From 43aeab6fdac78ed92ca1ee6be707e478e8e20473 Mon Sep 17 00:00:00 2001 From: Ivan Malison Date: Sun, 18 Aug 2024 21:33:58 -0600 Subject: [PATCH] kubernets WIP --- nixos/configuration.nix | 1 + nixos/kubernetes.nix | 40 ++++++++++++++++++ .../secrets/ryzen-shine-kubernetes-token.age | Bin 3587 -> 3587 bytes 3 files changed, 41 insertions(+) create mode 100644 nixos/kubernetes.nix diff --git a/nixos/configuration.nix b/nixos/configuration.nix index f3768445..07d862f1 100644 --- a/nixos/configuration.nix +++ b/nixos/configuration.nix @@ -21,6 +21,7 @@ ./internet-computer.nix ./kat.nix ./keybase.nix + ./kubernetes.nix ./nix.nix ./nixified.ai.nix ./options.nix diff --git a/nixos/kubernetes.nix b/nixos/kubernetes.nix new file mode 100644 index 00000000..d5cd9aee --- /dev/null +++ b/nixos/kubernetes.nix @@ -0,0 +1,40 @@ +{ pkgs, config, makeEnable, ... }: +makeEnable config "modules.railbirdKubernetesNode" true { + environment.etc."kubernetes/ca.crt" = { + text = builtins.readFile (pkgs.writeText "ca.crt" (builtins.fromBase64 "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUVMVENDQXBXZ0F3SUJBZ0lSQUxOeE9UN0o3Ti9lSzZlZHA5TGJLQUl3RFFZSktvWklodmNOQVFFTEJRQXcKTHpFdE1Dc0dBMVVFQXhNa00ySTJOMk0yTnpndE56STVNeTAwWVRJekxUZzNaV0l0WTJOaU1UWmpZV0ZrTXpGbQpNQ0FYRFRJek1USXlPVEU1TlRRME1sb1lEekl3TlRNeE1qSXhNakExTkRReVdqQXZNUzB3S3dZRFZRUURFeVF6CllqWTNZelkzT0MwM01qa3pMVFJoTWpNdE9EZGxZaTFqWTJJeE5tTmhZV1F6TVdZd2dnR2lNQTBHQ1NxR1NJYjMKRFFFQkFRVUFBNElCandBd2dnR0tBb0lCZ1FDVVlVdVRycERid1VTMkIzU1lVb2E3TEk1bWk4Tk5yMGxEZTF3NAozeVBwVm51NnVidm5UTm0yai92ODhIWXdFamxwcEVnNEhqaFA3WUVKOGdzR2RnVUNwSWFQV1RwaWZWbUE3RTRvCjJEYkpEaWVQa2tVR2tOTDB3aENDbE9PY08waHl4ZGs5UG9sNXdSemNpMGw2elNhbEU2REI0ckpybUI1UHBsL0EKdDJLQVZWcXB3YnlubWJpanI0eVpoN0JwN0xmYUlyRnRobHYyWlBFakxmUEx6N1l0aEJ3OS9pVXQ5NG1MTXlXWgpCcHlnQTV5L0NvY1FRbm5GTW5VMW8wZVVkMzdZTDd6RXJmSXh4L0FtTDEwU3EwcWRGWGlZT0pKcXViVVJiZFM4CkRaNmR5SGRYK1VseFBsczJSbHg5bkRhaU5HRkpkenFISnpEZE9sek4za2tkRFFvTzh4VWRIOWVrRlU3ck93a1AKNU5wdWJTd3JkMUZPR0hoK0VrbnVnbkVRRDRPaXAvWVE3SVVqM0FmbTVBZzJsYTlrNFdKUmdqQUNia1EyK2s5SQpzRm1QbW1NVkhuOW5lcENNaVlRTWpYN0FwWncwaXNEUGVWSzVFdVFlSW1ndTd1Tm9WOFI1VndHMFhvQkNYejRTClVxWXYxMXVFc01xRnUwN1p3bHpuc3hubTB1RUNBd0VBQWFOQ01FQXdEZ1lEVlIwUEFRSC9CQVFEQWdJRU1BOEcKQTFVZEV3RUIvd1FGTUFNQkFmOHdIUVlEVlIwT0JCWUVGSTczR3pubWVFQ0pPZHhKQUV6bWpoWWdHVkt0TUEwRwpDU3FHU0liM0RRRUJDd1VBQTRJQmdRQW0xOXpsbTNXVmVQZmxBNlpoL0Z4dkU4TWlyckpGNmptSnpSckJDRU01CkR3a1NtWTNkdk9OcUNZZWVOYjQreFdYV1E4ZVZLVmxQZGtvVzNWN0g1eG5KNjNkWFJOTjJsUTNKcFNURzMreVAKT21wNlhHWTltbWF0ZEh3eVY3TjRoMTBhS0VXQXVSaHkxNDhzZEpaTFlqMExiUjQycENWWWhFUDREM1FqN0tqTgpQSmUrY1I4TlNwaVltREg1eTg4SnF1Ynp0ajVOVmNEai9pTjloLzcvR2FqYlU2bENnTi9TeFpnaTljTkdqeFNiCkpIRkhFMk1wM3o5c2pzaWVUWE1wbExxSzA0NVRRMklCcW5KeU1kS2t2U05rUlVDYnoyeVhkaUlPS3R2VTRseTAKaDg4NHo5UDVKUTlieGUrNmN3WUM0a3kzRzVXWU1uKytSVXN1Q2s0U2NzcmJadE05anBLbnovVHlnTWRWVEM1dwpTaXE2T0hLdEFuaDhBeDFMRUtpY2c5RkxkNk9EeFIzT1ZLdStmVVBWNFhIQVdKbm12RWxHbGl2am5lSGlFK09MCmR6Z2IvQ2ZCRUdIWUJWYzJQRElod0JtVWRvRVovdDNVanZtU0k0NlpibFlwV29kSnZMRndnZTJIeFNpdlJsTFcKVWgvb1BXWDVOL0NIOUkzNEhUQWhJNDg9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K")); + mode = "0644"; + }; + services.kubernetes = { + roles = ["node"]; + kubelet = { + extraOpts = "--cloud-provider=external"; + registerNode = true; + kubeconfig = pkgs.writeText "kubelet-kubeconfig" (builtins.toJSON { + apiVersion = "v1"; + kind = "Config"; + clusters = [{ + name = "default"; + cluster = { + server = "https://34.31.205.230"; # Your GKE API server address + certificate-authority = "/etc/kubernetes/ca.crt"; + }; + }]; + users = [{ + name = "default"; + user = { + token = ""; + }; + }]; + contexts = [{ + context = { + cluster = "default"; + user = "default"; + }; + name = "default"; + }]; + current-context = "default"; + }); + }; + }; +} + diff --git a/nixos/secrets/ryzen-shine-kubernetes-token.age b/nixos/secrets/ryzen-shine-kubernetes-token.age index 36fcbbd5e031a05735798be2bd1cfa6835d4d7ca..2de2aa46f4084efb2eb6408ba2dbde243de50f9a 100644 GIT binary patch literal 3587 zcmZXV|Krp2oySGtbVXE9JO_Ao6Az?*Y|KCQ=6hPdurx{2rcKlIThhpZ zC@OBBjZIJ32FL`5uv5kzCx{L{6F6ju-cXqyeuEPQ`Qq0@+)iMhALf35zu@tHJ>Jjf z>m_OGfZC8-{br|XHf}Xrn!g8n24;EN?aF|v1Yj79c#B$#wNNk4^!oeg;4plEp}ij#3gE^s$0tb}e4% zDuGz4&Lx|vNCOelIj(OLb-10bpbY9k;5--XwYZ)lh8?y>nGi%OR+P(x1%hh_5|SV( zKCp!|5_LYUo#M2R<^?qli|Sy58-BQk7?qU8mTj^EMOx)_#5EP9T?-U^)sPv`Jh~Jz z8$!NWMKW?ZmG2QXODHFDFopf6uR&!@2ssbN!IL(uY4t_P|@EK~N` zXewT#^F60#wRxK4NxGlv@HMg%%>>&Xg=q(q7$0{ue~PS&UAH1pfqt85H8{0mw`D*I zM0$`*QHc31t<{#inoT$WK~ck#dbenOYY}=^%-xF}yVFs)ltPmaM^1T1c>M zjlgKUXd-I2(FW`)5|BFSy5@n2sGf8=-i_q?$&%lxg^MmMDFLcXBlQGkOZ{M{5=03; z(2l7+o>F45ikL#9T`-sC!94EK6FvrrcHoeq6A2=R0D)jd?E6B24wK6VMG;Qq!o@OA zihV+5`!QE=|F_bKn?Z^hDT0&EdaA=EGX&qC$eFtwTam5v)lpL)W z%A{T-+$f2oAX~@%M5tIKFkh_XangCdpGb!d%{BsrS+uHQiqO8b{cR@;iIkZ{y-9>G zXD}Dhd$iMa)6G2SBU(g^h7w7ksn#PPf@GT|i>_B|9#$}mp#}zWRNrqv86Jw)!&1}G za)mZz#G^2YTD_Lr4k*bBa+{{gRnzuDc}~@%K(DOST_0b~@o_lN3X1utzt%3pA0<944C;Jsqwf(k>IMbW=XI9YVN9!?mpvTp;3x9g~|Ghj*NQ9c`3=^J#xGNyI~9 zxJa9jMKu8%nXuNZbbxT( zF>6Ub*{mlj$-M2?FK7Uo#%nR#+b79l*>9SKI0w57n^2Q%t}JsMs)iXotP9247$qac zd|BW;aywmel)j$h@Fq^D$|<=e$E5(LO35CV5wcpCmJBFgR|^;12|#6FAL=cpqalr@ z8LFBFBP0?pP)SzQ8kUJG-58`0QNu?Ly9>b%smHxo`|E zXNztr19TgzLI7MWe7?zuAIi6EZ_UaFoQ70KVsf{|StT@uaJC)or#RQ`2SUDVQ105n zUQ?qqPaRW5j4?Vj2gYLvP|hepIvX=BpMUsk`(hf`b2^prn~CfNCN;Dc^ikfZj1&Z^ zU$L?d(@vZIP|+QpF$Cgnr`pT4XtQYvU0*K3)&LKjOvGeg2QbM}NGPCKJ}L=ptqb{5eRwL}ET9KTXVLP!x&;T)*7`|+dh%-1| zki`@Sd3f3C0Uaml=0k0?uh3#HDY#hQRTESENtFji8Vw5URnB-POk zFx+kdS}B_b(*77+)$H?WY!fJgl(*bvIVT;Ebx0uGbhX5lj5w$Q5K*QBU4_rZ{8rso zgUJktdbExjLIGMrtHGq%&}oV4pcO_9GldM|=d(yRL0M=wW~B7tz6}g`vyBdJB#V-d z$QRp14l4T?8V&L)6Dnn-V7%M&V@zFuijXhtxn|kYq3e+3;9zi6X4BxzB@2J@Mq1Bp z82@5u?%Z?h0l9IhaPtX%?@f_Y*l*@{|-;74!WF=FnEj~?IHvVwD8c=BxUqV|8w8{ht{ zF>;C-_I&*#miX?edr)R*jdr*9?%kWWO}(M;-l-o4i80frZK_Uq{+d7hc+~C6&(6$# zX6K{3294P67k&in`a&vxzHsbwo8v>Xm*W?&ziHv|Cue)lO<%fodEMDErNb-^ROyF92#I5{e^V zS5J@Sne>)@_g$R$@|T`Z3m2{5`n}5^e(j?~(*MXk;@LYVH^@1Y2KC;l$xlvNzPI?* zubyDm&YcH5{zR0#P2IV9-oT3X3VnRYl@#AMs{&xG*udG>>&J5gl@XAB8?mc>| zzQ`C!Q2#jM^Uv4LC*Rt!@ha@u*ZQrSpa0i+yS_QJ^69HDeP-X#dmsJrAI97}H0{*y zy>Hg!EAjZ9^XGWB(4%La+%j|Ay<5j0xt-1qf|1K&Bb=XdGDQ1DE3hW(2le)!!M{9fh0sjJ33Zavx&rf25-_V$S9m1oc9 zH~)VvY#dp)__665?ux9`-S>|D^O03&T08bV-?{waohSZh{R&_8Fm?Jrw=uB=_y6+7 z54O$^efi{qKd(Nv;PVaO^NZIkx^Ke#OHch%XCD>3syKS;v)0eY?|kivTc*8zaNGE$ zH?U{#`C{n}*Y5pr?Ej73`cnS;lZZQ^@lC@l1U8NqM@w+&p-Ky=}GgR^*|{=#&LX z79YER){g9E=fEA8%$PGX@csvHpPjNt{f}|V>f`x&%g^K|J%xR-apvNCUV7!zD|Wih zs>z6dYYl#G^~)zt&g%MhEm2}e_D?-@mHGf%*?q%jH~;0&2aY~Cecrz>8ah3FltsO; z=Fl5~Z8Nto{Pl+PHh9{IO@)=~!P??Q$C8ih+gE~1vM;^=?3}66hKIK8SU&X09fPA6 zsGD#3=$)(X%1ju2ZsM`07KKAIS6y`Y#`O|*^4G?>?c;U>E2i!_vUt;uJC>9u9+-OB z)i=JnbIIm~^YOC}7yq>5sj16IIla!j?wix^j9zs12fl0e4wOdf*Is`8YVD%EmwCQg p`!HL%oxJ7L@yVaOd)K?~%=>ETtfA?T@1JtxmYb$&-}~|j_OE%|GgANn literal 3587 zcmZve``6P1n#Y;tCKXv^SalfKtqwSh)$RN2jP181QlO|12 zWL%NkGNY?7BRIgItBANDD(qoi2VsCctFi}VLB~PX3!@C8z$hrg?7Hs{<1a7!7ktk1 zobU7bKD;6i$Stw!v`tlS&DOgLV1b^2yS;`{8<3>{1c5Oxr*zp4>}9(U!x(ZnqSR7l z1k%JxA1QT&9@3-Ad8Ql<6fg-v1PH-&51EJggl1Auj-*Q#3upqYi)=2Y2GK%;OJ@Yl z?lDr#s;B6yXgne@ikB~HDGkuM3KDWeUGlrNf><$gxExlBS(5H_8_l-QNfODr=ur^F zDp*vtfLnx-H+-sulZco^r4ZT0Nun;ud{+f%1F4b2X(Y}$4cqIO974bax!g0lc8*NN zQM`v|5JTkMcBC6ghuXb1i@8x$u{{o`$v~u_cPJ{!wsLta!l$!@FIx>G?P4_*@>?M{ zl^`lr03J>=QUxWfcuBO9GLne`lBosLZ7~zb`U6&<5i%7i$E%!`35r-ph|plO;E@`V zVp)nY?^c>&1>QikLZLL*~Tql({_5l~cFBf?5}QTO8^ z%`728tfhEyt< z2)LH4kU{~gK^?Y0GNA$-tnwbW)TU#k*)%L5&0)!K0~UNRKt_NP(Eth4skjhM#$Ya2 zCLlowR?0RYbQ)@m1N>}NQA3_Kn{qO0Kve2Q%5_oPViO4i2OK&YPL!iM8A;htP)TRa zmZh-?7R{;|-Hy_6KT{&IQLNp`7FY&4rQuDX&+BBkT7w~ES@X1;Fq zj2L0dsN5~|uy9AvDFcC^ezH=)I!-eZDmw9sryQxI`+;JF?zA(YJrq-+64ByWES!lV zdc_RZE8U8jMz9WcRc;Bos_M3v0U6cI5`@nmijon&WbqxgA5OE`W}ydCokqVGjhF^u z?;+e1cTID5P&sHVl&!iMPHgrD)nBFOaLi8firTNN*jf5lk}}`G)7GI6>s0o z`_x=U&++C0T9va1RhVQT)6({8GvcFNGm1cRv>>4^ojuo8m0`38~<2B2K5Vc7jB zQRekh3`@q73CjgpiKv$Hq2V;#ErYJ@6_R`~iIorz)bNbhV1~>BaZz1`{Vhgpn_N?@ zOB4WR_@v0aep}06l@4kJ0#Xr|Gf<(S0NrAu z74G#K4amqKgx!RMsxh1f>VdM~_To*>FKNkkSTi$F(5)s@N<&q11w(c-Kq2Omf}A6f zve;ut51y%UbTm)uTm)8`LK-5{TsNOA3ne|ym)Up(RP4T=%Om;!XEsPJz}|}7u)<`R zq?0+G5PMW9l?t&C=3}^g%?GIl*&*vOz9kWPzo(H4#NZ%pb8*XJ@T5ZVWRS^6ibX#F z^EIT)*7Za^4p6jtmEB+>siC%4549Wh9$TrFjYQJ*BQ}?dR4R%UrZW|p1~EBeIsCyrCrAn zq?VW{8Br>SC|7MV28425+pExmzXK*ZOeF0T>0G={wZO22#rs^MjJH@L!8TK&R#cU3 z(i23I1*}JOeDS))^qq37iGw2OFI1~FL~O-6u8x&Bg3D9st7cPRE$E}YL?YB4YHM5K zGd|Wt_;j!o&Biq}g=UsM?fMv+}i|ScCJF%;GHHjMd|4 zm1DE0S#xt}UWyLSWH~G+P1@V#qLQsSJp^*H5CKxH`1-{hll+ncFHgdu5| z9RsQ(PKd>=U{Q<5hn@?8@6=L!QN}yPVux^-w~sj4dMXg> zH8ecrk^EA#qdR#ltH+Q|uGW#rV7i*pL4yS#E}sR$F4+y%m}uMf3=9l-18IsSIzWZ& zi$l+jE|eNPV#q{IrP?mtN`oqZs!`Gx=bD-)di^R>qt$Kdv|IOmc|i;hDu-gT_HC)( zn?2*h$E=$*cQg0R^Jm64rtElh+WJ#>_nre`}szyX>xmo5uZaG4JLNXd!t@B`9Jca-G}!P`RzY{^Ug2dFy=2<{!imk=4s%Iy}iPdJG9Fm z{&LUQWh3tTbVqY=@cgy?`lkPw4-Y&To_yk!gG*OFeEwgj-S#kX`?j&{_7B`!|M4{Z z-I?y_+4tA>?_9fhu=U`YXSeR&aCFUR=HAZObMeXLhoA8M?aXr{{#k*3xcCpN(4ARL z**i}fw|dS$XnT71?_4o*mUG|dk9FTWb?L@=dk-&sf9K_;A3u>k_sIhXaxec#-uko8 z9+D0{GW*vPzuY)DSXup0y!g6dp6JP zZM!9&y*0MttAUNg5|3}jGgmUyBU7gyA%gF}Gk@=$3%|Z$%V(45zl?upb$0=J?dvm- zTzY!)-?YZgU3uVtuiW-J%1yrGzD-Ns{2Cqi!f&e|o*40B?(ALYHu~`9qd(aE{PibB zUi{+^_DdVrRmdEpL1s(W}Ur#^2*xu(Ocf13)8#DpB=l~ zdMrMtzF^r$Gmd7?ooD|0Y~YcH9>~45OZGE2ORZl8W|+-&Z; zKcNS~)7QRo>D_aC;2Rz<{^G;Sx6b&9_4C8?Z@lK%a{bKXlceP%V(%YmjNdxw>eJS@ zANbx6=hBB31;g_;{r#JB*R7oIOnV}CncFaJ$J^=6KOK|#&bsyAFMWRVqBBqZ-3$N8 ztXPtKL)zb)Q(1Maw`=D0{^*zY%)BeHc<-;?buYZ={qZp}t^RpQ