2026-10-06 15:31:20 +02:00
2026-10-06 15:31:20 +02:00
2026-09-27 15:35:51 +02:00
2026-09-27 15:35:51 +02:00
2026-10-06 15:31:20 +02:00

cirrus

Self-hosted edge: a host running only sish. Clusters without inbound ports (e.g. cumulus) open outbound SSH tunnels to it with sish-client, and the edge relays public traffic back through them:

client ──▶ edge :22/:80/:443/:200xx (sish) ══ssh══▶ sish-client ──▶ envoy gateway ──▶ app
  • :443 is routed by SNI without decrypting (TLS passthrough), optionally with a PROXY v2 header.
  • :80 is routed by Host header, raw TCP ports (e.g. :22 for Gitea SSH) by port.

Production runs on Fedora CoreOS (the VPS is too small for Talos), the dev edge on Talos + Kubernetes. Both use the same sish configuration.

Layout

coreos/       production edge: Butane config (sish quadlet, firewall, updates)     → coreos/README.md
talos/        dev edge node config: generated base + patches                        → talos/README.md
kubernetes/   dev edge sish deployment, kustomize base + overlay                    → kubernetes/README.md
**/.secrets/  host and connector private keys (gitignored)

Everything is applied by hand (butane + Ignition, talosctl, kubectl apply -k). Secrets never leave the gitignored files (coreos/.secrets/, coreos/*.ign, talos/controlplane.yaml, talos/talosconfig, **/.secrets/).

Environments

Edge Domains
cirrus tunnel.traberph.de, Fedora CoreOS (stable) any hostname pointed at the VPS
cirrus-dev 10.20.5.130 (LAN), Talos v1.14.1, Kubernetes v1.37.0 .test / .sto via local DNS

Production (cirrus) serves everything from cumulus (since 2026-10-06): traberph.de and *.traberph.de on :80/:443 (IPv4 and IPv6), Gitea SSH on :22. The cluster side (connectors, Envoy gateways, per-app routes) is documented in the cumulus README. The dev edge only serves .test/.sto names.

Production rollout (done 2026-10-06)

Rolled out as planned: CoreOS VPS with sish, second connector on cumulus for TLS passthrough + PROXY v2, Envoy HTTPS gateway with cert-manager (Let's Encrypt HTTP-01 over the :80 route), services moved from the Cloudflare tunnel one hostname at a time by switching DNS.

Still open

  • Backups. coreos/.secrets/ (edge host key, cumulus connector key) and the Talos dev credentials exist only in this folder. Store them in a password manager.
  • Uptime check. External check on the edge (sish :5002 and one route per protocol): the edge is a single point of failure for everything behind it.
  • Updates by hand. Production updates are automatic (OS in a nightly reboot window, sish within v2, see coreos/README.md). sish-client tags in cumulus and the dev edge (talosctl upgrade / upgrade-k8s, sish image tag) are updated by hand; the talosconfig admin certificate expires after one year.
S
Description
No description provided
Readme
64 KiB