initial commit: cirrus edge (Talos + sish)

- talos/: generated base config (gitignored) + patches for control-plane
  scheduling, unprivileged ports and the ingress firewall
- kubernetes/: sish base and cirrus-dev overlay, applied with kubectl
- READMEs incl. production rollout plan

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-27 12:16:27 +02:00
co-authored by Claude Opus 5.5
commit 3d3ddc98e9
14 changed files with 487 additions and 0 deletions
+61
View File
@@ -0,0 +1,61 @@
# Ingress firewall: block everything that is not listed here. Loopback and
# replies to outgoing connections are always allowed by Talos.
#
# Public TCP ports served by sish must match port-bind-range in
# kubernetes/base/sish/config.yml (plus :80 HTTP and :2222 sish SSH).
# Closed on purpose: flannel VXLAN 4789/udp (single node, unauthenticated),
# etcd 2379-2383, kubelet 10250, kube-proxy 10256, trustd 50001 (only needed
# when other nodes join).
apiVersion: v1alpha1
kind: NetworkDefaultActionConfig
ingress: block
---
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: sish-public
portSelector:
ports:
- 22 # gitea ssh (raw tcp forward)
- 80 # sish http, routed by Host header
- 443 # sish tls, routed by SNI
- 2222 # sish ssh endpoint for connectors (public key auth)
- 20000-20099 # reserved for raw tcp forwards
protocol: tcp
ingress:
- subnet: 0.0.0.0/0
- subnet: ::/0
---
# Talos API (apid) and Kubernetes API, both mTLS / client-cert authenticated
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: talos-and-kube-api
portSelector:
ports:
- 50000
- 6443
protocol: tcp
ingress:
- subnet: 0.0.0.0/0
- subnet: ::/0
---
# CoreDNS forwards to the Talos host DNS (forwardKubeDNSToHost), which pods reach
# on the host, so the pod network needs DNS to the node
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: pod-dns
portSelector:
ports:
- 53
protocol: udp
ingress:
- subnet: 10.244.0.0/16
---
apiVersion: v1alpha1
kind: NetworkRuleConfig
name: pod-dns-tcp
portSelector:
ports:
- 53
protocol: tcp
ingress:
- subnet: 10.244.0.0/16