docs: migrate all documentation to Discourse wiki topics
All knowledge docs (architecture, runbooks, references, audits, policies) have been migrated to community.turnsys.com as wiki topics in the VP TechOps category. Discourse is now the canonical source of truth for documentation; git edit history no longer serves as the doc changelog. 37 .md files converted to short pointers linking to their Discourse topics. AGENTS.md updated with new documentation workflow policy. Code (scripts, configs, playbooks) remains authoritative in git.
This commit is contained in:
+9
-56
@@ -1,57 +1,10 @@
|
||||
# k8s/ — pfv-k8s Cluster Setup Scripts
|
||||
# k8s/README.md
|
||||
|
||||
> **Redmine:** [#362](https://projects.knownelement.com/issues/362) (initial build, closed) · [#367](https://projects.knownelement.com/issues/367) (rebuild, open) · [#368](https://projects.knownelement.com/issues/368) (worker join, open)
|
||||
|
||||
Scripts to bootstrap and manage the k3s control plane on cnode1/2/3.
|
||||
All cluster communication goes over Tailscale IPs — no LAN traffic.
|
||||
|
||||
## Current State
|
||||
|
||||
3-node HA control plane (k3s v1.36.2+k3s1, embedded etcd):
|
||||
|
||||
| Node | Tailscale IP | Role | Tainted |
|
||||
|------|-------------|------|---------|
|
||||
| pfv-k8s-cnode1 | 100.97.178.106 | control-plane, etcd | NoSchedule |
|
||||
| pfv-k8s-cnode2 | 100.109.34.72 | control-plane, etcd | NoSchedule |
|
||||
| pfv-k8s-cnode3 | 100.106.222.18 | control-plane, etcd | NoSchedule |
|
||||
|
||||
## Scripts
|
||||
|
||||
| Script | Purpose |
|
||||
|--------|---------|
|
||||
| [`env.sh`](env.sh) | Shared config: node IPs, SSH opts, k3s version. Sourced by all scripts. |
|
||||
| [`wipe.sh`](wipe.sh) | Remove existing k3s from all cnodes (clean slate). |
|
||||
| [`install-cp.sh`](install-cp.sh) | Full bootstrap: cnode1 (--cluster-init) then cnode2/3 join. |
|
||||
| [`join-servers.sh`](join-servers.sh) | Re-join cnode2/3 only (if cnode1 is already up). |
|
||||
| [`post-setup.sh`](post-setup.sh) | Apply NoSchedule taints, fetch kubeconfig, verify. |
|
||||
| [`verify.sh`](verify.sh) | Health check: nodes Ready, Tailscale IPs, taints, etcd, CoreDNS. |
|
||||
| [`probe-nodes.sh`](probe-nodes.sh) | Verify SSH + Tailscale reachability. |
|
||||
|
||||
## Usage
|
||||
|
||||
```bash
|
||||
# Full bootstrap from scratch:
|
||||
bash k8s/wipe.sh
|
||||
bash k8s/install-cp.sh
|
||||
bash k8s/post-setup.sh
|
||||
bash k8s/verify.sh
|
||||
|
||||
# Access the cluster:
|
||||
export KUBECONFIG=~/.kube/config.pfv-k8s
|
||||
kubectl get nodes
|
||||
```
|
||||
|
||||
## Design Decisions
|
||||
|
||||
- **k3s (not Talos):** This is a regular R&D cluster, not ITAR/classified.
|
||||
Talos architecture is documented in [`docs/`](docs/) for when
|
||||
that requirement comes online. k3s on stock Debian is simpler to operate.
|
||||
- **Tailscale-only transport:** `--node-ip`, `--advertise-address`, and
|
||||
`--tls-san` are all set to Tailscale IPs. No LAN IP appears in any node
|
||||
status or certificate.
|
||||
- **VXLAN flannel:** Pods communicate via flannel VXLAN overlay on top of
|
||||
Tailscale's WireGuard. Double-encrypted, but functional and reliable.
|
||||
- **NoSchedule taint:** All 3 cnodes are tainted so no user workloads
|
||||
schedule on the control plane. Only system components (CoreDNS,
|
||||
metrics-server, flannel, kube-proxy) with built-in tolerations run here.
|
||||
- **Embedded etcd:** 3-node HA etcd quorum. Tolerates 1 node failure.
|
||||
> **Documentation moved to Discourse — the canonical source of truth.**
|
||||
>
|
||||
> **k3s cluster setup scripts: wipe, bootstrap, taint, verify**
|
||||
>
|
||||
> **Read it here:** https://community.turnsys.com/t/305
|
||||
>
|
||||
> *Migrated 2026-08-06. This file is kept as a pointer for git-browsing context.
|
||||
> Do not update content here — edit the Discourse wiki topic instead.*
|
||||
|
||||
Reference in New Issue
Block a user