Starting a new Cloud/HomeLab blog at this domain - let me know if you want a contributor invite!

  • @[email protected]OPM
    link
    fedilink
    29 months ago

    Thanks! I find most of the issues occur during upgrades to services, but that is to be expected.

    My internet service is usually more of an issue than most services I run. Though some things take longer to get tweaked and running well and that can cause issues.

    • @[email protected]
      link
      fedilink
      1
      edit-2
      9 months ago

      Upgrades to services - that’s why I run dev namespaces and copy over my production shares to dev and utilize zfs snapshotting.

      I haven’t set up testing yet and only just started with prometheus monitoring but so far things run pretty well.

        • @[email protected]
          link
          fedilink
          1
          edit-2
          9 months ago

          I toyed with dev domain but ended up using namespace.tld and postfixing -dev to my namespace so it works out to service.tld and service-dev.tld.

            • @[email protected]
              link
              fedilink
              19 months ago

              I have automated traefik to route the traffic, it sets the dns and ingress route. I’m also doing as you suggested for service to service connections.

              • @[email protected]OPM
                link
                fedilink
                29 months ago

                That makes sense!

                Have you played with anything like Istio to secure in-cluster communications? I think Hashicorp Consul can do something similar to encrypt service to service communications.

                • @[email protected]
                  link
                  fedilink
                  19 months ago

                  I looked into it but I felt at the time it was too complex, maybe I’ll look at it again. Currently I am using wireguard for all cluster node-to-node traffic. It seemed like a reasonable tradeoff at the time, but it is at the network layer instead of application, so I really should revisit that at some point.

                  • @[email protected]OPM
                    link
                    fedilink
                    29 months ago

                    Yeah it very adds some extra complexity and it’s more important for if you are hosting in public clouds anyways IMO.