Kubernetes / OpenShift

Kubernetes / OpenShift

Status and navigation hub for the site-local Kubernetes and OpenShift plan, including locked network allocations and still-tentative platform choices.

Kubernetes and OpenShift are future build phases centered on Site B compute and Ceph. The network boundaries are allocated, but no cluster is deployed and several platform choices remain intentionally open.

Planned: No Cluster Is Running

Treat deployment state, VM sizing, final distribution, ingress choice, and component versions as tentative. Reserved network allocations and hard site-separation rules remain the planning boundary.

Locked Architecture Boundary

  • Clusters stay site-local; no control plane, Ceph storage, or Layer 2 segment stretches across WireGuard.
  • Kubernetes node traffic uses VLAN 40 (10.10.40.0/22 and 10.20.40.0/22).
  • API, ingress, and MetalLB addresses use VLAN 50 (10.x0.50.0/24).
  • OpenShift cluster slots use dedicated /22 machine-network allocations from 10.x0.100.0+.
  • Pod and service CIDRs cannot overlap either site /16 or 10.255.0.0/24.

No Cross-Site Cluster

Keep every Kubernetes or OpenShift cluster within one site. Cross-site continuity uses application replication, GitOps, and backup/restore rather than a WAN-spanning control plane.

Tentative Platform Choices

Cilium in overlay mode, MetalLB, cert-manager, external-dns, ArgoCD, and an ingress controller form the current candidate stack. The final Kubernetes-versus-OpenShift choice, node VM sizing, ingress implementation, component versions, and actual pod/service CIDRs remain undecided until the network and Site B Ceph are stable.

Continue by Question