mirror of
https://github.com/dredx/prole.git
synced 2026-09-24 17:34:31 +00:00
- Monitoring: Migrated from manual Grafana/Prometheus manifests to kube-prometheus-stack based setup in etc/init_monitoring.sh. Removed old manifest files from deploy/ and k8s/. - Installer Core: Refactored installer with new modules for actions, environment handling, and UI screens. Enhanced Milestone logic to support advanced configuration (ArgoCD, Registry namespaces, Kerberos flags, etc.). - Service & Init Scripts: Updated multiple initialization scripts (init_*.sh) for better integration with OpenBao, Kerberos, and the new monitoring stack. Added new scripts for Nginx Ingress, Ollama parsing, and K3D route fixes. - Infrastructure: Enhanced Samba AD DC Ansible role with realm derivation, provisioning guidance, and group management. Updated K3s role tasks. - Configuration: Refined default settings in conf/ to align with the new deployment architecture. - App & Tools: Updated prole-app Swift code and prole.sh for improved environment variable handling and installation flow.
162 lines
5.3 KiB
Markdown
162 lines
5.3 KiB
Markdown
<div align="center">
|
|
<a href="https://svc.prole.org">
|
|
|
|
```
|
|
# ###########################
|
|
# ╭──────────────────────╮ #
|
|
# │ _ │ #
|
|
# │ _ __ _ _ ___| |___ │ #
|
|
# │ | '_ \ '_/ _ \ / -_) │ #
|
|
# │ | .__/_| \___/_\___| │ #
|
|
# │ |_| │ #
|
|
# ╰──────────────────────╯ #
|
|
# ###########################
|
|
```
|
|
</a>
|
|
</div>
|
|
|
|
# prole-db is a PostgreSQL database for Prole
|
|
# claudnative-pg cluster setup
|
|
|
|
# brew install pre-reqs
|
|
```commandline
|
|
brew install docker docker-compose
|
|
brew install kubernetes-cli kubectx k3d
|
|
brew install mysql-client python@3.14 python-tk@3.14 postgresql@17
|
|
```
|
|
|
|
# start k3d cluster
|
|
k3d cluster create prole-service-cluster -a 2 --registry-create k8s-prole-org-registry:k8s.prole.org:5000 --api-port 10.0.0.205:6443
|
|
k3d cluster create prole-dev-cluster -a 2 --api-port 0.0.0.0:6443
|
|
|
|
# build prole-db Docker image
|
|
```commandline
|
|
cd prole-db
|
|
docker build -t prole-db:17.7-037 .
|
|
k3d image import prole-db:17.7-037 -c prole-service-cluster
|
|
docker tag prole-db:17.7-037 k8s.prole.org:5000/prole-db:17.7-037
|
|
docker push k8s.prole.org:5000/prole-db:17.7-037
|
|
# vim ~/.docker/daemon.json
|
|
# "insecure-registries": [ "k3.localhost:5000", "k8s.prole.org:5000" ]
|
|
```
|
|
|
|
# install cloudnative postgres operator
|
|
```commandline
|
|
kubectl apply --server-side -f https://raw.githubusercontent.com/cloudnative-pg/cloudnative-pg/release-1.27/releases/cnpg-1.27.0.yaml
|
|
./etc/init_monitoring.sh
|
|
kubectl apply -f cloudnative-pg-prole-dB.yaml
|
|
```
|
|
|
|
# check status
|
|
```commandline
|
|
kubectl cnpg status prole-db
|
|
kubectl cnpg psql prole-db
|
|
```
|
|
|
|
# port forwards
|
|
```commandline
|
|
kubectl port-forward -n monitoring svc/kps-kube-prometheus-stack-prometheus 9090 &
|
|
kubectl -n kubernetes-dashboard port-forward svc/kubernetes-dashboard-kong-proxy 8443:443 &
|
|
kubectl port-forward svc/prole-db-rw 5432:5432 --address 0.0.0.0 &
|
|
kubectl port-forward -n monitoring svc/kps-grafana 3000:80 --address 0.0.0.0 &
|
|
```
|
|
|
|
# useful tool
|
|
```commandline
|
|
kubectl krew install view-secret
|
|
```
|
|
|
|
# Install from the cert-manager release manifest
|
|
```commandline
|
|
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.19.1/cert-manager.yaml
|
|
```
|
|
|
|
# install cmctl
|
|
```commandline
|
|
kubectl apply -f https://github.com/cert-manager/cert-manager/releases/download/v1.19.1/cert-manager.yaml
|
|
brew install cmctl
|
|
cmctl check api
|
|
|
|
```
|
|
|
|
# Install Barman-Cloud backup
|
|
```commandline
|
|
kubectl apply -f https://github.com/cloudnative-pg/plugin-barman-cloud/releases/download/v0.8.0/manifest.yaml
|
|
```
|
|
|
|
# prole logo cmd
|
|
# figlet -f small "prole" | boxes -d ansi-rounded | boxes -d shell
|
|
|
|
|
|
## K3s HA install for Prole (Pi cluster + local k3d agents)
|
|
|
|
This repository includes scripts to create an HA K3s control plane across Raspberry Pi hosts and attach local k3d agents.
|
|
|
|
Topology overview:
|
|
- raspberry.prole.org → first K3s server (embedded etcd)
|
|
- pi.prole.org → additional K3s server (recommended for HA)
|
|
- This host (developer machine) → local k3d agents that join the remote K3s server
|
|
|
|
Prerequisites:
|
|
- k3sup: https://github.com/alexellis/k3sup
|
|
- k3d: https://k3d.io/
|
|
- kubectl
|
|
- SSH access to the Pis (defaults assume user `pi` and key `~/.ssh/id_rsa`)
|
|
|
|
1) Install first K3s server on raspberry.prole.org
|
|
```bash
|
|
cd k3s
|
|
# Optional env overrides:
|
|
# export K3S_FIRST_SERVER_HOST=raspberry.prole.org
|
|
# export K3S_FIRST_SERVER_USER=pi
|
|
# export K3S_SSH_KEY=$HOME/.ssh/id_rsa
|
|
# export K3S_VERSION=v1.30.6+k3s1
|
|
# export K3S_EXTRA_ARGS="--cluster-init --tls-san raspberry.prole.org"
|
|
./install_k3s_first_server.sh
|
|
```
|
|
|
|
2) Join pi.prole.org as an additional HA server (optional but recommended)
|
|
```bash
|
|
cd k3s
|
|
# Optional env overrides:
|
|
# export K3S_EXISTING_SERVER_HOST=raspberry.prole.org
|
|
# export K3S_EXISTING_SERVER_USER=pi
|
|
# export K3S_ADDITIONAL_SERVER_HOST=pi.prole.org
|
|
# export K3S_ADDITIONAL_SERVER_USER=pi
|
|
# export K3S_SSH_KEY=$HOME/.ssh/id_rsa
|
|
# export K3S_VERSION=v1.30.6+k3s1
|
|
# export K3S_EXTRA_ARGS="--tls-san raspberry.prole.org --tls-san pi.prole.org"
|
|
./join_k3s_additional_server.sh
|
|
```
|
|
|
|
3) Get the K3s node token from the first server
|
|
```bash
|
|
cd k3s
|
|
# Optional env overrides:
|
|
# export K3S_SERVER_HOST=raspberry.prole.org
|
|
# export K3S_SERVER_USER=pi
|
|
# export K3S_SSH_KEY=$HOME/.ssh/id_rsa
|
|
TOKEN=$(./get_remote_k3s_node_token.sh)
|
|
echo "K3s token: $TOKEN"
|
|
```
|
|
|
|
4) Create a local k3d agents-only cluster that joins the remote K3s server
|
|
```bash
|
|
cd k3s
|
|
# Required: provide the token
|
|
export K3S_REMOTE_TOKEN="$TOKEN"
|
|
# Optional env overrides:
|
|
# export K3D_CLUSTER_NAME=prole-remote-agents
|
|
# export K3D_AGENTS=2
|
|
# export K3D_IMAGE=rancher/k3s:v1.30.6-k3s1
|
|
# export K3D_REGISTRY_CONFIG=$HOME/dev/prole/k3s/registries.yaml
|
|
# export K3S_REMOTE_SERVER_HOST=raspberry.prole.org
|
|
# export K3S_REMOTE_SERVER_PORT=6443
|
|
./create_k3d_join_remote_agents.sh
|
|
```
|
|
|
|
Notes:
|
|
- The scripts default to embedded etcd HA. For true quorum, use at least 3 servers where possible. With two servers, loss of one server can cause loss of quorum; consider adding a third server or running an external etcd.
|
|
- If you prefer an external datastore (e.g., MySQL/PG/etcd), adjust `K3S_EXTRA_ARGS` in the server install to set `--datastore-endpoint=...` and remove `--cluster-init`.
|
|
- The local k3d cluster creates only agents that connect to the remote control-plane; it does not run a separate control-plane locally.
|