Proxmox: node1-3 → 10.0.19.101-103 Talos cp1-3 → 10.0.19.1-3, workers → 10.0.19.4-6 K8s endpoint → VIP https://10.0.19.10:6443 Ansible: prom → 10.0.19.31, db → 10.0.19.30 Talos: added VIP block to controlplane.yaml base config Promtail: Loki URL → 10.0.19.31 Docs: all references updated, talos4 removed
67 lines
4.3 KiB
YAML
67 lines
4.3 KiB
YAML
version: v1alpha1 # Indicates the schema used to decode the contents.
|
|
debug: false # Enable verbose logging to the console.
|
|
persist: true
|
|
machine:
|
|
type: worker # Defines the role of the machine within the cluster.
|
|
token: t6u2b3.xkpavh9cex6s9958 # The `token` is used by a machine to join the PKI of the cluster.
|
|
ca:
|
|
crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJQakNCOGFBREFnRUNBaEJ0bzdreDVONWg2QXVwZE9Nd2ovUHVNQVVHQXl0bGNEQVFNUTR3REFZRFZRUUsKRXdWMFlXeHZjekFlRncweU5qQXhNVFF4TnpVeU1qSmFGdzB6TmpBeE1USXhOelV5TWpKYU1CQXhEakFNQmdOVgpCQW9UQlhSaGJHOXpNQ293QlFZREsyVndBeUVBTHNqQ1VJaDcvQUQ5RFYvS3RpVU45WmdibGYxNmE4Q2NkSm95Cjc1Rk84SmlqWVRCZk1BNEdBMVVkRHdFQi93UUVBd0lDaERBZEJnTlZIU1VFRmpBVUJnZ3JCZ0VGQlFjREFRWUkKS3dZQkJRVUhBd0l3RHdZRFZSMFRBUUgvQkFVd0F3RUIvekFkQmdOVkhRNEVGZ1FVd2lQcTN2U29nUlFOVEFYMQpBL1ZTRDVtS2U2Y3dCUVlESzJWd0EwRUE3UGQvUll4ekc4NXBmdVU1b1k4WnQ3dkpSM1BhNzM0ZW1aaWY3QzdSCmg5Qmx0SWx6NUFnbXFnSWdQSzlhOCt2VXpCa2p0M05scHFpZGZONzUwSTQ1QUE9PQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
|
key: ""
|
|
certSANs: []
|
|
|
|
kubelet:
|
|
image: ghcr.io/siderolabs/kubelet:v1.36.1 # The `image` field is an optional reference to an alternative kubelet image.
|
|
defaultRuntimeSeccompProfileEnabled: true # Enable container runtime default Seccomp profile.
|
|
disableManifestsDirectory: true # Disable static pod manifest directory.
|
|
|
|
network:
|
|
nameservers:
|
|
- 9.9.9.9
|
|
- 149.112.112.112
|
|
- 1.1.1.1
|
|
|
|
install:
|
|
disk: /dev/sda # The disk used for installations.
|
|
image: factory.talos.dev/installer/613e1592b2da41ae5e265e8789429f22e121aab91cb4deb6bc3c0b6262961245:v1.13.3 # Talos installer (factory image with iscsi-tools, util-linux-tools, qemu-guest-agent, tailscale).
|
|
grubUseUKICmdline: true # Use UKI cmdline instead of building from host.
|
|
wipe: false # Indicates if the installation disk should be wiped at installation time.
|
|
|
|
disks: []
|
|
registries: {}
|
|
features:
|
|
diskQuotaSupport: true # Enable XFS project quota support for EPHEMERAL partition and user disks.
|
|
kubePrism:
|
|
enabled: true # Enable KubePrism support - will start local load balancing proxy.
|
|
port: 7445 # KubePrism port.
|
|
hostDNS:
|
|
enabled: true # Enable host DNS caching resolver.
|
|
forwardKubeDNSToHost: true # Use the host DNS resolver as upstream for Kubernetes CoreDNS pods.
|
|
|
|
cluster:
|
|
id: d9wM2zW6ZcxGVQp8rujQajusx-HrV1s-gRfGfc5wExM= # Globally unique identifier for this cluster (base64 encoded random 32 bytes).
|
|
secret: V44y9ckGbghbUYYuLTqjagj0jzx3TcgfZ9a7C9J97mE= # Shared secret of cluster (base64 encoded random 32 bytes).
|
|
controlPlane:
|
|
endpoint: https://10.0.19.10:6443 # Shared VIP floating across all control plane nodes.
|
|
clusterName: home-cluster # Configures the cluster's name.
|
|
network:
|
|
dnsDomain: cluster.local # The domain used by Kubernetes DNS.
|
|
podSubnets:
|
|
- 10.244.0.0/16
|
|
serviceSubnets:
|
|
- 10.96.0.0/12
|
|
|
|
token: jhs5w8.tnf0lrt6ouico21x # The [bootstrap token](https://kubernetes.io/docs/reference/access-authn-authz/bootstrap-tokens/) used to join the cluster.
|
|
ca:
|
|
crt: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJpekNDQVRDZ0F3SUJBZ0lSQU5pSitIN3JtY0VEa3AxZ1BZMEpSVWt3Q2dZSUtvWkl6ajBFQXdJd0ZURVQKTUJFR0ExVUVDaE1LYTNWaVpYSnVaWFJsY3pBZUZ3MHlOakF4TVRReE56VXlNakphRncwek5qQXhNVEl4TnpVeQpNakphTUJVeEV6QVJCZ05WQkFvVENtdDFZbVZ5Ym1WMFpYTXdXVEFUQmdjcWhrak9QUUlCQmdncWhrak9QUU1CCkJ3TkNBQVRRMUpQeWl2bjkzc0FHSUhTUzJBN0VnQTI2N3ZJM0pWcC9rMWZQWnFNRnpmNHlmRHBwTUQ5cG42SEQKWUx2SjkyazNGRkRoYXh2UDZIUTRRQVV3UW5Mcm8yRXdYekFPQmdOVkhROEJBZjhFQkFNQ0FvUXdIUVlEVlIwbApCQll3RkFZSUt3WUJCUVVIQXdFR0NDc0dBUVVGQndNQ01BOEdBMVVkRXdFQi93UUZNQU1CQWY4d0hRWURWUjBPCkJCWUVGTXhodGtYOHZUbEtGMkJ4THBqUXhJZGRuNzJuTUFvR0NDcUdTTTQ5QkFNQ0Ewa0FNRVlDSVFDeGNaTTQKZ09RTHplU1BrSy9HTnZaV3pueTBoSXM0ZmUrYVJOMENhN1A2UndJaEFJSHc0Ni9EaDJtTWZLQm9GS3hmTnJWTQpiaVNoekF1QzQ2THdVZXJyNmNBcQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg==
|
|
key: ""
|
|
discovery:
|
|
enabled: true # Enable the cluster membership discovery feature.
|
|
registries:
|
|
kubernetes:
|
|
disabled: true # Disable Kubernetes discovery registry.
|
|
service: {}
|
|
|
|
---
|
|
apiVersion: v1alpha1
|
|
kind: HostnameConfig
|
|
|