Tom Alexander
7222df83ef
Install deferred manifests.
2026-02-06 11:28:44 -05:00
Tom Alexander
ea44e28256
Add a custom nftables firewall config.
2026-02-06 11:28:44 -05:00
Tom Alexander
72084f1a7e
Enable the firewall.
...
Now that we have networking working, I can enable the firewall and confirm nothing breaks.
2026-02-06 11:28:44 -05:00
Tom Alexander
4024847954
Fix CoreDNS IPv4 connectivity.
2026-02-06 11:28:44 -05:00
Tom Alexander
d8fa1a06c7
Increase timeout for coredns cache.
2026-02-06 11:28:44 -05:00
Tom Alexander
9cae3bbae3
More changes to try to fix coredns.
2026-02-06 11:28:43 -05:00
Tom Alexander
c62071f80e
Move the kubelet yaml config into nix.
2026-02-06 11:28:43 -05:00
Tom Alexander
29608e3376
Implement a generic helm templater package.
2026-02-06 11:28:43 -05:00
Tom Alexander
b7310a03b8
Switch to generating the coredns manifests via nix.
2026-02-06 11:28:43 -05:00
Tom Alexander
77c40726ff
Use CoreDNS for in-cluster DNS requests and caching.
2026-02-06 11:28:43 -05:00
Tom Alexander
710603e20b
Enable native routing.
2026-02-06 11:28:43 -05:00
Tom Alexander
96112bd40a
Build the cilium manifest automatically in nix.
2026-02-06 11:28:43 -05:00
Tom Alexander
6551fee05b
Allow pods to directly speak to the public internet on their own public IPv6 addresses.
2026-02-06 11:28:42 -05:00
Tom Alexander
f62e36b5af
Enable ipv4 and tunnel routing.
2026-02-06 11:28:42 -05:00
Tom Alexander
6d38265412
Switch to kubernetes ipam mode.
2026-02-06 11:28:42 -05:00
Tom Alexander
626f74ed2b
Fix service cluster ip range.
...
Kubernetes only allows a /112 for service ip range.
2026-02-06 11:28:42 -05:00
Tom Alexander
e364c6bafd
Fix trailing line break in kubernetes encryption config.
2026-02-06 11:28:42 -05:00
Tom Alexander
e9a8f78342
Move the yaml functions to their own file.
2026-02-06 11:28:42 -05:00
Tom Alexander
2c5acd15df
Introduce functions to generate yaml.
...
The toYAML function is just an alias to toJSON which is technically fine since YAML is a superset of JSON, but these new functions will generate actual YAML.
2026-02-06 11:28:42 -05:00
Tom Alexander
dcfbc0864e
Add missing cidr declarations.
2026-02-06 11:28:41 -05:00
Tom Alexander
f34e393803
Fix DNS resolution.
2026-02-06 11:28:41 -05:00
Tom Alexander
645c71ce33
Apply the git repo to the cluster.
2026-02-06 11:28:41 -05:00
Tom Alexander
4e0a42b143
Trust flux's ssh key in the yaml git repo.
2026-02-06 11:28:41 -05:00
Tom Alexander
8c70d4e829
Generic secrets for ssh keys.
2026-02-06 11:28:41 -05:00
Tom Alexander
df4260a35a
Generic secrets for pgp keys.
2026-02-06 11:28:41 -05:00
Tom Alexander
32fda29efe
Generate kubernetes secrets for ssh keys.
2026-02-06 11:28:41 -05:00
Tom Alexander
ffbd1b56c8
Install CoreDNS.
2026-02-06 11:28:41 -05:00
Tom Alexander
3affee9007
Generate pgp keys for sops.
2026-02-06 11:28:40 -05:00
Tom Alexander
144b39dfdd
Generate ssh keys for flux bootstrap.
2026-02-06 11:28:40 -05:00
Tom Alexander
d97edf0add
Move the cluster bootstrap into the keys flake.
...
Bootstrapping the cluster needs access to secrets, so I am moving it into the keys flake.
2026-02-06 11:28:40 -05:00
Tom Alexander
c9450ff9fa
Set up flux.
2026-02-06 11:28:40 -05:00
Tom Alexander
1753b5b4a6
Add a bootstrap role.
2026-02-06 11:28:40 -05:00
Tom Alexander
38b2b9ebf4
Add a bootstrap role to load manifests into the cluster.
2026-02-06 11:28:40 -05:00
Tom Alexander
8e58c3ffbd
Fix launching of containers.
2026-02-06 11:28:40 -05:00
Tom Alexander
d9c290f8b1
Create a debugging role.
2026-02-06 11:28:39 -05:00
Tom Alexander
95f0a891ac
Some networking fixes.
2026-02-06 11:28:39 -05:00
Tom Alexander
816e72eac7
Add cilium bootstrap.
2026-02-06 11:28:39 -05:00
Tom Alexander
1da6250301
Installing the cni plugins.
2026-02-06 11:28:39 -05:00
Tom Alexander
c61da527f2
Add kube-proxy.
2026-02-06 11:28:39 -05:00
Tom Alexander
0463d2cbd1
Add kubelet.
2026-02-06 11:28:39 -05:00
Tom Alexander
fa24540bb3
Add worker nodes.
2026-02-06 11:28:39 -05:00
Tom Alexander
3b96f8d26c
Add kube-scheduler.
2026-02-06 11:28:38 -05:00
Tom Alexander
6483b20b89
Add kube-controller-manager.
2026-02-06 11:28:38 -05:00
Tom Alexander
65cd71f0c6
Fix launching kube-apiserver.
2026-02-06 11:28:38 -05:00
Tom Alexander
f8b8005ab2
Move the encryption config into a package.
2026-02-06 11:28:38 -05:00
Tom Alexander
5d660cced8
Switch to generating certs with openssl.
2026-02-06 11:28:38 -05:00
Tom Alexander
d093c9185a
Add controller proxy certs.
2026-02-06 11:28:38 -05:00
Tom Alexander
1cd5ba2c5c
Add requestheader-client-ca.
2026-02-06 11:28:38 -05:00
Tom Alexander
626055e063
Add service account.
2026-02-06 11:28:37 -05:00
Tom Alexander
342a5e338c
Install kubernetes.
2026-02-06 11:28:37 -05:00