Skip to content

Uptime Kuma Deployment Design

Date: 2026-01-24 Issue: selfhosted-cluster-zpx Status: Approved

Deploy Uptime Kuma for external service monitoring and uptime tracking with minimal initial scope.

Uptime Kuma runs as a single-replica Deployment in a dedicated uptime-kuma namespace. It uses an embedded SQLite database stored on a Longhorn PVC for persistence.

ComponentDescription
DeploymentSingle pod running louislam/uptime-kuma:1
ServiceClusterIP exposing port 3001
PVC1Gi Longhorn volume at /app/data
IngressRoutestatus.fzymgc.house with Authentik ForwardAuth
CertificateTLS via cert-manager (Let’s Encrypt)
DecisionChoiceRationale
Monitoring scopeMinimal (3 services)Validate deployment before expanding
StorageLonghorn PVCStandard pattern, Velero backup included
AuthenticationForwardAuth onlySimpler than OIDC, established pattern
NotificationsNone initiallyKeep first deployment simple
argocd/app-configs/uptime-kuma/
├── kustomization.yaml # Kustomize entry point
├── namespace.yaml # uptime-kuma namespace
├── deployment.yaml # Pod spec with SQLite volume
├── service.yaml # ClusterIP on 3001
├── pvc.yaml # 1Gi Longhorn storage
├── certificate.yaml # TLS for status.fzymgc.house
└── ingress.yaml # IngressRoute with ForwardAuth

Configured manually post-deployment:

  1. https://auth.fzymgc.house - Authentik
  2. https://vault.fzymgc.house - Vault UI
  3. https://grafana.fzymgc.house - Grafana
  1. ArgoCD Application added to argocd/cluster-app/
  2. ArgoCD syncs namespace, PVC, deployment, ingress
  3. First access at https://status.fzymgc.house:
    • Authentik ForwardAuth prompts for SSO login
    • Uptime Kuma setup wizard creates local admin account
  4. Configure the 3 initial HTTP monitors manually
  • ForwardAuth via authentik@kubernetescrd middleware
  • No ExternalSecrets needed (admin created via UI)
  • Namespace automatically included in Velero backups
  • Add more service monitors
  • Configure notification channels (Slack, email)
  • Public status page feature