RESTRICTED ENCLAVE

Architecture Manual

Enter Sovereign Master Passphrase to decrypt the fleet topology, node network coordinates, and cluster runbooks.

Passphrase incorrect. Access denied.
Passphrase verified. Decrypting manual...
🛡️ STRICT PERSONAL ENCLAVE • 100% PRIVATE

xk3s Fleet Topology & Cluster Manual

Comprehensive reference architecture, static network coordinates, mutual SSH key authentication matrix, and containerized workload topologies for the personal edge Kubernetes cluster.

COORDINATES MASKED
Click any individual coordinate to peek, or toggle all.

1. 🗺️ Master Fleet Coordinates

The personal infrastructure consists of 7 primary devices and cluster nodes connected across local LAN, WireGuard cloud overlay, and Tailscale zero-trust meshes:

Device Hostname User LAN IP WireGuard Tailscale Ingress / Role
MacBook Air das-MacBook-Air.local da 192.168.4.••• 100.71.•••.•• Primary Workstation (M1, 16GB)
MacBook Pro Doxs-MacBook-Pro.local dx 192.168.4.••• 100.102.•••.•• Secondary Workstation (i9, 32GB)
x1 (Master) x1 x1 192.168.4.••• 10.10.0.•• 100.95.•••.•• K3s Master, NVMe Storage, API (6443)
x2 (Worker) x2 x2 192.168.4.••• 10.10.0.•• 100.71.•••.•• K3s Edge Worker, HDMI Kiosk, VNC (5900)
x (Worker) x x 192.168.4.••• 10.10.0.•• 100.111.•••.•• K3s AMD64 Compute Worker, Offload Node
AWS Hub (EC2) ip-172-31-2-180 ubuntu 10.10.0.•• Ingress Gateway (54.215.•••.••)
dphone dphone 100.64.•••.•• Mobile iOS Zero-Trust Client

2. 🔑 Remote Access & SSH Matrix

Passwordless ED25519 authentication is configured across all devices. Use these standard connection commands:

# Workstation Remote Access
ssh mbp # Connect to MacBook Pro (Tailscale)
ssh mbp-lan # Connect to MacBook Pro (LAN: 192.168.4.•••)
open vnc://dx@100.102.•••.•• # Screen Share VNC session

# Edge Cluster Node Access
ssh x1@100.95.•••.•• # Cluster Master x1 (Tailscale)
ssh x2@100.71.•••.•• # Edge Worker x2 (Tailscale)
ssh x@100.111.•••.•• # Compute Worker x (Tailscale)

# AWS Cloud Gateway
ssh ec2-pub # AWS EC2 Ingress Gateway (54.215.•••.••)

3. ⚡ Dedicated K3s Kubernetes Cluster

The cluster runs lightweight Kubernetes (K3s) with dedicated control plane and edge worker nodes:

👑 x1 Control Plane
MASTER
K3s API Server6443
Active WorkloadsIgnition, Influx, OpenPLC, Portainer
Storage Backend500GB NVMe PCIe
Internal ClusterIP10.43.0.0/16
Pod CIDR (Flannel)10.42.0.0/24
Operating SystemDebian 13 (Trixie)
⚙️ x2 Edge Worker
WORKER
Worker AgentK3s v1.31+
Active WorkloadsGitea, Web HUD, Telegraf UNS
HDMI Kiosk SurfaceLocal Display / Chromium
VNC ServerPort 5900 (wayvnc)
Pod CIDR (Flannel)10.42.1.0/24
Hardware PlatformEdge Worker Node (8GB)
x Compute Worker
WORKER
Hardware Archx86_64 AMD64 (4KB Pages)
Cluster RoleAMD64 Workload Offload Node
Flannel Mesh100.111.136.65 (tailscale0)
Pod CIDR10.42.3.0/24
Operating SystemUbuntu 24.04 LTS (Linux 7.0)
💻 mbp-worker Compute
HEAVY COMPUTE
Hardware PlatformIntel Core i9 (8C/16T, 32GB RAM)
Allocated Worker12 vCPU • 24GB RAM
Pod CIDR (Flannel)10.42.2.0/24
Tailscale IP100.102.•••.••
Operating SystemUbuntu 24.04 LTS AMD64
☁️ AWS EC2 Ingress
GATEWAY
Reverse ProxyNginx 1.24+
SSL TerminationLet's Encrypt TLS 1.3
WireGuard Hub10.10.0.•• (UDP 51820)
Cloudflare ProxyZero-Trust Shield
Public IP54.215.•••.••

4. 🌐 Multi-Tier Mesh Overlay

The network utilizes a three-tier overlay model guaranteeing encrypted connectivity across all environments:

5. 🖥️ Hardware & Operating System Specifications

Node Operating System Arch Processor RAM Storage
MacBook Air macOS 26.5.2 (Darwin 25) arm64 Apple M1 (8 cores) 16 GB Unified 500 GB NVMe APFS
MacBook Pro macOS 26.7 (Darwin 25) x86_64 Intel Core i9-9880H (8C/16T) 32 GB DDR4 1.1 TB NVMe APFS
x1 (Master) Debian 13 (Trixie) aarch64 Broadcom BCM2712 (4 cores) 16 GB LPDDR4X 500 GB NVMe PCIe Gen3
x2 (Worker) Debian 12 (Bookworm) aarch64 Broadcom BCM2712 (4 cores) 8 GB LPDDR4 64 GB MicroSD
x (Worker) Ubuntu 24.04.5 LTS x86_64 AMD64 (2 cores) 8 GB RAM 64 GB SSD
AWS Hub Ubuntu 24.04 LTS x86_64 AWS Nitro vCPU 1 GB Burst 30 GB gp3 EBS

6. 🌐 Active Edge Endpoints Directory

All services are routed securely through the AWS Ingress gateway with SSL termination:

Cluster Core & Operations
Level 4/5
Mission Control HUD
xk3s.com ↗
Headlamp K8s Console
headlamp.xk3s.com ↗
Portainer Enterprise
portainer.xk3s.com ↗
Grafana Observability
grafana.xk3s.com ↗
Pi-hole DNS Shield
pihole.xk3s.com ↗
Industrial SCADA Fleet
ISA-95 Level 3
Ignition Prod Master
prod.xk3s.com ↗
Ignition Prod Backup
backup.xk3s.com ↗
Ignition Dev Sandbox
dev.xk3s.com ↗
Ignition EAM Central
eam.xk3s.com ↗
Gateway Real-Time Logs
logs.xk3s.com ↗
IIoT & Unified Namespace
Sparkplug B
Node-RED OT Flows
nodered.xk3s.com ↗
EMQX UNS Broker
emqx.xk3s.com ↗
RabbitMQ Message Fabric
rabbitmq.xk3s.com ↗
InfluxDB Historian
influx.xk3s.com ↗
Neuron Edge Gateway
neuron.xk3s.com ↗
DevOps & Team Collaboration
CI/CD & C2
Gitea Industrial Git
gitea.xk3s.com ↗
Mattermost C2 / xk3s Hub
Join xk3s Channel ↗
OpenPLC Runtime (Web)
workbench.xk3s.com ↗
OpenPLC Modbus TCP
10.10.0.2:30502
PostgreSQL Fleet DB
192.168.4.139:30542