dumpnet-argo/README.md

4.8 KiB

dumpnet-argo

GitOps cluster management for dumpnet — a single-node Talos/Kubernetes cluster on AWS, managed via ArgoCD.

Architecture

  • Talos Linux on EC2 (t3.medium) — immutable, API-driven OS
  • ArgoCD — GitOps continuous delivery
  • ingress-nginx — ingress controller (hostNetwork mode)
  • App of Apps pattern — all workloads defined in manifests/
  • Terraform — cluster infrastructure and bootstrap
  • SOPS + age — secret encryption for sensitive cluster files

Prerequisites

  • terraform
  • kubectl
  • talosctl
  • sops + age
  • AWS CLI configured (aws configure)

Secrets Setup (first time only)

Sensitive files (talosconfig, controlplane.yaml, worker.yaml) are gitignored and never stored in the repo in any form. They are managed as follows:

  • Cluster credentials (kubeconfig, talosconfig, ArgoCD password) → stored in AWS Secrets Manager at dumpnet/cluster
  • Talos machine configs → encrypted with SOPS + age, stored outside the repo
  • Age private key → lives at ~/.age/key.txtback this up securely

To decrypt Talos configs to /tmp for one-off talosctl use:

make decrypt
# files appear at /tmp/controlplane.yaml, /tmp/worker.yaml, /tmp/talosconfig
# they are not persisted after reboot

First-Time Setup

1. Clone and init

git clone https://forge.keane.sh/ian/dumpnet-argo.git
cd dumpnet-argo
make init

2. Configure variables

cp terraform/terraform.tfvars.example terraform/terraform.tfvars
# edit terraform/terraform.tfvars with your hosted_zone_id

3. Spin up the cluster

make apply

This will:

  • Allocate an EIP
  • Create a dedicated subnet and security group
  • Launch a Talos EC2 instance (t3.medium) with machine config as user-data
  • Associate the EIP (no auto-assigned public IP)
  • Apply the machine configuration via Talos API
  • Bootstrap etcd
  • Retrieve the kubeconfig
  • Create the ingress-nginx namespace with privileged pod security
  • Install ArgoCD via Helm with a generated admin password
  • Create Route53 DNS records pointing to the EIP
  • Store all credentials in AWS Secrets Manager (dumpnet/cluster)

4. Configure local access

make kubeconfig    # merges kubeconfig into ~/.kube/config
make talosconfig   # merges talosconfig into ~/.talos/config

These pull from Secrets Manager and are safe to run repeatedly.

5. Bootstrap ArgoCD App of Apps

make bootstrap

One-time step that hands control of all apps to ArgoCD. After this, everything in manifests/ is managed automatically.

6. Get ArgoCD password

make argocd-password

Then log in at https://argocd.dumpnet.chat

Day-to-Day

  • Add a new app: add a manifest to manifests/ and values to charts/ — ArgoCD picks it up on next sync
  • Add a DNS record: add the subdomain to dns_records in terraform/terraform.tfvars and run make apply
  • Cluster access: make kubeconfig or make talosconfig (pulls from Secrets Manager)
  • Emergency talosctl access: make decrypt to get configs in /tmp

Makefile Reference

Command Description
make apply Create/update cluster infrastructure
make plan Preview infrastructure changes
make destroy Tear down everything
make bootstrap Apply App of Apps (one-time)
make kubeconfig Pull kubeconfig from Secrets Manager
make talosconfig Pull talosconfig from Secrets Manager
make argocd-password Print ArgoCD admin password
make decrypt Decrypt Talos configs to /tmp

Repo Structure

dumpnet-argo/
├── Makefile                  # top-level commands
├── apps/
│   └── apps.yaml             # ArgoCD App of Apps root
├── manifests/                # ArgoCD Application manifests
│   ├── argocd.yaml
│   ├── ingress-nginx.yaml
│   └── metrics-server.yaml
├── charts/                   # Helm values per app
│   ├── argocd/
│   │   └── values.yaml
│   └── ingress-nginx/
│       └── values.yaml
└── terraform/                # cluster infrastructure
    ├── main.tf
    ├── versions.tf
    ├── variables.tf
    ├── security_group.tf
    ├── network.tf
    ├── namespaces.tf
    ├── argocd.tf
    ├── dns.tf
    └── outputs.tf

Notes

  • The control plane taint is disabled via allowSchedulingOnControlPlanes: true in the Talos machine config — no manual taint removal needed
  • The ingress-nginx namespace is created by Terraform with pod-security.kubernetes.io/enforce=privileged to allow hostNetwork mode
  • ArgoCD manages itself after initial Helm install — future upgrades go through the repo
  • Sensitive files are gitignored entirely — there is no encrypt/commit workflow, only decrypt-to-tmp when needed