Commit graph

7 commits

Author SHA1 Message Date
39bedb08d1
renumber infrastructure from 10.0.15.0/24 to 10.0.16.0/22 (hosts in 10.0.19.x)
Proxmox: node1-3 → 10.0.19.101-103
Talos cp1-3 → 10.0.19.1-3, workers → 10.0.19.4-6
K8s endpoint → VIP https://10.0.19.10:6443
Ansible: prom → 10.0.19.31, db → 10.0.19.30
Talos: added VIP block to controlplane.yaml base config
Promtail: Loki URL → 10.0.19.31
Docs: all references updated, talos4 removed
2026-07-18 08:28:47 -05:00
Graham McInitre
514b346662 cloudflared: aggressive reconnects, always-pull latest, restricted PSS compliance
- imagePullPolicy: Always so :latest actually tracks upstream (nodes were
  running two different cached digests)
- --retries 1: supervisor retries forever; this caps the jittered backoff
  at ~2s instead of the exponential 1..32s ramp
- liveness failureThreshold 30: let cloudflared's own fast retry loop
  reconnect instead of killing pods into exponential CrashLoopBackOff
  (pods had 300+ restarts)
- maxSurge 0 / maxUnavailable 1: required anti-affinity on 3 workers
  deadlocked surge-based rollouts
- securityContext for restricted:latest PodSecurity (nonroot 65532,
  drop ALL caps, no privilege escalation, RuntimeDefault seccomp)

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-16 08:48:53 -05:00
baa50efccf
update 2026-03-26 17:53:51 -05:00
36265b9da7
changes 2026-02-05 12:46:51 -06:00
b951c77015
fix vntx cnames 2026-01-16 09:25:46 -06:00
aef669c115
Add Pangolin Newt site connector for home-cluster 2026-01-11 14:37:41 -06:00
57bd3290ec
update dns serials 2026-01-11 14:11:15 -06:00