9-node Talos Linux dual-cluster (SOC: 3 ctrl + 3 worker · SEC: 3 ctrl), running K8s v1.35.2 · Talos v1.12.6 · containerd 2.1.6. Cilium 1.19.2 CNI, MetalLB 0.15.3 load balancer, Longhorn 1.11.1 storage.
All nodes Ready. SOC: 3 control-plane (etcd · apiserver · scheduler) + 3 worker nodes (Longhorn · workloads). SEC: 3 control-plane-only nodes (all roles). Total: 130 + 92 = 222 pods across both clusters.
All nodes Ready. 3 control-plane-only nodes — no dedicated workers. Hosts OpenCTI 6.x + full CTI stack (Elasticsearch · RabbitMQ · Redis · MinIO). ClusterMesh peered with SOC. 92 pods · 90 Running · 1 Pending.
SOC ingress via MetalLB VIP 172.16.x.x. SEC cluster VIP 172.16.x.x — routes: cti.onelabs.work (OpenCTI).
| Namespace | Ingress Name | Host / URL | Class | TLS Secret | LB IP | Ports | Age |
|---|---|---|---|---|---|---|---|
| argocd | argocd-server | argo.onelabs.work | nginx | wildcard-onelabs-tls | 172.16.x.x | 80, 443 | 36m |
| kube-system | hubble-ui-ingress | hub.onelabs.work | nginx | wildcard-onelabs-tls | 172.16.x.x | 80, 443 | 3h48m |
| longhorn-system | longhorn-ui | stog.onelabs.work | nginx | wildcard-onelabs-tls | 172.16.x.x | 80, 443 | 6h19m |
| Name | Namespace | Chart | App Version | Revision | Status | Updated |
|---|---|---|---|---|---|---|
| argocd | argocd | argo-cd-9.5.0 | v3.3.6 | 1 | deployed | 2026-04-13 22:42:28 |
| cert-manager | cert-manager | cert-manager-v1.20.1 | v1.20.1 | 2 | deployed | 2026-04-13 16:54:12 |
| cilium | kube-system | cilium-1.19.2 | 1.19.2 | 5 | deployed | 2026-04-13 19:46:23 |
| ingress-nginx | ingress-nginx | ingress-nginx-4.15.1 | 1.15.1 | 1 | deployed | 2026-04-13 17:10:31 |
| longhorn | longhorn-system | longhorn-1.11.1 | v1.11.1 | 4 | deployed | 2026-04-13 17:49:25 |
| metallb | metallb-system | metallb-0.15.3 | v0.15.3 | 1 | deployed | 2026-04-13 17:02:22 |
These workloads pull from external registries (quay.io, ecr-public, registry.k8s.io) instead of regis.onelabs.work. Consider mirroring to internal registry for air-gap compliance.
| Kind | Namespace | Workload | External Image | Risk |
|---|---|---|---|---|
| Deployment | argocd | argocd-redis-ha-haproxy | ecr-public.aws.com/…haproxy:3.0.8-alpine | ⚠ EXTERNAL |
| StatefulSet | argocd | argocd-redis-ha-server | ecr-public.aws.com/…redis:8.2.3-alpine | ⚠ EXTERNAL |
| DaemonSet | kube-system | cilium | quay.io/cilium/cilium:v1.19.2 | CNI CORE |
| Deployment | kube-system | cilium-operator | quay.io/cilium/operator-generic:v1.19.2 | CNI CORE |
| DaemonSet | kube-system | cilium-envoy | quay.io/cilium/cilium-envoy:v1.35.9… | CNI CORE |
| Deployment | kube-system | coredns | registry.k8s.io/coredns/coredns:v1.13.2 | K8S CORE |
| Deployment | kube-system | hubble-relay | quay.io/cilium/hubble-relay:v1.19.2 | ⚠ EXTERNAL |
| Deployment | kube-system | hubble-ui | quay.io/cilium/hubble-ui:v0.13.3 | ⚠ EXTERNAL |