STRICT PERSONAL ENCLAVE • 100% PRIVATE

xk3s Fleet Topology & Cluster Manual

Comprehensive reference architecture, static network coordinates, mutual SSH key authentication matrix, and containerized workload topologies for the personal edge Kubernetes cluster.

COORDINATES MASKED
Click any individual coordinate to peek, or toggle all.

1. Master Fleet Coordinates

The decoupled dual-cluster personal infrastructure connects across local LAN, direct WireGuard cloud overlay, and Tailscale zero-trust meshes:

Device Hostname User LAN IP WireGuard Tailscale Ingress / Role
ec2 (Gateway)
aws-hub ubuntu — xx.xx.xx.1 — Ingress Gateway & HA Router (xx.xx.xx.95)
x1 (Master)
x1 x1 xx.xx.xx.139 xx.xx.xx.2 xx.xx.xx.43 K3s Master, NVMe Storage, API (6443)
x2 (Worker)
x2 x2 xx.xx.xx.146 xx.xx.xx.3 xx.xx.xx.80 K3s Edge Worker, HDMI Kiosk, Gitea (31410)
x3 (Compute Worker)
x3 x xx.xx.xx.172 xx.xx.xx.5 xx.xx.xx.65 AMD64 Compute Worker, Offload Target
x (Hypervisor)
x root xx.xx.xx.59 (Wi-Fi) xx.xx.xx.4 xx.xx.xx.102 Proxmox VE 9.2 Hypervisor • 100% Headless Clamshell (8C/16T, 32GB RAM, 2TB NVMe)

2. Remote Access & SSH Matrix

Passwordless ED25519 authentication is configured across all devices. Use these standard connection commands:

# Cluster 1: K3s Edge Fleet
ssh x1@xx.xx.xx.43 # Cluster Master x1 (Tailscale / WireGuard xx.xx.xx.2)
ssh x2@xx.xx.xx.80 # Edge Worker x2 (Tailscale / WireGuard xx.xx.xx.3)

# Tier 2: Distributed Compute & Hypervisor
ssh x3@xx.xx.xx.65 # Compute Worker x3 (Tailscale / WireGuard xx.xx.xx.5)
ssh x # Headless Hypervisor x (Tailscale xx.xx.xx.102 / LAN xx.xx.xx.59:8006)

# AWS Cloud Ingress Gateway
ssh ec2-pub # AWS EC2 Ingress Gateway (xx.xx.xx.95)

3. Decoupled Dual-Cluster Architecture

The infrastructure is strictly decoupled into two isolated orchestration fabrics to separate real-time industrial edge automation from heavy compute workloads and hot standby redundancy:

Cluster 1: Dedicated K3s Edge Fleet (Industrial Primary Tier)

Flannel 10.42.0.0/16 • ClusterIP 10.43.0.0/16

Optimized edge cluster running on low-power ARM64 nodes. Orchestrates real-time SCADA runtime, IEC 61131-3 soft PLC automation, telemetry historian, and physical HDMI kiosk surfaces.

x1 Control Plane
K3S MASTER
K3s API Server6443 (xx.xx.xx.2)
Active WorkloadsIgnition, Influx, OpenPLC, Portainer
Storage Backend939GB NVMe PCIe
Internal ClusterIP10.43.0.0/16
Pod CIDR (Flannel)10.42.0.0/24
Hardware Platform4C • 15 GB RAM
x2 Edge Worker
K3S WORKER
Worker AgentK3s v1.31+
Active WorkloadsGitea (:31410), Web HUD, Sparkplug B
HDMI Kiosk SurfaceLocal Display / Chromium
VNC ServerPort 5900 (wayvnc)
Pod CIDR (Flannel)10.42.1.0/24
Hardware Platform4C • 8 GB RAM

Tier 2: Distributed Compute & Hypervisor Tier

Proxmox VE 9.2 • QEMU/KVM • LXC • 100% Headless Clamshell

Bare-metal compute offload and hypervisor infrastructure. Node x operates 100% headless with internal display backlight powered down, lid-suspend masked, and stable 58°C thermals. Node x3 provides dedicated x86_64 compute capacity.

x (Hypervisor)
HYPERVISOR
Web Management GUIhttps://xx.xx.xx.59:8006/ (Wi-Fi)
Tailscale Remote GUIhttps://xx.xx.xx.102:8006/
Hardware PlatformIntel Core i9-9980HK (8C/16T, 32GB RAM, 2TB NVMe)
Headless ClamshellBacklight 0 • Lid Suspend Masked • 58°C
Cluster ServicesProxmox VE 9.2, QEMU/KVM, LXC, Multi-SAN SSL
WireGuard Meshxx.xx.xx.4 (Peer to EC2 xx.xx.xx.1)
x3 (Compute Worker)
COMPUTE WORKER
Operating SystemUbuntu 24.04 LTS
Hardware PlatformIntel N4500 (2C, 8GB RAM, 118GB NVMe)
WireGuard Meshxx.xx.xx.5 (Direct wg0)
Tailscale C2xx.xx.xx.65
Offload TargetGeneral Compute, Standby Host
Remote Terminalssh x3

Cloud Ingress Gateway & Automated HA Failover Routing

Active-Standby Zero Downtime

Nginx reverse proxy on aws-hub (ec2) routes external HTTPS traffic dynamically across the edge fleet. When primary edge nodes time out or pause, traffic fails over seamlessly within 3 seconds to standby compute capacity.

AWS EC2 Ingress Gateway
HA GATEWAY
Reverse ProxyNginx 1.24+
SSL TerminationLet's Encrypt TLS 1.3
WireGuard Hubxx.xx.xx.1 (UDP 51820)
Cloudflare ProxyZero-Trust Shield & HTTP/3
Public Origin IPxx.xx.xx.95
Automated Failover Mechanics
ARMED & ACTIVE
Primary Upstreamxx.xx.xx.2 (K3s Edge Master)
Standby Upstreamxx.xx.xx.5 (Compute Node x3 backup)
Failover Thresholdmax_fails=2 fail_timeout=5s
Connection Timeoutproxy_connect_timeout 3s
Cutover StatusAutomated next-upstream retry

4. Multi-Tier Mesh Overlay

The network utilizes a multi-tier overlay model guaranteeing encrypted connectivity across all fleet endpoints:

5. Hardware & Operating System Specifications

Node Operating System Arch Processor RAM Storage
ec2 (Gateway) Ubuntu 24.04 LTS x86_64 AWS Nitro vCPU 1 GB Burst 24 GB gp3 EBS
x1 (Master) Debian 13 (Trixie) aarch64 4C Cortex-A76 15 GB RAM 939 GB NVMe PCIe Gen3
x2 (Worker) Debian 12 (Bookworm) aarch64 4C Cortex-A76 8 GB RAM 29 GB Storage
x3 (Compute) Ubuntu 24.04 LTS x86_64 Intel Celeron N4500 (2 cores) 8 GB DDR4 118 GB NVMe SSD
x (Hypervisor) Debian 13 / Proxmox VE 9.2 x86_64 Intel Core i9-9980HK (8C/16T) 32 GB DDR4 2 TB NVMe SSD

6. Active Edge Endpoints Directory

All services are routed securely through the AWS Ingress gateway with SSL termination:

Cluster Core & Operations
Level 4/5
Mission Control HUD
xk3s.com ↗
Headlamp K8s Console
headlamp.xk3s.com ↗
Portainer Enterprise
portainer.xk3s.com ↗
Grafana Observability
grafana.xk3s.com ↗
Pi-hole DNS Shield
pihole.xk3s.com ↗
Industrial SCADA Fleet
ISA-95 Level 3
Ignition Prod Master
prod.xk3s.com ↗
Ignition Prod Backup
backup.xk3s.com ↗
Ignition Dev Sandbox
dev.xk3s.com ↗
Ignition EAM Central
eam.xk3s.com ↗
Gateway Real-Time Logs
logs.xk3s.com ↗
IIoT & Unified Namespace
Sparkplug B
Node-RED OT Flows
nodered.xk3s.com ↗
EMQX UNS Broker
emqx.xk3s.com ↗
RabbitMQ Message Fabric
rabbitmq.xk3s.com ↗
InfluxDB Historian
influx.xk3s.com ↗
Neuron Edge Gateway
neuron.xk3s.com ↗
DevOps & Team Collaboration
CI/CD & C2
Gitea Industrial Git
gitea.xk3s.com ↗
Mattermost C2 / xk3s Hub
Join xk3s Channel ↗
OpenPLC Runtime (Web)
workbench.xk3s.com ↗
OpenPLC Modbus TCP
xx.xx.xx.2:30502
PostgreSQL Fleet DB
xx.xx.xx.139:30542