Skip to content

CBC infra

Operational documentation for the GEWIS CBC infrastructure: the NixOS hosts, the OpenTofu that provisions them, and the Flux GitOps tree reconciled into the Talos Kubernetes cluster.

Hosts

Host Role
pcgewisa Service PC: Aurora narrowcasting on two screens
pcgewisb Bar service PC: Aurora narrowcasting on two screens, DMX to the lights, audio and Spotify Connect
pcgewisc Bar service PC: SudoSOS POS and Spotify on a touchscreen
pcgewisd Service PC: SudoSOS POS on a touchscreen
pcgewisinfo Info-screen kiosk; DHCP and print server for the booth LAN
s3-01 SeaweedFS S3 object store, single node
talos 3-node Talos Kubernetes cluster

What the five service PCs share, and how to install another, is Service PCs.

Inside the cluster

Topic What it covers
cluster Flux layering, ingress, certificates, DNS, OpenBao
databases HA Postgres and MariaDB placement and their backup model
authentik The identity provider and how it is wired up
observability The LGTM stack and its tenancy model
seaweedfs-buckets S3 buckets and the credentials the cluster reads for them
ssh-certificates OpenBao as the CA for short-lived SSH user certificates

The repository itself, its layout, and how to work on it are in the README.