refactor: readme, gitignore and talos_machine_config_version changes

Signed-off-by: Karteek <[email protected]>
This commit is contained in:
karteekiitg
2025-04-17 11:21:38 +02:00
committed by GitHub
parent 341fba89fa
commit eb15ae041c
4 changed files with 51 additions and 7 deletions
+1
View File
@@ -11,6 +11,7 @@ output
*secret*.tfvars *secret*.tfvars
*secret*.tfvars.json *secret*.tfvars.json
!sealed-secrets.auto.tfvars
*.lock.hcl *.lock.hcl
+45 -3
View File
@@ -1,18 +1,32 @@
# Kubernetes Tofu # Kubernetes Tofu
## Install pre-requisites
1. [tofu](https://opentofu.org/docs/intro/install/)
1. [talosctl](https://www.talos.dev/v1.9/talos-guides/install/talosctl/)
1. [kubectl](https://kubernetes.io/docs/tasks/tools/#kubectl)
## Initialize tofu
```shell ```shell
tofu output -raw kube_config tofu init
tofu output -raw talos_config
``` ```
## Proxmox ## Proxmox
Environment variable ### Environment variable
```shell ```shell
export TF_VAR_proxmox_api_token="<YOUR_API_TOKEN>" export TF_VAR_proxmox_api_token="<YOUR_API_TOKEN>"
``` ```
### Optional External Secrets Manager / Other methods
**Bitwarden Secrets Manager** - Name your secret TF_VAR_proxmox_api_token in bws.
```shell
bws run -- tofu ...
```
Note: By default the shell is sh. Change with --shell if required.
## Sealed-secrets ## Sealed-secrets
Generate certificate Generate certificate
@@ -36,3 +50,31 @@ Output `talosconfig`
```shell ```shell
tofu output -raw talos_config tofu output -raw talos_config
``` ```
## Upgrading Talos and Kubernetes
[Upgrade](https://blog.stonegarden.dev/articles/2024/08/talos-proxmox-tofu/#upgrading-the-cluster) talos nodes one by one.
1. Set talos_image.auto.tfvars -> image -> update_version to the required update version.
1. Set talos_cluster.auto.tfvars -> talos_cluster_config -> kubernetes_version to the required kubernetes version.
1. Set talos_nodes.auto.tfvars -> talos_nodes -> $node_1 -> update = true and run tofu apply.
1. Set talos_nodes.auto.tfvars -> talos_nodes -> $node_2 -> update = true, leave the previous nodes update = true and run tofu apply.
1. Set talos_nodes.auto.tfvars -> talos_nodes -> $node_3 -> update = true, leave the previous nodes update = true and run tofu apply.
1. ...
1. Set talos_nodes.auto.tfvars -> talos_nodes -> $node_n -> update = true, leave the previous nodes update = true and run tofu apply.
1. After upgrading all nodes, Set talos_image.auto.tfvars -> image -> version to match the update version and set update = false for all nodes.
## Upgrading Talos Schematic
1. Create a new schematic file.
1. Same process as above instead of image.version and image.update_version, change image.schematic and image.update_schematic, in talos_image.auto.tfvars.
## Upgrading Kubernetes Only
Dry Run
```shell
sh upgrade-k8s.sh $CONTROLPLANE_NODE_IP --dry-run # For testing
```
Upgrade
```shell
sh upgrade-k8s.sh $CONTROLPLANE_NODE_IP
```
+1 -1
View File
@@ -1,5 +1,5 @@
resource "talos_machine_secrets" "this" { resource "talos_machine_secrets" "this" {
talos_version = var.cluster.talos_machine_config_version talos_version = var.cluster.talos_machine_config_version != null ? var.cluster.talos_machine_config_version : var.image.update_version
} }
data "talos_client_configuration" "this" { data "talos_client_configuration" "this" {
+2 -1
View File
@@ -10,7 +10,8 @@ talos_cluster_config = {
gateway = "192.168.1.1" gateway = "192.168.1.1"
# The version of talos features to use in generated machine configuration. Generally the same as image version. # The version of talos features to use in generated machine configuration. Generally the same as image version.
# See https://github.com/siderolabs/terraform-provider-talos/blob/main/docs/data-sources/machine_configuration.md # See https://github.com/siderolabs/terraform-provider-talos/blob/main/docs/data-sources/machine_configuration.md
talos_machine_config_version = "v1.9.2" # Uncomment to use this instead of version from talos_image.
# talos_machine_config_version = "v1.9.2"
proxmox_cluster = "homelab" proxmox_cluster = "homelab"
kubernetes_version = "1.32.0" # renovate: github-releases=kubernetes/kubernetes kubernetes_version = "1.32.0" # renovate: github-releases=kubernetes/kubernetes
cilium = { cilium = {