Reusable, production-tested Kubernetes infrastructure components for bare-metal clusters.
| Component | Version |
|---|---|
| Kubernetes | v1.35.0 |
| Envoy Gateway | v1.5.9 |
| Gateway API | v1.4.0 |
| Longhorn | v1.10.1 |
| Crossplane | v2.3.2 |
| provider-cloudflare-dns | v0.1.3 |
| OS | Ubuntu 24.04 LTS |
| Container Runtime | containerd |
- Migrated from ingress-nginx to Kubernetes Gateway API
- Envoy Gateway as the Gateway API implementation
- MetalLB for bare-metal LoadBalancer support
- cert-manager + Let's Encrypt for automated TLS
- Cloudflare Tunnel for external access with zero exposed ports
- See
gateway-api/README.mdfor full migration guide
- 3-way replication across nodes for high availability
- Automatic failover for persistent volumes
- GitOps deployment via ArgoCD
- Zero single points of failure for stateful applications
- See
docs/longhorn-migration.mdfor implementation details
- Migrated from systemd service on a single node to 2-replica Kubernetes Deployment
topologySpreadConstraintsensure replicas run on different physical nodes- Credentials managed by HashiCorp Vault + External Secrets Operator
- Zero-downtime migration using Cloudflare's multi-connector support
- See
docs/cloudflared-migration.mdfor the full migration walkthrough
- DNS records managed as Kubernetes CRDs, reconciled continuously by Crossplane
- Existing Cloudflare records adopted via
crossplane.io/external-name— no re-creation, no downtime - Email records (MX, DKIM, SPF, DMARC) use
managementPolicies: ["Observe"]— watched but never modified - API token sourced from Vault via External Secrets Operator, never committed to Git
- Three-app structure enforces ordering: Crossplane core → provider + ProviderConfig → DNS records
application.resourceTrackingMethod: annotationrequired inargocd-cmfor correct Crossplane resource tracking- See
docs/crossplane.mdfor setup and adoption walkthrough
- Automatic pod rebalancing across nodes
- Optimizes cluster resource utilization
- Handles node recovery after failures
- Three profiles: aggressive, basic, conservative
For HashiCorp Vault + External Secrets Operator + AWS KMS auto-unseal, see the dedicated repo: vault-config-pub
Example ExternalSecrets for wiring apps to Vault are in external-secrets-configs/.
├── argocd/
│ └── applications/ # ArgoCD Application manifests
│ ├── cloudflared-app.yaml
│ ├── crossplane-helm-app.yaml # Crossplane core
│ ├── crossplane-config-app.yaml # provider + ProviderConfig
│ ├── crossplane-dns-app.yaml # DNS records
│ ├── envoy-gateway-app.yaml
│ ├── gateway-config-app.yaml
│ ├── descheduler-app.yaml
│ └── longhorn-app.yaml
├── cloudflared/ # In-cluster Cloudflare Tunnel
│ ├── namespace.yaml
│ ├── configmap.yaml
│ └── deployment.yaml
├── descheduler/
│ ├── base/ # Base Kustomize resources
│ └── examples/ # aggressive / basic / conservative profiles
├── docs/ # Migration guides and use cases
├── external-secrets-configs/
│ ├── cloudflared/ # Tunnel credentials via Vault
│ ├── crossplane/ # Cloudflare API token via Vault
│ ├── cluster-ai/ # Example ExternalSecret for app secrets
│ ├── job-tracker/ # App secrets - postgres and backend
│ └── netdata/ # Monitoring credentials
├── gateway-api/
│ ├── gateway/ # GatewayClass, Gateway, TLS, ClusterIssuer
│ └── routes/example/ # Example HTTPRoute template
├── longhorn/
│ └── overlays/production/
└── scripts/ # Utility and test scripts
# 1. Install Gateway API CRDs
kubectl apply -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.4.0/standard-install.yaml
# 2. Deploy Envoy Gateway via ArgoCD
kubectl apply -f argocd/applications/envoy-gateway-app.yaml
# 3. Deploy Gateway config (GatewayClass, Gateway, TLS)
kubectl apply -f argocd/applications/gateway-config-app.yamlkubectl apply -f argocd/applications/longhorn-app.yaml# 1. Store tunnel credentials in Vault (see docs/cloudflared-migration.md)
# 2. Deploy via ArgoCD
kubectl apply -f argocd/applications/cloudflared-app.yaml# 1. Store the Cloudflare API token in Vault as JSON
# vault kv put secret/cloudflare/credentials \
# credentials='{"api_token":"YOUR_TOKEN"}'
# 2. Set annotation-based resource tracking (required for Crossplane)
kubectl patch configmap argocd-cm -n argocd --type merge \
-p '{"data":{"application.resourceTrackingMethod":"annotation"}}'
# 3. Install Crossplane core
kubectl apply -f argocd/applications/crossplane-helm-app.yaml
# 4. Install the provider and ProviderConfig (wait for core to be healthy first)
kubectl apply -f argocd/applications/crossplane-config-app.yaml
# 5. Apply DNS records (wait for the provider to report HEALTHY)
kubectl apply -f argocd/applications/crossplane-dns-app.yaml# Choose a profile
kubectl apply -k descheduler/examples/aggressive/ # fast rebalancing
kubectl apply -k descheduler/examples/basic/ # default
kubectl apply -k descheduler/examples/conservative/ # minimal disruption- Environment: Bare-metal Kubernetes (no hypervisor)
- OS: Ubuntu 24.04 LTS
- Networking: MetalLB + Cloudflare Tunnel (no exposed ports)
- GitOps Workflow — All infrastructure as code, managed via ArgoCD
- Modern Ingress — Gateway API replaces legacy Ingress — native traffic splitting, header manipulation, multi-protocol
- Resilient Tunnel — Multi-replica cloudflared with topology-aware scheduling, no single node dependency
- High Availability — Longhorn 3-way replication eliminates storage single points of failure
- Infrastructure as Code Beyond the Cluster — Crossplane extends GitOps to Cloudflare DNS with continuous drift correction
- Automated Operations — Descheduler handles pod rebalancing after node failures
- Zero Trust Networking — Cloudflare Tunnel, no inbound firewall rules required
- Production-Grade — Running real applications with CI/CD pipelines
gateway-api/README.md— ingress-nginx → Envoy Gateway migration guidedocs/cloudflared-migration.md— systemd → in-cluster tunnel migrationdocs/longhorn-migration.md— hostPath → distributed storage walkthroughdocs/crossplane.md— Cloudflare DNS as code with Crossplanedocs/use-cases.md— descheduler configuration scenariosdocs/installation.md— getting started guide
- vault-config-pub — HashiCorp Vault + External Secrets Operator + AWS KMS auto-unseal
- crossplane — Cloudflare DNS and Zero Trust as code via Crossplane
- cluster-ai — Natural language Kubernetes assistant (FastAPI + React + Ollama + Claude)
Last Updated: August 2026