CBC infra¶
Operational documentation for the GEWIS CBC infrastructure: the NixOS hosts, the OpenTofu that provisions them, and the Flux GitOps tree reconciled into the Talos Kubernetes cluster.
Hosts¶
| Host | Role |
|---|---|
| pcgewisinfo | Info-screen kiosk; DHCP and print server for the booth LAN |
| s3-01 | Garage S3 object store, single node |
| talos | 3-node Talos Kubernetes cluster |
Inside the cluster¶
| Topic | What it covers |
|---|---|
| cluster | Flux layering, ingress, certificates, DNS, OpenBao |
| databases | HA Postgres and MariaDB placement and their backup model |
| authentik | The identity provider and how it is wired up |
| observability | The LGTM stack and its tenancy model |
| garage-buckets | S3 buckets and the credentials the cluster reads for them |
The repository itself, its layout, and how to work on it are in the README.