xk3s Fleet Topology & Cluster Manual
Comprehensive reference architecture, static network coordinates, mutual SSH key authentication matrix, and containerized workload topologies for the personal edge Kubernetes cluster.
1. Master Fleet Coordinates
The decoupled dual-cluster personal infrastructure connects across local LAN, direct WireGuard cloud overlay, and Tailscale zero-trust meshes:
| Device | Hostname | User | LAN IP | WireGuard | Tailscale | Ingress / Role |
|---|---|---|---|---|---|---|
| ec2 (Gateway) | aws-hub | ubuntu | — | xx.xx.xx.1 | — | Ingress Gateway & HA Router (xx.xx.xx.95) |
| x1 (Master) | x1 | x1 | xx.xx.xx.139 | xx.xx.xx.2 | xx.xx.xx.43 | K3s Master, NVMe Storage, API (6443) |
| x2 (Worker) | x2 | x2 | xx.xx.xx.146 | xx.xx.xx.3 | xx.xx.xx.80 | K3s Edge Worker, HDMI Kiosk, Gitea (31410) |
| x3 (Compute Worker) | x3 | x | xx.xx.xx.172 | xx.xx.xx.5 | xx.xx.xx.65 | AMD64 Compute Worker, Offload Target |
| x (Hypervisor) | x | root | xx.xx.xx.59 (Wi-Fi) | xx.xx.xx.4 | xx.xx.xx.102 | Proxmox VE 9.2 Hypervisor • 100% Headless Clamshell (8C/16T, 32GB RAM, 2TB NVMe) |
2. Remote Access & SSH Matrix
Passwordless ED25519 authentication is configured across all devices. Use these standard connection commands:
ssh x1@xx.xx.xx.43 # Cluster Master x1 (Tailscale / WireGuard xx.xx.xx.2)
ssh x2@xx.xx.xx.80 # Edge Worker x2 (Tailscale / WireGuard xx.xx.xx.3)
# Tier 2: Distributed Compute & Hypervisor
ssh x3@xx.xx.xx.65 # Compute Worker x3 (Tailscale / WireGuard xx.xx.xx.5)
ssh x # Headless Hypervisor x (Tailscale xx.xx.xx.102 / LAN xx.xx.xx.59:8006)
# AWS Cloud Ingress Gateway
ssh ec2-pub # AWS EC2 Ingress Gateway (xx.xx.xx.95)
3. Decoupled Dual-Cluster Architecture
The infrastructure is strictly decoupled into two isolated orchestration fabrics to separate real-time industrial edge automation from heavy compute workloads and hot standby redundancy:
Cluster 1: Dedicated K3s Edge Fleet (Industrial Primary Tier)
Flannel 10.42.0.0/16 • ClusterIP 10.43.0.0/16Optimized edge cluster running on low-power ARM64 nodes. Orchestrates real-time SCADA runtime, IEC 61131-3 soft PLC automation, telemetry historian, and physical HDMI kiosk surfaces.
Tier 2: Distributed Compute & Hypervisor Tier
Proxmox VE 9.2 • QEMU/KVM • LXC • 100% Headless ClamshellBare-metal compute offload and hypervisor infrastructure. Node x operates 100% headless with internal display backlight powered down, lid-suspend masked, and stable 58°C thermals. Node x3 provides dedicated x86_64 compute capacity.
Cloud Ingress Gateway & Automated HA Failover Routing
Active-Standby Zero Downtime
Nginx reverse proxy on aws-hub (ec2) routes external HTTPS traffic dynamically across the edge fleet. When primary edge nodes time out or pause, traffic fails over seamlessly within 3 seconds to standby compute capacity.
4. Multi-Tier Mesh Overlay
The network utilizes a multi-tier overlay model guaranteeing encrypted connectivity across all fleet endpoints:
- Tier 1: Cloud-to-Edge Mesh (WireGuard
10.10.0.0/24): Dedicated point-to-point encrypted link connecting AWS EC2 gatewayec2(xx.xx.xx.1) to K3s masterx1(xx.xx.xx.2), edge workerx2(xx.xx.xx.3), hypervisorx(xx.xx.xx.4), and compute workerx3(xx.xx.xx.5). - Tier 2: Zero-Trust Remote Mesh (Tailscale
100.64.0.0/10): Direct peer-to-peer WireGuard mesh connectingx1(xx.xx.xx.43),x2(xx.xx.xx.80),x3(xx.xx.xx.65), andx(xx.xx.xx.102). - Tier 3: Local Area Network (LAN
192.168.4.0/24): Ultra low-latency physical link connectingx1(xx.xx.xx.139),x2(xx.xx.xx.146),x3(xx.xx.xx.172), andx(xx.xx.xx.59).
5. Hardware & Operating System Specifications
| Node | Operating System | Arch | Processor | RAM | Storage |
|---|---|---|---|---|---|
| ec2 (Gateway) | Ubuntu 24.04 LTS | x86_64 | AWS Nitro vCPU | 1 GB Burst | 24 GB gp3 EBS |
| x1 (Master) | Debian 13 (Trixie) | aarch64 | 4C Cortex-A76 | 15 GB RAM | 939 GB NVMe PCIe Gen3 |
| x2 (Worker) | Debian 12 (Bookworm) | aarch64 | 4C Cortex-A76 | 8 GB RAM | 29 GB Storage |
| x3 (Compute) | Ubuntu 24.04 LTS | x86_64 | Intel Celeron N4500 (2 cores) | 8 GB DDR4 | 118 GB NVMe SSD |
| x (Hypervisor) | Debian 13 / Proxmox VE 9.2 | x86_64 | Intel Core i9-9980HK (8C/16T) | 32 GB DDR4 | 2 TB NVMe SSD |
6. Active Edge Endpoints Directory
All services are routed securely through the AWS Ingress gateway with SSL termination:
