Files
cirrus/README.md
T
2026-10-06 15:31:20 +02:00

57 lines
2.8 KiB
Markdown

# cirrus
Self-hosted edge: a host running only [sish](https://github.com/antoniomika/sish). Clusters
without inbound ports (e.g. `cumulus`) open outbound SSH tunnels to it with `sish-client`, and the
edge relays public traffic back through them:
```
client ──▶ edge :22/:80/:443/:200xx (sish) ══ssh══▶ sish-client ──▶ envoy gateway ──▶ app
```
- :443 is routed by SNI without decrypting (TLS passthrough), optionally with a PROXY v2 header.
- :80 is routed by `Host` header, raw TCP ports (e.g. :22 for Gitea SSH) by port.
Production runs on Fedora CoreOS (the VPS is too small for Talos), the dev edge on Talos +
Kubernetes. Both use the same sish configuration.
## Layout
```
coreos/ production edge: Butane config (sish quadlet, firewall, updates) → coreos/README.md
talos/ dev edge node config: generated base + patches → talos/README.md
kubernetes/ dev edge sish deployment, kustomize base + overlay → kubernetes/README.md
**/.secrets/ host and connector private keys (gitignored)
```
Everything is applied by hand (`butane` + Ignition, `talosctl`, `kubectl apply -k`). Secrets never
leave the gitignored files (`coreos/.secrets/`, `coreos/*.ign`, `talos/controlplane.yaml`,
`talos/talosconfig`, `**/.secrets/`).
## Environments
| | Edge | Domains |
|---|---|---|
| `cirrus` | `tunnel.traberph.de`, Fedora CoreOS (stable) | any hostname pointed at the VPS |
| `cirrus-dev` | `10.20.5.130` (LAN), Talos v1.14.1, Kubernetes v1.37.0 | `.test` / `.sto` via local DNS |
Production (`cirrus`) serves everything from `cumulus` (since 2026-10-06): `traberph.de` and
`*.traberph.de` on :80/:443 (IPv4 and IPv6), Gitea SSH on :22. The cluster side (connectors, Envoy
gateways, per-app routes) is documented in the `cumulus` README. The dev edge only serves
`.test`/`.sto` names.
## Production rollout (done 2026-10-06)
Rolled out as planned: CoreOS VPS with sish, second connector on `cumulus` for TLS passthrough +
PROXY v2, Envoy HTTPS gateway with cert-manager (Let's Encrypt HTTP-01 over the :80 route), services
moved from the Cloudflare tunnel one hostname at a time by switching DNS.
**Still open**
- **Backups.** `coreos/.secrets/` (edge host key, `cumulus` connector key) and the Talos dev
credentials exist only in this folder. Store them in a password manager.
- **Uptime check.** External check on the edge (sish :5002 and one route per protocol): the edge is
a single point of failure for everything behind it.
- **Updates by hand.** Production updates are automatic (OS in a nightly reboot window, sish within
v2, see `coreos/README.md`). sish-client tags in `cumulus` and the dev edge (`talosctl upgrade` /
`upgrade-k8s`, sish image tag) are updated by hand; the `talosconfig` admin certificate expires
after one year.