Justfile Recipes

Reference for the repo's just recipes. The root justfile loads one module per area: most live in .justfiles/<module>/justfile, Talos in talos/ and Ansible in ansible/.


Modules

ModuleSourceRecipes
talostalos/justfile → talos/pitower/justfile + talos/talos.justfileTalos lifecycle (topf) and diagnostics, see below
ansibleansible/justfiledeploy, check, deploy-ovh-vps, deploy-nut, deploy-homeassistant, ... (see ansible/README.md)
k8s.justfiles/k8sdelete-failed-pods, delete-succeeded-pods, delete-pending-pods, clear-restarts, clear-restarts-sequential, es-sync
vm.justfiles/vmstatus, start, stop, restart for KubeVirt VMs in vms (default omarchy)
infisical.justfiles/infisicalls <path>, set <path> <name> (value from stdin or prompt)
kanidm.justfiles/kanidmls, oidc-client, oidc-secret (copies a client secret into Infisical)
tf.justfiles/terraforminit-unifi, plan-unifi, apply-unifi (and older generic recipes)
docs.justfiles/docssync (bun install), serve (port 8888), build (Astro build, Pagefind index, link check)
sops.justfiles/sopsre-encrypt every *.sops.yaml
gh.justfiles/ghrepo, update-environment-variables

Root-level recipes: pre-commit-init, pre-commit-check, secret-ls, secret-encrypt, gh-all.


Talos

Lifecycle recipes are defined in talos/talos.justfile and wrap topf; diagnostics wrap talosctl. talos/pitower/justfile imports it and adds the node-group recipes. Run them from talos/pitower (just <recipe>) or from the repo root (just talos pitower <recipe>).

How It Works

topf reads topf.yaml in the cluster directory and assembles each node's machine config from layered strategic-merge patches:

talos/pitower/
├── topf.yaml              # cluster identity, nodes, versions, schematics
├── secrets.sops.yaml      # SOPS-encrypted secrets bundle (decrypted by topf)
├── extensions/            # factory schematics: amd, intel, r630, rpi-poe, nvidia
├── all/                   # patches applied to every node
│   ├── 01-general.yaml
│   ├── 02-hostname.yaml.tpl
│   └── 03-network.yaml.tpl
├── control-plane/         # role-specific patches
│   ├── 01-cluster.yaml
│   └── 02-uinput.yaml
└── node/<host>/           # node-specific patches (highest precedence)
    └── 01-install.yaml

Patches merge in order all/ → <role>/ → node/<host>/, lexicographically within each folder. Files ending in .tpl are Go templates with access to .Node.Host, .Node.Role, .Node.Data.<key>, etc.

The installer image is derived from talosVersion + schematicId in topf.yaml. Schematics are referenced as schematicId: "@extensions/<file>.yaml" and resolved to factory IDs locally.

Secrets: secretsPath: secrets.sops.yaml points topf at the encrypted bundle, which it decrypts via sops. The age key comes from SOPS_AGE_KEY_FILE: mise.toml sets it to ~/.config/mise/age.txt; the cluster justfile only falls back to <repo>/age.key when it is unset.

Status & Inspection

RecipeDescription
statustopf nodes: nodes with stage, readiness, schematic, Talos version
renderWrite fully merged machine configs to output/
difftopf apply --dry-run: pending config changes (exit 2 = changes, treated as success)
schematic-idsPrint resolved factory schematic IDs for all nodes

Deployment

RecipeDescription
apply [filter]Apply config to all nodes, or a regex subset of host names
apply-controlplanesApply to the control planes (worker-01/02/03)
apply-workersApply to worker-04..10 and worker-ai-01
bootstraptopf apply --auto-bootstrap: first-time cluster bring-up
addonsBuild and apply the kustomize addons (Cilium, kubelet-csr-approver)
render-addonsRe-render addons-rendered.yaml, which Talos applies at bootstrap via cluster.extraManifests
bash
just apply                  # all nodes
just apply 'worker-04'      # one node
just apply 'worker-0[123]'  # control planes (apply-controlplanes only previews)

--auto-bootstrap has no effect on an already-bootstrapped cluster. For a brand-new cluster: just bootstrap, just kubeconfig, just addons.

Credentials

RecipeDescription
kubeconfigWrite a short-lived (12h) admin kubeconfig to output/kubeconfig
talosconfigGenerate output/talosconfig from the secrets bundle
merge-configMerge the cluster talosconfig into ~/.talos/config

The diagnostics recipes need output/talosconfig; run just talosconfig once first.

Upgrade

RecipeDescription
upgrade [filter]Upgrade Talos to talosVersion/schematicId from topf.yaml
upgrade-checktopf upgrade --dry-run: pending upgrades (exit 2 = due)
upgrade-controlplanesUpgrade worker-01/02/03
upgrade-workersUpgrade worker-04..10 and worker-ai-01

topf compares the running version and schematic against the target installer image and only upgrades nodes that differ, so changing an extension file triggers an upgrade just like a version bump. By default it drains each node, upgrades one node at a time, and waits for it to stay Ready (--stabilization-duration, 30s). See Upgrades.

Reset & Reboot

RecipeDescription
reset <name>Reset a node by hostname: wipes STATE+EPHEMERAL, returns to maintenance mode
reboot-controlplanesSequential talosctl reboot --wait of 10.20.10.1-3
reboot-workersSequential talosctl reboot --wait of 10.20.10.4-11

Diagnostics (talosctl)

RecipeDescription
healthtalosctl health across all nodes
membersShow cluster members
uptimeUptime for all nodes
services <node>List Talos services on a node
image-list <node>List container images on a node sorted by size
image-usageImage count and containerd disk usage per node