Git-driven automation for secure, self-reliant infrastructure.
Find a file
codex c84fe7a3de
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Make the k3s API firewall allowlist declarative
The live host restricted 6443/tcp to specific operator addresses, added by hand,
while this role still declared the port open to Anywhere with no source
restriction. The declared config was weaker than reality: running the base role
would have REMOVED the restriction and exposed the Kubernetes API to the
internet. Security was tightened on the host and never fed back into the source
of truth.

Found 2026-08-11 while diagnosing lost cluster access, which turned out to be an
ISP lease rotation (89.244.90.246 -> .236) against a hand-maintained allowlist.

Changes:
- defaults: k3s_api_allowed_sources (empty = 6443 closed to all external
  sources, the safe failure; SSH unaffected so the host stays recoverable) and
  k3s_api_revoked_sources, so rotated addresses are pruned rather than left as
  standing grants to whoever the ISP reassigns them to
- tasks: grant approved sources, then remove any blanket rule, then revoke
  retired ones. Order matters - grants are added before the blanket rule is
  deleted so convergence never opens a window with no API access
- group_vars/all.yaml: the current operator address, plus the two stale grants
  (.246 rotated, 85.132.220.102 historic) marked for revocation
- docs/verification.md: state that 6443 is source-restricted rather than
  listing it as a plainly allowed port

Not yet converged against the live host - the role change is committed but
running it is a production action needing operator approval.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-11 23:56:28 +02:00
.claude/rules docs: workplan-first agent guidance prose (CUST-WP-0055 T04 batch 3) 2026-07-08 17:15:30 +02:00
.forgejo/workflows Add Forgejo CI smoke workflow (enablement template) 2026-07-04 12:49:52 +02:00
.githooks fix: Makefile target hooks makes precommit work finally 2025-09-13 21:58:19 +00:00
ansible Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00
capabilities/playbooks Add playbook capability declaration for bootstrap 2026-05-22 14:49:29 +02:00
cloudinit feat(relocate): receive cloudinit and railiance-plan-host from railiance-cluster 2026-03-10 00:34:50 +01:00
contrib chore(rename): railiance-hosts → railiance-infra 2026-03-10 00:34:18 +01:00
docs Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00
goss fix: correct Goss test suite to match actual server state 2026-03-09 15:50:06 +00:00
hosteurope added information on nydus dependency 2026-03-08 22:55:38 +01:00
infra/forgejo-restore-drill RAIL-HO-WP-0005-T09: Forgejo backup/restore drill assets and evidence 2026-07-04 11:26:50 +02:00
inventory feat(ansible): add swapfile + resource_limits roles; add CoulombCore to inventory 2026-03-27 01:49:35 +01:00
keys security: add admin ssh key 2025-09-14 00:39:03 +02:00
registry Draft capability entry (reuse-surface REUSE-WP-0017-T04, cohort 3) 2026-07-06 19:50:53 +02:00
reports chore: Goss verification reports 2026-03-09T164529Z 2026-03-09 16:45:29 +00:00
scripts build: first successfull plan, apply, destroy of server 2025-09-14 01:20:54 +00:00
secrets security: added encrypted hetzner api token 2025-09-13 22:23:24 +00:00
spec Define S1 reef rollout handoff 2026-07-25 15:13:41 +02:00
state-hub-inbox Define S1 reef rollout handoff 2026-07-25 15:13:41 +02:00
terraform/hetzner feat: add terraform-providers targets 2025-09-14 01:31:03 +00:00
tools WP-0005: wave-2 queue, promote ihp-railiance-probe, smaller restore chunks 2026-07-08 00:11:12 +02:00
workplans Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-11 14:45:48 +02:00
.gitignore chore: add .venv to .gitignore 2026-03-27 01:53:58 +01:00
.repo-classification.yaml Add .repo-classification.yaml (CUST-WP-0050 T11 agent first-pass) 2026-06-22 17:47:41 +02:00
.sops.yaml chores: configure sops with age masterkey 2025-09-13 21:34:04 +02:00
AGENTS.md Define S1 reef rollout handoff 2026-07-25 15:13:41 +02:00
CLAUDE.md Normalize agent instructions and workplan frontmatter (STATE-WP-0067) 2026-06-22 23:16:28 +02:00
INTENT.md Add self-coherent INTENT.md 2026-05-21 01:50:08 +02:00
LICENSE Adopt Target Revenue Source License V1C1 (org-wide preliminary rollout) 2026-07-30 00:53:42 +02:00
Makefile feat(ssh): add bootstrap-ssh-ca role for OpenBao SSH user CA trust 2026-06-18 01:06:43 +02:00
README.md Rename first home reef target to reef-railiance 2026-07-26 09:00:32 +02:00
sbom-tools.yaml chore(sbom): add system-level tool manifest for railiance-infra 2026-03-18 18:35:20 +01:00
SCOPE.md Define S1 reef rollout handoff 2026-07-25 15:13:41 +02:00
WORK-RECORDS.md Make the k3s API firewall allowlist declarative 2026-08-11 23:56:28 +02:00

railiance-infra

Tagline: Git-driven automation for secure, self-reliant servers.

railiance-infra is the canonical S1 ownership repo for the Railiance infrastructure substrate. It provisions and manages servers on HostEurope and Hetzner Cloud entirely from Git. It combines Terraform for lifecycle management, cloud-init for first-boot configuration, and Ansible for convergence. All secrets live in-repo encrypted with SOPS and are unlocked with your single age master key (which you keep in your password manager). The minimal server registry in inventory/servers.yaml is the source of truth.

Future reef-* repos will model purpose-bound substrate boundaries such as reef-railiance or reef-ops-workstations, but the source-backed S1 inventory, hardening baseline, and OS convergence facts stay here.

Quickstart

  1. Clone Repo: clone the repo
  2. Prerequisites: terraform >= 1.7, ansible >= 2.16, age, sops.
  3. Secrets Management: Generate master key (age), provide it to sops and provide your SSH key.
  4. Setup Provider: Create account, select payment option, establish API token.
  5. Provisioning: Plan and apply inventory/servers.yaml to add hosts with terraform.
  6. Convergence: Setup security and tooling with ansible.

🚀 0. Clone Repo

First, clone this repository to your workstation:

git clone https://<your-gitea-host>/coulomb/railiance-infra.git
cd railiance-infra

📦 1. Prerequisites

To use railiance-infra, make sure you have the following tools installed on your workstation:

Example installation (Ubuntu/Debian)

# System tools
sudo apt update
sudo apt install -y git make ansible

# Terraform
sudo apt install -y wget unzip
wget https://releases.hashicorp.com/terraform/1.9.5/terraform_1.9.5_linux_amd64.zip
unzip terraform_1.9.5_linux_amd64.zip
sudo mv terraform /usr/local/bin/

# age 
sudo apt install age 

# SOPS Get the latest release (example: v3.10.2 — check GitHub for updates)
wget https://github.com/getsops/sops/releases/download/v3.10.2/sops_3.10.2_amd64.deb
sudo apt install ./sops_3.10.2_amd64.deb

🔑 2. Secrets Management

Generate Age Masterkey and establish SOPS

This project uses SOPS with age for secret encryption.
To set up your own key and configure SOPS, follow the guide here:

➡️ Managing Age Keys

SSH Access Preparations

Learn how to add your SSH key and test connectivity after provisioning:

➡️ SSH Access & Connectivity Test

TL;DR

  • put your public key into keys/admin_ssh.pub

💻 3. Setup Provider

You need register an account and set it up for API access:

  • register
  • choose payment method
  • generate api-key
  • store api-key in secrets safely

🚀 4. Provisioning

How to declare hosts and bring them up on Hetzner:

➡️ Provisioning Servers

TL;DR

  • Define servers in inventory/servers.yaml (name, region, type, image, ssh_user, labels/role).
  • Provision with make tf-apply (or make apply to also run Ansible).
  • One-shot helper: scripts/hcloud_new_server.sh --type ... --region ....

💻 5. Convergence

After provisioning a server with Terraform, railiance-infra uses Ansible to converge hosts into a secure, baseline state.
This includes admin user setup, SSH hardening, firewall rules, essential tooling, and secret handling.

📖 See the full guide here: Convergence Documentation