4.9 KiB
4.9 KiB
dumpnet-argo
GitOps cluster management for dumpnet — a single-node Talos/Kubernetes cluster on AWS, managed via ArgoCD.
Architecture
- Talos Linux on EC2 (t3.medium) — immutable, API-driven OS
- ArgoCD — GitOps continuous delivery
- ingress-nginx — ingress controller (hostNetwork mode)
- App of Apps pattern — all workloads defined in
manifests/ - Terraform — cluster infrastructure and bootstrap
- SOPS + age — secret encryption for sensitive cluster files
Prerequisites
terraformkubectltalosctlsops+age- AWS CLI configured (
aws configure)
Secrets Setup (first time only)
Sensitive files (talosconfig, controlplane.yaml, worker.yaml) are gitignored and never stored in the repo in any form. They are managed as follows:
- Cluster credentials (kubeconfig, talosconfig, ArgoCD password) → stored in AWS Secrets Manager at
dumpnet/cluster - Talos machine configs → encrypted with SOPS + age, stored outside the repo
- Age private key → lives at
~/.age/key.txt— back this up securely
To decrypt Talos configs to /tmp for one-off talosctl use:
make decrypt
# files appear at /tmp/controlplane.yaml, /tmp/worker.yaml, /tmp/talosconfig
# they are not persisted after reboot
First-Time Setup
1. Clone and init
git clone https://forge.keane.sh/ian/dumpnet-argo.git
cd dumpnet-argo
make init
2. Configure variables
cp terraform/terraform.tfvars.example terraform/terraform.tfvars
# edit terraform/terraform.tfvars with your hosted_zone_id
3. Spin up the cluster
make apply
This will:
- Allocate an EIP
- Create a dedicated subnet and security group
- Launch a Talos EC2 instance (t3.medium) with machine config as user-data
- Associate the EIP (no auto-assigned public IP)
- Apply the machine configuration via Talos API
- Bootstrap etcd
- Retrieve the kubeconfig
- Create the
ingress-nginxnamespace with privileged pod security - Install ArgoCD via Helm with a generated admin password
- Create Route53 DNS records pointing to the EIP
- Store all credentials in AWS Secrets Manager (
dumpnet/cluster)
4. Post-apply bootstrap (one-time)
make post-apply
This script:
- Fetches kubeconfig and talosconfig from Secrets Manager
- Waits for the node to be ready
- Imports the ingress-nginx namespace into Terraform state
- Applies the ArgoCD App of Apps
5. Get ArgoCD password
make argocd-password
Then log in at https://argocd.dumpnet.chat — ArgoCD will finish deploying ingress-nginx and metrics-server automatically.
Day-to-Day
- Add a new app: add a manifest to
manifests/and values tocharts/— ArgoCD picks it up on next sync - Add a DNS record: add the subdomain to
dns_recordsinterraform/terraform.tfvarsand runmake apply - Cluster access:
make kubeconfigormake talosconfig(pulls from Secrets Manager) - Emergency talosctl access:
make decryptto get configs in/tmp
Makefile Reference
| Command | Description |
|---|---|
make apply |
Create/update cluster infrastructure |
make plan |
Preview infrastructure changes |
make destroy |
Tear down everything |
make post-apply |
One-time bootstrap after fresh cluster creation |
make bootstrap |
Apply App of Apps only |
make kubeconfig |
Pull kubeconfig from Secrets Manager |
make talosconfig |
Pull talosconfig from Secrets Manager |
make argocd-password |
Print ArgoCD admin password |
make decrypt |
Decrypt Talos configs to /tmp |
Repo Structure
dumpnet-argo/
├── Makefile # top-level commands
├── scripts/
│ └── post-apply.sh # one-time bootstrap after fresh cluster
├── apps/
│ └── apps.yaml # ArgoCD App of Apps root
├── manifests/ # ArgoCD Application manifests
│ ├── argocd.yaml
│ ├── ingress-nginx.yaml
│ └── metrics-server.yaml
├── charts/ # Helm values per app
│ ├── argocd/
│ │ └── values.yaml
│ └── ingress-nginx/
│ └── values.yaml
└── terraform/ # cluster infrastructure
├── main.tf
├── versions.tf
├── variables.tf
├── security_group.tf
├── network.tf
├── namespaces.tf
├── argocd.tf
├── dns.tf
└── outputs.tf
Notes
- The control plane taint is disabled via
allowSchedulingOnControlPlanes: truein the Talos machine config — no manual taint removal needed - The
ingress-nginxnamespace is created by Terraform withpod-security.kubernetes.io/enforce=privilegedto allow hostNetwork mode - ArgoCD manages itself after initial Helm install — future upgrades go through the repo
- Sensitive files are gitignored entirely — there is no encrypt/commit workflow, only decrypt-to-tmp when needed