- talos/: generated base config (gitignored) + patches for control-plane scheduling, unprivileged ports and the ingress firewall - kubernetes/: sish base and cirrus-dev overlay, applied with kubectl - READMEs incl. production rollout plan Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
7 lines
259 B
YAML
7 lines
259 B
YAML
# Lets non-root processes bind ports >= 22, so sish (hostNetwork, uid 65534,
|
|
# no capabilities) can listen on :22 (Gitea SSH), :80 and :443.
|
|
# The edge runs nothing else that could grab 22-79.
|
|
machine:
|
|
sysctls:
|
|
net.ipv4.ip_unprivileged_port_start: "22"
|