Ecosystem:Frank Chinembiri/Techarvest Projects/Mateere Lab (Showcase)
● LIVE TELEMETRY
Interactive Topology Visualizer

Platform Architecture & Hybrid Topology

Visual representation of network boundaries, security perimeters, host-level coexistence, and Kubernetes workload orchestration across our 4-node hybrid infrastructure. Click any highlighted component to inspect design rationale.

Cluster Physical & Logical Layout (Click to Inspect)Selected: Ingress & Perimeter Gateway
Perimeter Gateway

Ingress-NGINX & SSL

Node 2 (node-2-ingress) • [Ingress Gateway IP]
  • Let's Encrypt Wildcard TLS
  • Authentik Forward-Auth SSO
  • Dynamic Rate Limiting
Host-Level Coexistence

CloudPanel Host NGINX

Node 1 (node-1-control) • [Control Plane IP]
  • ~30 Commercial Virtual Hosts
  • Runs along K3s Control Plane
  • Log Analyzer & Traffic Matrix
Orchestration

K3s Embedded etcd HA

4 Nodes (3 Control + 1 Worker)
  • Quorum: 3-Node Embedded etcd
  • Mixed OS: Ubuntu 22 & Rocky 9/10
  • 185+ Workloads in 19 Namespaces
Network Security

Host Firewall Automation (fix-ufw-ds)

Custom DaemonSet ensuring cross-node overlay flannel CNI (10.42.0.0/16, 10.43.0.0/16) is never blocked by Ubuntu UFW.

Telemetry Engine

Unified Telemetry & FastAPI Adapter

Prometheus PromQL engine + Uptime Kuma heartbeats + NGINX log roll-ups + Air-gapped snapshot exporter.

Detailed Component Analysis

Ingress & Perimeter Gateway

Node 2 (Ingress Gateway)

Architecture & Rationale

Terminates wildcard Let's Encrypt TLS certificates managed automatically by cert-manager. Evaluates Forward-Auth against Authentik SSO for private dashboards while passing public traffic to static backends.

Technologies Used

Ingress-NGINX Controller + cert-manager

Platform Role

Central SSL termination and L7 routing engine.

Declarative Configuration Excerpt

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    cert-manager.io/cluster-issuer: letsencrypt-prod
    nginx.ingress.kubernetes.io/auth-url: "http://authentik-outpost.authentik.svc.cluster.local:80/outpost.goauthentik.io/auth/nginx"
    nginx.ingress.kubernetes.io/auth-signin: "https://sso.techarvest.co.zw/outpost.goauthentik.io/start?rd=$escaped_request_uri"