home.social

#k3s — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #k3s, aggregated by home.social.

  1. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  2. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  3. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  4. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  5. My first try at #k0s didn't go super well. I'm not giving up on it just yet, but doesn't seem to be near as simple/automagic out of box as #k3s is. I might try again in a few days.

  6. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  7. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  8. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  9. Has anyone tested Coraza as a WAF in Kubernetes? I switched to the traefik-modsecurity-plugin because roughly 50–75% of all HTTP/2 traffic was returning HTTP 500.

    #Kubernetes #k8s #k3s #traefik #waf #coraza #modsecurity

  10. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  11. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  12. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  13. Wow that was a long break, I've got very little time to talk here lately, work and life taking over...

    But damn was there some activity on the k3s cluster 😅

    Stalwart is finally up and running, with all of my domain names
    I've tested what happens when the server is down (because outages do happen) and everything was delivered as expected

    And using SMTP2Go to avoid having to maintain an IP reputation

    Chef's kiss

    #cluster #k3s #k8s #stalwart #mail #smtp #smtp2go #break #pause

  14. Updated my #homelab to #k3s 1.35, deployed #vaultwarden, #pihole with #unbound and #forgejo with #woodpecker. All the web guis have #letsencryt certificates. Storage redundancy is achieved by #longhorn which maintains redundant copies of pvcs across the nodes. The nodes are vms controlled by #incus, so that I can shut down the whole k8s thingy with a simple incus stop command when I’m done playing.
    k3s is really nice and easy to deploy and well documented, getting things to run in k8s though is mainly pasting yaml from the internet and hoping for the best.

  15. Updated my #homelab to #k3s 1.35, deployed #vaultwarden, #pihole with #unbound and #forgejo with #woodpecker. All the web guis have #letsencryt certificates. Storage redundancy is achieved by #longhorn which maintains redundant copies of pvcs across the nodes. The nodes are vms controlled by #incus, so that I can shut down the whole k8s thingy with a simple incus stop command when I’m done playing.
    k3s is really nice and easy to deploy and well documented, getting things to run in k8s though is mainly pasting yaml from the internet and hoping for the best.

  16. Jeder (Self-)Hoster kennt diesen Moment:
    Update klicken, kurz die Luft anhalten und hoffen, dass nicht wieder PHP, Datenbank oder Desktop-Client beschließen, heute kreativ zu werden.
    Nach Jahren mit Nextcloud habe ich 2026 für meinen eigenen Usecase die Reißleine gezogen. Nicht aus Dogmatismus. Sondern weil digitale Souveränität für mich am besten funktioniert, wenn Infrastruktur wieder ein bisschen langweilig wird.
    Darum bin ich bei #OpenCloud gelandet.
    Schlanker, fokussierter, weniger bewegliche Teile. Kein PHP. Keine Datenbank. Go-basiert, unter 200 MB RAM im Idle. Auf K3s mit ZFS-Snapshots dahinter läuft das sehr viel näher an „funktioniert“ als an „braucht Aufmerksamkeit“.
    Und dahinter steckt das Team von #mailbox.org,  #Heinlein Support. Kein US-Risikokapital, kein Exit-Druck. Keine fragwürdige Eigentümerstruktur. Einfach Leute, die seit 30 Jahren für datenschutzkonforme Infrastruktur in Deutschland kämpfen. Das ist kein Zufall, das ist eine Entscheidung.
    Der schönste Nebeneffekt:
    OpenCloud wurde bei mir quasi nebenbei zur souveränen E-Book-Bibliothek. DRM-freie EPUBs auf dem Boox Go 7, ohne Amazon-Ökosystem, ohne Plattform-Lock-in, ohne das übliche „wir kennen deinen Geschmack besser als du selbst“.
    Amazon weiß sehr genau, was du liest, wann du liest, wie schnell du liest und wo du aufgehört hast. Das ist keine Paranoia. Das steht in deren  AGB.
    Genau da wird digitale Souveränität sehr konkret:
    nicht als politische Folie, sondern als gelebter Alltag.
    Eigene Dateien - eigene Infrastruktur - eigene Regeln - eigene Verantwortung.
    Wie der Umzug lief, wo die kleinen HTTPS-/Traefik-Fallen lagen und warum weniger Komplexität manchmal der eigentliche Fortschritt ist:

    🔗 https://www.pandolin.io/warum-ich-2026-zu-opencloud-gewechselt-bin/

    One person. One homelab. One less excuse. :-)
    #Fediverse #DigitaleSouveränität #SelfHosting #Homelab #OpenSource #Nextcloud #K3s #Privacy #EBooks #Linux #Ubuntu #BigTechAlternatives

  17. Jeder (Self-)Hoster kennt diesen Moment:
    Update klicken, kurz die Luft anhalten und hoffen, dass nicht wieder PHP, Datenbank oder Desktop-Client beschließen, heute kreativ zu werden.
    Nach Jahren mit Nextcloud habe ich 2026 für meinen eigenen Usecase die Reißleine gezogen. Nicht aus Dogmatismus. Sondern weil digitale Souveränität für mich am besten funktioniert, wenn Infrastruktur wieder ein bisschen langweilig wird.
    Darum bin ich bei #OpenCloud gelandet.
    Schlanker, fokussierter, weniger bewegliche Teile. Kein PHP. Keine Datenbank. Go-basiert, unter 200 MB RAM im Idle. Auf K3s mit ZFS-Snapshots dahinter läuft das sehr viel näher an „funktioniert“ als an „braucht Aufmerksamkeit“.
    Und dahinter steckt das Team von #mailbox.org,  #Heinlein Support. Kein US-Risikokapital, kein Exit-Druck. Keine fragwürdige Eigentümerstruktur. Einfach Leute, die seit 30 Jahren für datenschutzkonforme Infrastruktur in Deutschland kämpfen. Das ist kein Zufall, das ist eine Entscheidung.
    Der schönste Nebeneffekt:
    OpenCloud wurde bei mir quasi nebenbei zur souveränen E-Book-Bibliothek. DRM-freie EPUBs auf dem Boox Go 7, ohne Amazon-Ökosystem, ohne Plattform-Lock-in, ohne das übliche „wir kennen deinen Geschmack besser als du selbst“.
    Amazon weiß sehr genau, was du liest, wann du liest, wie schnell du liest und wo du aufgehört hast. Das ist keine Paranoia. Das steht in deren  AGB.
    Genau da wird digitale Souveränität sehr konkret:
    nicht als politische Folie, sondern als gelebter Alltag.
    Eigene Dateien - eigene Infrastruktur - eigene Regeln - eigene Verantwortung.
    Wie der Umzug lief, wo die kleinen HTTPS-/Traefik-Fallen lagen und warum weniger Komplexität manchmal der eigentliche Fortschritt ist:

    🔗 https://www.pandolin.io/warum-ich-2026-zu-opencloud-gewechselt-bin/

    One person. One homelab. One less excuse. :-)
    #Fediverse #DigitaleSouveränität #SelfHosting #Homelab #OpenSource #Nextcloud #K3s #Privacy #EBooks #Linux #Ubuntu #BigTechAlternatives

  18. As Hetzner is deprecating dns configuration via the dns-console, I migrated my domains to the new Cloud API. Last piece of the puzzle was to create new tokens and move from the old cert-manager-webhook-hetzner (by vadimkim) to the official chart maintained by Hetzner.

    Migrated my 7 kubernetes clusters (k3s, rke2, OpenShift) without major hiccups, only had to do some cleanup due to old acme challenge entries being leftover after the migration (as cert-manager could not remove them without the new webhook and API token).

    Only things left are the machines without k3s using lego.

    #homelab #hetzner #certmanager #dns #hellyeah #kubernetes #k3s #rke2

  19. As Hetzner is deprecating dns configuration via the dns-console, I migrated my domains to the new Cloud API. Last piece of the puzzle was to create new tokens and move from the old cert-manager-webhook-hetzner (by vadimkim) to the official chart maintained by Hetzner.

    Migrated my 7 kubernetes clusters (k3s, rke2, OpenShift) without major hiccups, only had to do some cleanup due to old acme challenge entries being leftover after the migration (as cert-manager could not remove them without the new webhook and API token).

    Only things left are the machines without k3s using lego.

    #homelab #hetzner #certmanager #dns #hellyeah #kubernetes #k3s #rke2

  20. #k3s or #k3d? Is there even a difference - and also, what are they useful for? Is it really only good for a quick 'throw-away' #kubernetes cluster for testing, or something? coming from something like #rke2 (which i know is prolly not a good comparison, but still curious how they could be useful to me)

  21. #k3s or #k3d? Is there even a difference - and also, what are they useful for? Is it really only good for a quick 'throw-away' #kubernetes cluster for testing, or something? coming from something like #rke2 (which i know is prolly not a good comparison, but still curious how they could be useful to me)

  22. Updated #Orked, my collection of scripts to help set up a production-ready #RKE2 #Kubernetes cluster in your #homelab. This update brings general improvements to the scripts, improved documentation, #HAProxy load balancer support for load balancing multiple Master nodes, and upgraded all components including RKE2, #Longhorn, #Nginx Ingress, #Cert-manager, #MetalLB, #Rancher, etc. to their latest versions.

    I still hope someday to support more Kubernetes
    distributions like #k3s, but haven't gotten around to it. I've also been planning to support more #Linux distros as the base too, instead of only #RockyLinux/#RHEL, but that'll have to wait as well for now. Regardless, I am quite happy with how mature and stable these scripts have turned out to be. If you'd like to set up a cluster of your own, maybe check it out!

    🔗 https://github.com/irfanhakim-as/orked

    🔗 https://github.com/irfanhakim-as/orked/pull/41

  23. Updated #Orked, my collection of scripts to help set up a production-ready #RKE2 #Kubernetes cluster in your #homelab. This update brings general improvements to the scripts, improved documentation, #HAProxy load balancer support for load balancing multiple Master nodes, and upgraded all components including RKE2, #Longhorn, #Nginx Ingress, #Cert-manager, #MetalLB, #Rancher, etc. to their latest versions.

    I still hope someday to support more Kubernetes
    distributions like #k3s, but haven't gotten around to it. I've also been planning to support more #Linux distros as the base too, instead of only #RockyLinux/#RHEL, but that'll have to wait as well for now. Regardless, I am quite happy with how mature and stable these scripts have turned out to be. If you'd like to set up a cluster of your own, maybe check it out!

    🔗 https://github.com/irfanhakim-as/orked

    🔗 https://github.com/irfanhakim-as/orked/pull/41

  24. Updated #Orked, my collection of scripts to help set up a production-ready #RKE2 #Kubernetes cluster in your #homelab. This update brings general improvements to the scripts, improved documentation, #HAProxy load balancer support for load balancing multiple Master nodes, and upgraded all components including RKE2, #Longhorn, #Nginx Ingress, #Cert-manager, #MetalLB, #Rancher, etc. to their latest versions.

    I still hope someday to support more Kubernetes
    distributions like #k3s, but haven't gotten around to it. I've also been planning to support more #Linux distros as the base too, instead of only #RockyLinux/#RHEL, but that'll have to wait as well for now. Regardless, I am quite happy with how mature and stable these scripts have turned out to be. If you'd like to set up a cluster of your own, maybe check it out!

    🔗 https://github.com/irfanhakim-as/orked

    🔗 https://github.com/irfanhakim-as/orked/pull/41

  25. Updated #Orked, my collection of scripts to help set up a production-ready #RKE2 #Kubernetes cluster in your #homelab. This update brings general improvements to the scripts, improved documentation, #HAProxy load balancer support for load balancing multiple Master nodes, and upgraded all components including RKE2, #Longhorn, #Nginx Ingress, #Cert-manager, #MetalLB, #Rancher, etc. to their latest versions.

    I still hope someday to support more Kubernetes
    distributions like #k3s, but haven't gotten around to it. I've also been planning to support more #Linux distros as the base too, instead of only #RockyLinux/#RHEL, but that'll have to wait as well for now. Regardless, I am quite happy with how mature and stable these scripts have turned out to be. If you'd like to set up a cluster of your own, maybe check it out!

    🔗 https://github.com/irfanhakim-as/orked

    🔗 https://github.com/irfanhakim-as/orked/pull/41

  26. Updated #Orked, my collection of scripts to help set up a production-ready #RKE2 #Kubernetes cluster in your #homelab. This update brings general improvements to the scripts, improved documentation, #HAProxy load balancer support for load balancing multiple Master nodes, and upgraded all components including RKE2, #Longhorn, #Nginx Ingress, #Cert-manager, #MetalLB, #Rancher, etc. to their latest versions.

    I still hope someday to support more Kubernetes
    distributions like #k3s, but haven't gotten around to it. I've also been planning to support more #Linux distros as the base too, instead of only #RockyLinux/#RHEL, but that'll have to wait as well for now. Regardless, I am quite happy with how mature and stable these scripts have turned out to be. If you'd like to set up a cluster of your own, maybe check it out!

    🔗 https://github.com/irfanhakim-as/orked

    🔗 https://github.com/irfanhakim-as/orked/pull/41

  27. After years with #K3S + #RaspberryPi in my #HomeLab, my new #ZimaBoard 2 was a good reason for me to try #Proxmox. First two LXC are already running: #Pihole and #Jellyfin 💪

    Next: Backup, #TrueNas and a reverse Proxy, after i have figured out how private networking with Proxmox is working.

  28. @lucas3d second #PihHole Instance is now running and setup as second #DNS in my Network💪
    Only concern is, that the second Instance is running in the same #K3S Cluster as the first one, and it can happen that they run on the same node. Need to check how podAntiAffinity is working, never have used it before.
    Or i will run it on one of the not used #RaspberryPI or the #ZimaBoard 2, which should arrive in some weeks.

  29. @lucas3d second #PihHole Instance is now running and setup as second #DNS in my Network💪
    Only concern is, that the second Instance is running in the same #K3S Cluster as the first one, and it can happen that they run on the same node. Need to check how podAntiAffinity is working, never have used it before.
    Or i will run it on one of the not used #RaspberryPI or the #ZimaBoard 2, which should arrive in some weeks.

  30. We know #TalosLinux is 🤏 but is it really the smallest?

    We ran the tests. We’ve got the data. Check it out if you like numbers.

    Watch → youtu.be/atPvnJMGdfs
    Read → siderolabs.com/blog/which-kube

    #Kubeadm #K3s #K0s #Kairos #RKE2 #Kubernetes #K8s

  31. We know #TalosLinux is 🤏 but is it really the smallest?

    We ran the tests. We’ve got the data. Check it out if you like numbers.

    Watch → youtu.be/atPvnJMGdfs
    Read → siderolabs.com/blog/which-kube

    #Kubeadm #K3s #K0s #Kairos #RKE2 #Kubernetes #K8s

  32. We know is 🤏 but is it really the smallest?

    We ran the tests. We’ve got the data. Check it out if you like numbers.

    Watch → youtu.be/atPvnJMGdfs
    Read → siderolabs.com/blog/which-kube

  33. What a successful evening! 💪 Not only did I replace #Authentik with #TinyAuth as the #Traefik Forward Auth Provider, but I also resolved the integration issue between #PocketID and #Beszel. This allowed me to remove Authentik from my #k3s cluster and reclaim some resources.

    #HomeLab #Selfhosted

  34. What a successful evening! 💪 Not only did I replace #Authentik with #TinyAuth as the #Traefik Forward Auth Provider, but I also resolved the integration issue between #PocketID and #Beszel. This allowed me to remove Authentik from my #k3s cluster and reclaim some resources.

    #HomeLab #Selfhosted

  35. My #homelab wiki is getting really complicated to organise and write for haha, but it's definitely getting more interesting topics like more #RaspberryPi stuffs, #Docker, and some cool stuffs like #OpenMediaVault and #HomeAssistant. I'm taking my sweet time to update them 'properly' and hope it'll all link/piece together sensibly in the end.

    This is partially thanks to me embracing the fact that I just don't (yet) have the resources for a
    standalone 'mega' homelab (#Proxmox & #Kubernetes based) server cluster that I could simply throw everything to it, hence supplementing that setup with tinier SBC-based servers. Gives me a bit of peace of mind too that things are now more 'spread out'.

    The most interesting bit will probably be when I manage to explore replicating a mini version of my
    #RKE2 Kubernetes cluster, on a single (or at most, two) Raspberry Pi node - maybe based on #k3s, assuming that's better. I'm just not there yet cos I'm kinda reluctant if using something like #k8s on RPi makes much sense since I'm expecting a lot of resources will be wasted that way, when hosting on Docker alone (i.e. on #Portainer) should be leaner.

    🔗 Anyway, if y'all wanna keep an eye on it: https://github.com/irfanhakim-as/homelab-wiki

  36. My #homelab wiki is getting really complicated to organise and write for haha, but it's definitely getting more interesting topics like more #RaspberryPi stuffs, #Docker, and some cool stuffs like #OpenMediaVault and #HomeAssistant. I'm taking my sweet time to update them 'properly' and hope it'll all link/piece together sensibly in the end.

    This is partially thanks to me embracing the fact that I just don't (yet) have the resources for a
    standalone 'mega' homelab (#Proxmox & #Kubernetes based) server cluster that I could simply throw everything to it, hence supplementing that setup with tinier SBC-based servers. Gives me a bit of peace of mind too that things are now more 'spread out'.

    The most interesting bit will probably be when I manage to explore replicating a mini version of my
    #RKE2 Kubernetes cluster, on a single (or at most, two) Raspberry Pi node - maybe based on #k3s, assuming that's better. I'm just not there yet cos I'm kinda reluctant if using something like #k8s on RPi makes much sense since I'm expecting a lot of resources will be wasted that way, when hosting on Docker alone (i.e. on #Portainer) should be leaner.

    🔗 Anyway, if y'all wanna keep an eye on it: https://github.com/irfanhakim-as/homelab-wiki

  37. Angenommen ich habe einen Host miteinem halben Dutzend #Docker Containern. Ich hätte den Host (also eigentlich die Container) gerne hochverfügbar.
    Welche einfachen Lösungen bieten sich an?
    Kubernetes wäre scheinbar overkill.
    #Rancher? #K3s? #Portainer? Oder klassisch mit #Linux-HA und #DRBD? Oder ganz anders?
  38. Angenommen ich habe einen Host miteinem halben Dutzend #Docker Containern. Ich hätte den Host (also eigentlich die Container) gerne hochverfügbar.
    Welche einfachen Lösungen bieten sich an?
    Kubernetes wäre scheinbar overkill.
    #Rancher? #K3s? #Portainer? Oder klassisch mit #Linux-HA und #DRBD? Oder ganz anders?
  39. Що не так з #k3s ?

    Раніше я писав, що у мене є питання до k3s.
    Ось на скріні одне з них.
    Після оновлення proxmox, k3s в LXC перестав запускатись з дивними проблемами.

    Вилікував просто:
    Відновив LXC контейнер з бакапів на 3 дні раніше.

    І саме лікування також додає питання до k3s.

    За #k0s продовжую спостерігати.
    Питань поки немає.

  40. Що не так з #k3s ?

    Раніше я писав, що у мене є питання до k3s.
    Ось на скріні одне з них.
    Після оновлення proxmox, k3s в LXC перестав запускатись з дивними проблемами.

    Вилікував просто:
    Відновив LXC контейнер з бакапів на 3 дні раніше.

    І саме лікування також додає питання до k3s.

    За #k0s продовжую спостерігати.
    Питань поки немає.

  41. Що не так з #k3s ?

    Раніше я писав, що у мене є питання до k3s.
    Ось на скріні одне з них.
    Після оновлення proxmox, k3s в LXC перестав запускатись з дивними проблемами.

    Вилікував просто:
    Відновив LXC контейнер з бакапів на 3 дні раніше.

    І саме лікування також додає питання до k3s.

    За #k0s продовжую спостерігати.
    Питань поки немає.

  42. Hmmm, it seems like my websites appearing as down in Kener (or is it kener.ing ?) is because my coredns instance cannot solve the DNS request ?

    But I'm thinking, Longhorn has also shown, for a long time, dropped requests when rebuilding big volumes...

    Could it be, my wireguard under the hood dropping packages ? Hmmmmmm...

    #homelab #selfhosted #longhorn #wireguard #kener #dns #coredns #k3s #kubernetes #k8s

  43. вирішив перенести свої сервіси з k3s на k0s.... і зіштовхнувся з дивовижними проблемами...

    На лоад-балансері блокується порт 80 та 993...
    Може ще якісь блокуються, складно сказати, але що з цим робити поки зовсім не знаю.

    Якось воно працює дуже дивно.
    Якщо хтось може щось підказати - буду радий.

    @rada
    #kubernetes #k3s #k0s #bugs

  44. вирішив перенести свої сервіси з k3s на k0s.... і зіштовхнувся з дивовижними проблемами...

    На лоад-балансері блокується порт 80 та 993...
    Може ще якісь блокуються, складно сказати, але що з цим робити поки зовсім не знаю.

    Якось воно працює дуже дивно.
    Якщо хтось може щось підказати - буду радий.

    @rada
    #kubernetes #k3s #k0s #bugs

  45. вирішив перенести свої сервіси з k3s на k0s.... і зіштовхнувся з дивовижними проблемами...

    На лоад-балансері блокується порт 80 та 993...
    Може ще якісь блокуються, складно сказати, але що з цим робити поки зовсім не знаю.

    Якось воно працює дуже дивно.
    Якщо хтось може щось підказати - буду радий.

    @rada
    #kubernetes #k3s #k0s #bugs