26 Commits

Author SHA1 Message Date
Tom Alexander
1902e132a7
Enable the firewall.
Now that we have networking working, I can enable the firewall and confirm nothing breaks.
2026-02-21 15:11:13 -05:00
Tom Alexander
da9b91a47c
Fix CoreDNS IPv4 connectivity. 2026-02-21 15:11:13 -05:00
Tom Alexander
b9d916fdc7
Increase timeout for coredns cache. 2026-02-21 15:11:13 -05:00
Tom Alexander
7f6f8352c0
More changes to try to fix coredns. 2026-02-21 15:11:13 -05:00
Tom Alexander
8e043ba48a
Move the kubelet yaml config into nix. 2026-02-21 15:11:13 -05:00
Tom Alexander
218aaf97c6
Implement a generic helm templater package. 2026-02-21 15:11:12 -05:00
Tom Alexander
35a1b8c227
Switch to generating the coredns manifests via nix. 2026-02-21 15:11:12 -05:00
Tom Alexander
740e3a17e5
Build the cilium manifest automatically in nix. 2026-02-21 15:11:12 -05:00
Tom Alexander
70c10aba40
Apply the git repo to the cluster. 2026-02-21 15:11:10 -05:00
Tom Alexander
90a97f4e74
Generic secrets for ssh keys. 2026-02-21 15:11:10 -05:00
Tom Alexander
21ee9a631c
Generic secrets for pgp keys. 2026-02-21 15:11:10 -05:00
Tom Alexander
9529f4b805
Generate kubernetes secrets for ssh keys. 2026-02-21 15:11:10 -05:00
Tom Alexander
5593a1fccd
Generate pgp keys for sops. 2026-02-21 15:11:09 -05:00
Tom Alexander
ff04f8d951
Generate ssh keys for flux bootstrap. 2026-02-21 15:11:09 -05:00
Tom Alexander
50ba6f7c87
Move the cluster bootstrap into the keys flake.
Bootstrapping the cluster needs access to secrets, so I am moving it into the keys flake.
2026-02-21 15:11:09 -05:00
Tom Alexander
fbfa3dc5dc
Add kube-proxy. 2026-02-21 15:11:08 -05:00
Tom Alexander
2ac0bfe5f8
Add kubelet. 2026-02-21 15:11:07 -05:00
Tom Alexander
13f3237359
Add kube-scheduler. 2026-02-21 15:11:07 -05:00
Tom Alexander
cd86934dde
Move the encryption config into a package. 2026-02-21 15:11:07 -05:00
Tom Alexander
f1346a52ce
Switch to generating certs with openssl. 2026-02-21 15:11:07 -05:00
Tom Alexander
f57df2d855
Add controller proxy certs. 2026-02-21 15:11:06 -05:00
Tom Alexander
5f459db540
Add requestheader-client-ca. 2026-02-21 15:11:06 -05:00
Tom Alexander
9956009638
Add service account. 2026-02-21 15:11:06 -05:00
Tom Alexander
f713ac372b
Install kubernetes. 2026-02-21 15:11:06 -05:00
Tom Alexander
a140d691f4
Add additional controllers. 2026-02-21 15:11:06 -05:00
Tom Alexander
4c029aa0b0
Add configs for a new kubernetes cluster on NixOS. 2026-02-21 15:11:06 -05:00