1
0
Fork 0
mirror of https://github.com/poseidon/typhoon synced 2024-05-11 10:06:12 +02:00
typhoon/flatcar-linux/bare-metal/index.html

2275 lines
69 KiB
HTML

<!doctype html>
<html lang="en" class="no-js">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<meta name="description" content="A minimal and free Kubernetes distribution">
<meta name="author" content="Dalton Hubble">
<link rel="prev" href="../azure/">
<link rel="next" href="../digitalocean/">
<link rel="icon" href="../../img/favicon.ico">
<meta name="generator" content="mkdocs-1.5.3, mkdocs-material-9.5.14">
<title>Bare-Metal - Typhoon</title>
<link rel="stylesheet" href="../../assets/stylesheets/main.10ba22f1.min.css">
<link rel="stylesheet" href="../../assets/stylesheets/palette.06af60db.min.css">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto+Slab:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
<style>:root{--md-text-font:"Roboto Slab";--md-code-font:"Roboto Mono"}</style>
<script>__md_scope=new URL("../..",location),__md_hash=e=>[...e].reduce((e,_)=>(e<<5)-e+_.charCodeAt(0),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:site" content="@typhoon8s">
<meta name="twitter:creator" content="@dghubble">
<meta name="twitter:title" content="Minimal and free Kubernetes clusters">
<meta name="twitter:description" content="Kubernetes clusters for AWS, Azure, bare-metal, Google Cloud, and DigitalOcean">
<meta name="twitter:image" content="https://storage.googleapis.com/poseidon/typhoon-twitter-card.png">
</head>
<body dir="ltr" data-md-color-scheme="default" data-md-color-primary="blue" data-md-color-accent="pink">
<input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
<input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
<label class="md-overlay" for="__drawer"></label>
<div data-md-component="skip">
<a href="#bare-metal" class="md-skip">
Skip to content
</a>
</div>
<div data-md-component="announce">
</div>
<header class="md-header" data-md-component="header">
<nav class="md-header__inner md-grid" aria-label="Header">
<a href="../.." title="Typhoon" class="md-header__button md-logo" aria-label="Typhoon" data-md-component="logo">
<img src="../../img/spin.png" alt="logo">
</a>
<label class="md-header__button md-icon" for="__drawer">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3V6m0 5h18v2H3v-2m0 5h18v2H3v-2Z"/></svg>
</label>
<div class="md-header__title" data-md-component="header-title">
<div class="md-header__ellipsis">
<div class="md-header__topic">
<span class="md-ellipsis">
Typhoon
</span>
</div>
<div class="md-header__topic" data-md-component="header-topic">
<span class="md-ellipsis">
Bare-Metal
</span>
</div>
</div>
</div>
<label class="md-header__button md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5Z"/></svg>
</label>
<div class="md-search" data-md-component="search" role="dialog">
<label class="md-search__overlay" for="__search"></label>
<div class="md-search__inner" role="search">
<form class="md-search__form" name="search">
<input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
<label class="md-search__icon md-icon" for="__search">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5Z"/></svg>
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12Z"/></svg>
</label>
<nav class="md-search__options" aria-label="Search">
<button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12 19 6.41Z"/></svg>
</button>
</nav>
</form>
<div class="md-search__output">
<div class="md-search__scrollwrap" data-md-scrollfix>
<div class="md-search-result" data-md-component="search-result">
<div class="md-search-result__meta">
Initializing search
</div>
<ol class="md-search-result__list" role="presentation"></ol>
</div>
</div>
</div>
</div>
</div>
<div class="md-header__source">
<a href="https://github.com/poseidon/typhoon" title="Go to repository" class="md-source" data-md-component="source">
<div class="md-source__icon md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 480 512"><!--! Font Awesome Free 6.5.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2023 Fonticons, Inc.--><path d="M186.1 328.7c0 20.9-10.9 55.1-36.7 55.1s-36.7-34.2-36.7-55.1 10.9-55.1 36.7-55.1 36.7 34.2 36.7 55.1zM480 278.2c0 31.9-3.2 65.7-17.5 95-37.9 76.6-142.1 74.8-216.7 74.8-75.8 0-186.2 2.7-225.6-74.8-14.6-29-20.2-63.1-20.2-95 0-41.9 13.9-81.5 41.5-113.6-5.2-15.8-7.7-32.4-7.7-48.8 0-21.5 4.9-32.3 14.6-51.8 45.3 0 74.3 9 108.8 36 29-6.9 58.8-10 88.7-10 27 0 54.2 2.9 80.4 9.2 34-26.7 63-35.2 107.8-35.2 9.8 19.5 14.6 30.3 14.6 51.8 0 16.4-2.6 32.7-7.7 48.2 27.5 32.4 39 72.3 39 114.2zm-64.3 50.5c0-43.9-26.7-82.6-73.5-82.6-18.9 0-37 3.4-56 6-14.9 2.3-29.8 3.2-45.1 3.2-15.2 0-30.1-.9-45.1-3.2-18.7-2.6-37-6-56-6-46.8 0-73.5 38.7-73.5 82.6 0 87.8 80.4 101.3 150.4 101.3h48.2c70.3 0 150.6-13.4 150.6-101.3zm-82.6-55.1c-25.8 0-36.7 34.2-36.7 55.1s10.9 55.1 36.7 55.1 36.7-34.2 36.7-55.1-10.9-55.1-36.7-55.1z"/></svg>
</div>
<div class="md-source__repository">
poseidon/typhoon
</div>
</a>
</div>
</nav>
</header>
<div class="md-container" data-md-component="container">
<nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
<div class="md-grid">
<ul class="md-tabs__list">
<li class="md-tabs__item">
<a href="../.." class="md-tabs__link">
Home
</a>
</li>
<li class="md-tabs__item">
<a href="../../announce/" class="md-tabs__link">
Announce
</a>
</li>
<li class="md-tabs__item">
<a href="../../architecture/concepts/" class="md-tabs__link">
Architecture
</a>
</li>
<li class="md-tabs__item">
<a href="../../fedora-coreos/aws/" class="md-tabs__link">
Fedora CoreOS
</a>
</li>
<li class="md-tabs__item md-tabs__item--active">
<a href="../aws/" class="md-tabs__link">
Flatcar Linux
</a>
</li>
<li class="md-tabs__item">
<a href="../../topics/maintenance/" class="md-tabs__link">
Topics
</a>
</li>
<li class="md-tabs__item">
<a href="../../advanced/overview/" class="md-tabs__link">
Advanced
</a>
</li>
<li class="md-tabs__item">
<a href="../../addons/overview/" class="md-tabs__link">
Addons
</a>
</li>
</ul>
</div>
</nav>
<main class="md-main" data-md-component="main">
<div class="md-main__inner md-grid">
<div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
<label class="md-nav__title" for="__drawer">
<a href="../.." title="Typhoon" class="md-nav__button md-logo" aria-label="Typhoon" data-md-component="logo">
<img src="../../img/spin.png" alt="logo">
</a>
Typhoon
</label>
<div class="md-nav__source">
<a href="https://github.com/poseidon/typhoon" title="Go to repository" class="md-source" data-md-component="source">
<div class="md-source__icon md-icon">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 480 512"><!--! Font Awesome Free 6.5.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2023 Fonticons, Inc.--><path d="M186.1 328.7c0 20.9-10.9 55.1-36.7 55.1s-36.7-34.2-36.7-55.1 10.9-55.1 36.7-55.1 36.7 34.2 36.7 55.1zM480 278.2c0 31.9-3.2 65.7-17.5 95-37.9 76.6-142.1 74.8-216.7 74.8-75.8 0-186.2 2.7-225.6-74.8-14.6-29-20.2-63.1-20.2-95 0-41.9 13.9-81.5 41.5-113.6-5.2-15.8-7.7-32.4-7.7-48.8 0-21.5 4.9-32.3 14.6-51.8 45.3 0 74.3 9 108.8 36 29-6.9 58.8-10 88.7-10 27 0 54.2 2.9 80.4 9.2 34-26.7 63-35.2 107.8-35.2 9.8 19.5 14.6 30.3 14.6 51.8 0 16.4-2.6 32.7-7.7 48.2 27.5 32.4 39 72.3 39 114.2zm-64.3 50.5c0-43.9-26.7-82.6-73.5-82.6-18.9 0-37 3.4-56 6-14.9 2.3-29.8 3.2-45.1 3.2-15.2 0-30.1-.9-45.1-3.2-18.7-2.6-37-6-56-6-46.8 0-73.5 38.7-73.5 82.6 0 87.8 80.4 101.3 150.4 101.3h48.2c70.3 0 150.6-13.4 150.6-101.3zm-82.6-55.1c-25.8 0-36.7 34.2-36.7 55.1s10.9 55.1 36.7 55.1 36.7-34.2 36.7-55.1-10.9-55.1-36.7-55.1z"/></svg>
</div>
<div class="md-source__repository">
poseidon/typhoon
</div>
</a>
</div>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../.." class="md-nav__link">
<span class="md-ellipsis">
Home
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../announce/" class="md-nav__link">
<span class="md-ellipsis">
Announce
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_3" >
<label class="md-nav__link" for="__nav_3" id="__nav_3_label" tabindex="0">
<span class="md-ellipsis">
Architecture
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_3_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_3">
<span class="md-nav__icon md-icon"></span>
Architecture
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../architecture/concepts/" class="md-nav__link">
<span class="md-ellipsis">
Concepts
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../architecture/operating-systems/" class="md-nav__link">
<span class="md-ellipsis">
Operating Systems
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../architecture/aws/" class="md-nav__link">
<span class="md-ellipsis">
AWS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../architecture/azure/" class="md-nav__link">
<span class="md-ellipsis">
Azure
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../architecture/bare-metal/" class="md-nav__link">
<span class="md-ellipsis">
Bare-Metal
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../architecture/digitalocean/" class="md-nav__link">
<span class="md-ellipsis">
DigitalOcean
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../architecture/google-cloud/" class="md-nav__link">
<span class="md-ellipsis">
Google Cloud
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_4" >
<label class="md-nav__link" for="__nav_4" id="__nav_4_label" tabindex="0">
<span class="md-ellipsis">
Fedora CoreOS
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_4_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_4">
<span class="md-nav__icon md-icon"></span>
Fedora CoreOS
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../fedora-coreos/aws/" class="md-nav__link">
<span class="md-ellipsis">
AWS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../fedora-coreos/azure/" class="md-nav__link">
<span class="md-ellipsis">
Azure
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../fedora-coreos/bare-metal/" class="md-nav__link">
<span class="md-ellipsis">
Bare-Metal
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../fedora-coreos/digitalocean/" class="md-nav__link">
<span class="md-ellipsis">
DigitalOcean
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../fedora-coreos/google-cloud/" class="md-nav__link">
<span class="md-ellipsis">
Google Cloud
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--active md-nav__item--section md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_5" checked>
<label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="">
<span class="md-ellipsis">
Flatcar Linux
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="true">
<label class="md-nav__title" for="__nav_5">
<span class="md-nav__icon md-icon"></span>
Flatcar Linux
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../aws/" class="md-nav__link">
<span class="md-ellipsis">
AWS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../azure/" class="md-nav__link">
<span class="md-ellipsis">
Azure
</span>
</a>
</li>
<li class="md-nav__item md-nav__item--active">
<input class="md-nav__toggle md-toggle" type="checkbox" id="__toc">
<label class="md-nav__link md-nav__link--active" for="__toc">
<span class="md-ellipsis">
Bare-Metal
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<a href="./" class="md-nav__link md-nav__link--active">
<span class="md-ellipsis">
Bare-Metal
</span>
</a>
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#requirements" class="md-nav__link">
<span class="md-ellipsis">
Requirements
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#machines" class="md-nav__link">
<span class="md-ellipsis">
Machines
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#dns" class="md-nav__link">
<span class="md-ellipsis">
DNS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#matchbox" class="md-nav__link">
<span class="md-ellipsis">
Matchbox
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#pxe-environment" class="md-nav__link">
<span class="md-ellipsis">
PXE Environment
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#terraform-setup" class="md-nav__link">
<span class="md-ellipsis">
Terraform Setup
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#provider" class="md-nav__link">
<span class="md-ellipsis">
Provider
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#cluster" class="md-nav__link">
<span class="md-ellipsis">
Cluster
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ssh-agent" class="md-nav__link">
<span class="md-ellipsis">
ssh-agent
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#apply" class="md-nav__link">
<span class="md-ellipsis">
Apply
</span>
</a>
<nav class="md-nav" aria-label="Apply">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#power" class="md-nav__link">
<span class="md-ellipsis">
Power
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#bootstrap" class="md-nav__link">
<span class="md-ellipsis">
Bootstrap
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#verify" class="md-nav__link">
<span class="md-ellipsis">
Verify
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#going-further" class="md-nav__link">
<span class="md-ellipsis">
Going Further
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#variables" class="md-nav__link">
<span class="md-ellipsis">
Variables
</span>
</a>
<nav class="md-nav" aria-label="Variables">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#required" class="md-nav__link">
<span class="md-ellipsis">
Required
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#optional" class="md-nav__link">
<span class="md-ellipsis">
Optional
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="../digitalocean/" class="md-nav__link">
<span class="md-ellipsis">
DigitalOcean
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../google-cloud/" class="md-nav__link">
<span class="md-ellipsis">
Google Cloud
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_6" >
<label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
<span class="md-ellipsis">
Topics
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_6">
<span class="md-nav__icon md-icon"></span>
Topics
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../topics/maintenance/" class="md-nav__link">
<span class="md-ellipsis">
Maintenance
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../topics/hardware/" class="md-nav__link">
<span class="md-ellipsis">
Hardware
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../topics/security/" class="md-nav__link">
<span class="md-ellipsis">
Security
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../topics/performance/" class="md-nav__link">
<span class="md-ellipsis">
Performance
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../topics/faq/" class="md-nav__link">
<span class="md-ellipsis">
FAQ
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_7" >
<label class="md-nav__link" for="__nav_7" id="__nav_7_label" tabindex="0">
<span class="md-ellipsis">
Advanced
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_7_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_7">
<span class="md-nav__icon md-icon"></span>
Advanced
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../advanced/overview/" class="md-nav__link">
<span class="md-ellipsis">
Overview
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../advanced/arm64/" class="md-nav__link">
<span class="md-ellipsis">
ARM64
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../advanced/customization/" class="md-nav__link">
<span class="md-ellipsis">
Customization
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../advanced/nodes/" class="md-nav__link">
<span class="md-ellipsis">
Nodes
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../advanced/worker-pools/" class="md-nav__link">
<span class="md-ellipsis">
Worker Pools
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item md-nav__item--nested">
<input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_8" >
<label class="md-nav__link" for="__nav_8" id="__nav_8_label" tabindex="0">
<span class="md-ellipsis">
Addons
</span>
<span class="md-nav__icon md-icon"></span>
</label>
<nav class="md-nav" data-md-level="1" aria-labelledby="__nav_8_label" aria-expanded="false">
<label class="md-nav__title" for="__nav_8">
<span class="md-nav__icon md-icon"></span>
Addons
</label>
<ul class="md-nav__list" data-md-scrollfix>
<li class="md-nav__item">
<a href="../../addons/overview/" class="md-nav__link">
<span class="md-ellipsis">
Overview
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../addons/ingress/" class="md-nav__link">
<span class="md-ellipsis">
Nginx Ingress
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../addons/prometheus/" class="md-nav__link">
<span class="md-ellipsis">
Prometheus
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../addons/grafana/" class="md-nav__link">
<span class="md-ellipsis">
Grafana
</span>
</a>
</li>
<li class="md-nav__item">
<a href="../../addons/fleetlock/" class="md-nav__link">
<span class="md-ellipsis">
fleetlock
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" >
<div class="md-sidebar__scrollwrap">
<div class="md-sidebar__inner">
<nav class="md-nav md-nav--secondary" aria-label="Table of contents">
<label class="md-nav__title" for="__toc">
<span class="md-nav__icon md-icon"></span>
Table of contents
</label>
<ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
<li class="md-nav__item">
<a href="#requirements" class="md-nav__link">
<span class="md-ellipsis">
Requirements
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#machines" class="md-nav__link">
<span class="md-ellipsis">
Machines
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#dns" class="md-nav__link">
<span class="md-ellipsis">
DNS
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#matchbox" class="md-nav__link">
<span class="md-ellipsis">
Matchbox
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#pxe-environment" class="md-nav__link">
<span class="md-ellipsis">
PXE Environment
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#terraform-setup" class="md-nav__link">
<span class="md-ellipsis">
Terraform Setup
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#provider" class="md-nav__link">
<span class="md-ellipsis">
Provider
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#cluster" class="md-nav__link">
<span class="md-ellipsis">
Cluster
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#ssh-agent" class="md-nav__link">
<span class="md-ellipsis">
ssh-agent
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#apply" class="md-nav__link">
<span class="md-ellipsis">
Apply
</span>
</a>
<nav class="md-nav" aria-label="Apply">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#power" class="md-nav__link">
<span class="md-ellipsis">
Power
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#bootstrap" class="md-nav__link">
<span class="md-ellipsis">
Bootstrap
</span>
</a>
</li>
</ul>
</nav>
</li>
<li class="md-nav__item">
<a href="#verify" class="md-nav__link">
<span class="md-ellipsis">
Verify
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#going-further" class="md-nav__link">
<span class="md-ellipsis">
Going Further
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#variables" class="md-nav__link">
<span class="md-ellipsis">
Variables
</span>
</a>
<nav class="md-nav" aria-label="Variables">
<ul class="md-nav__list">
<li class="md-nav__item">
<a href="#required" class="md-nav__link">
<span class="md-ellipsis">
Required
</span>
</a>
</li>
<li class="md-nav__item">
<a href="#optional" class="md-nav__link">
<span class="md-ellipsis">
Optional
</span>
</a>
</li>
</ul>
</nav>
</li>
</ul>
</nav>
</div>
</div>
</div>
<div class="md-content" data-md-component="content">
<article class="md-content__inner md-typeset">
<h1 id="bare-metal">Bare-Metal<a class="headerlink" href="#bare-metal" title="Permanent link">&para;</a></h1>
<p>In this tutorial, we'll network boot and provision a Kubernetes v1.29.3 cluster on bare-metal with Flatcar Linux.</p>
<p>First, we'll deploy a <a href="https://github.com/poseidon/matchbox">Matchbox</a> service and setup a network boot environment. Then, we'll declare a Kubernetes cluster using the Typhoon Terraform module and power on machines. On PXE boot, machines will install Container Linux to disk, reboot into the disk install, and provision themselves as Kubernetes controllers or workers via Ignition.</p>
<p>Controller hosts are provisioned to run an <code>etcd-member</code> peer and a <code>kubelet</code> service. Worker hosts run a <code>kubelet</code> service. Controller nodes run <code>kube-apiserver</code>, <code>kube-scheduler</code>, <code>kube-controller-manager</code>, and <code>coredns</code> while <code>kube-proxy</code> and <code>calico</code> (or <code>flannel</code>) run on every node. A generated <code>kubeconfig</code> provides <code>kubectl</code> access to the cluster.</p>
<h2 id="requirements">Requirements<a class="headerlink" href="#requirements" title="Permanent link">&para;</a></h2>
<ul>
<li>Machines with 2GB RAM, 30GB disk, PXE-enabled NIC, IPMI</li>
<li>PXE-enabled <a href="https://coreos.com/matchbox/docs/latest/network-setup.html">network boot</a> environment (with HTTPS support)</li>
<li>Matchbox v0.6+ deployment with API enabled</li>
<li>Matchbox credentials <code>client.crt</code>, <code>client.key</code>, <code>ca.crt</code></li>
<li>Terraform v0.13.0+</li>
</ul>
<h2 id="machines">Machines<a class="headerlink" href="#machines" title="Permanent link">&para;</a></h2>
<p>Collect a MAC address from each machine. For machines with multiple PXE-enabled NICs, pick one of the MAC addresses. MAC addresses will be used to match machines to profiles during network boot.</p>
<ul>
<li>52:54:00:a1:9c:ae (node1)</li>
<li>52:54:00:b2:2f:86 (node2)</li>
<li>52:54:00:c3:61:77 (node3)</li>
</ul>
<p>Configure each machine to boot from the disk through IPMI or the BIOS menu.</p>
<div class="highlight"><pre><span></span><code>ipmitool -H node1 -U USER -P PASS chassis bootdev disk options=persistent
</code></pre></div>
<p>During provisioning, you'll explicitly set the boot device to <code>pxe</code> for the next boot only. Machines will install (overwrite) the operating system to disk on PXE boot and reboot into the disk install.</p>
<div class="admonition tip">
<p>Ask your hardware vendor to provide MACs and preconfigure IPMI, if possible. With it, you can rack new servers, <code>terraform apply</code> with new info, and power on machines that network boot and provision into clusters.</p>
</div>
<h2 id="dns">DNS<a class="headerlink" href="#dns" title="Permanent link">&para;</a></h2>
<p>Create a DNS A (or AAAA) record for each node's default interface. Create a record that resolves to each controller node (or re-use the node record if there's one controller).</p>
<ul>
<li>node1.example.com (node1)</li>
<li>node2.example.com (node2)</li>
<li>node3.example.com (node3)</li>
<li>myk8s.example.com (node1)</li>
</ul>
<p>Cluster nodes will be configured to refer to the control plane and themselves by these fully qualified names and they'll be used in generated TLS certificates.</p>
<h2 id="matchbox">Matchbox<a class="headerlink" href="#matchbox" title="Permanent link">&para;</a></h2>
<p>Matchbox is an open-source app that matches network-booted bare-metal machines (based on labels like MAC, UUID, etc.) to profiles to automate cluster provisioning.</p>
<p>Install Matchbox on a Kubernetes cluster or dedicated server.</p>
<ul>
<li>Installing on <a href="https://coreos.com/matchbox/docs/latest/deployment.html#kubernetes">Kubernetes</a> (recommended)</li>
<li>Installing on a <a href="https://coreos.com/matchbox/docs/latest/deployment.html#download">server</a></li>
</ul>
<div class="admonition tip">
<p class="admonition-title">Tip</p>
<p>Deploy Matchbox as service that can be accessed by all of your bare-metal machines globally. This provides a single endpoint to use Terraform to manage bare-metal clusters at different sites. Typhoon will never include secrets in provisioning user-data so you may even deploy matchbox publicly.</p>
</div>
<p>Matchbox provides a TLS client-authenticated API that clients, like Terraform, can use to manage machine matching and profiles. Think of it like a cloud provider API, but for creating bare-metal instances.</p>
<p><a href="https://coreos.com/matchbox/docs/latest/deployment.html#generate-tls-certificates">Generate TLS</a> client credentials. Save the <code>ca.crt</code>, <code>client.crt</code>, and <code>client.key</code> where they can be referenced in Terraform configs.</p>
<div class="highlight"><pre><span></span><code>mv<span class="w"> </span>ca.crt<span class="w"> </span>client.crt<span class="w"> </span>client.key<span class="w"> </span>~/.config/matchbox/
</code></pre></div>
<p>Verify the matchbox read-only HTTP endpoints are accessible (port is configurable).</p>
<div class="highlight"><pre><span></span><code>$<span class="w"> </span>curl<span class="w"> </span>http://matchbox.example.com:8080
matchbox
</code></pre></div>
<p>Verify your TLS client certificate and key can be used to access the Matchbox API (port is configurable).</p>
<div class="highlight"><pre><span></span><code>$<span class="w"> </span>openssl<span class="w"> </span>s_client<span class="w"> </span>-connect<span class="w"> </span>matchbox.example.com:8081<span class="w"> </span><span class="se">\</span>
<span class="w"> </span>-CAfile<span class="w"> </span>~/.config/matchbox/ca.crt<span class="w"> </span><span class="se">\</span>
<span class="w"> </span>-cert<span class="w"> </span>~/.config/matchbox/client.crt<span class="w"> </span><span class="se">\</span>
<span class="w"> </span>-key<span class="w"> </span>~/.config/matchbox/client.key
</code></pre></div>
<h2 id="pxe-environment">PXE Environment<a class="headerlink" href="#pxe-environment" title="Permanent link">&para;</a></h2>
<p>Create an iPXE-enabled network boot environment. Configure PXE clients to chainload <a href="http://ipxe.org/cmd">iPXE</a> firmware compiled to support <a href="https://ipxe.org/crypto">HTTPS downloads</a>. Instruct iPXE clients to chainload from your Matchbox service's <code>/boot.ipxe</code> endpoint.</p>
<p>For networks already supporting iPXE clients, you can add a <code>default.ipxe</code> config.</p>
<div class="highlight"><pre><span></span><code><span class="c1"># /var/www/html/ipxe/default.ipxe</span>
<span class="na">chain http</span><span class="o">:</span><span class="s">//matchbox.foo:8080/boot.ipxe</span>
</code></pre></div>
<p>For networks with Ubiquiti Routers, you can <a href="/topics/hardware/#ubiquiti">configure the router</a> itself to chainload machines to iPXE and Matchbox.</p>
<p>Read about the <a href="https://coreos.com/matchbox/docs/latest/network-setup.html">many ways</a> to setup a compliant iPXE-enabled network. There is quite a bit of flexibility:</p>
<ul>
<li>Continue using existing DHCP, TFTP, or DNS services</li>
<li>Configure specific machines, subnets, or architectures to chainload from Matchbox</li>
<li>Place Matchbox behind a menu entry (timeout and default to Matchbox)</li>
</ul>
<div class="admonition note">
<p>TFTP chainloading to modern boot firmware, like iPXE, avoids issues with old NICs and allows faster transfer protocols like HTTP to be used.</p>
</div>
<div class="admonition warning">
<p class="admonition-title">Warning</p>
<p>Compile iPXE from <a href="https://github.com/ipxe/ipxe">source</a> with support for <a href="https://ipxe.org/crypto">HTTPS downloads</a>. iPXE's pre-built firmware binaries do not enable this. If you cannot enable HTTPS downloads, set <code>download_protocol = "http"</code> (discouraged).</p>
</div>
<h2 id="terraform-setup">Terraform Setup<a class="headerlink" href="#terraform-setup" title="Permanent link">&para;</a></h2>
<p>Install <a href="https://www.terraform.io/downloads.html">Terraform</a> v0.13.0+ on your system.</p>
<div class="highlight"><pre><span></span><code>$<span class="w"> </span>terraform<span class="w"> </span>version
Terraform<span class="w"> </span>v1.0.0
</code></pre></div>
<p>Read <a href="/architecture/concepts/">concepts</a> to learn about Terraform, modules, and organizing resources. Change to your infrastructure repository (e.g. <code>infra</code>).</p>
<div class="highlight"><pre><span></span><code>cd infra/clusters
</code></pre></div>
<h2 id="provider">Provider<a class="headerlink" href="#provider" title="Permanent link">&para;</a></h2>
<p>Configure the Matchbox provider to use your Matchbox API endpoint and client certificate in a <code>providers.tf</code> file.</p>
<div class="highlight"><pre><span></span><code><span class="kr">provider</span><span class="w"> </span><span class="nv">&quot;matchbox&quot;</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">endpoint</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;matchbox.example.com:8081&quot;</span>
<span class="w"> </span><span class="na">client_cert</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nf">file</span><span class="p">(</span><span class="s2">&quot;~/.config/matchbox/client.crt&quot;</span><span class="p">)</span>
<span class="w"> </span><span class="na">client_key</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nf">file</span><span class="p">(</span><span class="s2">&quot;~/.config/matchbox/client.key&quot;</span><span class="p">)</span>
<span class="w"> </span><span class="na">ca</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nf">file</span><span class="p">(</span><span class="s2">&quot;~/.config/matchbox/ca.crt&quot;</span><span class="p">)</span>
<span class="p">}</span>
<span class="kr">provider</span><span class="w"> </span><span class="nv">&quot;ct&quot;</span><span class="w"> </span><span class="p">{}</span>
<span class="nb">terraform</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="nb">required_providers</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="nb">ct</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">source</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;poseidon/ct&quot;</span>
<span class="w"> </span><span class="na">version</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;0.11.0&quot;</span>
<span class="w"> </span><span class="p">}</span>
<span class="w"> </span><span class="nb">matchbox</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">source</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;poseidon/matchbox&quot;</span>
<span class="w"> </span><span class="na">version</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;0.5.2&quot;</span>
<span class="w"> </span><span class="p">}</span>
<span class="w"> </span><span class="p">}</span>
<span class="p">}</span>
</code></pre></div>
<h2 id="cluster">Cluster<a class="headerlink" href="#cluster" title="Permanent link">&para;</a></h2>
<p>Define a Kubernetes cluster using the module <code>bare-metal/flatcar-linux/kubernetes</code>.</p>
<div class="highlight"><pre><span></span><code><span class="kr">module</span><span class="w"> </span><span class="nv">&quot;mercury&quot;</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">source</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;git::https://github.com/poseidon/typhoon//bare-metal/flatcar-linux/kubernetes?ref=v1.29.3&quot;</span>
<span class="c1"> # bare-metal</span>
<span class="w"> </span><span class="na">cluster_name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;mercury&quot;</span>
<span class="w"> </span><span class="na">matchbox_http_endpoint</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;http://matchbox.example.com&quot;</span>
<span class="w"> </span><span class="na">os_channel</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;flatcar-stable&quot;</span>
<span class="w"> </span><span class="na">os_version</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;2345.3.1&quot;</span>
<span class="c1"> # configuration</span>
<span class="w"> </span><span class="na">k8s_domain_name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node1.example.com&quot;</span>
<span class="w"> </span><span class="na">ssh_authorized_key</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;ssh-rsa AAAAB3Nz...&quot;</span>
<span class="c1"> # machines</span>
<span class="w"> </span><span class="na">controllers</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">[{</span>
<span class="w"> </span><span class="na">name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node1&quot;</span>
<span class="w"> </span><span class="na">mac</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;52:54:00:a1:9c:ae&quot;</span>
<span class="w"> </span><span class="na">domain</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node1.example.com&quot;</span>
<span class="w"> </span><span class="p">}]</span>
<span class="w"> </span><span class="na">workers</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">[</span>
<span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node2&quot;</span><span class="p">,</span>
<span class="w"> </span><span class="na">mac</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;52:54:00:b2:2f:86&quot;</span>
<span class="w"> </span><span class="na">domain</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node2.example.com&quot;</span>
<span class="w"> </span><span class="p">},</span>
<span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node3&quot;</span><span class="p">,</span>
<span class="w"> </span><span class="na">mac</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;52:54:00:c3:61:77&quot;</span>
<span class="w"> </span><span class="na">domain</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node3.example.com&quot;</span>
<span class="w"> </span><span class="p">}</span>
<span class="w"> </span><span class="p">]</span>
<span class="c1"> # set to http only if you cannot chainload to iPXE firmware with https support</span>
<span class="c1"> # download_protocol = &quot;http&quot;</span>
<span class="p">}</span>
</code></pre></div>
<p>Workers with similar features can be defined inline using the <code>workers</code> field as shown above. It's also possible to define discrete workers that attach to the cluster. Discrete workers are more advanced, but more verbose.</p>
<div class="highlight"><pre><span></span><code><span class="kr">module</span><span class="w"> </span><span class="nv">&quot;mercury-node1&quot;</span><span class="w"> </span><span class="p">{</span>
<span class="w"> </span><span class="na">source</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;git::https://github.com/poseidon/typhoon//bare-metal/fedora-coreos/kubernetes/worker?ref=v1.29.3&quot;</span>
<span class="c1"> # bare-metal</span>
<span class="w"> </span><span class="na">cluster_name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;mercury&quot;</span>
<span class="w"> </span><span class="na">matchbox_http_endpoint</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;http://matchbox.example.com&quot;</span>
<span class="w"> </span><span class="na">os_channel</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;flatcar-stable&quot;</span>
<span class="w"> </span><span class="na">os_version</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;2345.3.1&quot;</span>
<span class="c1"> # configuration</span>
<span class="w"> </span><span class="na">name</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node2&quot;</span>
<span class="w"> </span><span class="na">mac</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;52:54:00:b2:2f:86&quot;</span>
<span class="w"> </span><span class="na">domain</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;node2.example.com&quot;</span>
<span class="w"> </span><span class="na">kubeconfig</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="nv">module.mercury.kubeconfig</span>
<span class="w"> </span><span class="na">ssh_authorized_key</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;ssh-rsa AAAAB3Nz...&quot;</span>
<span class="c1"> # optional</span>
<span class="w"> </span><span class="na">snippets</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">[]</span>
<span class="w"> </span><span class="na">node_labels</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">[]</span>
<span class="w"> </span><span class="na">node_tains</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="p">[]</span>
<span class="w"> </span><span class="na">install_disk</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="s2">&quot;/dev/vda&quot;</span>
<span class="w"> </span><span class="na">cached_install</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="no">false</span>
<span class="p">}</span>
<span class="p">...</span>
</code></pre></div>
<p>Reference the <a href="#variables">variables docs</a> or the <a href="https://github.com/poseidon/typhoon/blob/master/bare-metal/flatcar-linux/kubernetes/variables.tf">variables.tf</a> source.</p>
<h2 id="ssh-agent">ssh-agent<a class="headerlink" href="#ssh-agent" title="Permanent link">&para;</a></h2>
<p>Initial bootstrapping requires <code>bootstrap.service</code> be started on one controller node. Terraform uses <code>ssh-agent</code> to automate this step. Add your SSH private key to <code>ssh-agent</code>.</p>
<div class="highlight"><pre><span></span><code>ssh-add<span class="w"> </span>~/.ssh/id_rsa
ssh-add<span class="w"> </span>-L
</code></pre></div>
<h2 id="apply">Apply<a class="headerlink" href="#apply" title="Permanent link">&para;</a></h2>
<p>Initialize the config directory if this is the first use with Terraform.</p>
<div class="highlight"><pre><span></span><code>terraform<span class="w"> </span>init
</code></pre></div>
<p>Plan the resources to be created.</p>
<div class="highlight"><pre><span></span><code>$<span class="w"> </span>terraform<span class="w"> </span>plan
Plan:<span class="w"> </span><span class="m">55</span><span class="w"> </span>to<span class="w"> </span>add,<span class="w"> </span><span class="m">0</span><span class="w"> </span>to<span class="w"> </span>change,<span class="w"> </span><span class="m">0</span><span class="w"> </span>to<span class="w"> </span>destroy.
</code></pre></div>
<p>Apply the changes. Terraform will generate bootstrap assets and create Matchbox profiles (e.g. controller, worker) and matching rules via the Matchbox API.</p>
<div class="highlight"><pre><span></span><code>$<span class="w"> </span>terraform<span class="w"> </span>apply
module.mercury.null_resource.copy-controller-secrets.0:<span class="w"> </span>Still<span class="w"> </span>creating...<span class="w"> </span><span class="o">(</span>10s<span class="w"> </span>elapsed<span class="o">)</span>
module.mercury.null_resource.copy-worker-secrets.0:<span class="w"> </span>Still<span class="w"> </span>creating...<span class="w"> </span><span class="o">(</span>10s<span class="w"> </span>elapsed<span class="o">)</span>
...
</code></pre></div>
<p>Apply will then loop until it can successfully copy credentials to each machine and start the one-time Kubernetes bootstrap service. Proceed to the next step while this loops.</p>
<h3 id="power">Power<a class="headerlink" href="#power" title="Permanent link">&para;</a></h3>
<p>Power on each machine with the boot device set to <code>pxe</code> for the next boot only.</p>
<div class="highlight"><pre><span></span><code>ipmitool<span class="w"> </span>-H<span class="w"> </span>node1.example.com<span class="w"> </span>-U<span class="w"> </span>USER<span class="w"> </span>-P<span class="w"> </span>PASS<span class="w"> </span>chassis<span class="w"> </span>bootdev<span class="w"> </span>pxe
ipmitool<span class="w"> </span>-H<span class="w"> </span>node1.example.com<span class="w"> </span>-U<span class="w"> </span>USER<span class="w"> </span>-P<span class="w"> </span>PASS<span class="w"> </span>power<span class="w"> </span>on
</code></pre></div>
<p>Machines will network boot, install Container Linux to disk, reboot into the disk install, and provision themselves as controllers or workers.</p>
<div class="admonition tip">
<p>If this is the first test of your PXE-enabled network boot environment, watch the SOL console of a machine to spot any misconfigurations.</p>
</div>
<h3 id="bootstrap">Bootstrap<a class="headerlink" href="#bootstrap" title="Permanent link">&para;</a></h3>
<p>Wait for the <code>bootstrap</code> step to finish bootstrapping the Kubernetes control plane. This may take 5-15 minutes depending on your network.</p>
<div class="highlight"><pre><span></span><code>module.mercury.null_resource.bootstrap: Still creating... (6m10s elapsed)
module.mercury.null_resource.bootstrap: Still creating... (6m20s elapsed)
module.mercury.null_resource.bootstrap: Still creating... (6m30s elapsed)
module.mercury.null_resource.bootstrap: Still creating... (6m40s elapsed)
module.mercury.null_resource.bootstrap: Creation complete (ID: 5441741360626669024)
Apply complete! Resources: 55 added, 0 changed, 0 destroyed.
</code></pre></div>
<p>To watch the install to disk (until machines reboot from disk), SSH to port 2222.</p>
<div class="highlight"><pre><span></span><code># before v1.10.1
$ ssh debug@node1.example.com
# after v1.10.1
$ ssh -p 2222 core@node1.example.com
</code></pre></div>
<p>To watch the bootstrap process in detail, SSH to the first controller and journal the logs.</p>
<div class="highlight"><pre><span></span><code>$ ssh core@node1.example.com
$ journalctl -f -u bootstrap
The connection to the server cluster.example.com:6443 was refused - did you specify the right host or port?
Waiting for static pod control plane
...
serviceaccount/calico-node unchanged
systemd[1]: Started Kubernetes control plane.
</code></pre></div>
<h2 id="verify">Verify<a class="headerlink" href="#verify" title="Permanent link">&para;</a></h2>
<p><a href="https://kubernetes.io/docs/tasks/tools/install-kubectl/">Install kubectl</a> on your system. Obtain the generated cluster <code>kubeconfig</code> from module outputs (e.g. write to a local file).</p>
<div class="highlight"><pre><span></span><code>resource &quot;local_file&quot; &quot;kubeconfig-mercury&quot; {
content = module.mercury.kubeconfig-admin
filename = &quot;/home/user/.kube/configs/mercury-config&quot;
}
</code></pre></div>
<p>List nodes in the cluster.</p>
<div class="highlight"><pre><span></span><code>$ export KUBECONFIG=/home/user/.kube/configs/mercury-config
$ kubectl get nodes
NAME STATUS ROLES AGE VERSION
node1.example.com Ready &lt;none&gt; 10m v1.29.3
node2.example.com Ready &lt;none&gt; 10m v1.29.3
node3.example.com Ready &lt;none&gt; 10m v1.29.3
</code></pre></div>
<p>List the pods.</p>
<div class="highlight"><pre><span></span><code>$ kubectl get pods --all-namespaces
NAMESPACE NAME READY STATUS RESTARTS AGE
kube-system calico-node-6qp7f 2/2 Running 1 11m
kube-system calico-node-gnjrm 2/2 Running 0 11m
kube-system calico-node-llbgt 2/2 Running 0 11m
kube-system coredns-1187388186-dj3pd 1/1 Running 0 11m
kube-system coredns-1187388186-mx9rt 1/1 Running 0 11m
kube-system kube-apiserver-node1.example.com 1/1 Running 0 11m
kube-system kube-controller-node1.example.com 1/1 Running 1 11m
kube-system kube-proxy-50sd4 1/1 Running 0 11m
kube-system kube-proxy-bczhp 1/1 Running 0 11m
kube-system kube-proxy-mp2fw 1/1 Running 0 11m
kube-system kube-scheduler-node1.example.com 1/1 Running 0 11m
</code></pre></div>
<h2 id="going-further">Going Further<a class="headerlink" href="#going-further" title="Permanent link">&para;</a></h2>
<p>Learn about <a href="/topics/maintenance/">maintenance</a> and <a href="/addons/overview/">addons</a>.</p>
<h2 id="variables">Variables<a class="headerlink" href="#variables" title="Permanent link">&para;</a></h2>
<p>Check the <a href="https://github.com/poseidon/typhoon/blob/master/bare-metal/flatcar-linux/kubernetes/variables.tf">variables.tf</a> source.</p>
<h3 id="required">Required<a class="headerlink" href="#required" title="Permanent link">&para;</a></h3>
<table>
<thead>
<tr>
<th style="text-align: left;">Name</th>
<th style="text-align: left;">Description</th>
<th style="text-align: left;">Example</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;">cluster_name</td>
<td style="text-align: left;">Unique cluster name</td>
<td style="text-align: left;">"mercury"</td>
</tr>
<tr>
<td style="text-align: left;">matchbox_http_endpoint</td>
<td style="text-align: left;">Matchbox HTTP read-only endpoint</td>
<td style="text-align: left;">"<a href="http://matchbox.example.com:port">http://matchbox.example.com:port</a>"</td>
</tr>
<tr>
<td style="text-align: left;">os_channel</td>
<td style="text-align: left;">Channel for a Container Linux derivative</td>
<td style="text-align: left;">flatcar-stable, flatcar-beta, flatcar-alpha</td>
</tr>
<tr>
<td style="text-align: left;">os_version</td>
<td style="text-align: left;">Version for a Container Linux derivative to PXE and install</td>
<td style="text-align: left;">"2345.3.1"</td>
</tr>
<tr>
<td style="text-align: left;">k8s_domain_name</td>
<td style="text-align: left;">FQDN resolving to the controller(s) nodes. Workers and kubectl will communicate with this endpoint</td>
<td style="text-align: left;">"myk8s.example.com"</td>
</tr>
<tr>
<td style="text-align: left;">ssh_authorized_key</td>
<td style="text-align: left;">SSH public key for user 'core'</td>
<td style="text-align: left;">"ssh-rsa AAAAB3Nz..."</td>
</tr>
<tr>
<td style="text-align: left;">controllers</td>
<td style="text-align: left;">List of controller machine detail objects (unique name, identifying MAC address, FQDN)</td>
<td style="text-align: left;"><code>[{name="node1", mac="52:54:00:a1:9c:ae", domain="node1.example.com"}]</code></td>
</tr>
</tbody>
</table>
<h3 id="optional">Optional<a class="headerlink" href="#optional" title="Permanent link">&para;</a></h3>
<table>
<thead>
<tr>
<th style="text-align: left;">Name</th>
<th style="text-align: left;">Description</th>
<th style="text-align: left;">Default</th>
<th style="text-align: left;">Example</th>
</tr>
</thead>
<tbody>
<tr>
<td style="text-align: left;">workers</td>
<td style="text-align: left;">List of worker machine detail objects (unique name, identifying MAC address, FQDN)</td>
<td style="text-align: left;">[]</td>
<td style="text-align: left;"><code>[{name="node2", mac="52:54:00:b2:2f:86", domain="node2.example.com"}, {name="node3", mac="52:54:00:c3:61:77", domain="node3.example.com"}]</code></td>
</tr>
<tr>
<td style="text-align: left;">download_protocol</td>
<td style="text-align: left;">Protocol iPXE uses to download the kernel and initrd. iPXE must be compiled with <a href="https://ipxe.org/crypto">crypto</a> support for https. Unused if cached_install is true</td>
<td style="text-align: left;">"https"</td>
<td style="text-align: left;">"http"</td>
</tr>
<tr>
<td style="text-align: left;">cached_install</td>
<td style="text-align: left;">PXE boot and install from the Matchbox <code>/assets</code> cache. Admin MUST have downloaded Container Linux or Flatcar images into the cache</td>
<td style="text-align: left;">false</td>
<td style="text-align: left;">true</td>
</tr>
<tr>
<td style="text-align: left;">install_disk</td>
<td style="text-align: left;">Disk device where Container Linux should be installed</td>
<td style="text-align: left;">"/dev/sda"</td>
<td style="text-align: left;">"/dev/sdb"</td>
</tr>
<tr>
<td style="text-align: left;">networking</td>
<td style="text-align: left;">Choice of networking provider</td>
<td style="text-align: left;">"cilium"</td>
<td style="text-align: left;">"calico" or "cilium" or "flannel"</td>
</tr>
<tr>
<td style="text-align: left;">network_mtu</td>
<td style="text-align: left;">CNI interface MTU (calico-only)</td>
<td style="text-align: left;">1480</td>
<td style="text-align: left;">-</td>
</tr>
<tr>
<td style="text-align: left;">snippets</td>
<td style="text-align: left;">Map from machine names to lists of Container Linux Config snippets</td>
<td style="text-align: left;">{}</td>
<td style="text-align: left;"><a href="/advanced/customization/">examples</a></td>
</tr>
<tr>
<td style="text-align: left;">network_ip_autodetection_method</td>
<td style="text-align: left;">Method to detect host IPv4 address (calico-only)</td>
<td style="text-align: left;">"first-found"</td>
<td style="text-align: left;">"can-reach=10.0.0.1"</td>
</tr>
<tr>
<td style="text-align: left;">pod_cidr</td>
<td style="text-align: left;">CIDR IPv4 range to assign to Kubernetes pods</td>
<td style="text-align: left;">"10.2.0.0/16"</td>
<td style="text-align: left;">"10.22.0.0/16"</td>
</tr>
<tr>
<td style="text-align: left;">service_cidr</td>
<td style="text-align: left;">CIDR IPv4 range to assign to Kubernetes services</td>
<td style="text-align: left;">"10.3.0.0/16"</td>
<td style="text-align: left;">"10.3.0.0/24"</td>
</tr>
<tr>
<td style="text-align: left;">kernel_args</td>
<td style="text-align: left;">Additional kernel args to provide at PXE boot</td>
<td style="text-align: left;">[]</td>
<td style="text-align: left;">["kvm-intel.nested=1"]</td>
</tr>
<tr>
<td style="text-align: left;">worker_node_labels</td>
<td style="text-align: left;">Map from worker name to list of initial node labels</td>
<td style="text-align: left;">{}</td>
<td style="text-align: left;">{"node2" = ["role=special"]}</td>
</tr>
<tr>
<td style="text-align: left;">worker_node_taints</td>
<td style="text-align: left;">Map from worker name to list of initial node taints</td>
<td style="text-align: left;">{}</td>
<td style="text-align: left;">{"node2" = ["role=special:NoSchedule"]}</td>
</tr>
<tr>
<td style="text-align: left;">oem_type</td>
<td style="text-align: left;">An OEM type to install with <code>flatcar-install</code>.</td>
<td style="text-align: left;">""</td>
<td style="text-align: left;">"vmware_raw"</td>
</tr>
</tbody>
</table>
</article>
</div>
<script>var target=document.getElementById(location.hash.slice(1));target&&target.name&&(target.checked=target.name.startsWith("__tabbed_"))</script>
</div>
</main>
<footer class="md-footer">
<div class="md-footer-meta md-typeset">
<div class="md-footer-meta__inner md-grid">
<div class="md-copyright">
<div class="md-copyright__highlight">
Poseidon Laboratories
</div>
Made with
<a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
Material for MkDocs
</a>
</div>
<div class="md-social">
<a href="https://github.com/poseidon" target="_blank" rel="noopener" title="github.com" class="md-social__link">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 480 512"><!--! Font Awesome Free 6.5.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2023 Fonticons, Inc.--><path d="M186.1 328.7c0 20.9-10.9 55.1-36.7 55.1s-36.7-34.2-36.7-55.1 10.9-55.1 36.7-55.1 36.7 34.2 36.7 55.1zM480 278.2c0 31.9-3.2 65.7-17.5 95-37.9 76.6-142.1 74.8-216.7 74.8-75.8 0-186.2 2.7-225.6-74.8-14.6-29-20.2-63.1-20.2-95 0-41.9 13.9-81.5 41.5-113.6-5.2-15.8-7.7-32.4-7.7-48.8 0-21.5 4.9-32.3 14.6-51.8 45.3 0 74.3 9 108.8 36 29-6.9 58.8-10 88.7-10 27 0 54.2 2.9 80.4 9.2 34-26.7 63-35.2 107.8-35.2 9.8 19.5 14.6 30.3 14.6 51.8 0 16.4-2.6 32.7-7.7 48.2 27.5 32.4 39 72.3 39 114.2zm-64.3 50.5c0-43.9-26.7-82.6-73.5-82.6-18.9 0-37 3.4-56 6-14.9 2.3-29.8 3.2-45.1 3.2-15.2 0-30.1-.9-45.1-3.2-18.7-2.6-37-6-56-6-46.8 0-73.5 38.7-73.5 82.6 0 87.8 80.4 101.3 150.4 101.3h48.2c70.3 0 150.6-13.4 150.6-101.3zm-82.6-55.1c-25.8 0-36.7 34.2-36.7 55.1s10.9 55.1 36.7 55.1 36.7-34.2 36.7-55.1-10.9-55.1-36.7-55.1z"/></svg>
</a>
<a href="https://twitter.com/typhoon8s" target="_blank" rel="noopener" title="twitter.com" class="md-social__link">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512"><!--! Font Awesome Free 6.5.1 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2023 Fonticons, Inc.--><path d="M459.37 151.716c.325 4.548.325 9.097.325 13.645 0 138.72-105.583 298.558-298.558 298.558-59.452 0-114.68-17.219-161.137-47.106 8.447.974 16.568 1.299 25.34 1.299 49.055 0 94.213-16.568 130.274-44.832-46.132-.975-84.792-31.188-98.112-72.772 6.498.974 12.995 1.624 19.818 1.624 9.421 0 18.843-1.3 27.614-3.573-48.081-9.747-84.143-51.98-84.143-102.985v-1.299c13.969 7.797 30.214 12.67 47.431 13.319-28.264-18.843-46.781-51.005-46.781-87.391 0-19.492 5.197-37.36 14.294-52.954 51.655 63.675 129.3 105.258 216.365 109.807-1.624-7.797-2.599-15.918-2.599-24.04 0-57.828 46.782-104.934 104.934-104.934 30.213 0 57.502 12.67 76.67 33.137 23.715-4.548 46.456-13.32 66.599-25.34-7.798 24.366-24.366 44.833-46.132 57.827 21.117-2.273 41.584-8.122 60.426-16.243-14.292 20.791-32.161 39.308-52.628 54.253z"/></svg>
</a>
</div>
</div>
</div>
</footer>
</div>
<div class="md-dialog" data-md-component="dialog">
<div class="md-dialog__inner md-typeset"></div>
</div>
<script id="__config" type="application/json">{"base": "../..", "features": ["navigation.tabs", "navigation.instant"], "search": "../../assets/javascripts/workers/search.b8dbb3d2.min.js", "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}}</script>
<script src="../../assets/javascripts/bundle.bd41221c.min.js"></script>
</body>
</html>