initial commit: cirrus edge (Talos + sish)
- talos/: generated base config (gitignored) + patches for control-plane scheduling, unprivileged ports and the ingress firewall - kubernetes/: sish base and cirrus-dev overlay, applied with kubectl - READMEs incl. production rollout plan Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
# sish configuration (keys mirror the CLI flags, see `sish --help`).
|
||||
# Cluster-specific values (domain, bind-hosts) are injected as SISH_* env vars
|
||||
# from the `sish-env` ConfigMap in each overlay. Env takes precedence over this file.
|
||||
|
||||
# Listeners
|
||||
ssh-address: ":2222"
|
||||
http-address: ":80"
|
||||
https: false # sish never terminates TLS; :443 is an SNI passthrough listener
|
||||
|
||||
# SNI passthrough + multiple connectors per hostname
|
||||
sni-proxy: true
|
||||
sni-load-balancer: true
|
||||
tcp-load-balancer: true
|
||||
http-load-balancer: true
|
||||
|
||||
# Connectors get exactly what they ask for, or the bind fails
|
||||
bind-random-ports: false
|
||||
bind-random-subdomains: false
|
||||
bind-random-aliases: false
|
||||
force-requested-subdomains: true
|
||||
force-requested-ports: true
|
||||
bind-wildcards: true
|
||||
# Ports connectors may claim. Must match the sish-public rule in
|
||||
# talos/patches/firewall.yaml, otherwise a claimed port is silently unreachable.
|
||||
# 22 gitea ssh, 443 SNI, 20000-20099 reserved for raw tcp forwards.
|
||||
# Ports below 80 also need talos/patches/unprivileged-ports.yaml.
|
||||
port-bind-range: "22,443,20000-20099"
|
||||
|
||||
# PROXY header version for connectors that request it (sish-client default: v2)
|
||||
proxy-protocol: true
|
||||
proxy-protocol-version: "2"
|
||||
|
||||
# Default is 5s, which kills idle websockets/SSE/slow uploads
|
||||
idle-connection-timeout: 1h
|
||||
|
||||
# Auth: public keys only
|
||||
authentication: true
|
||||
authentication-keys-directory: /pubkeys
|
||||
private-keys-directory: /keys
|
||||
|
||||
# No web UI / consoles
|
||||
redirect-root: false
|
||||
admin-console: false
|
||||
service-console: false
|
||||
load-templates: false
|
||||
# Default -1 makes the HTTP muxer io.ReadAll() every request/response body into memory
|
||||
# (for the console), even with consoles disabled: large uploads OOM-kill sish.
|
||||
# 0 = never buffer, stream bodies through.
|
||||
service-console-max-content-length: 0
|
||||
|
||||
log-to-stdout: true
|
||||
log-to-file: false
|
||||
Reference in New Issue
Block a user