{"id":28955895,"url":"https://github.com/meroxdotdev/infrastructure","last_synced_at":"2026-05-07T17:38:44.458Z","repository":{"id":298878899,"uuid":"1001403032","full_name":"meroxdotdev/infrastructure","owner":"meroxdotdev","description":"🏠 Personal Homelab Infrastructure Production-ready Kubernetes homelab with Talos Linux and GitOps automation. Multi-node setup with automated deployments via Flux and comprehensive infrastructure management.","archived":false,"fork":false,"pushed_at":"2026-04-26T20:08:25.000Z","size":1941,"stargazers_count":13,"open_issues_count":1,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-04-26T20:29:20.989Z","etag":null,"topics":["blog","homelab","k8s","kubesearch","linux","server"],"latest_commit_sha":null,"homepage":"https://merox.dev/","language":"YAML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/meroxdotdev.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-06-13T10:15:00.000Z","updated_at":"2026-04-26T20:08:08.000Z","dependencies_parsed_at":"2026-01-12T14:03:06.519Z","dependency_job_id":null,"html_url":"https://github.com/meroxdotdev/infrastructure","commit_stats":null,"previous_names":["meroxdotdev/infrastructure"],"tags_count":0,"template":false,"template_full_name":"onedr0p/cluster-template","purl":"pkg:github/meroxdotdev/infrastructure","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/meroxdotdev%2Finfrastructure","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/meroxdotdev%2Finfrastructure/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/meroxdotdev%2Finfrastructure/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/meroxdotdev%2Finfrastructure/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/meroxdotdev","download_url":"https://codeload.github.com/meroxdotdev/infrastructure/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/meroxdotdev%2Finfrastructure/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32749318,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-05-07T02:14:30.463Z","status":"ssl_error","status_checked_at":"2026-05-07T02:14:29.405Z","response_time":62,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["blog","homelab","k8s","kubesearch","linux","server"],"created_at":"2025-06-23T20:12:04.415Z","updated_at":"2026-05-07T17:38:44.450Z","avatar_url":"https://github.com/meroxdotdev.png","language":"YAML","funding_links":[],"categories":[],"sub_categories":[],"readme":"# merox.dev Infrastructure\n\nGitOps-managed homelab: Kubernetes cluster (Talos + Flux) + VPS services + Infrastructure agent.\n\n---\n\n## Architecture\n\n```\n┌─────────────────────────────────────────────────────────┐\n│  VPS (Oracle/Hetzner)   cloudlab-infrastructure/        │\n│  ├── Traefik (reverse proxy + SSL)                      │\n│  ├── Pi-hole (DNS)                                      │\n│  ├── Portainer (container management)                   │\n│  ├── Homepage (dashboard)                               │\n│  ├── Netdata (monitoring)                               │\n│  └── Garage S3 (Longhorn backup target)                 │\n└────────────────────┬────────────────────────────────────┘\n                     │ Tailscale mesh VPN\n┌────────────────────▼────────────────────────────────────┐\n│  Kubernetes Cluster (Talos Linux + Flux)                │\n│  ├── Cilium (CNI + Gateway API)                         │\n│  ├── Longhorn (storage → backs up to Garage S3)         │\n│  ├── cert-manager, external-dns, k8s-gateway            │\n│  └── Apps: see kubernetes/apps/                         │\n└─────────────────────────────────────────────────────────┘\n                     │\n┌────────────────────▼────────────────────────────────────┐\n│  OpenClaw — openclaw.ai                                 │\n│  Telegram bot → Claude API → kubectl/docker             │\n│  Config: agent/openclaw.json  Skill: agent/skills/infra │\n└─────────────────────────────────────────────────────────┘\n```\n\n---\n\n## Hardware\n\n| Device | Role | Specs |\n|--------|------|-------|\n| Dell OptiPlex 3050 #1 | K8s node (Proxmox VM) | i5-6500T, 16GB, 128GB NVMe |\n| Dell OptiPlex 3050 #2 | K8s node (Proxmox VM) | i5-6500T, 16GB, 128GB NVMe |\n| Beelink GTi 13 Pro | K8s node (Proxmox VM) | i9-13900H, 64GB, 2x2TB NVMe |\n| Dell PowerEdge R720 | Proxmox Backup Server | 2x Xeon E5-2697v2, 192GB |\n| Synology DS223+ | NAS / NFS + Backup | 2x2TB HDD RAID1 |\n| XCY X44 | pfSense Firewall | N100, 8GB |\n| Oracle/Hetzner VPS | Off-site services | 4 vCPU, 8GB |\n\n---\n\n## Repository Layout\n\n```\ninfrastructure/\n├── cloudlab-infrastructure/    # Ansible — VPS provisioning\n├── kubernetes/\n│   ├── apps/                   # Flux app manifests (namespaced)\n│   ├── flux/                   # Flux bootstrap + HelmRepositories\n│   └── components/             # Shared Kustomize components (common, repos)\n├── talos/                      # Talos node configs + patches\n├── bootstrap/                  # Cluster bootstrap vars\n├── agent/                      # OpenClaw config template + infra skill\n│   ├── openclaw.json           # Gateway config (no secrets — use ~/.openclaw/.env)\n│   └── skills/infra/           # kubectl/docker skill context\n├── DEPLOY.md                   # Full rebuild + DR guide\n└── Taskfile.yaml               # Task runner (talosctl, flux, etc.)\n```\n\n---\n\n## Disaster Recovery\n\n\u003e Full step-by-step rebuild guide: **[DEPLOY.md](DEPLOY.md)**\n\n| Scenario | Where to look |\n|----------|--------------|\n| Full rebuild (new server + new cluster) | [DEPLOY.md — Phase 1 (VPS)](DEPLOY.md#phase-1--vps) → [Phase 2 (K8s)](DEPLOY.md#phase-2--kubernetes-cluster) → [Phase 3 (Agent)](DEPLOY.md#phase-3--agent-openclaw) |\n| Restore Longhorn volumes from S3 backup | [DEPLOY.md — Phase 2, step 7](DEPLOY.md#phase-2--kubernetes-cluster): `task restore:longhorn` |\n| New hardware (different IPs/disks) | [DEPLOY.md — Phase 2, step 3](DEPLOY.md#phase-2--kubernetes-cluster): update `talos/talconfig.yaml`, `cluster-vars.yaml`, `cilium/networks.yaml` |\n| Intel iGPU absent on new hardware | Remove `gpu.intel.com/i915` from `kubernetes/apps/default/jellyfin/app/helmrelease.yaml` and disable `intel-device-plugin-operator` |\n| Jellyfin restored but streaming slow / Tailscale broken | See **[docs/jellyfin-post-restore.md](docs/jellyfin-post-restore.md)** — manual UI steps required after every restore |\n| Re-install OpenClaw agent only | [DEPLOY.md — Phase 3](DEPLOY.md#phase-3--agent-openclaw) |\n\n**The two things to back up before decommissioning a server:**\n1. `age.key` — losing this = losing all SOPS-encrypted secrets\n2. `~/.openclaw/.env` — Anthropic API key, Telegram tokens\n\n---\n\n## Day-to-Day Operations\n\n### Cluster\n\n```bash\n# Check overall health\nkubectl get nodes\nkubectl get kustomizations -A\nkubectl get helmreleases -A\ncilium status\n\n# Force Flux sync\ntask reconcile\n\n# Regenerate Talos config (after editing talconfig.yaml)\ntask talos:generate-config\n\n# Apply updated config to a node\ntask talos:apply-node IP=10.57.57.80\n\n# Upgrade Talos on a node (update talenv.yaml version first)\ntask talos:upgrade-node IP=10.57.57.80\ntask talos:upgrade-k8s\n\n# Reset entire cluster (destructive)\ntask talos:reset\n```\n\n### VPS\n\n```bash\ncd cloudlab-infrastructure/\n\nmake health-check     # Verify all services running\nmake setup            # Full redeploy (idempotent)\nmake update           # OS package updates only\nmake check            # Dry-run (--check --diff)\nmake check-resources  # Disk, memory, Docker usage\nmake cleanup          # Remove unused Docker images/volumes\n```\n\n---\n\n## Troubleshooting\n\n### Flux not reconciling\n\n```bash\nflux get sources git -A                              # Check git source is reachable\nflux get kustomizations -A                           # Find which ks is failing\nflux logs --level=error                              # See error messages\nflux reconcile kustomization cluster-apps --with-source  # Force sync\n```\n\n### HelmRelease stuck / failed\n\n```bash\nkubectl get helmreleases -A | grep -v True\nflux logs --kind HelmRelease --name \u003cname\u003e -n \u003cnamespace\u003e\nflux reconcile helmrelease \u003cname\u003e -n \u003cnamespace\u003e --with-source\n# If values changed and Helm refuses — suspend + resume:\nflux suspend helmrelease \u003cname\u003e -n \u003cnamespace\u003e\nflux resume helmrelease \u003cname\u003e -n \u003cnamespace\u003e\n```\n\n### Pod issues\n\n```bash\nkubectl -n \u003cnamespace\u003e get pods -o wide\nkubectl -n \u003cnamespace\u003e describe pod \u003cpod\u003e\nkubectl -n \u003cnamespace\u003e logs \u003cpod\u003e -f\nkubectl -n \u003cnamespace\u003e logs \u003cpod\u003e --previous            # crashed container\nkubectl -n \u003cnamespace\u003e get events --sort-by='.metadata.creationTimestamp'\n```\n\n### Longhorn storage\n\n```bash\n# Volume / replica status\nkubectl -n longhorn-system get volumes\nkubectl -n longhorn-system get nodes.longhorn.io\n\n# Orphaned replicas (safe to delete)\nkubectl get orphan -n longhorn-system -o name | \\\n  xargs kubectl delete -n longhorn-system\n\n# Trigger a backup manually\n# Longhorn UI → Volume → Create Backup\n\n# Old snapshots cleanup\nkubectl get snapshots -n longhorn-system -o json | \\\n  jq -r '.items[] | select(.status.creationTime \u003c \"2025-01-01\") | .metadata.name' | \\\n  xargs kubectl delete snapshot -n longhorn-system\n```\n\n### Replacing a disk on a K8s node\n\n```bash\n# 1. Drain node\nkubectl drain \u003cnode\u003e --ignore-daemonsets --delete-emptydir-data\n\n# 2. In Proxmox: shutdown VM, swap physical disk, boot VM\n\n# 3. Regenerate and re-apply Talos config\ntask talos:generate-config\ntalosctl apply-config --insecure --nodes \u003cip\u003e \\\n  --file talos/clusterconfig/\u003cnode\u003e.yaml\n\n# 4. Uncordon\nkubectl uncordon \u003cnode\u003e\n\n# 5. If Longhorn disk UUID changed — evict replicas then re-add disk:\nkubectl -n longhorn-system patch node.longhorn.io \u003cnode\u003e \\\n  --type merge -p '{\"spec\":{\"evictionRequested\":true}}'\n# Wait for replicas to evacuate (~20-60 min), then remove old disk\n# and add new disk via Longhorn UI\n```\n\n\u003e Wait 1-2 hours between disk swaps to allow replica rebuild.\n\n### Node unreachable\n\n```bash\ntalosctl -n \u003cnode-ip\u003e health\ntalosctl -n \u003cnode-ip\u003e dmesg\ntalosctl -n \u003cnode-ip\u003e services\nkubectl describe node \u003cnode-name\u003e\n```\n\n### Garage S3 (Longhorn backup target)\n\n```bash\nssh root@\u003cvps-ip\u003e \"docker exec garage /garage status\"\nssh root@\u003cvps-ip\u003e \"docker exec garage /garage bucket list\"\n# Verify Longhorn can reach it:\nkubectl -n longhorn-system get secret minio-secret\n```\n\n---\n\n## Maintenance\n\n### Adding a node\n\n\u003e Keep an odd number of control plane nodes (1, 3, 5) for quorum.\n\n```bash\n# 1. Boot new node from Talos ISO — same schematic ID as existing nodes\n#    Get disk and MAC from the node in maintenance mode:\ntalosctl get disks -n \u003cnew-node-ip\u003e --insecure\ntalosctl get links -n \u003cnew-node-ip\u003e --insecure\n\n# 2. Add node entry to talos/talconfig.yaml with the disk and MAC above\n\n# 3. Regenerate config and apply to new node\ntask talos:generate-config\ntask talos:apply-node IP=\u003cnew-node-ip\u003e\n\n# 4. Node joins automatically — watch it become Ready:\nkubectl get nodes --watch\n```\n\n### Talos config changes\n\n```bash\n# After editing talos/talconfig.yaml or any patch:\ntask talos:generate-config\ntask talos:apply-node IP=\u003cnode-ip\u003e MODE=auto\n# MODE=auto applies without reboot if possible, reboots if required\n```\n\n### Dependency updates\n\nRenovate runs every weekend and opens PRs automatically for:\n- Helm chart versions (all HelmReleases)\n- Container image tags (annotated with `# renovate:`)\n- Talos / Kubernetes versions (`.mise.toml`)\n\nConfig: `.renovaterc.json5`\n\n### SOPS secret rotation\n\n```bash\n# Edit any encrypted secret\nsops kubernetes/apps/\u003cnamespace\u003e/\u003capp\u003e/app/secret.sops.yaml\n\n# Re-encrypt all secrets after AGE key rotation\nfind . -name \"*.sops.*\" -exec sops updatekeys {} \\;\n```\n\n### Security\n\n- Kubernetes secrets encrypted with SOPS (AGE key — back up manually)\n- Ansible secrets in encrypted Vault (`cloudlab-infrastructure/`)\n- All traffic via Tailscale mesh or Cloudflare Tunnel (no open ports)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmeroxdotdev%2Finfrastructure","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmeroxdotdev%2Finfrastructure","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmeroxdotdev%2Finfrastructure/lists"}