Repository navigation
Network Configuration
This Kubernetes cluster uses a comprehensive networking setup with several components working together to provide internal pod networking, service discovery, load balancing, and external access.
The network architecture consists of:
- Calico (via Tigera Operator) - For pod-to-pod networking
- CoreDNS - For internal DNS resolution
- MetalLB - For bare metal load balancing
- Traefik - As the ingress controller
- External Access - Via Cloudflare and/or Tor hidden services
Calico provides the networking fabric for pod-to-pod communication. In this deployment, we use the Tigera Operator to manage Calico.
Key configuration details:
- VXLAN encapsulation for pod traffic
- CIDR block 10.42.0.0/16 for pod IP addresses
- Container IP forwarding enabled
See the Calico Configuration page for more details.
CoreDNS is deployed as the cluster DNS provider, replacing the default K3s CoreDNS installation. The custom configuration allows for:
- A custom cluster domain (k8s.home.example.com)
- Integration with your home DNS system
- Service discovery for all applications
MetalLB provides Layer 2 load balancing for services, allowing the assignment of dedicated IP addresses to services without requiring a cloud provider.
Multiple IP address pools are configured for different purposes:
-
ingress-pool: For the Traefik ingress controller (172.16.100.251) -
default-pool: For general services -
mc-pool: For Minecraft servers -
transmission-pool: For Transmission BitTorrent client
See the MetalLB Configuration page for more details.
Traefik serves as the ingress controller, routing external traffic to the appropriate services within the cluster. It provides:
- TLS termination with Let's Encrypt certificates
- Route-based traffic management
- HTTP to HTTPS redirection
- Access to web-based dashboards for various services
For internal cluster functionality and external access, several DNS configurations are necessary:
- Cluster Domain: Set to k8s.home.example.com during K3s installation
-
Wildcard DNS Record: Create a wildcard record
*.k8s.home.example.compointing to your Traefik ingress IP - Service-Specific Records: Optional additional DNS records for specific services
For accessing services from outside your home network, several options are available:
- Cloudflare Proxy: Set up Cloudflare as a reverse proxy for your services, providing additional security and caching
- Tor Hidden Services: Configure Tor hidden services for alternative secure access
See the External Access page for detailed configuration steps.