Changes

Jump to: navigation, search

Infrastructure:Bastille

918 bytes added, 14 September
m
no edit summary
They are at the moment netbooted from [[Infrastructure:Vesuvius]] as NixOS k3s nodes.
 
{| class="wikitable sortable"
! Hostname !! Frontend IP4 !! Backend IP4 !! Global IP6 !! Notes
|-
| [[Infrastructure:Vesuvius|vesuvius]] || 10.98.0.23 || 10.98.3.1 || 2607:b400:6:cc80:21e:67ff:feca:9c12 || k3s control plane; PXE boot image server
|-
| backbiter || 10.98.0.25 || 10.98.3.2 || 2607:b400:6:cc80:42f2:e9ff:fec6:655f ||
|-
| damocles || 10.98.0.26 || 10.98.3.3 || 2607:b400:6:cc80:42f2:e9ff:fec6:67db ||
|-
| durendal || 10.98.0.27 || 10.98.3.4 || 2607:b400:6:cc80:42f2:e9ff:fec6:6895 ||
|-
| excalibur || 10.98.0.29 || 10.98.3.5 || 2607:b400:6:cc80:42f2:e9ff:fec6:6967 ||
|-
| eyelander || 10.98.0.28 || 10.98.3.6 || 2607:b400:6:cc80:42f2:e9ff:fec6:6943 ||
|-
| gram || 10.98.0.30 || 10.98.3.7 || 2607:b400:6:cc80:42f2:e9ff:fec6:7459 ||
|-
| [[Infrastructure:Prospit|prospit]] || - || - || - || [[User:Enzoisotton]] took this out of the server room to test pxe booting, yell at him until it's back
|-
| gryffindor || 10.98.0.31 || 10.98.3.8 || 2607:b400:6:cc80:42f2:e9ff:fec6:74d7 ||
|-
| kusanagi || 10.98.0.32 || - || 2607:b400:6:cc80:42f2:e9ff:fec6:7597 || the SFP+ NIC appears broken. may work if re-seated.
|-
| narsil || 10.98.0.33 || 10.98.3.10 || 2607:b400:6:cc80:42f2:e9ff:fec6:759d ||
|-
| oathbringer || 10.98.0.34 || 10.98.3.11 || 2607:b400:6:cc80:42f2:e9ff:fec6:75f1 ||
|-
| riptide || 10.98.0.35 || 10.98.3.13 || 2607:b400:6:cc80:42f2:e9ff:fec6:7621 ||
|-
| sting || 10.98.0.36 || 10.98.3.14 || 2607:b400:6:cc80:42f2:e9ff:fec6:7723 ||
|}
 
Each machine can be remotely accessed on port 2222 from it's global IP6 address, or by DNS at <name>.vtluug.org.
Each machine has a management interface on 10.98.2.0/24, with the same last octet as its backend IP -- i.e. riptide can be managed from 10.98.2.13.
The frontend networks, uses DHCP with [[Infrastructure:Shellshock]], while the backend network is statically routed.
 
The blades have completely ephemeral disks -- the k3s node passwords and join tokens are shipped via agenix, targeting an ssh host key that is sealed by TPM1.2 and kept in the netboot image.
You can spy their config here [https://github.com/vtluug/construct/blob/main/hosts/bastille/blade.nix]
=== Operational ===
All users with a VTLUUG SSO account (read: FreeIPA/acidburn) can SSH to [[Infrastructure:Vesuvius]] on from the VTLUUG LANor the public IPv6 address.
From there, all users with sudo access can use `kubectl` to manage the cluster, or proxy/jump to other nodes through the backend fabric.
 
Non-admin tenant namespaces coming Soon^{tm}
== Things To Host On All This (Post Suggestions!!!) ==
261
edits

Navigation menu