{"id":31644498,"url":"https://github.com/alfi0812/talos","last_synced_at":"2026-05-16T11:32:08.515Z","repository":{"id":317435099,"uuid":"1064205702","full_name":"alfi0812/talos","owner":"alfi0812","description":"Personal Talos Cluster","archived":false,"fork":false,"pushed_at":"2025-09-30T20:17:29.000Z","size":93,"stargazers_count":1,"open_issues_count":1,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-09-30T22:14:54.942Z","etag":null,"topics":["clustertool","gitops","helm","kubernetes","kubesearch"],"latest_commit_sha":null,"homepage":"https://alfi0812.de","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/alfi0812.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-09-25T17:35:44.000Z","updated_at":"2025-09-30T20:17:32.000Z","dependencies_parsed_at":"2025-09-30T22:15:06.131Z","dependency_job_id":"279b7706-70fd-4570-87f5-642df7c51b84","html_url":"https://github.com/alfi0812/talos","commit_stats":null,"previous_names":["alfi0812/talos"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/alfi0812/talos","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/alfi0812%2Ftalos","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/alfi0812%2Ftalos/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/alfi0812%2Ftalos/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/alfi0812%2Ftalos/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/alfi0812","download_url":"https://codeload.github.com/alfi0812/talos/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/alfi0812%2Ftalos/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":278722768,"owners_count":26034461,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-07T02:00:06.786Z","response_time":59,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["clustertool","gitops","helm","kubernetes","kubesearch"],"created_at":"2025-10-07T04:53:27.379Z","updated_at":"2026-05-16T11:32:08.507Z","avatar_url":"https://github.com/alfi0812.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n# 🧊 Personal Talos Kubernetes Cluster\n\n*A self-hosted, GitOps-driven Kubernetes cluster built on Talos Linux, focused on reliability, observability, and clean automation.*\n\n[![Truenas](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Ftruenas_version\u0026style=for-the-badge\u0026logo=truenas\u0026logoColor=white\u0026label=%20\u0026color=blue)](https://www.truenas.com/)\u0026nbsp;\u0026nbsp;\n[![Talos](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Ftalos_version\u0026style=for-the-badge\u0026logo=talos\u0026logoColor=white\u0026label=%20\u0026color=blue)](https://www.talos.dev/)\u0026nbsp;\u0026nbsp;\n[![Kubernetes](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fkubernetes_version\u0026style=for-the-badge\u0026logo=kubernetes\u0026logoColor=white\u0026label=%20\u0026color=blue)](https://www.kubernetes.io/)\u0026nbsp;\u0026nbsp;\n[![Flux](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fflux_version\u0026style=for-the-badge\u0026logo=flux\u0026logoColor=white\u0026color=blue\u0026label=%20)](https://fluxcd.io)\u0026nbsp;\u0026nbsp;\n\n[![Home-Internet](https://img.shields.io/endpoint?url=https%3A%2F%2Fstatus.boemeltrein.nl%2Fapi%2Fv1%2Fendpoints%2Fbuddy_ping-(buddy)%2Fhealth%2Fbadge.shields\u0026style=for-the-badge\u0026logo=ubiquiti\u0026logoColor=white\u0026label=Home%20Internet)](https://status.goeppel.dev)\u0026nbsp;\u0026nbsp;\n[![Status-Page](https://img.shields.io/endpoint?url=https%3A%2F%2Fstatus.boemeltrein.nl%2Fapi%2Fv1%2Fendpoints%2Fbuddy_status-page-(buddy)%2Fhealth%2Fbadge.shields\u0026style=for-the-badge\u0026logo=statuspage\u0026logoColor=white\u0026label=Status%20Page)](https://status.goeppel.dev)\u0026nbsp;\u0026nbsp;\n[![Alertmanager](https://img.shields.io/endpoint?url=https%3A%2F%2Fstatus.boemeltrein.nl%2Fapi%2Fv1%2Fendpoints%2Fbuddy_heartbeat-(buddy)%2Fhealth%2Fbadge.shields\u0026style=for-the-badge\u0026logo=prometheus\u0026logoColor=white\u0026label=Alertmanager)](https://status.goeppel.dev)\n\n[![Age-Days](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_age_days\u0026style=flat-square\u0026label=Age)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n[![Uptime-Days](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_uptime_days\u0026style=flat-square\u0026label=Uptime)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n[![Node-Count](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_node_count\u0026style=flat-square\u0026label=Nodes)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n[![Pod-Count](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_pod_count\u0026style=flat-square\u0026label=Pods)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n[![CPU-Usage](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_cpu_usage\u0026style=flat-square\u0026label=CPU)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n[![Memory-Usage](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_memory_usage\u0026style=flat-square\u0026label=Memory)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n[![Alerts](https://img.shields.io/endpoint?url=https%3A%2F%2Fkromgo.alfi0812.de%2Fcluster_alert_count\u0026style=flat-square\u0026label=Alerts)](https://github.com/kashalls/kromgo)\u0026nbsp;\u0026nbsp;\n\n\u003c/div\u003e\n\n---\n\n## 📌 Overview\n\nThis repository contains the full **GitOps-managed configuration** for my personal Kubernetes cluster.\nThe cluster runs on **Talos Linux** and is fully declarative: every component, application, and configuration is defined in Git and continuously reconciled using **FluxCD**.\n\nKey goals of this setup:\n\n* 🔁 **Reproducibility** – rebuild the entire cluster from Git\n* 🔒 **Immutability \u0026 Security** – minimal OS, no SSH, API-driven management\n* 📈 **Observability** – metrics, alerts, and public status visibility\n* 🤖 **Automation-first** – updates, deployments, and testing without manual intervention\n\n---\n\n## 🧠 Design Decisions\n\n### Why Talos Linux?\n- Immutable, minimal OS reduces attack surface\n- No SSH or package manager\n- Fully API-driven, ideal for GitOps-based Kubernetes clusters\n\n### Why FluxCD?\n- Continuous reconciliation instead of one-shot deployments\n- Native Kubernetes integration\n- Works seamlessly with SOPS for encrypted secrets\n\n### Why a Single-Node Cluster?\n- Simplifies operations and reduces complexity\n- Ideal for homelab and learning environments\n- Focuses on reproducibility rather than high availability\n\n---\n\n## 📡 Networking Assumptions\n\nThis cluster assumes a **simple and reliable home network environment**.\n\n- The Talos VM relies on the Fritzbox router for primary network connectivity\n- No advanced routing, BGP, or multi-homing is assumed\n- Networking is optimized for simplicity and stability rather than redundancy\n- External access is handled via managed ingress and tunnels where required\n\n---\n\n## 🧩 Core Components\n\n| Component          | Description                                                                        |\n| ------------------ | -----------------------------------------------------------------------------------|\n| **Kubernetes**     | Container orchestration platform for running and managing workloads                |\n| **Talos Linux**    | Immutable, API-driven Linux distribution purpose-built for Kubernetes              |\n| **FluxCD**         | GitOps operator used for continuous reconciliation of cluster state                |\n| **Mend Renovate**  | Automatically tracks and updates container images and dependencies                 |\n| **GitHub Actions** | CI pipelines for validation, linting, and testing of cluster configs               |\n| **SOPS**           | Encryption of all secrets and credentials stored in Git, integrated with FluxCD    |\n| **ForgeTool**    | Bootstrap tool from TrueForge used to build the basic Cluster Structure and Setup  |\n\n---\n\n## 🗂 Directory Structure\n\n~~~text\nclusters/\n└── main/\n    ├── components/   # Common components applied to multiple parts of the cluster\n    ├── kubernetes/   # Applications and Kubernetes workloads\n    └── talos/        # Talos Linux machine and cluster configuration\n\nrepositories/\n├── entries/           # Repository entry definitions\n├── git/               # Flux GitRepository sources\n├── helm/              # Flux HelmRepository sources\n└── oci/               # Flux OCIRepository sources\n~~~\n\n---\n\n## 🔐 Secrets Management\n\nAll secrets and credentials are stored in this repository **encrypted with SOPS**.\n\n- Secrets are committed to Git in encrypted form\n- Decryption happens inside the cluster via FluxCD\n- Decryption keys are managed externally and are never stored in Git\n- This enables full GitOps workflows without exposing sensitive data\n\n---\n\n## ☁️ Cloud \u0026 External Dependencies\n\n| Service        | Usage                                                     |\n| -------------- | --------------------------------------------------------- |\n| **Cloudflare** | DNS management, tunnels, and S3-compatible object storage |\n| **GitHub**     | Source control, CI, and GitOps reconciliation source      |\n\n---\n\n## 🖥 Hardware\n\n### TrueNAS Storage Server\n\n| Component             | Specification                    |\n| --------------------- | -------------------------------- |\n| **CPU**               | AMD Ryzen 7 5700G                |\n| **RAM**               | 64 GB DDR4 @ 3200 MHz            |\n| **SAS Controller**    | LSI SAS 9300-16i                 |\n| **Boot Drive**        | 1× Crucial P310 500 GB NVMe      |\n| **Metadata VDEV**     | 2× Samsung 870 EVO 1 TB (Mirror) |\n| **Data VDEV**         | 6× Seagate Exos X24 16 TB HDD    |\n| **Remote Management** | NanoKVM PCIe Edition             |\n\n### Talos Kubernetes Node\n\n| Component             | Specification                  |\n| --------------------- | ------------------------------ |\n| **CPU**               | AMD Ryzen 9 9950X              |\n| **RAM**               | 128 GB DDR5 @ 5600 MHz         |\n| **Storage**           | 2 TB Crucial P3 Plus NVMe      |\n| **GPU**               | Sparkle Intel Arc A770 (16 GB) |\n| **Remote Management** | NanoKVM PCIe Edition           |\n\n---\n\n## 📊 Monitoring \u0026 Status\n\n* 📈 **Metrics \u0026 Dashboards** via Prometheus-compatible tooling\n* 🚨 **Alerting** with Alertmanager\n* 🌍 **Public Status Page** for service and connectivity visibility\n* 🧮 **Cluster Statistics** exposed via Kromgo and Shields.io\n\n---\n\n## 🙏 Acknowledgements\n\nThis cluster is heavily inspired by and built upon the excellent work of:\n\n* **TrueForge** – [https://trueforge.org/](https://trueforge.org/)\n* **Home Operations** – [https://github.com/home-operations](https://github.com/home-operations)\n\nTheir open-source contributions and documentation made this setup possible.\n\n---\n\n\u003e ⚠️ **Note**\n\u003e This repository is public for transparency and learning purposes. Secrets and credentials **are stored in Git in encrypted form** using **SOPS**.\n\u003e Decryption keys are managed externally and are **not** committed to the repository, ensuring sensitive values remain protected.\n\n\u003e 🧪 This cluster is used as a learning, testing, and long-running homelab environment.  \n\u003e Configurations may evolve as new Kubernetes, Talos, or GitOps features are evaluated.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Falfi0812%2Ftalos","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Falfi0812%2Ftalos","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Falfi0812%2Ftalos/lists"}