57 lines
2.8 KiB
Markdown
57 lines
2.8 KiB
Markdown
# cirrus
|
|
|
|
Self-hosted edge: a host running only [sish](https://github.com/antoniomika/sish). Clusters
|
|
without inbound ports (e.g. `cumulus`) open outbound SSH tunnels to it with `sish-client`, and the
|
|
edge relays public traffic back through them:
|
|
|
|
```
|
|
client ──▶ edge :22/:80/:443/:200xx (sish) ══ssh══▶ sish-client ──▶ envoy gateway ──▶ app
|
|
```
|
|
|
|
- :443 is routed by SNI without decrypting (TLS passthrough), optionally with a PROXY v2 header.
|
|
- :80 is routed by `Host` header, raw TCP ports (e.g. :22 for Gitea SSH) by port.
|
|
|
|
Production runs on Fedora CoreOS (the VPS is too small for Talos), the dev edge on Talos +
|
|
Kubernetes. Both use the same sish configuration.
|
|
|
|
## Layout
|
|
|
|
```
|
|
coreos/ production edge: Butane config (sish quadlet, firewall, updates) → coreos/README.md
|
|
talos/ dev edge node config: generated base + patches → talos/README.md
|
|
kubernetes/ dev edge sish deployment, kustomize base + overlay → kubernetes/README.md
|
|
**/.secrets/ host and connector private keys (gitignored)
|
|
```
|
|
|
|
Everything is applied by hand (`butane` + Ignition, `talosctl`, `kubectl apply -k`). Secrets never
|
|
leave the gitignored files (`coreos/.secrets/`, `coreos/*.ign`, `talos/controlplane.yaml`,
|
|
`talos/talosconfig`, `**/.secrets/`).
|
|
|
|
## Environments
|
|
|
|
| | Edge | Domains |
|
|
|---|---|---|
|
|
| `cirrus` | `tunnel.traberph.de`, Fedora CoreOS (stable) | any hostname pointed at the VPS |
|
|
| `cirrus-dev` | `10.20.5.130` (LAN), Talos v1.14.1, Kubernetes v1.37.0 | `.test` / `.sto` via local DNS |
|
|
|
|
Production (`cirrus`) serves everything from `cumulus` (since 2026-10-06): `traberph.de` and
|
|
`*.traberph.de` on :80/:443 (IPv4 and IPv6), Gitea SSH on :22. The cluster side (connectors, Envoy
|
|
gateways, per-app routes) is documented in the `cumulus` README. The dev edge only serves
|
|
`.test`/`.sto` names.
|
|
|
|
## Production rollout (done 2026-10-06)
|
|
|
|
Rolled out as planned: CoreOS VPS with sish, second connector on `cumulus` for TLS passthrough +
|
|
PROXY v2, Envoy HTTPS gateway with cert-manager (Let's Encrypt HTTP-01 over the :80 route), services
|
|
moved from the Cloudflare tunnel one hostname at a time by switching DNS.
|
|
|
|
**Still open**
|
|
- **Backups.** `coreos/.secrets/` (edge host key, `cumulus` connector key) and the Talos dev
|
|
credentials exist only in this folder. Store them in a password manager.
|
|
- **Uptime check.** External check on the edge (sish :5002 and one route per protocol): the edge is
|
|
a single point of failure for everything behind it.
|
|
- **Updates by hand.** Production updates are automatic (OS in a nightly reboot window, sish within
|
|
v2, see `coreos/README.md`). sish-client tags in `cumulus` and the dev edge (`talosctl upgrade` /
|
|
`upgrade-k8s`, sish image tag) are updated by hand; the `talosconfig` admin certificate expires
|
|
after one year.
|