feat: configure K3s DNS resolver and update firewall rules for new subnet
Some checks failed
validate / lint (push) Failing after 7s

This commit is contained in:
Nik Afiq 2026-08-23 14:07:49 +09:00
parent 9f9bd04b4b
commit 53d02b7522
13 changed files with 74 additions and 9 deletions

View File

@ -0,0 +1,10 @@
---
# Vars for: K3s cluster-wide DNS resolver
# Applied by: ansible/roles/k3s-server, ansible/roles/k3s-agent
# Description: Single source of truth for the resolver IP written into
# /etc/rancher/k3s/resolv.conf on every K3s node, so CoreDNS's
# "forward . /etc/resolv.conf" always reaches Technitium regardless of
# which node CoreDNS is scheduled on, or that node's own (possibly stale)
# host resolvers.
k3s_dns_resolver: 10.10.40.53

View File

@ -27,8 +27,8 @@ ufw_allowed_ports:
# agent's outbound connection to the k3s server on 6443, not a direct # agent's outbound connection to the k3s server on 6443, not a direct
# inbound connection). # inbound connection).
- { port: "6443", proto: tcp, comment: "K3s API server" } - { port: "6443", proto: tcp, comment: "K3s API server" }
- { port: "10250", proto: tcp, comment: "Kubelet" } - { port: "10250", proto: tcp, comment: "Kubelet", src: "10.10.40.0/24" }
- { port: "8472", proto: udp, comment: "Flannel VXLAN" } - { port: "8472", proto: udp, comment: "Flannel VXLAN", src: "10.10.40.0/24" }
data_dirs: data_dirs:
- /data/tts-gateway - /data/tts-gateway

View File

@ -23,8 +23,8 @@ ufw_allowed_ports:
- { port: 80, proto: tcp, comment: HTTP } - { port: 80, proto: tcp, comment: HTTP }
- { port: 443, proto: tcp, comment: HTTPS } - { port: 443, proto: tcp, comment: HTTPS }
- { port: 6443, proto: tcp, comment: K3s API server } - { port: 6443, proto: tcp, comment: K3s API server }
- { port: 10250, proto: tcp, comment: Kubelet } - { port: 10250, proto: tcp, comment: Kubelet, src: 10.10.40.0/24 }
- { port: 8472, proto: udp, comment: Flannel VXLAN } - { port: 8472, proto: udp, comment: Flannel VXLAN, src: 10.10.40.0/24 }
data_dirs: data_dirs:
- /data/gitea - /data/gitea

View File

@ -60,6 +60,7 @@
rule: allow rule: allow
port: "{{ item.port }}" port: "{{ item.port }}"
proto: "{{ item.proto }}" proto: "{{ item.proto }}"
src: "{{ item.src | default('any') }}"
comment: "{{ item.comment }}" comment: "{{ item.comment }}"
loop: "{{ ufw_allowed_ports }}" loop: "{{ ufw_allowed_ports }}"

View File

@ -6,3 +6,6 @@
k3s_version: v1.32.4+k3s1 k3s_version: v1.32.4+k3s1
k3s_server_url: https://10.10.40.53:6443 k3s_server_url: https://10.10.40.53:6443
k3s_node_token: "" k3s_node_token: ""
k3s_agent_config:
resolv-conf: /etc/rancher/k3s/resolv.conf

View File

@ -0,0 +1,9 @@
---
# Part of role: k3s-agent
# Called by: ansible/roles/k3s-agent/tasks/main.yaml
# Description: Restarts the K3s agent when its config.yaml or resolv.conf changes.
- name: Restart k3s-agent
ansible.builtin.service:
name: k3s-agent
state: restarted

View File

@ -2,7 +2,29 @@
# Part of role: k3s-agent # Part of role: k3s-agent
# Called by: ansible/playbooks/join-debian-agent.yaml # Called by: ansible/playbooks/join-debian-agent.yaml
# ansible/playbooks/setup-gpu-node.yaml # ansible/playbooks/setup-gpu-node.yaml
# Description: Installs K3s in agent mode, joins the cluster, labels and taints the node. # Description: Configures the K3s agent's DNS resolver, installs K3s in agent mode, joins the cluster, labels and taints the node.
- name: Create K3s config directory
ansible.builtin.file:
path: /etc/rancher/k3s
state: directory
mode: "0755"
- name: Write K3s agent config
ansible.builtin.copy:
dest: /etc/rancher/k3s/config.yaml
content: "{{ k3s_agent_config | to_nice_yaml }}"
mode: "0644"
notify: Restart k3s-agent
- name: Write K3s DNS resolver file
ansible.builtin.copy:
dest: /etc/rancher/k3s/resolv.conf
content: "nameserver {{ k3s_dns_resolver }}\n"
owner: root
group: root
mode: "0644"
notify: Restart k3s-agent
- name: Download and install K3s agent - name: Download and install K3s agent
ansible.builtin.shell: ansible.builtin.shell:

View File

@ -11,6 +11,7 @@ k3s_server_config:
- traefik - traefik
flannel-backend: vxlan flannel-backend: vxlan
node-ip: "{{ k3s_server_ip }}" node-ip: "{{ k3s_server_ip }}"
resolv-conf: /etc/rancher/k3s/resolv.conf
tls-san: tls-san:
- "{{ k3s_server_ip }}" - "{{ k3s_server_ip }}"
- minisforum - minisforum

View File

@ -0,0 +1,9 @@
---
# Part of role: k3s-server
# Called by: ansible/roles/k3s-server/tasks/main.yaml
# Description: Restarts K3s when its config.yaml or resolv.conf changes.
- name: Restart k3s
ansible.builtin.service:
name: k3s
state: restarted

View File

@ -1,7 +1,7 @@
--- ---
# Part of role: k3s-server # Part of role: k3s-server
# Called by: ansible/playbooks/setup-k3s.yaml # Called by: ansible/playbooks/setup-k3s.yaml
# Description: Installs K3s server, fetches kubeconfig, installs Helm, and labels the node as primary. # Description: Installs K3s server, configures its DNS resolver, fetches kubeconfig, installs Helm, and labels the node as primary.
- name: Create K3s config directory - name: Create K3s config directory
ansible.builtin.file: ansible.builtin.file:
@ -14,6 +14,16 @@
dest: /etc/rancher/k3s/config.yaml dest: /etc/rancher/k3s/config.yaml
content: "{{ k3s_server_config | to_nice_yaml }}" content: "{{ k3s_server_config | to_nice_yaml }}"
mode: "0644" mode: "0644"
notify: Restart k3s
- name: Write K3s DNS resolver file
ansible.builtin.copy:
dest: /etc/rancher/k3s/resolv.conf
content: "nameserver {{ k3s_dns_resolver }}\n"
owner: root
group: root
mode: "0644"
notify: Restart k3s
- name: Download and install K3s - name: Download and install K3s
ansible.builtin.shell: ansible.builtin.shell:

View File

@ -49,7 +49,7 @@ spec:
- name: HTTPPROXY_LOG - name: HTTPPROXY_LOG
value: "off" value: "off"
- name: FIREWALL_OUTBOUND_SUBNETS - name: FIREWALL_OUTBOUND_SUBNETS
value: "10.42.0.0/16,10.43.0.0/16,192.168.7.0/24" value: "10.42.0.0/16,10.43.0.0/16,10.10.40.0/24"
- name: BLOCK_IPV6 - name: BLOCK_IPV6
value: "on" value: "on"
ports: ports:

View File

@ -46,7 +46,7 @@ spec:
name: pia-credentials name: pia-credentials
key: OPENVPN_PASSWORD key: OPENVPN_PASSWORD
- name: FIREWALL_OUTBOUND_SUBNETS - name: FIREWALL_OUTBOUND_SUBNETS
value: "10.42.0.0/16,10.43.0.0/16,192.168.7.0/24" value: "10.42.0.0/16,10.43.0.0/16,10.10.40.0/24"
- name: BLOCK_IPV6 - name: BLOCK_IPV6
value: "on" value: "on"
startupProbe: startupProbe:

View File

@ -65,7 +65,7 @@ spec:
name: pia-credentials name: pia-credentials
key: OPENVPN_PASSWORD key: OPENVPN_PASSWORD
- name: FIREWALL_OUTBOUND_SUBNETS - name: FIREWALL_OUTBOUND_SUBNETS
value: "10.42.0.0/16,10.43.0.0/16,192.168.7.0/24" value: "10.42.0.0/16,10.43.0.0/16,10.10.40.0/24"
- name: BLOCK_IPV6 - name: BLOCK_IPV6
value: "on" value: "on"
startupProbe: startupProbe: