STRICT PERSONAL ENCLAVE • 100% PRIVATE

xk3s Fleet Topology & Cluster Manual

Comprehensive reference architecture, static network coordinates, mutual SSH key authentication matrix, and containerized workload topologies for the personal edge Kubernetes cluster.

COORDINATES MASKED
Click any individual coordinate to peek, or toggle all.

1. Master Fleet Coordinates

The decoupled dual-cluster personal infrastructure connects across local LAN, direct WireGuard cloud overlay, and Tailscale zero-trust meshes:

Device Hostname User LAN IP WireGuard Tailscale Ingress / Role
MacBook Air
das-MacBook-Air.local da 192.168.4.••• — 100.71.•••.•• Primary Workstation (M1, 16GB)
MacBook Pro (k8s-mac)
Doxs-MacBook-Pro.local dx 192.168.4.••• 10.10.0.•• 100.102.•••.•• / 100.92.•••.•• K8s Control Plane Host (i9, 32GB)
x1 (Master)
x1 x1 192.168.4.••• 10.10.0.•• 100.95.•••.•• K3s Master, NVMe Storage, API (6443)
x2 (Worker)
x2 x2 192.168.4.••• 10.10.0.•• 100.71.•••.•• K3s Edge Worker, HDMI Kiosk, Gitea (31410)
x (Worker)
x x 192.168.4.••• 10.10.0.•• 100.111.•••.•• K8s Compute Worker, Failover Target
AWS Hub (EC2)
ip-172-31-2-180 ubuntu — 10.10.0.•• — Ingress Gateway & HA Router (54.215.•••.••)
dphone
dphone
dphone — — 10.10.0.•• 100.64.•••.•• Mobile iOS Zero-Trust Client

2. Remote Access & SSH Matrix

Passwordless ED25519 authentication is configured across all devices. Use these standard connection commands:

# Workstation Remote Access
ssh mbp # Connect to MacBook Pro (Tailscale)
ssh mbp-lan # Connect to MacBook Pro (LAN: 192.168.4.•••)
open vnc://dx@100.102.•••.•• # Screen Share VNC session

# Cluster 1: K3s Edge Fleet
ssh x1@100.95.•••.•• # Cluster Master x1 (Tailscale / WireGuard 10.10.0.2)
ssh x2@100.71.•••.•• # Edge Worker x2 (Tailscale / WireGuard 10.10.0.3)

# Cluster 2: Standard K8s Compute Mesh
ssh mbp # K8s Control Plane Host (k8s-mac Lima VM at 100.92.49.86)
ssh x@100.111.•••.•• # K8s Worker x (Tailscale / WireGuard 10.10.0.5)

# AWS Cloud Ingress Gateway
ssh ec2-pub # AWS EC2 Ingress Gateway (54.215.•••.••)

3. Decoupled Dual-Cluster Architecture

The infrastructure is strictly decoupled into two isolated orchestration fabrics to separate real-time industrial edge automation from heavy compute workloads and hot standby redundancy:

Cluster 1: Dedicated K3s Edge Fleet (Industrial Primary Tier)

Flannel 10.42.0.0/16 • ClusterIP 10.43.0.0/16

Optimized edge cluster running on low-power ARM64 nodes. Orchestrates real-time SCADA runtime, IEC 61131-3 soft PLC automation, telemetry historian, and physical HDMI kiosk surfaces.

x1 Control Plane
K3S MASTER
K3s API Server6443 (10.10.0.2)
Active WorkloadsIgnition, Influx, OpenPLC, Portainer
Storage Backend939GB NVMe PCIe
Internal ClusterIP10.43.0.0/16
Pod CIDR (Flannel)10.42.0.0/24
Hardware Platform4C • 15 GB RAM
x2 Edge Worker
K3S WORKER
Worker AgentK3s v1.31+
Active WorkloadsGitea (:31410), Web HUD, Sparkplug B
HDMI Kiosk SurfaceLocal Display / Chromium
VNC ServerPort 5900 (wayvnc)
Pod CIDR (Flannel)10.42.1.0/24
Hardware Platform4C • 8 GB RAM

Cluster 2: Standard K8s Compute Mesh (Hot Standby & Offload Tier)

Flannel 10.244.0.0/16 • ClusterIP 10.96.0.0/12

Standard upstream Kubernetes cluster deployed across x86_64 AMD64 architecture. Provides high-compute simulation capacity, continuous container mirrors, and immediate automated failover target when edge nodes pause.

MacBook Pro (k8s-mac)
K8S MASTER
K8s API Server6443 (100.92.49.86)
Hardware PlatformIntel Core i9-9980HK (8C/16T, 32GB)
Internal ClusterIP10.96.0.0/12
Pod CIDR (Flannel)10.244.0.0/24
Cluster ServicesEtcd, Kube-Apiserver, Flannel Master
WireGuard Mesh10.10.0.4 (via x1)
x (Compute Worker)
K8S WORKER
Worker AgentKubelet v1.31+
Hardware PlatformIntel N4500 • 8GB RAM • 118GB NVMe
Pod CIDR (Flannel)10.244.1.0/24
WireGuard Mesh10.10.0.5 (Direct wg0)
Tailscale C2100.111.•••.••
Standby NodePortsSCADA (:30188), Grafana (:30300), Node-RED

Cloud Ingress Gateway & Automated HA Failover Routing

Active-Standby Zero Downtime

Nginx reverse proxy on aws-hub routes external HTTPS traffic dynamically across both clusters. When primary edge nodes time out or pause, traffic fails over seamlessly within 3 seconds to the K8s compute mesh.

AWS EC2 Ingress Gateway
HA GATEWAY
Reverse ProxyNginx 1.24+
SSL TerminationLet's Encrypt TLS 1.3
WireGuard Hub10.10.0.•• (UDP 51820)
Cloudflare ProxyZero-Trust Shield & HTTP/3
Public Origin IP54.215.•••.••
Automated Failover Mechanics
ARMED & ACTIVE
Primary Upstream10.10.0.2 (K3s Edge Master)
Standby Upstream10.10.0.5 (K8s Node x backup)
Failover Thresholdmax_fails=2 fail_timeout=5s
Connection Timeoutproxy_connect_timeout 3s
Cutover StatusAutomated next-upstream retry

4. Multi-Tier Mesh Overlay

The network utilizes a three-tier overlay model guaranteeing encrypted connectivity across all environments:

5. Hardware & Operating System Specifications

Node Operating System Arch Processor RAM Storage
MacBook Air macOS 26.5.2 (Darwin 25) arm64 Apple M1 (8 cores) 16 GB Unified 500 GB NVMe APFS
MacBook Pro macOS 26.7 (Darwin 25) x86_64 Intel Core i9-9880H (8C/16T) 32 GB DDR4 1.1 TB NVMe APFS
x1 (Master) Debian 13 (Trixie) aarch64 Broadcom BCM2712 (4 cores) 16 GB LPDDR4X 500 GB NVMe PCIe Gen3
x2 (Worker) Debian 12 (Bookworm) aarch64 Broadcom BCM2712 (4 cores) 8 GB LPDDR4 64 GB MicroSD
x (Compute Worker) Ubuntu 24.04 LTS x86_64 Intel Celeron N4500 (2 cores) 8 GB DDR4 118 GB NVMe SSD
AWS Hub Ubuntu 24.04 LTS x86_64 AWS Nitro vCPU 1 GB Burst 30 GB gp3 EBS

6. Active Edge Endpoints Directory

All services are routed securely through the AWS Ingress gateway with SSL termination:

Cluster Core & Operations
Level 4/5
Mission Control HUD
xk3s.com ↗
Headlamp K8s Console
headlamp.xk3s.com ↗
Portainer Enterprise
portainer.xk3s.com ↗
Grafana Observability
grafana.xk3s.com ↗
Pi-hole DNS Shield
pihole.xk3s.com ↗
Industrial SCADA Fleet
ISA-95 Level 3
Ignition Prod Master
prod.xk3s.com ↗
Ignition Prod Backup
backup.xk3s.com ↗
Ignition Dev Sandbox
dev.xk3s.com ↗
Ignition EAM Central
eam.xk3s.com ↗
Gateway Real-Time Logs
logs.xk3s.com ↗
IIoT & Unified Namespace
Sparkplug B
Node-RED OT Flows
nodered.xk3s.com ↗
EMQX UNS Broker
emqx.xk3s.com ↗
RabbitMQ Message Fabric
rabbitmq.xk3s.com ↗
InfluxDB Historian
influx.xk3s.com ↗
Neuron Edge Gateway
neuron.xk3s.com ↗
DevOps & Team Collaboration
CI/CD & C2
Gitea Industrial Git
gitea.xk3s.com ↗
Mattermost C2 / xk3s Hub
Join xk3s Channel ↗
OpenPLC Runtime (Web)
workbench.xk3s.com ↗
OpenPLC Modbus TCP
10.10.0.2:30502
PostgreSQL Fleet DB
192.168.4.139:30542