STRICT PERSONAL ENCLAVE • 100% PRIVATE

xk3s Fleet Topology & Cluster Manual

Comprehensive reference architecture, static network coordinates, mutual SSH key authentication matrix, and containerized workload topologies for the personal edge Kubernetes cluster.

COORDINATES MASKED
Click any individual coordinate to peek, or toggle all.

1. Master Fleet Coordinates

The decoupled dual-cluster personal infrastructure connects across local LAN, direct WireGuard cloud overlay, and Tailscale zero-trust meshes:

Device Hostname User LAN IP WireGuard Tailscale Ingress / Role
x1 · LXD Edge Host · VMs & LXC x1 x1 xx.xx.xx.33 (eth0) / xx.xx.xx.139 (wlan0) xx.xx.xx.2 xx.xx.xx.43 LXD edge virtualization, LXC applications, NVMe storage
x2 · Field RF Radar & Scanner Node x2 x2 xx.xx.xx.42 (eth0) / xx.xx.xx.210 (wlan0) xx.xx.xx.3 xx.xx.xx.80 Dedicated field RF radar and scanner operations
x3 · Compute & Engineering Station x3 x xx.xx.xx.172 xx.xx.xx.5 xx.xx.xx.65 Field compute, emergency engineering, disaster recovery
xpve · Host x · VMs & LXC x root xx.xx.xx.59 (Wi-Fi) xx.xx.xx.4 xx.xx.xx.102 Proxmox VE 9.2 Hypervisor • 100% Headless Clamshell (8C/16T, 32GB RAM, 2TB NVMe)
ec2 · Cloud Ingress aws-hub ubuntu — xx.xx.xx.1 — Ingress Gateway & HA Router (xx.xx.xx.95)

2. Remote Access & SSH Matrix

Passwordless ED25519 authentication is configured across all devices. Use these standard connection commands:

# Operator SSH aliases · current fleet
ssh x1 # LXD Edge Host · VMs & LXC
ssh x2 # Field RF Radar & Scanner Node
ssh x3 # Compute & Engineering Station
ssh xpve # Host x · Proxmox VMs & LXC
ssh ec2-pub # Cloud ingress

3. Fleet Virtualization & RKE2 Architecture

RKE2 application cluster

VM 101 on xpve · 1 verified node(s): rke2-master. Actual namespace and pod placement appear in live telemetry.

x1 · LXD Edge Host · VMs & LXC

LXD edge virtualization: 7 LXC containers. K3s is stopped.

x2 · Field RF Radar & Scanner Node

Field RF radar and scanner operations. K3s is stopped.

x3 · Compute & Engineering Station

Field compute and engineering. K3s is stopped.

xpve · Host x · VMs & LXC

Host x runs Proxmox VMs and LXC, including RKE2 VM 101 and the x-db SQL historian.

ec2 · Cloud Ingress

Public HTTPS ingress, WireGuard hub and private Fleet Intelligence portal.

4. Multi-Tier Mesh Overlay

The network utilizes a multi-tier overlay model guaranteeing encrypted connectivity across all fleet endpoints:

5. Hardware & Operating System Specifications

Device / roleOS & kernelProcessorRAMStorage
x1 · LXD Edge Host · VMs & LXCUbuntu 24.04.5 LTS
6.8.0-1065-raspi
Cortex-A76 · 4 logical CPUs15.60 GiB938.38 GiB root filesystem
x2 · Field RF Radar & Scanner NodeDebian GNU/Linux 12 (bookworm)
6.12.109+rpt-rpi-2712
Cortex-A76 · 4 logical CPUs7.87 GiB28.77 GiB root filesystem
x3 · Compute & Engineering StationUbuntu 24.04.5 LTS
7.0.0-38-generic
Intel(R) Celeron(R) N4500 @ 1.10GHz · 2 logical CPUs7.57 GiB117.55 GiB root filesystem
xpve · Host x · VMs & LXCProxmox VE 9.2.21 / Debian GNU/Linux 13 (trixie)
7.0.14-20-pve
Intel(R) Core(TM) i9-9980HK CPU @ 2.40GHz · 16 logical CPUs31.24 GiB93.93 GiB root filesystem
ec2 · Cloud IngressUbuntu 24.04.5 LTS
7.0.0-1012-aws
Intel(R) Xeon(R) Platinum 8175M CPU @ 2.50GHz · 2 logical CPUs0.89 GiB23.17 GiB root filesystem

Host labels match Mission Control. CPU and memory values are measured independently of VM/container allocations; storage shows root-filesystem capacity. VM and LXC guest details appear in live telemetry.

6. Active Edge Endpoints Directory

36 services, using the same names, device/environment assignments, logos and launch URLs as the main dashboard. Expand a category or search for a service.

Cyber & Network Defense (4)
rke2-compliance logo
rke2-compliancexpve · RKE2 · RKE2 · 30891 · RKE2 data connected
Open ↗
rke2-cyber logo
rke2-cyberxpve · RKE2 · RKE2 · 30850 · RKE2 data connected
Open ↗
rke2-otsec logo
rke2-otsecxpve · RKE2 · RKE2 · 30860 · RKE2 data connected
Open ↗
rke2-pi-hole-dns-shield logo
rke2-pi-hole-dns-shieldxpve · RKE2 · :30990 · HTTP verified
Open ↗
DevOps & Infrastructure (6)
ec2-host-fleet-intelligence-portal logo
ec2-host-fleet-intelligence-portalec2 · HOST · :8095 · Active Gateway
Open ↗
rke2-docs logo
rke2-docsxpve · RKE2 · RKE2 · 30870 · RKE2 data connected
Open ↗
rke2-gitea-industrial-devops logo
rke2-gitea-industrial-devopsxpve · RKE2 · :31410 · UI reachable
Open ↗
rke2-headlamp-k8s-hud logo
rke2-headlamp-k8s-hudxpve · RKE2 · :32619 · UI reachable
Open ↗
rke2-mattermost-chatops logo
rke2-mattermost-chatopsxpve · RKE2 · :32758 · HTTP reachable
Open ↗
rke2-portainer-ce logo
rke2-portainer-cexpve · RKE2 · :30779 · UI reachable
Open ↗
Edge IIoT & Home (9)
rke2-emqx-neuron-gateway logo
rke2-emqx-neuron-gatewayxpve · RKE2 · :30700 · HTTP verified
Open ↗
rke2-emqx-uns-broker logo
rke2-emqx-uns-brokerxpve · RKE2 · :31808 · HTTP verified
Open ↗
rke2-node-red-flow-studio logo
rke2-node-red-flow-studioxpve · RKE2 · :31880 · HTTP verified
Open ↗
rke2-rabbitmq-broker logo
rke2-rabbitmq-brokerxpve · RKE2 · :31672 · HTTP verified
Open ↗
x1-lxc-mosquitto logo
x1-lxc-mosquittox1 · LXC · :1883 · Inventory verified
Open ↗
x1-lxc-opcua logo
x1-lxc-opcuax1 · LXC · :1880 · :4840 · Login required
Open ↗
x1-lxc-rabbitmq logo
x1-lxc-rabbitmqx1 · LXC · :15672 · Inventory verified
Open ↗
xpct-103-x-mosquitto logo
xpct-103-x-mosquittoxpve · LXC · :1883 · Inventory verified
Open ↗
xpct-104-x-rabbitmq logo
xpct-104-x-rabbitmqxpve · LXC · :15672 · Inventory verified
Open ↗
Observability & Historian (7)
rke2-adminer-database-studio logo
rke2-adminer-database-studioxpve · RKE2 · :30875 · HTTP verified
Open ↗
rke2-grafana-observability logo
rke2-grafana-observabilityxpve · RKE2 · :30300 · HTTP verified
Open ↗
rke2-influxdb-historian logo
rke2-influxdb-historianxpve · RKE2 · :30086 · HTTP verified
Open ↗
rke2-jupyterlab-analytics logo
rke2-jupyterlab-analyticsxpve · RKE2 · :30895 · HTTP verified
Open ↗
x1-lxc-influx logo
x1-lxc-influxx1 · LXC · :8086 · Inventory verified
Open ↗
x1-lxc-postgres logo
x1-lxc-postgresx1 · LXC · :5432 · Inventory verified
Open ↗
xpct-102-x-db logo
xpct-102-x-dbxpve · LXC · :5432 · Inventory verified
Open ↗
RF Radar & Scanning (1)
x2-rf-radar-scanner logo
x2-rf-radar-scannerx2 · HOST · :443 · Login required
Open ↗
SCADA & Control (9)
rke2-ignition-dev-gateway logo
rke2-ignition-dev-gatewayxpve · RKE2 · :30388 · HTTP verified
Open ↗
rke2-ignition-eam-central logo
rke2-ignition-eam-centralxpve · RKE2 · :30488 · HTTP verified
Open ↗
rke2-ignition-gateway-logs logo
rke2-ignition-gateway-logsxpve · RKE2 · RKE2 · 31950 · RKE2 data connected
Open ↗
rke2-ignition-prod-backup logo
rke2-ignition-prod-backupxpve · RKE2 · :30288 · HTTP verified
Open ↗
rke2-ignition-prod-master logo
rke2-ignition-prod-masterxpve · RKE2 · :30188 · HTTP verified
Open ↗
rke2-openplc-runtime logo
rke2-openplc-runtimexpve · RKE2 · :30880 · HTTP verified
Open ↗
x1-lxc-mes logo
x1-lxc-mesx1 · LXC · :8088 · Inventory verified
Open ↗
x1-lxc-scada logo
x1-lxc-scadax1 · LXC · :8088 · Inventory verified
Open ↗
xpct-105-x-ignition logo
xpct-105-x-ignitionxpve · LXC · :8088 · Inventory verified
Open ↗

Fleet telemetry, naming & service endpoints

xpveVirtualization host
xpct-ID-servicexpve LXC container
xpve-vm-ID-servicexpve virtual machine
x1-lxc-servicex1 LXD-managed LXC
rke2-applicationRKE2 application route

Temperature every 5 minutes · CPU/RAM every 10 minutes · Storage every 12 hours. Values retain individual timestamps.

SQL historian: xpct-102-x-db → ignition_logs → cluster_telemetry.fleet_samples. RKE2 readiness and actual pod placement are shown when its API is available.

Environment DNS names

Canonical URLs below match the main service catalog. Friendly DNS exceptions: mm, cyber, otsec, logs, radar, portal and docs retain their short names. Existing compatibility aliases remain available; Home Assistant is retired.

Portal hosting & data sources

Public HTTPS ingress runs on ec2. Application hosting and database hosting are listed separately below.

PortalApplication hostData source
Fleet Intelligenceec2 · private portalFleet inventory / operator directory
DocsRKE2 host · VM 101 · port 30870Published fleet documentation + RKE2 PostgreSQL
CyberRKE2 host · VM 101 · port 30850RKE2 PostgreSQL ignition_db
OTSecRKE2 host · VM 101 · port 30860RKE2 PostgreSQL ignition_db
Ignition LogsRKE2 host · VM 101 · port 31950RKE2 gateways / PostgreSQL ignition_db

These Python portals run on the RKE2 VM host. PostgreSQL runs as a Kubernetes workload inside RKE2. Fleet telemetry history is stored separately on xpve → x-db → ignition_logs.

RKE2 (22)
ec2 · Cloud Ingress (1)
x1 · LXC (5)
x2 · Field RF Radar & Scanner Node (1)
xpct · xpve LXC (2)
xpve · Host console (1)