Setup
- RKE2 with two control-plane nodes and an external etcd witness for quorum
- Managed with Rancher, persistent storage with Longhorn
- TLS certificates issued automatically by cert-manager and Let’s Encrypt
- A private container registry for every image
From the internet to the basement
Public traffic arrives at a small VPS and travels through an L2TP/IPsec tunnel to a MikroTik router on the home network. Behind it an nginx ingress routes requests to the services in the cluster.
Build and deploy
Jenkins builds every project as a container image and pushes it to the registry. Helm charts and manifests are versioned in a separate infrastructure repository. New sites like this one go to a preview first and only go live after a manual approval.
What it teaches me
The cluster is my training ground for operations: high availability, storage, certificates, mail delivery and networking. I am currently going deeper on the networking side with the CCNA series.