Skip to content

CBC infra

Operational documentation for the GEWIS CBC infrastructure: the NixOS hosts, the OpenTofu that provisions them, and the Flux GitOps tree reconciled into the Talos Kubernetes cluster.

Hosts

Host Role
pcgewisinfo Info-screen kiosk; DHCP and print server for the booth LAN
s3-01 Garage S3 object store, single node
talos 3-node Talos Kubernetes cluster

Inside the cluster

Topic What it covers
cluster Flux layering, ingress, certificates, DNS, OpenBao
databases HA Postgres and MariaDB placement and their backup model
authentik The identity provider and how it is wired up
observability The LGTM stack and its tenancy model
garage-buckets S3 buckets and the credentials the cluster reads for them

The repository itself, its layout, and how to work on it are in the README.