{"id":43551686,"url":"https://github.com/jfreed-dev/turing-rk1-cluster","last_synced_at":"2026-02-03T19:34:09.681Z","repository":{"id":329957505,"uuid":"1120820507","full_name":"jfreed-dev/turing-rk1-cluster","owner":"jfreed-dev","description":"4-node bare-metal Kubernetes cluster on Turing RK1 (RK3588) with Talos Linux, Longhorn storage, and RKNN NPU support","archived":false,"fork":false,"pushed_at":"2026-01-26T14:24:07.000Z","size":353,"stargazers_count":3,"open_issues_count":2,"forks_count":1,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-01-26T17:56:04.465Z","etag":null,"topics":["arm64","armbian","bare-metal","edge-computing","homelab","k3s","kubernetes","longhorn","machine-learning","npu","rk3588","rknn","rockchip","talos-linux","turing-pi"],"latest_commit_sha":null,"homepage":"https://github.com/jfreed-dev/turing-rk1-cluster","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jfreed-dev.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-12-22T02:03:32.000Z","updated_at":"2026-01-26T02:58:04.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/jfreed-dev/turing-rk1-cluster","commit_stats":null,"previous_names":["jfreed-dev/turing-rk1-cluster"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/jfreed-dev/turing-rk1-cluster","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jfreed-dev%2Fturing-rk1-cluster","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jfreed-dev%2Fturing-rk1-cluster/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jfreed-dev%2Fturing-rk1-cluster/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jfreed-dev%2Fturing-rk1-cluster/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jfreed-dev","download_url":"https://codeload.github.com/jfreed-dev/turing-rk1-cluster/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jfreed-dev%2Fturing-rk1-cluster/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29054763,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-03T15:43:47.601Z","status":"ssl_error","status_checked_at":"2026-02-03T15:43:46.709Z","response_time":96,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["arm64","armbian","bare-metal","edge-computing","homelab","k3s","kubernetes","longhorn","machine-learning","npu","rk3588","rknn","rockchip","talos-linux","turing-pi"],"created_at":"2026-02-03T19:34:09.546Z","updated_at":"2026-02-03T19:34:09.674Z","avatar_url":"https://github.com/jfreed-dev.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Turing RK1 Kubernetes Cluster\n\n[![GitHub Release](https://img.shields.io/github/v/release/jfreed-dev/turing-rk1-cluster)](https://github.com/jfreed-dev/turing-rk1-cluster/releases)\n[![Lint](https://github.com/jfreed-dev/turing-rk1-cluster/actions/workflows/lint.yml/badge.svg)](https://github.com/jfreed-dev/turing-rk1-cluster/actions/workflows/lint.yml)\n[![CodeQL](https://github.com/jfreed-dev/turing-rk1-cluster/actions/workflows/codeql.yml/badge.svg)](https://github.com/jfreed-dev/turing-rk1-cluster/actions/workflows/codeql.yml)\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![Talos](https://img.shields.io/badge/Talos-v1.11.6-blue)](https://www.talos.dev/)\n[![K3s](https://img.shields.io/badge/K3s-v1.31-FFC61C)](https://k3s.io/)\n[![Kubernetes](https://img.shields.io/badge/Kubernetes-v1.34.1-326CE5?logo=kubernetes\u0026logoColor=white)](https://kubernetes.io/)\n\nA 4-node bare-metal Kubernetes cluster built on Turing RK1 compute modules, supporting both **Talos Linux** and **K3s on Armbian** distributions. Designed for edge computing, AI/ML workloads with NPU acceleration, and distributed storage.\n\n## Choose Your Distribution\n\n| Distribution | Best For | NPU/GPU | Shell Access |\n|--------------|----------|---------|--------------|\n| **[Talos Linux](docs/INSTALLATION.md)** | Production, Security | No | API only |\n| **[K3s on Armbian](docs/INSTALLATION-K3S.md)** | Development, AI/ML | **Yes** | SSH |\n\nSee [docs/COMPARISON.md](docs/COMPARISON.md) for detailed feature comparison.\n\n### Quick Start\n\n```bash\n# Talos Linux (automated deployment)\n./scripts/deploy-talos-cluster.sh prereq    # Check prerequisites\n./scripts/deploy-talos-cluster.sh deploy    # Full deployment\n\n# K3s on Armbian\n./scripts/setup-k3s-node.sh   # Run on each node\n./scripts/deploy-k3s-cluster.sh  # Deploy from workstation\n\n# Check cluster status (works with both distributions)\n./scripts/talos-cluster-status.sh           # Auto-detects and shows health summary\n```\n\n\u003e **Note**: This project is under active development. See [CONTRIBUTING.md](CONTRIBUTING.md) for how to get involved.\n\n## Hardware Summary\n\n### Turing Pi 2 Board\n\n| Component | Specification |\n|-----------|---------------|\n| Form Factor | Mini-ITX |\n| Node Slots | 4x CM4/RK1 compatible |\n| BMC | Integrated management controller |\n| Networking | Gigabit Ethernet per node |\n| Storage | NVMe slot per node |\n\n### Turing RK1 Compute Modules (x4)\n\n| Component | Specification |\n|-----------|---------------|\n| SoC | Rockchip RK3588 |\n| CPU | 4x Cortex-A76 @ 2.4GHz + 4x Cortex-A55 @ 1.8GHz |\n| RAM | 16GB / 32GB LPDDR4X |\n| GPU | Mali-G610 MP4 |\n| NPU | 6 TOPS (INT8) - *see limitations* |\n| eMMC | 32GB (system disk) |\n| NVMe | 500GB Crucial P3 (worker nodes) |\n\n### Cluster Topology\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│                    Turing Pi 2 BMC                          │\n│                     10.10.88.70                             │\n├─────────────┬─────────────┬─────────────┬───────────────────┤\n│   Node 1    │   Node 2    │   Node 3    │      Node 4       │\n│ Control Pl. │   Worker    │   Worker    │      Worker       │\n│ 10.10.88.73 │ 10.10.88.74 │ 10.10.88.75 │   10.10.88.76     │\n│   32GB eMMC │ 32GB + 500GB│ 32GB + 500GB│  32GB + 500GB     │\n└─────────────┴─────────────┴─────────────┴───────────────────┘\n```\n\n### Total Resources\n\n| Resource | Amount |\n|----------|--------|\n| CPU Cores | 32 (8 per node) |\n| RAM | 64-128GB |\n| Storage (eMMC) | 128GB |\n| Storage (NVMe) | 1.5TB |\n| Network | 4x 1Gbps |\n\n---\n\n## Software Stack\n\n### Operating System\n\n| Component | Version | Notes |\n|-----------|---------|-------|\n| Talos Linux | v1.11.6 | Immutable, API-driven Kubernetes OS |\n| Linux Kernel | 6.12.62 | Mainline kernel (ARM64) |\n\n### Kubernetes Components\n\n| Component | Version | Purpose |\n|-----------|---------|---------|\n| Kubernetes | v1.34.1 | Container orchestration |\n| containerd | v2.1.5 | Container runtime |\n| etcd | Bundled | Distributed key-value store |\n\n### Storage\n\n| Component | Version | Purpose |\n|-----------|---------|---------|\n| Longhorn | Latest | Distributed block storage |\n| CSI Driver | Longhorn | Persistent volume provisioning |\n\n### Networking\n\n| Component | Version | Purpose |\n|-----------|---------|---------|\n| Flannel | Bundled | Pod networking (CNI) |\n| MetalLB | Latest | LoadBalancer for bare-metal |\n| NGINX Ingress | Latest | HTTP/HTTPS ingress controller |\n\n### Monitoring\n\n| Component | Version | Purpose |\n|-----------|---------|---------|\n| Prometheus | Latest | Metrics collection \u0026 alerting |\n| Grafana | Latest | Visualization \u0026 dashboards |\n| Alertmanager | Latest | Alert routing \u0026 management |\n| Node Exporter | Latest | Host-level metrics |\n| kube-state-metrics | Latest | Kubernetes state metrics |\n\n### Management\n\n| Component | Version | Purpose |\n|-----------|---------|---------|\n| Portainer Agent | v2.33.6 | Remote cluster management |\n| talosctl | v1.11.6 | Talos node management |\n| kubectl | v1.34.x | Kubernetes CLI |\n| Helm | v3.x | Package manager |\n\n---\n\n## Cluster Capabilities\n\n### What This Cluster Can Do\n\n**Container Orchestration**\n- Run containerized workloads across 4 nodes\n- Automatic pod scheduling and load balancing\n- Rolling updates and rollbacks\n- Health monitoring and self-healing\n\n**Distributed Storage**\n- ~1.5TB distributed storage via Longhorn\n- Volume replication across nodes (configurable 1-3 replicas)\n- Snapshots and backups\n- Dynamic volume provisioning\n- High-performance NVMe-backed storage class\n\n**Networking**\n- LoadBalancer services via MetalLB (10.10.88.80-89)\n- HTTP/HTTPS ingress with NGINX\n- TLS termination\n- Path and host-based routing\n\n**Edge Computing**\n- Low-power ARM64 architecture (~10W per node)\n- Compact form factor (Mini-ITX)\n- Suitable for remote/edge deployments\n\n**Development \u0026 Testing**\n- Full Kubernetes API compatibility\n- Helm chart deployment\n- GitOps-ready\n- Multi-architecture image support (arm64)\n\n**AI/ML Workloads (CPU)**\n- ARM64-optimized inference\n- NumPy, ONNX Runtime, PyTorch (CPU)\n- ~12 GFLOPS matrix operations per node\n- Distributed training/inference across nodes\n\n**Monitoring \u0026 Observability**\n- Full cluster metrics via Prometheus\n- Pre-configured Grafana dashboards\n- Node, pod, and container-level monitoring\n- Alerting with Alertmanager\n- External Docker host monitoring support\n- Longhorn storage metrics integration\n\n---\n\n## Limitations \u0026 Known Issues\n\n### NPU Not Available (Talos Only)\n\n| Issue | Status | Details |\n|-------|--------|---------|\n| RK3588 NPU inaccessible | **Talos: Not Supported** | Talos uses mainline Linux kernel which lacks Rockchip's proprietary RKNPU driver |\n| | **K3s/Armbian: Supported** | BSP kernel includes full NPU support |\n\n**Impact:** On Talos, the 6 TOPS NPU in each RK3588 cannot be used for hardware-accelerated AI inference.\n\n**Solutions:**\n1. **Use K3s on Armbian** - Full NPU support with RKNN SDK (see [docs/INSTALLATION-K3S.md](docs/INSTALLATION-K3S.md))\n2. Use CPU-based inference on Talos (ONNX Runtime, TensorFlow Lite)\n3. Wait for mainline NPU driver (in kernel review)\n\n### GPU Not Available (Talos Only)\n\n| Issue | Status | Details |\n|-------|--------|---------|\n| Mali-G610 GPU inaccessible | **Talos: Not Supported** | No GPU driver/passthrough in Talos |\n| | **K3s/Armbian: Supported** | OpenCL and Vulkan available |\n\n**Impact:** On Talos, no GPU acceleration for graphics or compute workloads. K3s on Armbian provides full GPU support.\n\n### Storage Limitations\n\n| Issue | Status | Details |\n|-------|--------|---------|\n| Control plane has no NVMe | By Design | Only workers have NVMe; CP uses eMMC only |\n| Single replica risk | Configurable | Default 3 replicas; 2-replica mode loses redundancy if node fails |\n\n### Network Limitations\n\n| Issue | Status | Details |\n|-------|--------|---------|\n| No native LoadBalancer | Mitigated | MetalLB provides L2 LoadBalancer functionality |\n| Single network interface | Hardware | Each node has only 1x 1Gbps NIC |\n\n### Talos-Specific Considerations\n\n| Issue | Details |\n|-------|---------|\n| Immutable filesystem | Cannot install packages; must use extensions or containers |\n| No SSH access | Nodes managed via `talosctl` API only |\n| Privileged namespaces | Many add-ons require `pod-security.kubernetes.io/enforce=privileged` label |\n\n### Known Bugs\n\n| Issue | Status | Workaround |\n|-------|--------|------------|\n| PodSecurity warnings on deploy | Expected | Label namespaces as privileged |\n| MetalLB speaker pods require privileges | Expected | Namespace is pre-labeled |\n\n---\n\n## Network Configuration\n\n### IP Allocation\n\n| Resource | IP Address | Port(s) |\n|----------|------------|---------|\n| BMC | 10.10.88.70 | 22 (SSH) |\n| Control Plane | 10.10.88.73 | 6443 (API) |\n| Worker 1 | 10.10.88.74 | - |\n| Worker 2 | 10.10.88.75 | - |\n| Worker 3 | 10.10.88.76 | - |\n| Ingress Controller | 10.10.88.80 | 80, 443 |\n| Portainer Agent | 10.10.88.81 | 9001 |\n| Available Pool | 10.10.88.82-89 | - |\n\n### Internal Networks\n\n| Network | CIDR | Purpose |\n|---------|------|---------|\n| Pod Network | 10.244.0.0/16 | Container IPs |\n| Service Network | 10.96.0.0/12 | ClusterIP services |\n\n---\n\n## Quick Access\n\n### Management URLs\n\n| Service | URL | Notes |\n|---------|-----|-------|\n| Kubernetes API | https://10.10.88.73:6443 | Use kubeconfig |\n| Grafana | http://grafana.local | Default: admin/admin |\n| Prometheus | http://prometheus.local | Metrics \u0026 queries |\n| Alertmanager | http://alertmanager.local | Alert management |\n| Longhorn UI | http://longhorn.local | Storage management |\n| Portainer | Your Portainer instance | Connect agent: `10.10.88.81:9001` |\n\nAdd to `/etc/hosts`:\n```\n10.10.88.80  grafana.local prometheus.local alertmanager.local longhorn.local\n```\n\n### CLI Access\n\n```bash\n# Set environment variables\nexport TALOSCONFIG=/path/to/cluster-config/talosconfig\nexport KUBECONFIG=/path/to/cluster-config/kubeconfig\n\n# Verify cluster\nkubectl get nodes\ntalosctl health\n```\n\n### BMC Access Setup\n\nThe deployment scripts require access to the Turing Pi BMC. Configure credentials by copying the example file:\n\n```bash\ncp .env.example .env\n# Edit .env with your BMC credentials\n```\n\nRequired variables in `.env`:\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `TPI_HOSTNAME` | BMC IP address | `10.10.88.70` |\n| `TPI_USERNAME` | BMC login username | - |\n| `TPI_PASSWORD` | BMC login password | - |\n| `USE_LOCAL_TPI` | Use local tpi CLI (1) or SSH to BMC (0) | `1` |\n\nTest BMC connectivity:\n\n```bash\n./scripts/wipe-cluster.sh status\n```\n\n---\n\n## Documentation Map\n\n### Primary Documentation\n\n| Document | Path | Description |\n|----------|------|-------------|\n| Docs Index | [docs/README.md](docs/README.md) | Documentation overview |\n| **Talos Installation** | [docs/INSTALLATION.md](docs/INSTALLATION.md) | Talos Linux setup guide |\n| **K3s Installation** | [docs/INSTALLATION-K3S.md](docs/INSTALLATION-K3S.md) | K3s on Armbian setup guide |\n| **Distribution Comparison** | [docs/COMPARISON.md](docs/COMPARISON.md) | Talos vs K3s feature matrix |\n| Architecture Diagrams | [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) | Visual cluster architecture (Mermaid) |\n| Storage Guide | [docs/STORAGE.md](docs/STORAGE.md) | Longhorn and NVMe configuration |\n| Networking Guide | [docs/NETWORKING.md](docs/NETWORKING.md) | MetalLB and Ingress setup |\n| Monitoring Guide | [docs/MONITORING.md](docs/MONITORING.md) | Prometheus, Grafana \u0026 external monitoring |\n| Quick Reference | [docs/QUICKREF.md](docs/QUICKREF.md) | Command cheatsheet |\n\n### Configuration Files\n\n| File | Path | Description |\n|------|------|-------------|\n| Talos Config | [cluster-config/talosconfig](cluster-config/talosconfig) | Talos CLI configuration |\n| Kubeconfig | [cluster-config/kubeconfig](cluster-config/kubeconfig) | Kubernetes access |\n| Cluster Secrets | [cluster-config/secrets.yaml](cluster-config/secrets.yaml) | **Keep secure!** |\n| MetalLB Config | [cluster-config/metallb-config.yaml](cluster-config/metallb-config.yaml) | IP pool configuration |\n| Ingress Config | [cluster-config/ingress-config.yaml](cluster-config/ingress-config.yaml) | Ingress rules |\n| Portainer Agent | [cluster-config/portainer-agent.yaml](cluster-config/portainer-agent.yaml) | Agent deployment |\n| Prometheus Values | [cluster-config/prometheus-values.yaml](cluster-config/prometheus-values.yaml) | Monitoring stack config |\n| External Scrape | [cluster-config/external-scrape-config.yaml](cluster-config/external-scrape-config.yaml) | Docker host monitoring |\n\n### Reference Documentation\n\n| Document | Path | Description |\n|----------|------|-------------|\n| Cluster Plan | [CLUSTER_PLAN.md](CLUSTER_PLAN.md) | Original deployment plan |\n| Talos Schematic | [talos-schematic.yaml](talos-schematic.yaml) | Custom image configuration |\n\n### External Resources\n\n| Resource | URL |\n|----------|-----|\n| Talos Documentation | https://www.talos.dev/docs/ |\n| K3s Documentation | https://docs.k3s.io/ |\n| Longhorn Documentation | https://longhorn.io/docs/ |\n| Turing Pi Documentation | https://docs.turingpi.com/ |\n| MetalLB Documentation | https://metallb.io/ |\n| NGINX Ingress | https://kubernetes.github.io/ingress-nginx/ |\n| Prometheus Documentation | https://prometheus.io/docs/ |\n| Grafana Documentation | https://grafana.com/docs/ |\n| RKNN SDK (NPU) | https://github.com/airockchip/rknn-toolkit2 |\n| RKLLM (LLM inference) | https://github.com/airockchip/rknn-llm |\n\n---\n\n## Directory Structure\n\n```\nturing-rk1-cluster/\n├── README.md                 # This file\n├── CLUSTER_PLAN.md           # Deployment planning document\n├── .env.example              # Environment variables template\n├── talos-schematic.yaml      # Talos image customization\n├── cluster-config/           # Cluster configurations\n│   ├── talosconfig           # Talos CLI config\n│   ├── kubeconfig            # Kubernetes access\n│   ├── secrets.yaml          # Cluster secrets (sensitive!)\n│   ├── controlplane.yaml     # Control plane config (Talos)\n│   ├── worker.yaml           # Worker config (Talos)\n│   ├── metallb-config.yaml   # MetalLB IP pool\n│   ├── ingress-config.yaml   # Ingress rules\n│   ├── prometheus-values.yaml # Monitoring stack config\n│   ├── external-scrape-config.yaml # External targets\n│   └── *.yaml                # Other configurations\n├── scripts/                  # Automation scripts\n│   ├── deploy-talos-cluster.sh # Automated Talos deployment\n│   ├── talos-cluster-status.sh # Cluster health and status checker\n│   ├── setup-k3s-node.sh     # Armbian node preparation\n│   ├── deploy-k3s-cluster.sh # K3s cluster deployment\n│   └── wipe-cluster.sh       # Cluster reset/migration tool\n├── docs/                     # Documentation\n│   ├── README.md             # Docs index\n│   ├── INSTALLATION.md       # Talos setup guide\n│   ├── INSTALLATION-K3S.md   # K3s on Armbian setup guide\n│   ├── COMPARISON.md         # Talos vs K3s comparison\n│   ├── ARCHITECTURE.md       # Cluster architecture diagrams\n│   ├── STORAGE.md            # Storage guide\n│   ├── NETWORKING.md         # Network guide\n│   ├── MONITORING.md         # Monitoring guide\n│   └── QUICKREF.md           # Quick reference\n├── images/                   # Talos images\n│   └── latest/\n│       └── metal-arm64.raw   # Current Talos image\n└── repo/                     # Submodules/repos\n    ├── sbc-rockchip/         # Talos Rockchip overlay\n    ├── rknn-toolkit2/        # RKNN SDK v2.3.2 (for K3s)\n    ├── rknn-llm/             # RKLLM v1.2.3 (for K3s)\n    └── rknn_model_zoo/       # Pre-built models (for K3s)\n```\n\n---\n\n## Security Notes\n\n1. **Secrets Protection**: `cluster-config/secrets.yaml` contains cluster credentials. Keep it secure and never commit to public repositories.\n\n2. **BMC Access**: The BMC (10.10.88.70) has full control over all nodes. Restrict network access appropriately.\n\n3. **Privileged Workloads**: Many add-ons require privileged namespace labels. Review security implications before deploying untrusted workloads.\n\n4. **Network Segmentation**: Consider isolating the cluster network (10.10.88.x) from untrusted networks.\n\n---\n\n## Contributing\n\nThis is a personal homelab cluster. Configuration files and documentation are provided as-is for reference.\n\n## License\n\nConfiguration files and documentation are provided under MIT license. Third-party components retain their original licenses.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjfreed-dev%2Fturing-rk1-cluster","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjfreed-dev%2Fturing-rk1-cluster","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjfreed-dev%2Fturing-rk1-cluster/lists"}