initial commit: cirrus edge (Talos + sish)

- talos/: generated base config (gitignored) + patches for control-plane
  scheduling, unprivileged ports and the ingress firewall
- kubernetes/: sish base and cirrus-dev overlay, applied with kubectl
- READMEs incl. production rollout plan

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-27 12:16:27 +02:00
co-authored by Claude Opus 5.5
commit 3d3ddc98e9
14 changed files with 487 additions and 0 deletions
+9
View File
@@ -0,0 +1,9 @@
apiVersion: v1
kind: Namespace
metadata:
name: sish
labels:
# hostNetwork is only permitted by the privileged profile.
# The pod itself still runs non-root with all capabilities dropped.
pod-security.kubernetes.io/enforce: privileged
pod-security.kubernetes.io/audit: baseline