Skip to content

Network Configuration

Aleksei Sviridkin edited this page Apr 22, 2025 · 1 revision

Network Configuration

This Kubernetes cluster uses a comprehensive networking setup with several components working together to provide internal pod networking, service discovery, load balancing, and external access.

Overview

The network architecture consists of:

  1. Calico (via Tigera Operator) - For pod-to-pod networking
  2. CoreDNS - For internal DNS resolution
  3. MetalLB - For bare metal load balancing
  4. Traefik - As the ingress controller
  5. External Access - Via Cloudflare and/or Tor hidden services

Pod Networking with Calico

Calico provides the networking fabric for pod-to-pod communication. In this deployment, we use the Tigera Operator to manage Calico.

Key configuration details:

  • VXLAN encapsulation for pod traffic
  • CIDR block 10.42.0.0/16 for pod IP addresses
  • Container IP forwarding enabled

See the Calico Configuration page for more details.

Service Discovery with CoreDNS

CoreDNS is deployed as the cluster DNS provider, replacing the default K3s CoreDNS installation. The custom configuration allows for:

  • A custom cluster domain (k8s.home.example.com)
  • Integration with your home DNS system
  • Service discovery for all applications

Load Balancing with MetalLB

MetalLB provides Layer 2 load balancing for services, allowing the assignment of dedicated IP addresses to services without requiring a cloud provider.

Multiple IP address pools are configured for different purposes:

  • ingress-pool: For the Traefik ingress controller (172.16.100.251)
  • default-pool: For general services
  • mc-pool: For Minecraft servers
  • transmission-pool: For Transmission BitTorrent client

See the MetalLB Configuration page for more details.

Ingress with Traefik

Traefik serves as the ingress controller, routing external traffic to the appropriate services within the cluster. It provides:

  • TLS termination with Let's Encrypt certificates
  • Route-based traffic management
  • HTTP to HTTPS redirection
  • Access to web-based dashboards for various services

DNS Configuration

For internal cluster functionality and external access, several DNS configurations are necessary:

  1. Cluster Domain: Set to k8s.home.example.com during K3s installation
  2. Wildcard DNS Record: Create a wildcard record *.k8s.home.example.com pointing to your Traefik ingress IP
  3. Service-Specific Records: Optional additional DNS records for specific services

External Access Options

For accessing services from outside your home network, several options are available:

  1. Cloudflare Proxy: Set up Cloudflare as a reverse proxy for your services, providing additional security and caching
  2. Tor Hidden Services: Configure Tor hidden services for alternative secure access

See the External Access page for detailed configuration steps.

Clone this wiki locally