initial commit: cirrus edge (Talos + sish)

- talos/: generated base config (gitignored) + patches for control-plane
  scheduling, unprivileged ports and the ingress firewall
- kubernetes/: sish base and cirrus-dev overlay, applied with kubectl
- READMEs incl. production rollout plan

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-27 12:16:27 +02:00
co-authored by Claude Opus 5.5
commit 3d3ddc98e9
14 changed files with 487 additions and 0 deletions
+23
View File
@@ -0,0 +1,23 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: sish
resources:
- ../base/sish
configMapGenerator:
- name: sish-env
literals:
# .test is a reserved TLD: fine for dev, replace with real domains on the edge.
- SISH_DOMAIN=tunnel.cirrus.test
# Parents a connector may bind under (exact match on everything after the first label).
# "sto" allows cirrus.sto itself (and any <name>.sto); "cirrus.sto" allows <name>.cirrus.sto
- SISH_BIND_HOSTS=cirrus.test,apps.cirrus.test,sto,cirrus.sto
- name: sish-pubkeys
files:
- pubkeys/connector-dev.pub
- pubkeys/connector-hello.pub
secretGenerator:
# Edge SSH host key (connectors pin its public half). Kept only locally in
# .secrets/ (gitignored), so back it up outside this folder.
- name: sish-hostkey
files:
- ssh_host_ed25519_key=.secrets/ssh_host_ed25519_key
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOHcrMOuL1K6TPPprZi/W3N29SBRN23pAGmxp3SfQ6qr connector-dev
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINZ1rT2t5rUS3tJesxzY7HogcBRCvzMT8HF+xNddV7e1 connector-hello