home.social

#k3s — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #k3s, aggregated by home.social.

  1. The migration from Docker Compose to k3s is complete. What took months of gradual migration now runs on a 3-node cluster with proper rolling updates, secrets management, and GitOps via ArgoCD. The operational overhead is actually *lower* now - declarative state means no more "works on my machine" drift. #HomeLab #Kubernetes #k3s #GitOps #DevOps

  2. Kubernetes is really neat tech, and I know I spent a few days learning how to use it and stuff, but I really don't see a need for it in my homelab. I might just bring my k3s down and convert them to docker-compose.

    This isn't anti-K8s, or something extreme, it's more like pro-right-tool-for-the-job. For a single-VM setup running a handful of services, Compose reduces maintenance overhead without sacrificing anything I actually need.

    #homelab #kubernetes #k3s #docker #selfhosted #linux #devops #FOSS

  3. Kubernetes is really neat tech, and I know I spent a few days learning how to use it and stuff, but I really don't see a need for it in my homelab. I might just bring my k3s down and convert them to docker-compose.

    This isn't anti-K8s, or something extreme, it's more like pro-right-tool-for-the-job. For a single-VM setup running a handful of services, Compose reduces maintenance overhead without sacrificing anything I actually need.

    #homelab #kubernetes #k3s #docker #selfhosted #linux #devops #FOSS

  4. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  5. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  6. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  7. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  8. RE: social.bund.de/@zendis/1169581

    Gratulation ans @zendis !

    Als das damals im Projekt mit dem @bmi cloudnative gebaut haben gab es doch den einen oder anderen Vorbehalt.

    Aber ein Vorteil von ist eben auch die schnelle Deploybarkeit und die Migrationsfähigkeit.

    Kleinster "Server" Hardware auf dem das läuft ist ein Laptop mi 32 GB und K3S. Wenn ich Zeit habe, bringe ich das auch noch auf k0s ans laufen.

    #OpenDesk #kubernetes #k8s #k3s #k0s #cloud #cloudnative

  9. Last night and today was spent trying to get #gluetun working under #k3s with #protonvpn 's free plan...

    Still can't get it to work.

  10. Last night and today was spent trying to get #gluetun working under #k3s with #protonvpn 's free plan...

    Still can't get it to work.

  11. Last night and today was spent trying to get #gluetun working under #k3s with #protonvpn 's free plan...

    Still can't get it to work.

  12. Last night and today was spent trying to get #gluetun working under #k3s with #protonvpn 's free plan...

    Still can't get it to work.

  13. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  14. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  15. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  16. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  17. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  18. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  19. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  20. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  21. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  22. Need to document how I deployed a home #EDR #SIEM on #k3s with Tailscale but had to update my #mcp server first! github.com/mdfranz/elastic-sec

  23. Need to document how I deployed a home #EDR #SIEM on #k3s with Tailscale but had to update my #mcp server first! github.com/mdfranz/elastic-sec

  24. Need to document how I deployed a home #EDR #SIEM on #k3s with Tailscale but had to update my #mcp server first! github.com/mdfranz/elastic-sec

  25. Need to document how I deployed a home #EDR #SIEM on #k3s with Tailscale but had to update my #mcp server first! github.com/mdfranz/elastic-sec

  26. Need to document how I deployed a home #EDR #SIEM on #k3s with Tailscale but had to update my #mcp server first! github.com/mdfranz/elastic-sec

  27. 🧱 Defense in depth across four policy domains: filesystem (blocks reads/writes outside allowed paths), network (hot-reloadable), process (blocks privilege escalation & dangerous syscalls), and inference (reroutes model API calls)

    ⚙️ Under the hood it runs a #K3s #Kubernetes cluster inside a single #Docker container — no separate K8s install needed. A gateway coordinates sandbox lifecycle & acts as the auth boundary

  28. 🧱 Defense in depth across four policy domains: filesystem (blocks reads/writes outside allowed paths), network (hot-reloadable), process (blocks privilege escalation & dangerous syscalls), and inference (reroutes model API calls)

    ⚙️ Under the hood it runs a #K3s #Kubernetes cluster inside a single #Docker container — no separate K8s install needed. A gateway coordinates sandbox lifecycle & acts as the auth boundary

  29. 🧱 Defense in depth across four policy domains: filesystem (blocks reads/writes outside allowed paths), network (hot-reloadable), process (blocks privilege escalation & dangerous syscalls), and inference (reroutes model API calls)

    ⚙️ Under the hood it runs a #K3s #Kubernetes cluster inside a single #Docker container — no separate K8s install needed. A gateway coordinates sandbox lifecycle & acts as the auth boundary

  30. 🧱 Defense in depth across four policy domains: filesystem (blocks reads/writes outside allowed paths), network (hot-reloadable), process (blocks privilege escalation & dangerous syscalls), and inference (reroutes model API calls)

    ⚙️ Under the hood it runs a #K3s #Kubernetes cluster inside a single #Docker container — no separate K8s install needed. A gateway coordinates sandbox lifecycle & acts as the auth boundary

  31. 🧱 Defense in depth across four policy domains: filesystem (blocks reads/writes outside allowed paths), network (hot-reloadable), process (blocks privilege escalation & dangerous syscalls), and inference (reroutes model API calls)

    ⚙️ Under the hood it runs a #K3s #Kubernetes cluster inside a single #Docker container — no separate K8s install needed. A gateway coordinates sandbox lifecycle & acts as the auth boundary

  32. 🚀 alexellis/k3sup

    bootstrap K3s over SSH in < 60s 🚀

    Deploys lightweight Kubernetes (k3s) clusters via SSH in under 60 seconds, fetching kubeconfig automatically for local kubectl access and supporting multi-node HA setups

    ⭐ Stars: 7384
    📅 Last Update: May 23, 2026

    github.com/alexellis/k3sup

    #selfhosted #homelab #selfhost #selfhosting #opensource #kubernetes #k3s

  33. 🚀 alexellis/k3sup

    bootstrap K3s over SSH in < 60s 🚀

    Deploys lightweight Kubernetes (k3s) clusters via SSH in under 60 seconds, fetching kubeconfig automatically for local kubectl access and supporting multi-node HA setups

    ⭐ Stars: 7384
    📅 Last Update: May 23, 2026

    github.com/alexellis/k3sup

    #selfhosted #homelab #selfhost #selfhosting #opensource #kubernetes #k3s

  34. Not sure why, but upgrading a #k3s test node from #AlpineLinux v3.22 to v3.23 causes etcd to shit itself.

    Holding the nodes in the cluster at v3.22 for now until I figure out why.

    This is why I have a test cluster that does mostly nothing! Better to FAFO in test than in prod. :)

    #AdventuresInSelfHosting

  35. 病假给了我很多时间去搞homelab 今天把terraform module 加上了, ansible playbook也跑起来了,这边 tofu apply 然后 ansible-playbook 进行config. 还把tasks 整合进了 roles. 今天还读了一点production kubernetes 觉得受益匪浅! 非常棒的一本书!

    病假后半段我状态好点了不再一整天都虚弱躺着了就开始不停思考, 我感觉自己把整个人生都分析和重构了一遍, 从财务规划到退休计划从职业发展到知识管理…

    明天打算把这两步整合一下:provision a VM, install k3s, install Rancher, then let Rancher create/register another downstream cluster 顺便处理下cert-manager DNS-01 拿证书

    #homelab #ansible #opentofu #k3s #rancher #certmanager

  36. 病假给了我很多时间去搞homelab 今天把terraform module 加上了, ansible playbook也跑起来了,这边 tofu apply 然后 ansible-playbook 进行config. 还把tasks 整合进了 roles. 今天还读了一点production kubernetes 觉得受益匪浅! 非常棒的一本书!

    病假后半段我状态好点了不再一整天都虚弱躺着了就开始不停思考, 我感觉自己把整个人生都分析和重构了一遍, 从财务规划到退休计划从职业发展到知识管理…

    明天打算把这两步整合一下:provision a VM, install k3s, install Rancher, then let Rancher create/register another downstream cluster 顺便处理下cert-manager DNS-01 拿证书

    #homelab #ansible #opentofu #k3s #rancher #certmanager

  37. I'm making progress on my local #LLM experiments. Now we moved from single node to 2 node Kubernetes, here a blog post about my initial setup with a bunch of new Bench-marking results: blog.t1m.me/blog/building-own-

    Currently using a simple #k3s server / agent set-up, with DNS-1 certificate issuing and everything in a private #tailscale network.

    Already taking the next steps towards migrating from #ollama to #vLLM and optimizing prompt / model caching + routing. Several more changes coming up :)

  38. I'm making progress on my local #LLM experiments. Now we moved from single node to 2 node Kubernetes, here a blog post about my initial setup with a bunch of new Bench-marking results: blog.t1m.me/blog/building-own-

    Currently using a simple #k3s server / agent set-up, with DNS-1 certificate issuing and everything in a private #tailscale network.

    Already taking the next steps towards migrating from #ollama to #vLLM and optimizing prompt / model caching + routing. Several more changes coming up :)

  39. I'm making progress on my local #LLM experiments. Now we moved from single node to 2 node Kubernetes, here a blog post about my initial setup with a bunch of new Bench-marking results: blog.t1m.me/blog/building-own-

    Currently using a simple #k3s server / agent set-up, with DNS-1 certificate issuing and everything in a private #tailscale network.

    Already taking the next steps towards migrating from #ollama to #vLLM and optimizing prompt / model caching + routing. Several more changes coming up :)

  40. I'm making progress on my local #LLM experiments. Now we moved from single node to 2 node Kubernetes, here a blog post about my initial setup with a bunch of new Bench-marking results: blog.t1m.me/blog/building-own-

    Currently using a simple #k3s server / agent set-up, with DNS-1 certificate issuing and everything in a private #tailscale network.

    Already taking the next steps towards migrating from #ollama to #vLLM and optimizing prompt / model caching + routing. Several more changes coming up :)

  41. I'm making progress on my local #LLM experiments. Now we moved from single node to 2 node Kubernetes, here a blog post about my initial setup with a bunch of new Bench-marking results: blog.t1m.me/blog/building-own-

    Currently using a simple #k3s server / agent set-up, with DNS-1 certificate issuing and everything in a private #tailscale network.

    Already taking the next steps towards migrating from #ollama to #vLLM and optimizing prompt / model caching + routing. Several more changes coming up :)

  42. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  43. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  44. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  45. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause