@rachel
How do you issue certs? LE with public DNS?
(btw, you remind me I need to look at renovate bot)
@rachel
How do you issue certs? LE with public DNS?
(btw, you remind me I need to look at renovate bot)
Cluster Rebuild Status :ablobcatbongokeyboard:
Completed:
* Talos cluster, with almost sane configs
* Cilium with BGP LB, ingress, hubble, gateway-api
* frr bgp-ospf bridge
* external-dns
* cert-manager w/ dns challenge
* cloudnative-pg operator
* nfs-subdir storage
* keycloak operator
* keycloak realm/client management via terraform (because the operator is lacking tbh)
* Keycloak ream with google auth (only for existing users) and webauthn/passkey login options
* Forgejo
Upcoming:
* Organize and move repo into Forgejo
* ArgoCD
* Pull infra into argo
* Configure renovate against forgejo
* Configure a pile of missing smtp configs
* Forgejo GPG signing
* Fix Cilium shared ingress
* migrates local-only apps to new cluster
Unanswered questions:
* CI Runners in Forgejo? Use alternative CI engine?
* Secret management? May skip it -- may not be worth it given the smaller number of secrets
* Storage migration? Ceph/Rook
#HomeLab #Kuberetes #HomeLab #Kuberetes
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.