cleanup talos

This commit is contained in:
2026-10-06 15:48:50 +02:00
parent d78e570b44
commit 3769647b77
11 changed files with 140 additions and 348 deletions
@@ -1,7 +0,0 @@
# Single node: let workloads (sish) run on the control plane by dropping the
# default control-plane NoSchedule taint.
apiVersion: v1alpha1
kind: KubeNodeConfig
taints:
node-role.kubernetes.io/control-plane:
$patch: delete
-5
View File
@@ -1,5 +0,0 @@
# Single node: no cluster discovery, so no dependency on discovery.talos.dev.
apiVersion: v1alpha1
kind: DiscoveryServiceConfig
name: default
$patch: delete
-61
View File
@@ -1,61 +0,0 @@
# Ingress firewall: block everything that is not listed here. Loopback and
# replies to outgoing connections are always allowed by Talos.
#
# Public TCP ports served by sish must match port-bind-range in
# kubernetes/base/sish/config.yml (plus :80 HTTP and :2222 sish SSH).
# Closed on purpose: flannel VXLAN 4789/udp (single node, unauthenticated),
# etcd 2379-2383, kubelet 10250, kube-proxy 10256, trustd 50001 (only needed
# when other nodes join).
apiVersion: v1alpha1
kind: NetworkDefaultActionConfig
ingress: block
---
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: sish-public
portSelector:
ports:
- 22 # gitea ssh (raw tcp forward)
- 80 # sish http, routed by Host header
- 443 # sish tls, routed by SNI
- 2222 # sish ssh endpoint for connectors (public key auth)
- 20000-20099 # reserved for raw tcp forwards
protocol: tcp
ingress:
- subnet: 0.0.0.0/0
- subnet: ::/0
---
# Talos API (apid) and Kubernetes API, both mTLS / client-cert authenticated
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: talos-and-kube-api
portSelector:
ports:
- 50000
- 6443
protocol: tcp
ingress:
- subnet: 0.0.0.0/0
- subnet: ::/0
---
# CoreDNS forwards to the Talos host DNS (forwardKubeDNSToHost), which pods reach
# on the host, so the pod network needs DNS to the node
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: pod-dns
portSelector:
ports:
- 53
protocol: udp
ingress:
- subnet: 10.244.0.0/16
---
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: pod-dns-tcp
portSelector:
ports:
- 53
protocol: tcp
ingress:
- subnet: 10.244.0.0/16
-5
View File
@@ -1,5 +0,0 @@
# Static hostname instead of the generated auto: stable one.
apiVersion: v1alpha1
kind: HostnameConfig
auto: off
hostname: cirrus-01
-6
View File
@@ -1,6 +0,0 @@
# Lets non-root processes bind ports >= 22, so sish (hostNetwork, uid 65534,
# no capabilities) can listen on :22 (Gitea SSH), :80 and :443.
# The edge runs nothing else that could grab 22-79.
machine:
sysctls:
net.ipv4.ip_unprivileged_port_start: "22"