3.3 KiB
Networking
The Nest's networking stack handles external ingress (from the internet), internal routing (between services), and load balancing for services that require public IP addresses.
External Ingress: HAProxy on pfSense
All traffic from the internet enters through an HAProxy instance running on the pfSense router. HAProxy performs:
- TLS termination — Handles SSL certificates for all
*.mynest.lovedomains - Hostname-based routing — Forwards requests to the appropriate internal service based on the
Hostheader - Health checks — Monitors backend availability and fails over if a node is down
HAProxy routes traffic to MetalLB-assigned IPs within the cluster, which then forward to Traefik ingress controllers.
Internal Ingress: Traefik
Traefik is the Kubernetes-native ingress controller. It receives traffic from HAProxy and routes it to the correct service based on:
- Host headers (e.g.,
beak.mynest.love→ Jellyfin) - Path prefixes (e.g.,
/_matrix/...→ Synapse,/sfu/get→ LiveKit JWT service) - Middleware annotations for headers, redirects, and TLS enforcement
Traefik is configured via Kubernetes CRDs (Ingress, Middleware) defined in YAML files under services/*/.
Load Balancing: MetalLB
MetalLB provides Layer 2 load balancing for services that need a public IP (e.g., Matrix LiveKit's UDP ports, Forgejo SSH).
Configuration
- IP Pool:
192.168.1.150–192.168.1.200(defined inmetallb/metallb.yaml) - Advertisement Protocol: L2 (ARP) — suitable for home networks without BGP support
Services Using MetalLB
| Service | IP Assignment | Purpose |
|---|---|---|
| LiveKit (Matrix RTC) | 192.168.1.160 |
WebRTC media relay (UDP/TCP) |
| Forgejo SSH | Load-balanced | Git over SSH (port 22) |
DNS & Hostname Resolution
- External: The
*.mynest.lovedomain points to the pfSense router's public IP. HAProxy handles virtual hosting. - Internal: Services resolve via Kubernetes DNS (
<service>.<namespace>.svc.cluster.local). External hostnames (e.g.,robin.home.nest) are resolved via the home network's DNS server.
TLS & Certificates
All external-facing services use TLS certificates issued by Let's Encrypt via cert-manager:
- Cluster Issuer:
letsencrypt-prod(defined incert-manager/letsencrypt-cluster-issuer.yaml) - Challenge Type: HTTP-01 (validated through Traefik)
- Auto-renewal: Handled automatically by cert-manager 30 days before expiry
Internal-only services (e.g., *.k3s.home.nest) may use self-signed certificates or no TLS, depending on the service configuration.
Network Policies
The cluster does not enforce strict network policies between namespaces by default. Services communicate freely within the cluster via Kubernetes DNS and ClusterIP services. For enhanced security, consider implementing Kubernetes NetworkPolicies in future iterations.
Related Documentation
- MetalLB — Detailed MetalLB configuration
- Security & Identity — TLS termination and authentication flow
- Architecture Overview — High-level data flow