CBC infra¶
Operational documentation for the GEWIS CBC infrastructure: the NixOS hosts, the OpenTofu that provisions them, and the Flux GitOps tree reconciled into the Talos Kubernetes cluster.
Hosts¶
| Host | Role |
|---|---|
| pcgewisa | Service PC: Aurora narrowcasting on two screens |
| pcgewisb | Bar service PC: Aurora narrowcasting on two screens, DMX to the lights, audio and Spotify Connect |
| pcgewisc | Bar service PC: SudoSOS POS and Spotify on a touchscreen |
| pcgewisd | Service PC: SudoSOS POS on a touchscreen |
| pcgewisinfo | Info-screen kiosk; DHCP and print server for the booth LAN |
| s3-01 | SeaweedFS S3 object store, single node |
| talos | 3-node Talos Kubernetes cluster |
What the five service PCs share, and how to install another, is Service PCs.
Inside the cluster¶
| Topic | What it covers |
|---|---|
| cluster | Flux layering, ingress, certificates, DNS, OpenBao |
| databases | HA Postgres and MariaDB placement and their backup model |
| authentik | The identity provider and how it is wired up |
| observability | The LGTM stack and its tenancy model |
| seaweedfs-buckets | S3 buckets and the credentials the cluster reads for them |
| ssh-certificates | OpenBao as the CA for short-lived SSH user certificates |
The repository itself, its layout, and how to work on it are in the README.