Update Legion LAN IP from 192.168.68.77 to 192.168.8.148
Static IP assigned on new network segment. Updates: - variables.tf default legion_ip - headscale nameserver config - bootstrap.sh default target - README/RUNBOOK documentation - media ingress comment
This commit is contained in:
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
Ubuntu 24.04 home server running k3s. Hosts all personal and platform infrastructure.
|
Ubuntu 24.04 home server running k3s. Hosts all personal and platform infrastructure.
|
||||||
|
|
||||||
**LAN IP:** `192.168.68.77`
|
**LAN IP:** `192.168.8.148`
|
||||||
**SSH:** `ssh legion`
|
**SSH:** `ssh legion`
|
||||||
**Kubeconfig:** `~/.kube/legion-config`
|
**Kubeconfig:** `~/.kube/legion-config`
|
||||||
|
|
||||||
@@ -76,14 +76,14 @@ git push # Argo CD auto-syncs within ~30s
|
|||||||
|
|
||||||
## Networking
|
## Networking
|
||||||
|
|
||||||
**Router:** TP-Link Deco BE5000 mesh network, router mode. Subnet `192.168.68.x`, DHCP DNS points to AdGuard (`192.168.68.77`).
|
**Router:** TP-Link Deco BE5000 mesh network, router mode. Subnet `192.168.68.x`, DHCP DNS points to AdGuard (`192.168.8.148`).
|
||||||
|
|
||||||
External traffic reaches Legion two ways:
|
External traffic reaches Legion two ways:
|
||||||
|
|
||||||
1. **Cloudflare Tunnel** — public services (`*.neuralplatform.ai`) route through a tunnel pod in k8s. No ports open on the router.
|
1. **Cloudflare Tunnel** — public services (`*.neuralplatform.ai`) route through a tunnel pod in k8s. No ports open on the router.
|
||||||
2. **Direct port forward** — DoT on port 853 (TCP) is forwarded from the router to `192.168.68.77:853`. Required because Cloudflare can't proxy raw TCP.
|
2. **Direct port forward** — DoT on port 853 (TCP) is forwarded from the router to `192.168.8.148:853`. Required because Cloudflare can't proxy raw TCP.
|
||||||
|
|
||||||
LAN devices use AdGuard as their DNS server (`192.168.68.77`). AdGuard rewrites `*.nook.family` and `*.neuralplatform.ai` to the LAN IP so local traffic stays local.
|
LAN devices use AdGuard as their DNS server (`192.168.8.148`). AdGuard rewrites `*.nook.family` and `*.neuralplatform.ai` to the LAN IP so local traffic stays local.
|
||||||
|
|
||||||
ddclient keeps the `dot.nook.family` A record updated if the home IP changes.
|
ddclient keeps the `dot.nook.family` A record updated if the home IP changes.
|
||||||
|
|
||||||
|
|||||||
@@ -47,11 +47,11 @@ source ~/Secrets/credentials/infrastructure.env
|
|||||||
|
|
||||||
## Step 2 — Provision Fresh Machine
|
## Step 2 — Provision Fresh Machine
|
||||||
|
|
||||||
Fresh Ubuntu 24.04 LTS, same LAN IP (`192.168.68.77`).
|
Fresh Ubuntu 24.04 LTS, same LAN IP (`192.168.8.148`).
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
# From Mac — copy SSH key and cloudflared credentials
|
# From Mac — copy SSH key and cloudflared credentials
|
||||||
ssh-copy-id will@192.168.68.77
|
ssh-copy-id will@192.168.8.148
|
||||||
scp ~/Secrets/certs/cloudflared-gitea.json legion:/tmp/cloudflared-gitea.json
|
scp ~/Secrets/certs/cloudflared-gitea.json legion:/tmp/cloudflared-gitea.json
|
||||||
|
|
||||||
# Run bootstrap
|
# Run bootstrap
|
||||||
@@ -135,7 +135,7 @@ kubectl get pods -A | grep -v Running | grep -v Completed
|
|||||||
kubectl get applications -n argocd
|
kubectl get applications -n argocd
|
||||||
|
|
||||||
# DNS working (AdGuard)
|
# DNS working (AdGuard)
|
||||||
dig @192.168.68.77 git.neuralplatform.ai
|
dig @192.168.8.148 git.neuralplatform.ai
|
||||||
|
|
||||||
# Services reachable
|
# Services reachable
|
||||||
curl -sk https://git.neuralplatform.ai/api/v1/version
|
curl -sk https://git.neuralplatform.ai/api/v1/version
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ data:
|
|||||||
base_domain: ts.neuralplatform.ai
|
base_domain: ts.neuralplatform.ai
|
||||||
nameservers:
|
nameservers:
|
||||||
global:
|
global:
|
||||||
- 192.168.68.77
|
- 192.168.8.148
|
||||||
- 1.1.1.1
|
- 1.1.1.1
|
||||||
derp:
|
derp:
|
||||||
server:
|
server:
|
||||||
|
|||||||
@@ -10,7 +10,7 @@
|
|||||||
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
LEGION_IP="${1:-192.168.68.77}"
|
LEGION_IP="${1:-192.168.8.148}"
|
||||||
NVIDIA_DRIVER="nvidia-driver-580"
|
NVIDIA_DRIVER="nvidia-driver-580"
|
||||||
|
|
||||||
log() { echo ""; echo "==> $*"; }
|
log() { echo ""; echo "==> $*"; }
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
# Admin ingresses — LAN only, not added to Cloudflare tunnel
|
# Admin ingresses — LAN only, not added to Cloudflare tunnel
|
||||||
# Accessible on home network via AdGuard DNS (*.nook.family → 192.168.68.77)
|
# Accessible on home network via AdGuard DNS (*.nook.family → 192.168.8.148)
|
||||||
---
|
---
|
||||||
apiVersion: networking.k8s.io/v1
|
apiVersion: networking.k8s.io/v1
|
||||||
kind: Ingress
|
kind: Ingress
|
||||||
|
|||||||
@@ -5,9 +5,9 @@ variable "kubeconfig_path" {
|
|||||||
}
|
}
|
||||||
|
|
||||||
variable "legion_ip" {
|
variable "legion_ip" {
|
||||||
description = "Legion server LAN IP (DHCP reserved)"
|
description = "Legion server LAN IP (static)"
|
||||||
type = string
|
type = string
|
||||||
default = "192.168.68.77"
|
default = "192.168.8.148"
|
||||||
}
|
}
|
||||||
|
|
||||||
variable "domain_suffix" {
|
variable "domain_suffix" {
|
||||||
|
|||||||
Reference in New Issue
Block a user