initial commit: cirrus edge (Talos + sish)
- talos/: generated base config (gitignored) + patches for control-plane scheduling, unprivileged ports and the ingress firewall - kubernetes/: sish base and cirrus-dev overlay, applied with kubectl - READMEs incl. production rollout plan Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
# Single node: let workloads (sish) run on the control plane by dropping the
|
||||
# default control-plane NoSchedule taint.
|
||||
apiVersion: v1alpha1
|
||||
kind: KubeNodeConfig
|
||||
taints:
|
||||
node-role.kubernetes.io/control-plane:
|
||||
$patch: delete
|
||||
@@ -0,0 +1,61 @@
|
||||
# Ingress firewall: block everything that is not listed here. Loopback and
|
||||
# replies to outgoing connections are always allowed by Talos.
|
||||
#
|
||||
# Public TCP ports served by sish must match port-bind-range in
|
||||
# kubernetes/base/sish/config.yml (plus :80 HTTP and :2222 sish SSH).
|
||||
# Closed on purpose: flannel VXLAN 4789/udp (single node, unauthenticated),
|
||||
# etcd 2379-2383, kubelet 10250, kube-proxy 10256, trustd 50001 (only needed
|
||||
# when other nodes join).
|
||||
apiVersion: v1alpha1
|
||||
kind: NetworkDefaultActionConfig
|
||||
ingress: block
|
||||
---
|
||||
apiVersion: v1alpha1
|
||||
kind: NetworkRuleConfig
|
||||
name: sish-public
|
||||
portSelector:
|
||||
ports:
|
||||
- 22 # gitea ssh (raw tcp forward)
|
||||
- 80 # sish http, routed by Host header
|
||||
- 443 # sish tls, routed by SNI
|
||||
- 2222 # sish ssh endpoint for connectors (public key auth)
|
||||
- 20000-20099 # reserved for raw tcp forwards
|
||||
protocol: tcp
|
||||
ingress:
|
||||
- subnet: 0.0.0.0/0
|
||||
- subnet: ::/0
|
||||
---
|
||||
# Talos API (apid) and Kubernetes API, both mTLS / client-cert authenticated
|
||||
apiVersion: v1alpha1
|
||||
kind: NetworkRuleConfig
|
||||
name: talos-and-kube-api
|
||||
portSelector:
|
||||
ports:
|
||||
- 50000
|
||||
- 6443
|
||||
protocol: tcp
|
||||
ingress:
|
||||
- subnet: 0.0.0.0/0
|
||||
- subnet: ::/0
|
||||
---
|
||||
# CoreDNS forwards to the Talos host DNS (forwardKubeDNSToHost), which pods reach
|
||||
# on the host, so the pod network needs DNS to the node
|
||||
apiVersion: v1alpha1
|
||||
kind: NetworkRuleConfig
|
||||
name: pod-dns
|
||||
portSelector:
|
||||
ports:
|
||||
- 53
|
||||
protocol: udp
|
||||
ingress:
|
||||
- subnet: 10.244.0.0/16
|
||||
---
|
||||
apiVersion: v1alpha1
|
||||
kind: NetworkRuleConfig
|
||||
name: pod-dns-tcp
|
||||
portSelector:
|
||||
ports:
|
||||
- 53
|
||||
protocol: tcp
|
||||
ingress:
|
||||
- subnet: 10.244.0.0/16
|
||||
@@ -0,0 +1,6 @@
|
||||
# Lets non-root processes bind ports >= 22, so sish (hostNetwork, uid 65534,
|
||||
# no capabilities) can listen on :22 (Gitea SSH), :80 and :443.
|
||||
# The edge runs nothing else that could grab 22-79.
|
||||
machine:
|
||||
sysctls:
|
||||
net.ipv4.ip_unprivileged_port_start: "22"
|
||||
Reference in New Issue
Block a user