A self-hosted Kubernetes homelab cluster managed with ArgoCD GitOps. The repository contains declarative configuration for a 4-node K3s v1.36.3 cluster, organized as a Kustomize hierarchy with automated ArgoCD application.
| Node | Role | Operating System | Architecture | Internal IP |
|---|---|---|---|---|
| blue.rainbow.tuckerthomas.com | Control plane (scheduling disabled) | Debian 13 (Trixie) | arm64 | 192.168.1.50 |
| green.rainbow.tuckerthomas.com | Worker | AlmaLinux 10.2 | amd64 | 192.168.1.54 |
| orange.rainbow.tuckerthomas.com | Worker | Debian 13 (Trixie) | arm64 | 192.168.1.52 |
| ruby.rainbow.tuckerthomas.com | Worker | Debian 13 (Trixie) | arm64 | 192.168.1.51 |
| Component | Technology |
|---|---|
| Orchestrator | K3s v1.36.3 |
| GitOps | ArgoCD |
| Source Control | Forgejo |
| Networking | Cilium (WireGuard encryption, ClusterPool IPAM) |
| Ingress | Traefik with automatic HTTPS |
| DNS | CoreDNS |
| Load Balancing | MetalLB (L2) |
| TLS | cert-manager + Let's Encrypt (Cloudflare DNS-01) |
| Secrets | Sealed Secrets |
| Logging | Loki |
| Monitoring | kube-prometheus-stack |
| Storage | NFS CSI Driver |
| Object Storage | RustFS |
| Database | CloudNative-PG |
- Pod CIDR:
10.1.0.0/16(IPv4),fd12:3456:1::/56(IPv6) — ClusterPool IPAM - Service CIDR:
10.2.0.0/16(IPv4),fd12:3456:2::/112(IPv6) - Encryption: WireGuard for node-to-node and pod-to-pod traffic
All configuration is organized under clusters/rainbow/:
clusters/rainbow/
├── kustomization.yml # Root Kustomization
├── rainbow.yaml # ArgoCD Application definition
├── namespaces/ # Namespace definitions
├── core/ # Core infrastructure (ArgoCD app)
├── apps/ # Application workloads (ArgoCD app)
├── public/ # Public-facing services (ArgoCD app)
└── install.txt # Node provisioning notes
| Directory | Component |
|---|---|
argocd/ |
ArgoCD with production overlays |
cilium/ |
Cilium CNI and networking |
coredns/ |
Cluster DNS |
cert-manager/ |
cert-manager, ClusterIssuer, and certificates |
metallb/ |
MetalLB load balancer |
traefik/ |
Traefik ingress controller |
kube-prometheus-stack/ |
Prometheus, Grafana, Alertmanager |
loki/ |
Loki logging |
alloy-operator/ |
Grafana Alloy for telemetry collection |
cloudnative-pg/ |
CloudNative-PG operator |
csi-driver-nfs/ |
NFS CSI storage driver |
rustfs/ |
RustFS object storage |
sealed-secrets/ |
Sealed Secrets controller |
Workload definitions for self-hosted services:
- Media Managers: Radarr, Sonarr, Prowlarr
- Database: PostgreSQL cluster via CloudNative-PG
- Matrix: Dendrite homeserver with Hookshot registration (currently offline — Helm chart repositories unreachable)
- Proxy Rules: Ingress routing for Coder, Forgejo, Piped, and NZB services
Externally accessible service ingress configurations:
- Jellyfin (media streaming, behind Anubis)
- Foundry VTT (three instances)
- Headscale (WireGuard management, on ruby node)
- Anubis (anti-bot gateway)
- Whoami (identity verification)
The cluster defines the following namespaces: apps, cert-manager, cilium-secrets, cloudnative-pg, metallb, pod-gateway, public, system-monitoring, traefik, and vpn. Note that the traefik namespace is defined but empty; the Traefik ingress controller runs in kube-system.
Configuration is applied via ArgoCD, which monitors the argo branch of this repository. Manual application is also supported:
kubectl apply -k clusters/rainbow/Node provisioning and bootstrap instructions are documented in clusters/rainbow/install.txt.
| Platform | URL |
|---|---|
| GitHub | https://github.com/tuckerthomas/rainbow |
| Forgejo | http://cyan.rainbow.tuckerthomas.com:4000/tuckerthomas/rainbow |