# cirrus Self-hosted edge: a host running only [sish](https://github.com/antoniomika/sish). Clusters without inbound ports (e.g. `cumulus`) open outbound SSH tunnels to it with `sish-client`, and the edge relays public traffic back through them: ``` client ──▶ edge :22/:80/:443/:200xx (sish) ══ssh══▶ sish-client ──▶ envoy gateway ──▶ app ``` - :443 is routed by SNI without decrypting (TLS passthrough), optionally with a PROXY v2 header. - :80 is routed by `Host` header, raw TCP ports (e.g. :22 for Gitea SSH) by port. Production runs on Fedora CoreOS (the VPS is too small for Talos), the dev edge on Talos + Kubernetes. Both use the same sish configuration. ## Layout ``` coreos/ production edge: Butane config (sish quadlet, firewall, updates) → coreos/README.md talos/ dev edge node config: generated base + patches → talos/README.md kubernetes/ dev edge sish deployment, kustomize base + overlay → kubernetes/README.md **/.secrets/ host and connector private keys (gitignored) ``` Everything is applied by hand (`butane` + Ignition, `talosctl`, `kubectl apply -k`). Secrets never leave the gitignored files (`coreos/.secrets/`, `coreos/*.ign`, `talos/controlplane.yaml`, `talos/talosconfig`, `**/.secrets/`). ## Environments | | Edge | Domains | |---|---|---| | `cirrus` | `tunnel.traberph.de`, Fedora CoreOS (stable) | any hostname pointed at the VPS | | `cirrus-dev` | `10.20.5.130` (LAN), Talos v1.14.1, Kubernetes v1.37.0 | `.test` / `.sto` via local DNS | Production (`cirrus`) serves everything from `cumulus` (since 2026-10-06): `traberph.de` and `*.traberph.de` on :80/:443 (IPv4 and IPv6), Gitea SSH on :22. The cluster side (connectors, Envoy gateways, per-app routes) is documented in the `cumulus` README. The dev edge only serves `.test`/`.sto` names. ## Production rollout (done 2026-10-06) Rolled out as planned: CoreOS VPS with sish, second connector on `cumulus` for TLS passthrough + PROXY v2, Envoy HTTPS gateway with cert-manager (Let's Encrypt HTTP-01 over the :80 route), services moved from the Cloudflare tunnel one hostname at a time by switching DNS. **Still open** - **Backups.** `coreos/.secrets/` (edge host key, `cumulus` connector key) and the Talos dev credentials exist only in this folder. Store them in a password manager. - **Uptime check.** External check on the edge (sish :5002 and one route per protocol): the edge is a single point of failure for everything behind it. - **Updates by hand.** Production updates are automatic (OS in a nightly reboot window, sish within v2, see `coreos/README.md`). sish-client tags in `cumulus` and the dev edge (`talosctl upgrade` / `upgrade-k8s`, sish image tag) are updated by hand; the `talosconfig` admin certificate expires after one year.