8a432791646422a6ab34997e1a624147bed716f2
The protonvpn provider mode uses gluetun's embedded server database which doesn't contain US-TX#253 or US-TX#34. Our WireGuard keys are registered for specific ProtonVPN servers, so connecting to other servers (US-TX#179, US-TX#220) results in successful WireGuard handshake but ProtonVPN drops all internet-bound traffic. Fix: use VPN_SERVICE_PROVIDER=custom to directly configure the correct server peer public key and endpoint IP for each worker. ExternalSecrets updated to also pull public_key and endpoint_ip from Vault. - tx253: endpoint=95.173.217.29, peer=mngiSxBpH7GU24nnWdBEcnhDnCPn2jq5+ZP3zwPwISA= - tx34: endpoint=146.70.58.130, peer=wqJcz4akzVFxx35aJ5B7G/IJ9qsRvpcGNub3rLHcqXo=
infrastructure
Personal infrastructure-as-code for Legion (k3s home server) and supporting tooling.
| Doc | What it covers |
|---|---|
AGENTS.md |
Full reference: machines, secrets, services, domains, namespaces, common operations |
servers/legion/README.md |
What's running on Legion and how deployment works |
servers/legion/RUNBOOK.md |
Disaster recovery — full restore from scratch |
Quick start
cd servers/legion
direnv allow
terraform plan
terraform apply
Push to servers/ to deploy app changes via Argo CD.
Languages
HCL
78.4%
Shell
17.5%
Python
2.6%
Dockerfile
1.5%