xk3s Fleet Topology & Cluster Manual
Comprehensive reference architecture, static network coordinates, mutual SSH key authentication matrix, and containerized workload topologies for the personal edge Kubernetes cluster.
1. Master Fleet Coordinates
The decoupled dual-cluster personal infrastructure connects across local LAN, direct WireGuard cloud overlay, and Tailscale zero-trust meshes:
| Device | Hostname | User | LAN IP | WireGuard | Tailscale | Ingress / Role |
|---|---|---|---|---|---|---|
| x1 | x1 | xx.xx.xx.33 (eth0) / xx.xx.xx.139 (wlan0) | xx.xx.xx.2 | xx.xx.xx.43 | LXD edge virtualization, LXC applications, NVMe storage | |
| x2 | x2 | xx.xx.xx.42 (eth0) / xx.xx.xx.210 (wlan0) | xx.xx.xx.3 | xx.xx.xx.80 | Dedicated field RF radar and scanner operations | |
| x3 | x | xx.xx.xx.172 | xx.xx.xx.5 | xx.xx.xx.65 | Field compute, emergency engineering, disaster recovery | |
| x | root | xx.xx.xx.59 (Wi-Fi) | xx.xx.xx.4 | xx.xx.xx.102 | Proxmox VE 9.2 Hypervisor • 100% Headless Clamshell (8C/16T, 32GB RAM, 2TB NVMe) | |
| aws-hub | ubuntu | — | xx.xx.xx.1 | — | Ingress Gateway & HA Router (xx.xx.xx.95) |
2. Remote Access & SSH Matrix
Passwordless ED25519 authentication is configured across all devices. Use these standard connection commands:
ssh x1 # LXD Edge Host · VMs & LXC
ssh x2 # Field RF Radar & Scanner Node
ssh x3 # Compute & Engineering Station
ssh xpve # Host x · Proxmox VMs & LXC
ssh ec2-pub # Cloud ingress
3. Fleet Virtualization & RKE2 Architecture
RKE2 application cluster
VM 101 on xpve · 1 verified node(s): rke2-master. Actual namespace and pod placement appear in live telemetry.
x1 · LXD Edge Host · VMs & LXC
LXD edge virtualization: 7 LXC containers. K3s is stopped.
x2 · Field RF Radar & Scanner Node
Field RF radar and scanner operations. K3s is stopped.
x3 · Compute & Engineering Station
Field compute and engineering. K3s is stopped.
xpve · Host x · VMs & LXC
Host x runs Proxmox VMs and LXC, including RKE2 VM 101 and the x-db SQL historian.
ec2 · Cloud Ingress
Public HTTPS ingress, WireGuard hub and private Fleet Intelligence portal.
4. Multi-Tier Mesh Overlay
The network utilizes a multi-tier overlay model guaranteeing encrypted connectivity across all fleet endpoints:
- Tier 1: Cloud-to-Edge Mesh (WireGuard
10.10.0.0/24): Dedicated point-to-point encrypted link connecting AWS EC2 gatewayec2(xx.xx.xx.1) to the appropriate edge hostx1(xx.xx.xx.2), edge workerx2(xx.xx.xx.3), hypervisorx(xx.xx.xx.4), and compute workerx3(xx.xx.xx.5). - Tier 2: Zero-Trust Remote Mesh (Tailscale
100.64.0.0/10): Direct peer-to-peer WireGuard mesh connectingx1(xx.xx.xx.43),x2(xx.xx.xx.80),x3(xx.xx.xx.65), andx(xx.xx.xx.102). - Tier 3: Local Area Network (LAN
192.168.4.0/22): Ultra low-latency physical link connecting Gigabit Ethernet onx1(xx.xx.xx.33 / standby Wi-Fi xx.xx.xx.139), Gigabit Ethernet onx2(xx.xx.xx.42 / standby Wi-Fi xx.xx.xx.210),x3(xx.xx.xx.172), andx(xx.xx.xx.59).
5. Hardware & Operating System Specifications
| Device / role | OS & kernel | Processor | RAM | Storage |
|---|---|---|---|---|
| x1 · LXD Edge Host · VMs & LXC | Ubuntu 24.04.5 LTS 6.8.0-1065-raspi | Cortex-A76 · 4 logical CPUs | 15.60 GiB | 938.38 GiB root filesystem |
| x2 · Field RF Radar & Scanner Node | Debian GNU/Linux 12 (bookworm) 6.12.109+rpt-rpi-2712 | Cortex-A76 · 4 logical CPUs | 7.87 GiB | 28.77 GiB root filesystem |
| x3 · Compute & Engineering Station | Ubuntu 24.04.5 LTS 7.0.0-38-generic | Intel(R) Celeron(R) N4500 @ 1.10GHz · 2 logical CPUs | 7.57 GiB | 117.55 GiB root filesystem |
| xpve · Host x · VMs & LXC | Proxmox VE 9.2.21 / Debian GNU/Linux 13 (trixie) 7.0.14-20-pve | Intel(R) Core(TM) i9-9980HK CPU @ 2.40GHz · 16 logical CPUs | 31.24 GiB | 93.93 GiB root filesystem |
| ec2 · Cloud Ingress | Ubuntu 24.04.5 LTS 7.0.0-1012-aws | Intel(R) Xeon(R) Platinum 8175M CPU @ 2.50GHz · 2 logical CPUs | 0.89 GiB | 23.17 GiB root filesystem |
Host labels match Mission Control. CPU and memory values are measured independently of VM/container allocations; storage shows root-filesystem capacity. VM and LXC guest details appear in live telemetry.
6. Active Edge Endpoints Directory
36 services, using the same names, device/environment assignments, logos and launch URLs as the main dashboard. Expand a category or search for a service.
Cyber & Network Defense (4)
DevOps & Infrastructure (6)
Edge IIoT & Home (9)
Observability & Historian (7)
RF Radar & Scanning (1)
SCADA & Control (9)
Fleet telemetry, naming & service endpoints
xpveVirtualization hostxpct-ID-servicexpve LXC containerxpve-vm-ID-servicexpve virtual machinex1-lxc-servicex1 LXD-managed LXCrke2-applicationRKE2 application routeTemperature every 5 minutes · CPU/RAM every 10 minutes · Storage every 12 hours. Values retain individual timestamps.
SQL historian: xpct-102-x-db → ignition_logs → cluster_telemetry.fleet_samples. RKE2 readiness and actual pod placement are shown when its API is available.
Environment DNS names
Canonical URLs below match the main service catalog. Friendly DNS exceptions: mm, cyber, otsec, logs, radar, portal and docs retain their short names. Existing compatibility aliases remain available; Home Assistant is retired.
Portal hosting & data sources
Public HTTPS ingress runs on ec2. Application hosting and database hosting are listed separately below.
| Portal | Application host | Data source |
|---|---|---|
| Fleet Intelligence | ec2 · private portal | Fleet inventory / operator directory |
| Docs | RKE2 host · VM 101 · port 30870 | Published fleet documentation + RKE2 PostgreSQL |
| Cyber | RKE2 host · VM 101 · port 30850 | RKE2 PostgreSQL ignition_db |
| OTSec | RKE2 host · VM 101 · port 30860 | RKE2 PostgreSQL ignition_db |
| Ignition Logs | RKE2 host · VM 101 · port 31950 | RKE2 gateways / PostgreSQL ignition_db |
These Python portals run on the RKE2 VM host. PostgreSQL runs as a Kubernetes workload inside RKE2. Fleet telemetry history is stored separately on xpve → x-db → ignition_logs.
RKE2 (22)
- cyber.xk3s.com
- logs.xk3s.com
- mm.xk3s.com
- otsec.xk3s.com
- rke2emqx.xk3s.com
- rke2gitea.xk3s.com
- rke2grafana.xk3s.com
- rke2headlamp.xk3s.com
- rke2ignition.xk3s.com
- rke2ignitionbackup.xk3s.com
- rke2ignitiondev.xk3s.com
- rke2ignitioneam.xk3s.com
- rke2influx.xk3s.com
- rke2jupyter.xk3s.com
- rke2neuron.xk3s.com
- rke2nodered.xk3s.com
- rke2pihole.xk3s.com
- rke2portainer.xk3s.com
- rke2rabbitmq.xk3s.com
- rke2studio.xk3s.com
- rke2workbench.xk3s.com
- u.xk3s.com