Compare commits

..

18 Commits

18 changed files with 59 additions and 174 deletions
+1
View File
@@ -8,3 +8,4 @@ ansible/lookup_plugins
!.editorconfig !.editorconfig
!.vscode !.vscode
!.pre-commit-config.yaml !.pre-commit-config.yaml
!.yamlfmt.yaml
+5
View File
@@ -0,0 +1,5 @@
formatter:
indent: 2
retain_line_breaks_single: true
scan_folded_as_literal: true
indentless_arrays: false
+1 -1
View File
@@ -5,7 +5,7 @@ ansible_proton_pass_plugin_ref := "4bd0741c347646060ec59c73f8adf7ed8e706cf3"
ansible_proton_pass_plugin_url := "https://raw.githubusercontent.com/protonpass/proton-pass-ansible-integration/" + ansible_proton_pass_plugin_ref + "/lookup_plugins/proton_pass.py" ansible_proton_pass_plugin_url := "https://raw.githubusercontent.com/protonpass/proton-pass-ansible-integration/" + ansible_proton_pass_plugin_ref + "/lookup_plugins/proton_pass.py"
up: tofu-apply ansible-run-playbook up: tofu-apply ansible-run-playbook
down: tofu-destroy-instances down: tofu-destroy
tofu-init: tofu-init:
tofu -chdir={{ opentofu_dir }} init -upgrade tofu -chdir={{ opentofu_dir }} init -upgrade
+41
View File
@@ -1,5 +1,30 @@
# Home Infrastructure # Home Infrastructure
## Quick Start
Get started with a local Kubernetes cluster which can be used to design and test
new configuration before pushing them to real machines.
1. Login with Proton Pass and start the SSH daemon.
```shell
pass-cli login
pass-cli ssh-agent daemon start
export SSH_AUTH_SOCK="$HOME/.ssh/proton-pass-agent.sock"
```
2. Launch Incus virtual machines
```shell
just up
```
3. Tear down the Incus virtual machines
```shell
just down
```
## Setup ## Setup
```shell ```shell
@@ -15,3 +40,19 @@ The Kolibri automation user is used for all other playbooks and has permissions
```shell ```shell
ansible-playbook -i ansible/inventories/bare_metal/hosts.yaml ansible/playbooks/provision.yaml -K -e ansible_user=<your_interactive_user> ansible-playbook -i ansible/inventories/bare_metal/hosts.yaml ansible/playbooks/provision.yaml -K -e ansible_user=<your_interactive_user>
``` ```
## Local Testing with Incus
```shell
just up
```
```shell
just headlamp
```
> The above command runs the Flatpak version of Headlamp which may not have permissions
> to access the Kubernetes config file copied from the instance.
>
> You should run `flatpak override --user --filesystem=$(pwd) io.kinvolk.Headlamp`
> to ensure that Headlamp can access the directory contents.
@@ -5,5 +5,3 @@ vip_interface: eno1
vip_address: 10.0.0.200 vip_address: 10.0.0.200
cluster_pod_subnet: 172.16.0.0/16 cluster_pod_subnet: 172.16.0.0/16
cluster_service_subnet: 10.96.0.0/16 cluster_service_subnet: 10.96.0.0/16
lb_pool_start: 10.0.0.210
lb_pool_stop: 10.0.0.220
@@ -4,5 +4,3 @@ vip_interface: enp5s0
vip_address: 10.150.0.100 vip_address: 10.150.0.100
cluster_pod_subnet: 172.16.0.0/16 cluster_pod_subnet: 172.16.0.0/16
cluster_service_subnet: 10.96.0.0/16 cluster_service_subnet: 10.96.0.0/16
lb_pool_start: 10.150.0.210
lb_pool_stop: 10.150.0.220
@@ -1,4 +0,0 @@
- name: Restart keepalived
ansible.builtin.service:
name: keepalived
state: restarted
-12
View File
@@ -1,12 +0,0 @@
- name: Install keepalived
ansible.builtin.apt:
pkg:
- keepalived
state: present
- name: Install keepalived config
ansible.builtin.template:
src: keepalived.conf.j2
dest: /etc/keepalived/keepalived.conf
mode: "0644"
notify: Restart keepalived
@@ -1,19 +0,0 @@
vrrp_instance VI_1 {
state MASTER
interface enp5s0
virtual_router_id 51
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass 1111
}
virtual_ipaddress {
10.150.0.100
10.150.0.101
10.150.0.102
}
# Allow packets addressed to the VIPs above to be received
accept
}
@@ -1,14 +0,0 @@
cilium_chart_version: 1.19.5
cilium_values:
ipam:
operator:
clusterPoolIPv4PodCIDRList:
- "{{ cluster_pod_subnet }}"
hubble:
relay:
enabled: true
ui:
enabled: true
l2announcements:
enabled: true
@@ -1,27 +0,0 @@
- name: Ensure Cilium repository exists
kubernetes.core.helm_repository:
name: cilium
url: https://helm.cilium.io/
- name: Ensure Cilium is installed
kubernetes.core.helm:
release_name: cilium
release_namespace: kube-system
chart_ref: cilium/cilium
chart_version: "{{ cilium_chart_version }}"
values: "{{ cilium_values }}"
run_once: true
- name: Ensure LoadBalancer IP pool exists
kubernetes.core.k8s:
state: present
definition:
apiVersion: cilium.io/v2
kind: CiliumLoadBalancerIPPool
metadata:
name: homelab-pool
spec:
blocks:
- start: "{{ lb_pool_start }}"
stop: "{{ lb_pool_stop }}"
run_once: true
@@ -29,9 +29,7 @@ spec:
- name: cp_namespace - name: cp_namespace
value: kube-system value: kube-system
- name: svc_enable - name: svc_enable
value: "true" value: "false"
- name: svc_leasename
value: plndr-svcs-lock
- name: vip_leaderelection - name: vip_leaderelection
value: "true" value: "true"
- name: vip_leasename - name: vip_leasename
@@ -1,18 +0,0 @@
- name: Ensure open-iscsi is installed
ansible.builtin.apt:
pkg: open-iscsi
state: present
- name: Ensure Longhorn repository exists
kubernetes.core.helm_repository:
name: longhorn
url: https://charts.longhorn.io
- name: Ensure Longhorn is installed
kubernetes.core.helm:
release_name: longhorn
release_namespace: longhorn-system
chart_ref: longhorn/longhorn
chart_version: 1.12.0
create_namespace: true
run_once: true
@@ -1,15 +0,0 @@
- name: Ensure Metrics Server repository exists
kubernetes.core.helm_repository:
name: metrics-server
url: https://kubernetes-sigs.github.io/metrics-server/
- name: Ensure Metrics Server is installed
kubernetes.core.helm:
release_name: metrics-server
release_namespace: kube-system
chart_ref: metrics-server/metrics-server
chart_version: 3.13.1
values:
args:
- --kubelet-insecure-tls
run_once: true
@@ -1,12 +0,0 @@
traefik_chart_version: 41.0.1
traefik_values:
providers:
kubernetesGateway:
enabled: true
gateway:
enabled: true
listeners:
web:
port: 8000
protocol: HTTP
@@ -1,20 +0,0 @@
- name: Install Gateway API CRDs
kubernetes.core.k8s:
src: https://github.com/kubernetes-sigs/gateway-api/releases/latest/download/standard-install.yaml
state: present
run_once: true
- name: Ensure Traefik repository exists
kubernetes.core.helm_repository:
name: traefik
url: https://traefik.github.io/charts
- name: Ensure Traefik is installed
kubernetes.core.helm:
release_name: traefik
release_namespace: traefik
chart_ref: traefik/traefik
chart_version: "{{ traefik_chart_version }}"
create_namespace: true
values: "{{ traefik_values }}"
run_once: true
-15
View File
@@ -14,18 +14,3 @@
become: true become: true
roles: roles:
- kubernetes_control_plane - kubernetes_control_plane
- kubernetes_cilium
- kubernetes_metrics_server
- kubernetes_longhorn
- kubernetes_traefik
# # =======================
# # JOIN MASTERS TO CLUSTER
# # =======================
# - name: Adkfk
# hosts: masters[0]
# tasks:
# - name: Generate Kubernetes 'join' command
# ansible.builtin.command: echo hi
# changed_when: true
+10 -10
View File
@@ -48,11 +48,11 @@ module "master" {
source = "./modules/incus_vm" source = "./modules/incus_vm"
count = local.master_count count = local.master_count
name = "master-${count.index}" name = "master-${count.index}"
project = incus_project.this.name project = incus_project.this.name
image = incus_image.this.fingerprint image = incus_image.this.fingerprint
cpu = 2 cpu = 2
memory = "2GiB" memory = "2GiB"
network = incus_network.this.name network = incus_network.this.name
ipv4_address = cidrhost(local.network_cidr, 2 + (2 * count.index)) ipv4_address = cidrhost(local.network_cidr, 2 + (2 * count.index))
@@ -62,11 +62,11 @@ module "worker" {
source = "./modules/incus_vm" source = "./modules/incus_vm"
count = local.worker_count count = local.worker_count
name = "worker-${count.index}" name = "worker-${count.index}"
project = incus_project.this.name project = incus_project.this.name
image = incus_image.this.fingerprint image = incus_image.this.fingerprint
cpu = 2 cpu = 2
memory = "2GiB" memory = "2GiB"
network = incus_network.this.name network = incus_network.this.name
ipv4_address = cidrhost(local.network_cidr, 3 + (2 * count.index)) ipv4_address = cidrhost(local.network_cidr, 3 + (2 * count.index))