Prerequisites

Before working with the cluster, ensure you have the required tools installed, the necessary access credentials, and network connectivity to the cluster.


CLI Tools

Most tools are pinned in the root mise.toml; running mise install from the repository root installs them at the right versions.

ToolPurposeSource
talosctlRead-only Talos diagnostics (health, services, logs)mise.toml
kubectlInteract with the Kubernetes APImise.toml
kustomizeRender manifests and the Talos bootstrap addonsmise.toml
helmChart rendering (kustomize helmCharts uses it)mise.toml
sopsEncrypt and decrypt secrets; topf shells out to itmise.toml
jqJSON processing, used in several recipesmise.toml
topfTalos lifecycle: render, apply, upgrade, resetpostfinance/topf (not in mise.toml)
justTask runner for the justfile recipescasey/just
ToolPurpose
argocdArgoCD CLI for app inspection and sync operations
infisicalInfisical CLI, wrapped by just infisical ls / just infisical set
terraformPlans and applies under terraform/
yqYAML processing for manifest inspection
ghGitHub CLI for interacting with the repository
tailscaleVPN client for remote access to internal services

Access Requirements

GitHub Repository

You need read access to the swibrow/home-ops repository. Write access is required if you intend to make changes and trigger GitOps deployments.

Infisical

App secrets live in Infisical (EU instance, project ID set in mise.toml) at /category/app/SECRET_NAME, and are synced into the cluster by External Secrets Operator through the infisical ClusterSecretStore. You need access to the Infisical project to read or set them.

SOPS / age Key

Talos secrets (talos/pitower/secrets.sops.yaml) and the ArgoCD bootstrap secrets (kubernetes/bootstrap/*.sops.yaml) are encrypted with SOPS using a single age key (.sops.yaml). mise.toml points SOPS_AGE_KEY_FILE at the key:

bash
export SOPS_AGE_KEY_FILE=~/.config/mise/age.txt

Cloudflare API Token

A Cloudflare API token (stored in Infisical) is used by:

  • external-dns: DNS records for wibrow.dev
  • cert-manager: DNS-01 challenges for Let's Encrypt certificates

Network Access

Cluster nodes live on VLAN 20 (servers, 10.20.0.0/16). You must be on the home network (or connected via Tailscale) to reach:

EndpointAddressPurpose
Talos API10.20.10.1 - 10.20.10.11Node management (port 50000)
Kubernetes API10.20.10.0:6443kubectl access (control plane VIP)
Envoy External10.20.10.239Public gateway (towonel tunnel target)
Envoy Internal10.20.10.238Internal gateway (LAN / VPN access)
ArgoCDargocd.wibrow.devGitOps dashboard

Remote Access

  • Tailscale: the pitower Connector advertises the home subnets (including VLAN 20 and the pod CIDR), so internal services and the APIs above are reachable remotely
  • towonel tunnel: public apps on *.wibrow.dev reach envoy-external through the hub on a VPS

Verify Your Setup

Once all tools are installed and credentials are in place, verify connectivity:

bash
# Generate a talosconfig and check the Talos API
just talos pitower talosconfig
just talos pitower members

# Check Kubernetes API connectivity
kubectl get nodes

# Verify SOPS can decrypt the Talos secrets
sops -d talos/pitower/secrets.sops.yaml > /dev/null && echo "SOPS decryption OK"

# Check topf can read the cluster definition (runs `topf nodes`, read-only)
just talos pitower status