<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloudinit-Nm on Janusworx</title><link>https://janusworx.com/tags/cloudinit-nm/</link><description>Recent content in Cloudinit-Nm on Janusworx</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>feedback@janusworx.com (Mario Jason Braganza)</managingEditor><webMaster>feedback@janusworx.com (Mario Jason Braganza)</webMaster><copyright>© 2026, Mario Jason Braganza</copyright><lastBuildDate>Fri, 12 Dec 2025 08:15:59 +0530</lastBuildDate><atom:link href="https://janusworx.com/tags/cloudinit-nm/index.xml" rel="self" type="application/rss+xml"/><item><title>2025-12-12 Notes</title><link>https://janusworx.com/nm/2025-12-12/</link><pubDate>Fri, 12 Dec 2025 08:15:59 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/nm/2025-12-12/</guid><description>
&lt;h2 class="relative group"&gt;Goals + Recap
 &lt;div id="goals--recap" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#goals--recap" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Read a book on &lt;a href="https://www.oreilly.com/library/view/traefik-api-gateway/9781484263761/" target="_blank" rel="noreferrer"&gt;Traefik&lt;/a&gt;, yesterday. Pretty helpful. It covered the older version of Traefik though, so I’ll have to adapt the advice to my new version. I tried reading the actual documentation next, but they are umm, I cannot put my finger on it, but I keep getting lost. What is written, is pretty well written, but I think there is a lack of a connecting link from the big picture to the nitty gritty, or if there is, is just glossed over. If it wasn’t for the book, I’d be pretty lost. But as a reference though, it is really good.&lt;/li&gt;
&lt;li&gt;The cluster is still up and running well. Miniflux works. Been using it all day yesterday and today. Pretty please with the decision to move to a cluster, now that it is set up.&lt;/li&gt;
&lt;li&gt;Look at &lt;a href="https://janusworx.com/work/the-big-plan-change-my-vm-to-be-gitops-driven/" &gt;The Big Plan (&lt;em&gt;Done!&lt;/em&gt; 🎉🎉🎉)&lt;/a&gt;, to see if anything needs adding or changing&lt;/li&gt;
&lt;li&gt;Today, figure out http to https redirects. And move the main site &lt;a href="https://janusworx.com" target="_blank" rel="noreferrer"&gt;https://janusworx.com&lt;/a&gt; to the cluster&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h3 class="relative group"&gt;2025-12-12 09:15
 &lt;div id="2025-12-12-0915" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-12-0915" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Let’s get to work!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 09:30:&lt;/em&gt; Changed all my Hugo archetypes to no longer include links to my discourse. Will need to maket the time someday to remove existing links from all the pages.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 10:04:&lt;/em&gt; Got my http to https redirect working! Also fixed my tls sealed-secret for traefix. Nothing big, but in my haste, yesterday, I forgot to export it in yaml. And today, I wondered why my manifest was formatted so queerly, until I realisde I was looking at json. Surprisingly, Traefik had taken that json-in-yaml manifest and worked without complaint! Tea break.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-12 10:30
 &lt;div id="2025-12-12-1030" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-12-1030" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Thoughts to move &lt;a href="https://janusworx.com" target="_blank" rel="noreferrer"&gt;https://janusworx.com&lt;/a&gt; to the new cluster.
&lt;ul&gt;
&lt;li&gt;Doing this first, because this is the most public facing part of my VM. If there are any issues here, better get them out as soon as possible.&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have a folder that I can rsync all my new posts to (like it is on the old one)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Have an nginx container look at it via some hostpath pvc?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Serve!&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Now to go stumble about doing it and fixing any hiccoughs along the way&lt;/li&gt;
&lt;li&gt;Disabled miniflux on the old VM as well&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 10:45:&lt;/em&gt; Ok think I will first fix my deploy action to sync to the new VM&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 11:27:&lt;/em&gt; Use ansible to create a folder for my hugo deploy&lt;/li&gt;
&lt;li&gt;Switched variables in my forgejo action to the new VM, gave it my new key, as well as updated known hosts (No other change)&lt;/li&gt;
&lt;li&gt;Manually running the action now. Did &lt;em&gt;not&lt;/em&gt; realise how big my site has grown in size over the years&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 11:33:&lt;/em&gt; Ok my action timed out. Think I will manually move stuff first with a syncthing sync. (Thank god i set it up yesterday!)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 11:40:&lt;/em&gt; Running action again. It works! It works!&lt;/li&gt;
&lt;li&gt;Now I know why gitops! Change a few variables, drink some soup et voilà, your new site deploy is done! Wow! Love this!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 11:45:&lt;/em&gt; Also realised my original manual action run had not timed out. It was, in fact, interrupted by a subsequent automated run, which had succeeded!&lt;/li&gt;
&lt;li&gt;Now that the data is in place, I’m off to get nginx working in the cluster.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 12:45:&lt;/em&gt; Just realised, I might have to have &lt;em&gt;two&lt;/em&gt; containers. One for &lt;a href="https://fr.janusworx.com" target="_blank" rel="noreferrer"&gt;https://fr.janusworx.com&lt;/a&gt; as well. Seems wasteful. Checking to see, if one pod / nginx instance can do both.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 12:57:&lt;/em&gt; Realised, I am then asking Nginx to do another level of routing. Hmm, no thank you. I’ll keep things simple, be a little wasteful and run two nginx containers.&lt;/li&gt;
&lt;li&gt;Lunch break&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-12 13:30
 &lt;div id="2025-12-12-1330" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-12-1330" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back for a while&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 14:28:&lt;/em&gt; Yay! Done! &lt;a href="https://janusworx.com" target="_blank" rel="noreferrer"&gt;https://janusworx.com&lt;/a&gt; is now served from the cluster! Done with work for the day :)&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-12 14:45
 &lt;div id="2025-12-12-1445" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-12-1445" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Some NMC work now&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 15:00:&lt;/em&gt; Tea. Be back later.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-12 16:20
 &lt;div id="2025-12-12-1620" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-12-1620" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Done with French. Off for a walk.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-12 17:30
 &lt;div id="2025-12-12-1730" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-12-1730" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 18:00:&lt;/em&gt; Send out a mail to the newsletter list. I might not be able to later, with this migration.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-12 19:20:&lt;/em&gt; Moved the french version of the site over as well. One less thing to do tomorrow.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Tomorrow
 &lt;div id="tomorrow" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#tomorrow" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Enable image updation of the nginx image for both jw and fr.jw&lt;/li&gt;
&lt;li&gt;Figure out how to go about moving the mastodon archive and keeping it updated&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: 2025-12-12 Notes
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;
&lt;/p&gt;</description></item><item><title>2025-12-11 Notes</title><link>https://janusworx.com/nm/2025-12-11/</link><pubDate>Thu, 11 Dec 2025 08:18:29 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/nm/2025-12-11/</guid><description>
&lt;h2 class="relative group"&gt;Goals + Recap
 &lt;div id="goals--recap" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#goals--recap" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;I think, I &lt;em&gt;think,&lt;/em&gt; that most of the fundamental pieces are in places after yesterday’s work.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;The Big Plan is done!&lt;/strong&gt;&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Now to move each production item from the old VM to the new cluster.&lt;/li&gt;
&lt;li&gt;Today, figure out http to https redirects. And move one app.&lt;/li&gt;
&lt;li&gt;Note to Self: Quit at 1p. Get back to life.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;The Big Plan (&lt;em&gt;Done!&lt;/em&gt; 🎉🎉🎉)
 &lt;div id="the-big-plan-done-" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-big-plan-done-" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The plan is to redo the cluster again and do my own instance of
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; K3s&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Sealed Secrets&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Certmanager&lt;/del&gt; (Not using it)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Letsencrypt&lt;/del&gt; (using pre existing Letsencrypt certs)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get Traefik Ingress to work&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out a way to get certs automatically into the cluster&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;And once &lt;em&gt;that&lt;/em&gt; is done, figure out an app to move (Miniflux or Hedgedoc?); 2025-12-03: Kanboard it is!&lt;/li&gt;
&lt;li&gt;Begin by moving (lifting and shifting in popular parlance) Kanboard to the cluster
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Cert will probably be needed (Wildcard cert works now, just like it does without the cluster)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert a docker-compose to kubernetes manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to configure an app with code&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to store data and back it up&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out secrets, if there are any (for now sealed secrets ok, figure out vault and vault injection later)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to tunnel through and reverse proxy&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Make Kubernetes manifests work with flux&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to automate deployment of manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to migrate there if there is any in an old app&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figue out how to automate updation of images in manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get another app (Miniflux) deployed&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out what needs to happen as part of the lifecycle. What you want in the cluster, what stays out, do they intersect, how do updates of cluster happen? VM (node) updates as well?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Then begin to think along the lines of Live Deploys. Prototype locally and once it works, migrate to production immediately&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert Kubernetes manifests to Helm Charts (optional, based on energy)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Go live! Git is source of truth. Two repos.
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; One for the Main node and its update
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Terraform will provision node and install package, setup firewall&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to get Terraform to get the node talking to the git forge&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Structure repo, copy every thing node related there, and make sure stuff gets updated periodically and idempotantly, via ansible pull and a systemd timer&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; The other one for k3s and flux
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert everything I have done locally to run on prod. Add more steps as you do them below&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h3 class="relative group"&gt;2025-12-11 09:30
 &lt;div id="2025-12-11-0930" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-11-0930" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;The night passed well for the new VM. It rebooted on time, just as scheduled. Hetzner backed it up, just as instructed.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 09:37:&lt;/em&gt; Also, &lt;em&gt;&lt;strong&gt;Oi, wot?&lt;/strong&gt;&lt;/em&gt; &lt;em&gt;&lt;a href="https://doc.traefik.io/traefik/reference/install-configuration/tls/certificate-resolvers/acme/#the-different-acme-challenges" target="_blank" rel="noreferrer"&gt;Traefik natively supports what I have been trying to do with Lego!&lt;/a&gt;&lt;/em&gt; Get Lego to generate certs and install them as a sealed secret into the cluster for Traefik to use. Will try to figure out what to do once my Letsencrypt jail time gets over. Maybe do both. Traefik can handle stuff for the cluster and Lego can get them as well and keep them in another place in the VM in case I need it outside the cluster.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 09:55:&lt;/em&gt; Don’t think I want to work on the VM today. Will sit and read a book about Traefik. Tea Break&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-11 10:15
 &lt;div id="2025-12-11-1015" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-11-1015" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back. Begin reading!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 12:42:&lt;/em&gt; Lunch. Finished half of the book. Will do the rest after lunch.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-11 13:05
 &lt;div id="2025-12-11-1305" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-11-1305" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back to the book.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 13:30:&lt;/em&gt; Done with the book. Nap time!&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-11 17:15
 &lt;div id="2025-12-11-1715" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-11-1715" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Did my Duolingo and had a long walk after quite a few weeks&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 17:16:&lt;/em&gt; Reading Traefik docs&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 17:54:&lt;/em&gt; Client call&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-11 18:35
 &lt;div id="2025-12-11-1835" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-11-1835" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-11 19:12:&lt;/em&gt; Shutting down for the day!&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: 2025-12-11 Notes
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;
&lt;/p&gt;</description></item><item><title>2025-12-10 Notes</title><link>https://janusworx.com/nm/2025-12-10/</link><pubDate>Wed, 10 Dec 2025 08:26:26 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/nm/2025-12-10/</guid><description>
&lt;h2 class="relative group"&gt;Goals + Recap
 &lt;div id="goals--recap" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#goals--recap" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Got Ansible Pull working, so now I can update a playbook and the VM fetches it and does what I tell to! Who’s a good VM?&lt;/li&gt;
&lt;li&gt;Struggled with getting LEGO to generate a first time cert. And then like a ignorant fool, I made too many requests of Letsencrypt and got locked out. Shoulda done dry runs! I forgot!
Will simply copy over my certs from ye olde plaice and then figure out a way to do the renew script. Even for later, methinks I will leave initial certificate generation to be a manual thing. For the big AWS project, I will figure something else out.&lt;/li&gt;
&lt;li&gt;Will focus on getting Lego and certs working and getting an app or two at most deployed on the new production cluster.&lt;/li&gt;
&lt;li&gt;Note to Self: Quit at 3p. Get back to life.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;The Big Plan
 &lt;div id="the-big-plan" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-big-plan" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The plan is to redo the cluster again and do my own instance of
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; K3s&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Sealed Secrets&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Certmanager&lt;/del&gt; (Not using it)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Letsencrypt&lt;/del&gt; (using pre existing Letsencrypt certs)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get Traefik Ingress to work&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out a way to get certs automatically into the cluster&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;And once &lt;em&gt;that&lt;/em&gt; is done, figure out an app to move (Miniflux or Hedgedoc?); 2025-12-03: Kanboard it is!&lt;/li&gt;
&lt;li&gt;Begin by moving (lifting and shifting in popular parlance) Kanboard to the cluster
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Cert will probably be needed (Wildcard cert works now, just like it does without the cluster)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert a docker-compose to kubernetes manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to configure an app with code&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to store data and back it up&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out secrets, if there are any (for now sealed secrets ok, figure out vault and vault injection later)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to tunnel through and reverse proxy&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Make Kubernetes manifests work with flux&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to automate deployment of manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to migrate there if there is any in an old app&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figue out how to automate updation of images in manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get another app (Miniflux) deployed&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Figure out what needs to happen as part of the lifecycle. What you want in the cluster, what stays out, do they intersect, how do updates of cluster happen? VM (node) updates as well?&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Then begin to think along the lines of Live Deploys. Prototype locally and once it works, migrate to production immediately&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert Kubernetes manifests to Helm Charts (optional, based on energy)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Go live! Git is source of truth. Two repos.
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; One for the Main node and its update
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Terraform will provision node and install package, setup firewall&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to get Terraform to get the node talking to the git forge&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Structure repo, copy every thing node related there, and make sure stuff gets updated periodically and idempotantly, via ansible pull and a systemd timer&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; The other one for k3s and flux
&lt;ul&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert everything I have done locally to run on prod. Add more steps as you do them below&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h3 class="relative group"&gt;2025-12-10 09:50
 &lt;div id="2025-12-10-0950" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-10-0950" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Paused a systemd service via Ansible-Pull. Feels very cool!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 10:21:&lt;/em&gt; I keep getting distracted with the bigger picture and what ifs rather than focussing on what is right in front of me.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 13:00:&lt;/em&gt; Lots of ansible work. Good progress. Lunch break. I used to think that Ansible roles were too granular and now I seem to be doing the same with my tasks 😂&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-10 14:15
 &lt;div id="2025-12-10-1415" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-10-1415" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Will just copy the certs for now&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 17:23:&lt;/em&gt; Got the plays structured nad worknig just the way i want&lt;br&gt;
Got syncthing installed, service installed, and working through the firewall.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 18:14:&lt;/em&gt; Copied files and got sealed secrets up and runnig within seconds!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 18:35:&lt;/em&gt; Got Kubeseal installed via ansible, without a single hitch!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 19:24:&lt;/em&gt; Manually put in the secret to the cluster. Will look at automation after a few days when Letsencrypt decides to talk to me.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 19:25:&lt;/em&gt; And just like that Traefik is up!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 20:06:&lt;/em&gt; Couldn’t get Miniflux working. Will work on it tomorrow. Calling it a night.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 20:30:&lt;/em&gt; Couldn’t quite leave it alone. I think I forgot to encrypt the cert with the new cluster’s sealed certificate. Will give that a try. If it works good. If not, we try again tomorrow! :)&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-10 21:00:&lt;/em&gt; It was the damned cert! Ok, now I know I was not going batty :)&lt;/li&gt;
&lt;li&gt;Figure out http to https tomorrow. Haproxy was doing it here. Need to figure out how to do it with Traefix directly. Time for bed.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: 2025-12-10 Notes
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;
&lt;/p&gt;</description></item><item><title>2025-12-09 Notes</title><link>https://janusworx.com/nm/2025-12-09/</link><pubDate>Tue, 09 Dec 2025 09:05:32 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/nm/2025-12-09/</guid><description>
&lt;h2 class="relative group"&gt;Goals + Recap
 &lt;div id="goals--recap" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#goals--recap" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Got Terraform working and the node is now up, exactly the way I want it!&lt;/li&gt;
&lt;li&gt;The cluster also got installed perfectly and I was able to connect to it.&lt;/li&gt;
&lt;li&gt;Today will work on Ansible, so that local updates are easy.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;The Big Plan
 &lt;div id="the-big-plan" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-big-plan" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The plan is to redo the cluster again and do my own instance of
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; K3s&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Sealed Secrets&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Certmanager&lt;/del&gt; (Not using it)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Letsencrypt&lt;/del&gt; (using pre existing Letsencrypt certs)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get Traefik Ingress to work&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out a way to get certs automatically into the cluster&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;And once &lt;em&gt;that&lt;/em&gt; is done, figure out an app to move (Miniflux or Hedgedoc?); 2025-12-03: Kanboard it is!&lt;/li&gt;
&lt;li&gt;Begin by moving (lifting and shifting in popular parlance) Kanboard to the cluster
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Cert will probably be needed (Wildcard cert works now, just like it does without the cluster)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert a docker-compose to kubernetes manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to configure an app with code&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to store data and back it up&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out secrets, if there are any (for now sealed secrets ok, figure out vault and vault injection later)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to tunnel through and reverse proxy&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Make Kubernetes manifests work with flux&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to automate deployment of manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to migrate there if there is any in an old app&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figue out how to automate updation of images in manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get another app (Miniflux) deployed&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Figure out what needs to happen as part of the lifecycle. What you want in the cluster, what stays out, do they intersect, how do updates of cluster happen? VM (node) updates as well?&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Then begin to think along the lines of Live Deploys. Prototype locally and once it works, migrate to production immediately&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert Kubernetes manifests to Helm Charts (optional, based on energy)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Go live! Git is source of truth. Two repos.
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; One for the Main node and its update
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Terraform will provision node and install package, setup firewall&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to get Terraform to get the node talking to the git forge&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Structure repo, copy every thing node related there, and make sure stuff gets updated periodically and idempotantly, via ansible pull and a systemd timer&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; The other one for k3s and flux
&lt;ul&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert everything I have done locally to run on prod. Add more steps as you do them below&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h3 class="relative group"&gt;2025-12-09 09:00
 &lt;div id="2025-12-09-0900" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-09-0900" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;2025-12-09 10:13:&lt;/em&gt; The net is down, so am trying to work via codeberg. Makes me thankful, that I worked out of a private repo and didn’t commit private stuff to it&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-09 10:13:&lt;/em&gt; Tea break&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-09 10:52
 &lt;div id="2025-12-09-1052" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-09-1052" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-09 11:21:&lt;/em&gt; Now learing the push/pull dance with ansible-pull. Making changes here. Pushing to the forge and then pulling in on the VM is a novel experience. As compared to editing conf files on the VM itself&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-09 13:12:&lt;/em&gt; Lunch. making steady progress though&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-09 13:39
 &lt;div id="2025-12-09-1339" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-09-1339" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back. Got ansible pull working as well.&lt;/li&gt;
&lt;li&gt;Now, to take all the changes I’ve done, commit them to git and rebuild the cluster, hopefully, one last time&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-09 15:00:&lt;/em&gt; It worked! It all worked! Tea break.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-09 17:20
 &lt;div id="2025-12-09-1720" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-09-1720" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Bootstrapped flux on the VM cluster&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-09 21:01
 &lt;div id="2025-12-09-2101" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-09-2101" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Bootstrapping a Letencrypt cert with lego is causing no end of problems.&lt;/li&gt;
&lt;li&gt;Tomrrow will just import. and then use the current certs&lt;/li&gt;
&lt;li&gt;And adapt the ansible playbook to just do an install&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: 2025-12-09 Notes
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;
&lt;/p&gt;</description></item><item><title>2025-12-08 Notes</title><link>https://janusworx.com/nm/2025-12-08/</link><pubDate>Mon, 08 Dec 2025 09:25:33 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/nm/2025-12-08/</guid><description>
&lt;h2 class="relative group"&gt;Goals + Recap
 &lt;div id="goals--recap" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#goals--recap" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Thank you &lt;a href="https://psaggu.com" target="_blank" rel="noreferrer"&gt;PS&lt;/a&gt;, for being my sounding board.&lt;/li&gt;
&lt;li&gt;Created repos and moved around directories and fixed scripts so that most of my infrastructure stuff is properly organised. Created the repos I needed for the new VM and the single node cluster that will run on it.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;The Big Plan
 &lt;div id="the-big-plan" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-big-plan" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The plan is to redo the cluster again and do my own instance of
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; K3s&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Sealed Secrets&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Certmanager&lt;/del&gt; (Not using it)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Letsencrypt&lt;/del&gt; (using pre existing Letsencrypt certs)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get Traefik Ingress to work&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out a way to get certs automatically into the cluster&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;And once &lt;em&gt;that&lt;/em&gt; is done, figure out an app to move (Miniflux or Hedgedoc?); 2025-12-03: Kanboard it is!&lt;/li&gt;
&lt;li&gt;Begin by moving (lifting and shifting in popular parlance) Kanboard to the cluster
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Cert will probably be needed (Wildcard cert works now, just like it does without the cluster)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert a docker-compose to kubernetes manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to configure an app with code&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to store data and back it up&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out secrets, if there are any (for now sealed secrets ok, figure out vault and vault injection later)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to tunnel through and reverse proxy&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Make Kubernetes manifests work with flux&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to automate deployment of manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to migrate there if there is any in an old app&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figue out how to automate updation of images in manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get another app (Miniflux) deployed&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Figure out what needs to happen as part of the lifecycle. What you want in the cluster, what stays out, do they intersect, how do updates of cluster happen? VM (node) updates as well?&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Then begin to think along the lines of Live Deploys. Prototype locally and once it works, migrate to production immediately&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert Kubernetes manifests to Helm Charts (optional, based on energy)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Go live! Git is source of truth. Two repos.
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; One for the Main node and its update
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Terraform will provision node and install package, setup firewall&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to get Terraform to get the node talking to the git forge&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Structure repo, copy every thing node related there, and make sure stuff gets updated periodically and idempotantly, via ansible pull and a systemd timer&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; The other one for k3s and flux
&lt;ul&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert everything I have done locally to run on prod. Add more steps as you do them below&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h3 class="relative group"&gt;2025-12-08 09:00
 &lt;div id="2025-12-08-0900" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-08-0900" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Client call&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-08 10:30
 &lt;div id="2025-12-08-1030" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-08-1030" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Beginning work&lt;/li&gt;
&lt;li&gt;Installed the 1Password CLI tool and figured out how to read stuff into an environment variable. Will see how to integrate this with scripts over time. I am getting tired of copy pasting stuff. Plus a few critical secrets are on text files on the disk. The disk is encrypted, so I’m not that worried; but still.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-08 11:10:&lt;/em&gt; Found &lt;a href="https://yaml-multiline.info/" target="_blank" rel="noreferrer"&gt;https://yaml-multiline.info/&lt;/a&gt;. Pretty handy!&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-08 12:16:&lt;/em&gt; Lunch Break. Got into a flow state after a long time&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-08 13:30
 &lt;div id="2025-12-08-1330" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-08-1330" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back&lt;/li&gt;
&lt;li&gt;Currently working on setting up and getting ansible-pull installed and working.&lt;/li&gt;
&lt;li&gt;Ansible lint wasn’t working. Got it to work. Ansible and Ansible Lint&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-12-08 16:15:&lt;/em&gt; Tea Break&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-12-08 17:15
 &lt;div id="2025-12-08-1715" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-12-08-1715" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back.&lt;/li&gt;
&lt;li&gt;Thought I had it all setup, and the VM gets deployed, but I cannot seem to login&lt;/li&gt;
&lt;li&gt;Simplifying my cloud-init and doing things one by one&lt;/li&gt;
&lt;li&gt;TIL, even if I botch my cloud-init config, keys are inserted into the root login, so I can do a root login and diagnose. This helps!&lt;/li&gt;
&lt;li&gt;Stuff was getting stuck, because point 1. an operation had to be deferred to the end. Checking the second thing now&lt;/li&gt;
&lt;li&gt;Figured it out. It was some multiline data, that is sticking in cloud-init’s craw. Now to base64 encode it and pass it.&lt;/li&gt;
&lt;li&gt;Done! At least the Terraform bit :) The cluster’s up.&lt;/li&gt;
&lt;li&gt;Most of the plumbing for Ansible updates is done as well. I can talk to my Git forge from the VM. Next step is to get VM updates working tomorrow.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: 2025-12-08 Notes
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;
&lt;/p&gt;</description></item></channel></rss>