Initial commit: imcu.ro HA k3s cluster manifests

- 3-node HA cluster (k3s v1.36.3+k3s1, embedded etcd) on Hetzner
- Netbird VPN mesh (wt0) for all cluster traffic
- Longhorn distributed storage (2 replicas, /var/lib/longhorn/)
- Traefik ingress (3 replicas, LoadBalancer on all node IPs)
- cert-manager with Let's Encrypt (auto-renewing TLS)
- Gitea (git + container registry) with SQLite on Longhorn
- 4 migrated workloads: wolsey, school-games (3 variants), randomly
- All HelmCharts and workload manifests as YAML
- deploy.sh for one-shot cluster setup
This commit is contained in:
2026-08-16 21:35:21 +03:00
commit fd7c529255
16 changed files with 1439 additions and 0 deletions
Executable
+37
View File
@@ -0,0 +1,37 @@
#!/bin/bash
# Deploy script - applies all manifests to the cluster
# Usage: SSH to k3s-fi-01 (or any node), then run:
# KUBECONFIG=/etc/rancher/k3s/k3s.yaml ./deploy.sh
#
# Or from local machine with kubectl configured:
# ./deploy.sh
set -e
KUBECTL="${KUBECTL:-k3s kubectl}"
if ! command -v k3s &>/dev/null; then
KUBECTL="kubectl"
fi
DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
echo "=== Applying namespaces ==="
$KUBECTL apply -f "$DIR/cluster-config/namespaces.yaml"
echo "=== Applying cluster config ==="
$KUBECTL apply -f "$DIR/cluster-config/clusterissuer.yaml"
echo "=== Applying HelmCharts ==="
$KUBECTL apply -f "$DIR/helmcharts/"
echo "=== Applying workloads ==="
for f in "$DIR"/workloads/*/*.yaml; do
echo " -> $(basename "$f")"
$KUBECTL apply -f "$f"
done
echo ""
echo "=== Done. Check status with: ==="
echo " $KUBECTL get pods -A"
echo " $KUBECTL get ingress -A"
echo " $KUBECTL get certificate -A"