Interactive Topology Visualizer
Platform Architecture & Hybrid Topology
Visual representation of network boundaries, security perimeters, host-level coexistence, and Kubernetes workload orchestration across our 4-node hybrid infrastructure. Click any highlighted component to inspect design rationale.
Cluster Physical & Logical Layout (Click to Inspect)Selected: Ingress & Perimeter Gateway
Perimeter Gateway
Ingress-NGINX & SSL
Node 2 (node-2-ingress) • [Ingress Gateway IP]
- Let's Encrypt Wildcard TLS
- Authentik Forward-Auth SSO
- Dynamic Rate Limiting
Host-Level Coexistence
CloudPanel Host NGINX
Node 1 (node-1-control) • [Control Plane IP]
- ~30 Commercial Virtual Hosts
- Runs along K3s Control Plane
- Log Analyzer & Traffic Matrix
Orchestration
K3s Embedded etcd HA
4 Nodes (3 Control + 1 Worker)
- Quorum: 3-Node Embedded etcd
- Mixed OS: Ubuntu 22 & Rocky 9/10
- 185+ Workloads in 19 Namespaces
Network Security
Host Firewall Automation (fix-ufw-ds)
Custom DaemonSet ensuring cross-node overlay flannel CNI (10.42.0.0/16, 10.43.0.0/16) is never blocked by Ubuntu UFW.
Telemetry Engine
Unified Telemetry & FastAPI Adapter
Prometheus PromQL engine + Uptime Kuma heartbeats + NGINX log roll-ups + Air-gapped snapshot exporter.
Detailed Component Analysis
Ingress & Perimeter Gateway
Node 2 (Ingress Gateway)
Architecture & Rationale
Terminates wildcard Let's Encrypt TLS certificates managed automatically by cert-manager. Evaluates Forward-Auth against Authentik SSO for private dashboards while passing public traffic to static backends.
Technologies Used
Ingress-NGINX Controller + cert-manager
Platform Role
Central SSL termination and L7 routing engine.
Declarative Configuration Excerpt
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
nginx.ingress.kubernetes.io/auth-url: "http://authentik-outpost.authentik.svc.cluster.local:80/outpost.goauthentik.io/auth/nginx"
nginx.ingress.kubernetes.io/auth-signin: "https://sso.techarvest.co.zw/outpost.goauthentik.io/start?rd=$escaped_request_uri"