261
edits
Changes
m
no edit summary
The frontend networks, uses DHCP with [[Infrastructure:Shellshock]], while the backend network is statically routed.
The blades have completely ephemeral disks -- the k3s node passwords and join tokens are shipped via agenix, targeting an ssh host key that is sealed by TPM1.2 and kept in the netboot image.
You can spy their config here [https://github.com/vtluug/construct/blob/main/hosts/bastille/blade.nix]
=== Operational ===
All users with a VTLUUG SSO account (read: FreeIPA/acidburn) can SSH to [[Infrastructure:Vesuvius]] on from the VTLUUG LANor the public IPv6 address.
From there, all users with sudo access can use `kubectl` to manage the cluster, or proxy/jump to other nodes through the backend fabric.
Non-admin tenant namespaces coming Soon^{tm}
== Things To Host On All This (Post Suggestions!!!) ==