Grafana | Scrapes metrics from every workload and graphs them in Grafana, 30-day retention |
Data & Streaming
State and streams. The data layer everything else reads and writes.
| Service | What it does |
|---|---|
| Apache Flink | Processes event streams in real time with stateful, exactly-once pipelines |
| AutoMQ | Kafka with logs on S3-compatible storage: the event backbone every producer and consumer shares |
| Metabase | Query builder and dashboards over the cluster databases, no SQL knowledge required |
| PostgreSQL (CloudNativePG) | PostgreSQL as a primary with replicas, backed up to object storage via the CNPG operator |
| RustFS | S3-compatible object storage that backs Velero, AutoMQ, and the media pipeline |
AI Stack
Local inference. No cloud API keys in the request path.
| Service | What it does |
|---|---|
| OpenVINO Model Server | Self-hosted LLM, embedding, and image models behind an OpenAI-compatible API |
| Open WebUI | ChatGPT-style interface over the local models, with per-user history and presets |
| Qdrant | Vector database powering semantic search and grounding the local models with RAG |
Media
A full self-hosted media pipeline, pinned to a single node with local SSD storage.
| Service | What it does |
|---|---|
| Bazarr | Fetches and syncs subtitles for everything Sonarr and Radarr download |
| FlareSolverr | Solves Cloudflare challenges so Prowlarr can reach protected indexers |
| Jellyfin | Media server that streams the shared library to every screen in the house |
| Prowlarr | Manages the torrent indexers and feeds them to Sonarr, Radarr, and qBittorrent |
| qBittorrent | The download workhorse: pulls torrents to the media NAS and seeds them back |
| Radarr | Watches for movie releases, grabs them, and hands them to the download stack |
| Seerr | Where the household requests films and shows; approvals flow into Radarr and Sonarr |
| Sonarr | Watches for new TV episodes, grabs them, and hands them to the download stack |
| Tdarr | Transcodes and optimises the library so files play efficiently on every device |
| Whisper | Turns audio into text with local speech-to-text models |
Decommissioned Services
Services that have run on the cluster in the past. Kept for reference: their configuration is frozen as it last deployed.
| Service | What it does |
|---|---|
| Traefik | The front door: every inbound HTTP and HTTPS route enters through it via the Gateway API |
Discord Bots
Every Blocksensus bot runs on the cluster, deployed the same way as the services above. Bots do not get configuration pages here; each bot documents itself on its own product page instead.
| Bot | What it does |
|---|---|
| Beacon | Beacon is a Discord events, polls, and notification scheduler. It delivers scheduled embeds, per-guild event boards, and timezone-aware reminders, so important announcements stop getting scrolled past.Polls are defined in simple YAML and can be pinned to any channel, and every delivery is logged and observable from the built-in dashboard. |
| Bouncer | Bouncer is an onboarding and verification concierge. New members get a welcome, a simple reaction-based verification step, and the right roles from the moment they join.Optionally, Bouncer can walk new members through a short guided tour of the server via ephemeral messages. No clutter, no spam.Bouncer keeps per-guild concierge state in PostgreSQL, so a restart never loses track of who has been verified. |
| Meridian | Meridian is a persistent world-clock board for Discord communities. It keeps an auto-refreshing embed in a channel showing the current time across every configured location.Working-hours indicators make it obvious who is awake, event-countdown boards keep launches and raids on schedule, and DST changes are handled automatically, with UTC kept as the central scheduling reference. |
| Muse | Muse keeps a Discord community alive with conversation starters, brain teasers, party games, debates, trivia, and community events.Under the hood, Muse is a multi-tenant engagement engine with 8 Activity providers, plus ratings, badges, streaks, and a Hall of Fame to reward the members who show up.Muse is in private preview. It works, but it is not generally available yet. |
| Quote My Shizzle | Quote My Shizzle turns Discord messages into funny, random, shareable artefacts: posters, headlines, wanted notices, magazine covers, and other chaotic creations.A YAML-template engine drives 10+ layouts with weighted-random selection, reactions are tracked, duplicates are suppressed via PostgreSQL-backed dedup, and servers get a daily digest of their best quotes. |
| Whistle | Whistle delivers live sports updates to Discord, covering football, F1, MMA, NFL and more, from kickoff to the final whistle and beyond.Follow a team and Whistle pins it per server, opens a thread per game, and streams goals, points, and key events as they happen. The producer/consumer/bot pipeline runs on Kafka (AutoMQ) with Avro-encoded events for durability. |
| WoS-Assistant | WoS-Assistant streamlines Whiteout Survival alliance management, automating the day-to-day so officers can focus on the game.It handles gift-code redemption, minister scheduling, SvS participation tracking, and player management. The three-service ecosystem (bot + API + web UI) communicates over Avro events on AutoMQ for durability.WoS-Assistant is private. It is built for a specific alliance. |