No description
  • Dockerfile 68.7%
  • Nix 31.3%
Find a file
Felix Wolf 186243c263 feat(matrix): add mautrix-googlechat appservice bridge
A new `mautrix-googlechat` bridge is deployed in the `matrix` namespace, wired to Synapse as an appservice.
It uses the Python implementation (v0.5.2), distinct from the Go bridges, requiring cookie login and specific env var handling for secrets.
It uses its own Postgres role/database on the existing `synapse-cnpg` cluster.
Appservice tokens and provisioning secret are generated in-cluster, with Synapse substituting placeholders in the registration file.
The deployment runs as a single `Recreate` replica, and probes check `/_matrix/mau/live`.
2026-09-13 19:32:42 +02:00
.forgejo/workflows chore(deps): update docker docker tag to v29.7.2 2026-08-22 13:13:10 +00:00
ci/renovate-myks chore(deps): update renovate/renovate docker tag to v44 2026-07-30 07:49:52 +00:00
docs feat(matrix): add mautrix-googlechat appservice bridge 2026-09-13 19:32:42 +02:00
envs feat(matrix): add mautrix-googlechat appservice bridge 2026-09-13 19:32:42 +02:00
prototypes feat(matrix): add mautrix-googlechat appservice bridge 2026-09-13 19:32:42 +02:00
rendered feat(matrix): add mautrix-googlechat appservice bridge 2026-09-13 19:32:42 +02:00
talos perf(talos): cap kube-apiserver heap with GOMEMLIMIT 2026-08-23 20:36:27 +02:00
.envrc chore: add read-only Grafana MCP server for Claude Code 2026-07-27 14:27:56 +02:00
.envrc.local.example chore: add read-only Grafana MCP server for Claude Code 2026-07-27 14:27:56 +02:00
.gitattributes feat(talos): enable swap with zswap compression on control plane nodes 2026-04-24 19:33:06 +02:00
.gitignore chore: gitignore plaintext sops output under talos/ 2026-08-23 20:41:19 +02:00
.mcp.json chore: add read-only Grafana MCP server for Claude Code 2026-07-27 14:27:56 +02:00
.myks.yaml feat: Initial setup of GitOps-managed Kubernetes cluster 2026-03-30 18:21:05 +02:00
.sops.yaml feat: Initial setup of GitOps-managed Kubernetes cluster 2026-03-30 18:21:05 +02:00
CLAUDE.md feat(matrix): add mautrix-googlechat appservice bridge 2026-09-13 19:32:42 +02:00
flake.lock chore(upgrade-talos): update talos and k8s on the talos-nodes + flake.lock 2026-08-23 19:33:10 +02:00
flake.nix chore: add read-only Grafana MCP server for Claude Code 2026-07-27 14:27:56 +02:00
README.md feat: Initial setup of GitOps-managed Kubernetes cluster 2026-03-30 18:21:05 +02:00
renovate.json feat(renovate): automerge minor, patch, digest 2026-08-30 22:29:14 +02:00

k8s-and-chill

Private Kubernetes cluster running on 3x Hetzner CAX11 (ARM64) instances with Talos Linux, managed by myks.

Cluster Setup

Prerequisites

Enter the dev shell (via direnv or nix develop), which provides:

  • talosctl
  • kubectl
  • helm
  • myks
  • hcloud

Infrastructure

Node Public IP Private IP Location
ubuntu-4gb-nbg1-1 195.201.219.17 10.0.0.3 nbg1
ubuntu-4gb-nbg1-2 195.201.140.75 10.0.0.4 nbg1
ubuntu-4gb-nbg1-3 195.201.219.111 10.0.0.2 nbg1

All nodes are control plane nodes (3-node HA etcd). The Kubernetes API endpoint is https://195.201.219.111:6443.

The nodes are connected via a Hetzner private network (thalos-k8s), which is used for inter-node communication.

Installing Talos on Hetzner Cloud

The servers were originally provisioned with Ubuntu. Talos was installed by writing the Talos disk image via Hetzner rescue mode.

1. Get the Talos image URL

Talos images for Hetzner Cloud are generated via the Talos Image Factory. For vanilla Talos (no extensions), get the schematic ID:

curl -sX POST https://factory.talos.dev/schematics \
  -H 'Content-Type: application/json' \
  -d '{"customization":{"systemExtensions":{"officialExtensions":[]}}}'
# Returns: {"id":"376567988ad370138ad8b2698212367b8edcb69b5fd68c80be1f2ec7d603b4ba"}

The image URL follows this pattern:

https://factory.talos.dev/image/<schematic-id>/<talos-version>/hcloud-arm64.raw.xz

2. Enable rescue mode and reboot

For each server:

hcloud server enable-rescue <server-name> --ssh-key "<ssh-key-name>"
hcloud server reboot <server-name>

3. Write Talos to disk

SSH into each server's rescue system and write the image:

ssh root@<server-ip> "curl -fsSL '<image-url>' | xz -d | dd of=/dev/sda bs=4M status=progress && sync"

4. Reboot into Talos

hcloud server reboot <server-name>

Bootstrapping the Cluster

1. Generate machine configs

mkdir -p talos
talosctl gen config k8s-and-chill https://195.201.219.111:6443 --output talos/

This creates controlplane.yaml, worker.yaml, and talosconfig.

2. Configure talosctl

export TALOSCONFIG=talos/talosconfig
talosctl config endpoint 195.201.219.111 195.201.140.75 195.201.219.17
talosctl config node 195.201.219.111 195.201.140.75 195.201.219.17

3. Apply configs

Apply the controlplane config to each node (use --insecure on first apply since the nodes don't have matching certs yet):

talosctl apply-config --insecure --nodes 195.201.219.111 --file talos/controlplane.yaml
talosctl apply-config --insecure --nodes 195.201.140.75  --file talos/controlplane.yaml
talosctl apply-config --insecure --nodes 195.201.219.17  --file talos/controlplane.yaml

4. Bootstrap etcd

Run this on exactly one node:

talosctl bootstrap --nodes 195.201.219.111

5. Get kubeconfig

talosctl kubeconfig talos/kubeconfig --nodes 195.201.219.111

6. Verify

export KUBECONFIG=talos/kubeconfig
kubectl get nodes -o wide
kubectl get pods -A