cirrus
Self-hosted edge: a host running only sish. Clusters
without inbound ports (e.g. cumulus) open outbound SSH tunnels to it with sish-client, and the
edge relays public traffic back through them:
client ──▶ edge :22/:80/:443/:200xx (sish) ══ssh══▶ sish-client ──▶ envoy gateway ──▶ app
- :443 is routed by SNI without decrypting (TLS passthrough), optionally with a PROXY v2 header.
- :80 is routed by
Hostheader, raw TCP ports (e.g. :22 for Gitea SSH) by port.
Production runs on Fedora CoreOS (the VPS is too small for Talos), the dev edge on Talos + Kubernetes. Both use the same sish configuration.
Layout
coreos/ production edge: Butane config (sish quadlet, firewall, updates) → coreos/README.md
talos/ dev edge node config: generated base + patches → talos/README.md
kubernetes/ dev edge sish deployment, kustomize base + overlay → kubernetes/README.md
**/.secrets/ host and connector private keys (gitignored)
Everything is applied by hand (butane + Ignition, talosctl, kubectl apply -k). Secrets never
leave the gitignored files (coreos/.secrets/, coreos/*.ign, talos/controlplane.yaml,
talos/talosconfig, **/.secrets/).
Environments
| Edge | Domains | |
|---|---|---|
cirrus |
tunnel.traberph.de, Fedora CoreOS (stable) |
any hostname pointed at the VPS |
cirrus-dev |
10.20.5.130 (LAN), Talos v1.14.1, Kubernetes v1.37.0 |
.test / .sto via local DNS |
Production (cirrus) serves everything from cumulus (since 2026-10-06): traberph.de and
*.traberph.de on :80/:443 (IPv4 and IPv6), Gitea SSH on :22. The cluster side (connectors, Envoy
gateways, per-app routes) is documented in the cumulus README. The dev edge only serves
.test/.sto names.
Production rollout (done 2026-10-06)
Rolled out as planned: CoreOS VPS with sish, second connector on cumulus for TLS passthrough +
PROXY v2, Envoy HTTPS gateway with cert-manager (Let's Encrypt HTTP-01 over the :80 route), services
moved from the Cloudflare tunnel one hostname at a time by switching DNS.
Still open
- Backups.
coreos/.secrets/(edge host key,cumulusconnector key) and the Talos dev credentials exist only in this folder. Store them in a password manager. - Uptime check. External check on the edge (sish :5002 and one route per protocol): the edge is a single point of failure for everything behind it.
- Updates by hand. Production updates are automatic (OS in a nightly reboot window, sish within
v2, see
coreos/README.md). sish-client tags incumulusand the dev edge (talosctl upgrade/upgrade-k8s, sish image tag) are updated by hand; thetalosconfigadmin certificate expires after one year.