Home Lab

How pitower is built and run: an 11-node Talos Linux cluster in a 12U rack, managed through GitOps from swibrow/home-ops.

The pitower rack: mini PCs, a Dell R630, Raspberry Pis, switches and a UPS

Home Lab

Welcome to the documentation for pitower, a Kubernetes home lab built on Talos Linux and managed entirely through GitOps with ArgoCD. This repository defines the complete infrastructure-as-code for an 11-node, mixed-architecture cluster: AMD and Intel mini PCs, a Dell R630, a GPU workstation and Raspberry Pis.


Architecture Overview

flowchart LR
    Internet((Internet))
    CF[Cloudflare DNS]
    Hub[towonel hub\nVPS]
    Agent[towonel-agent]
    EE[Envoy External\n10.20.10.239]
    EI[Envoy Internal\n10.20.10.238]
    Apps[Applications]
    TS[Tailscale\nVPN]
    User((User))

    Internet -->|"*.wibrow.dev"| CF
    CF -->|unproxied CNAME| Hub
    Hub -->|outbound tunnel| Agent
    Agent --> EE
    EE --> Apps

    User -->|LAN / VPN| TS
    TS --> EI
    EI --> Apps

Documentation Sections

SectionDescription
Getting StartedRepository overview, prerequisites, and architecture
InfrastructureHardware, Talos Linux, cluster bootstrap, node management
NetworkingCilium CNI, Envoy Gateway, DNS, towonel tunnel, Tailscale
GitOpsArgoCD setup, ApplicationSets, sync policies
StorageRook Ceph, OpenEBS, Garage S3, backup and restore
SecurityKanidm, External Secrets, SOPS, cert-manager
MonitoringPrometheus, Grafana, VictoriaMetrics, VictoriaLogs, Fluent Bit
ApplicationsMedia stack, home automation, self-hosted apps, databases
OperationsJustfile recipes, Talos commands, troubleshooting, upgrades
CI/CDGitHub Actions, Docker builds, Renovate
DevelopmentApp template patterns, adding new apps
ReferenceIP allocation table, full app catalog

Hardware Summary

Compute

NodesHardwareRoleArchitecture
worker-01..03AMD Ryzen mini PCs (16 threads)Control plane + workloads, Ceph OSDsAMD64
worker-04..06Intel nodes (4 cores, 8 GB)Workers, Intel iGPUAMD64
worker-07Dell R630 (48 threads, ~755 GiB RAM)Worker, ZFS storage, Garage S3, CI runnersAMD64
worker-08..10Raspberry Pi 4 (4 GB)WorkersARM64
worker-ai-01ASUS ProArt B850 + RTX 3090 Ti (16 threads, 64 GB)GPU workerAMD64

Storage

DeviceDetails
Rook CephOne SATA SSD per control plane node (worker-01..03), ceph-block default StorageClass
worker-07 ZFSfast (4 SSDs, two mirrors) and hdd (4x 10K SAS, raidz1) pools behind OpenEBS hostpath classes and Garage
worker-ai-012 TB NVMe models volume for LLM weights
Synology NASNFS server data for media and bulk data

Network & Power

DeviceDetails
UniFi Cloud Gateway FiberRouter, VLANs, DHCP, BGP peer for LoadBalancer and pod routes
TP-Link PoE switchPowers the Raspberry Pi nodes
UniFi access pointsWi-Fi
PowerWalker UPSBattery backup in the rack

The hardware lives in an open-frame 12U rack with a patch panel and PDU. See Hardware for the full inventory.


Key Technologies

LayerTechnologyPurpose
Operating SystemTalos Linux v1.14.0Immutable, API-driven Kubernetes OS, lifecycle managed with topf
Kubernetesv1.36.1Dual-stack (IPv4 primary)
GitOpsArgoCD (chart 10.9.6)One ApplicationSet with a Git directory generator
CNICilium 1.20.2eBPF, kube-proxy replacement, native routing, L2 + BGP announcements; Multus for secondary interfaces
IngressEnvoy GatewayGateway API, envoy-external and envoy-internal gateways
DNSCloudflare + external-dnsAutomated DNS record management (Cloudflare and UniFi)
TunneltowonelSelf-hosted tunnel for public ingress, no port forwarding
VPNTailscaleRemote access via a subnet router
StorageRook Ceph + OpenEBS + GarageDistributed block, local hostpath, and S3
Backupskopiur (Kopia)PVC snapshots to Garage S3; CNPG via the Barman Cloud plugin
DatabasesCloudNativePG, Dragonfly, ClickHousePostgreSQL clusters, Redis-compatible cache, analytics
SecretsExternal Secrets + Infisical, SOPS + ageSecrets synced from Infisical; bootstrap and Talos secrets encrypted in Git
AuthKanidmOIDC / OAuth2 identity provider (+ LDAP)
Monitoringkube-prometheus-stack, Grafana Operator, VictoriaMetrics, VictoriaLogs, Fluent Bit, Tempo, GatusMetrics, dashboards, logs, traces, and uptime
VMsKubeVirt + CDIVirtual machines on the AMD64 nodes
Domainwibrow.devManaged via Cloudflare

Repository Structure

home-ops/
├── .github/workflows/   # CI/CD pipelines
├── .justfiles/          # just modules (docs, k8s, kanidm, sops, terraform, vm, ...)
├── ansible/             # Host provisioning (NUT, towonel hub, ...)
├── docs/                # These pages (Markdown)
├── kubernetes/
│   ├── apps/pitower/    # Application manifests: {category}/{app}
│   ├── argocd/          # ApplicationSets (applied manually)
│   ├── bootstrap/       # ArgoCD install, self-managed after bootstrap
│   └── components/      # Reusable kustomize components (kopiur, pvc, cnpg-db-shared)
├── talos/
│   └── pitower/         # topf.yaml, patches (all/, control-plane/, node/<host>/), extensions, addons
├── site/                # Astro project that builds docs/ into this site
├── terraform/           # AWS, Cloudflare, UniFi, and more
├── justfile             # Root task runner (imports the modules above)
└── mise.toml            # Tool versions and environment (KUBECONFIG, SOPS_AGE_KEY_FILE)