{"repo":"digitalis-io/k3s-on-prem-production","free":true,"listed":false,"github":"https://github.com/digitalis-io/k3s-on-prem-production","clone":"git clone https://github.com/digitalis-io/k3s-on-prem-production.git","description":"Playbooks needed to set up an on-premises K3s cluster and securize it","language":"YAML","stars":161,"topics":["kubernetes","kubernetes-cluster","kubernetes-deployment","k3s","k3s-cluster","security","onprem","onpremise","onpremises","ansible"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"K3s Lightweight Kubernetes — Production-Ready On-Premises Built and maintained by Digitalis.IO This repository contains an Ansible playbook that provisions a hardened, production-grade k3s Kubernetes cluster on bare metal or virtual machines. It targets RHEL 9, Rocky Linux 9, and CentOS Stream 9, and implements security controls aligned with CIS Benchmarks and STIG guidelines. Read the accompanying blog series: K3s Lightweight Kubernetes Made Ready for Production --- Table of Contents - Architecture Overview - What's Included - Requirements - Quick Start - Inventory Structure - Secrets Management - Roles - Hardening - K3s Dependencies - K3s Deploy - Variables Reference - Dual-Network Layout - Terraform (Exoscale) - Known Limitations - Professional Support --- Architecture Overview The default topology is a 3-master HA control plane with 3 worker nodes. kube-vip provides both the control-plane VIP and LoadBalancer IP address management, replacing the need for separate MetalLB and Keepalived installations. --- What's Included Component Version Notes --- --- --- k3s v1.32.2+k3s1 Multi-arch binary (amd64 / arm64) kube-vip v1.1.2 Control-plane HA VIP + LoadBalancer IPs kube-vip cloud provider v0.0.12 Allocates IPs to LoadBalancer services Traefik Built into k3s Ingress controller (no separate deployment needed) Portainer v2.39.2 Deployed via HelmChart CRD Kubernetes Dashboard v2.7.6 Service account token compatible with Kubernetes 1.24+ Falco Latest Runtime security Falcosidekick ","default_branch":null,"files":null,"tree":[],"storefront":"/r/digitalis-io","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/digitalis-io/k3s-on-prem-production/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}