Skip Navigation
simonmicro simonmicro @programming.dev
Posts 1
Comments 24
Multiple Kubernetes Services Using Same Port Without SNI
  • Ah yes, I see. Because TCP has no SNI built-in this is not really possible.

    You could try IPv6, as within even a single /64 routable prefix you can choose the address section freely. Also take a look at overlay-vpn solutions like Netbird: They allow you to offer you multiple clients, which you could use to assign multiple IPv4 to your server and then routing them differently (you mentioned installing client software before)...

    Finally, I'm not sure why you would inject Treafik into the networking chain. In the end is the direct, kernel-space connection always faster than having an user-space proxy in between.

  • Multiple Kubernetes Services Using Same Port Without SNI
  • Okay, I'll try explaining it. Yes, there is especially for this very little documentation, so... Yeah.

    You start by installing kube-vip into your cluster. Make sure to configure it correctly, so the uplink interface of your workers is being used for the vip, but not e.g. internal ones (see the env vars "vip_interface"). Make sure to enable service based functions and the respective election mechanism ("svc_enable", "vip_leaderelection"). I would also recommend the ARP usage, because others I've never tested.

    Then you create a new "LoadBalancer"-service in k8s, on which you also set the "loadBalancerIP" field with the desired IPv4-VIP. Due to the previous kube-vip configuration, it should pick that up. You may take a look into its operators logs to learn more.

    Theoretically that's it. Now one of your nodes will start serving the service-port under the vip. The service may target every TCP/UDP traffic, not only Traefik.

    There is one more thing: The field "externalTrafficPolicy" on the LB-service allows you to disable any kind of internal routing via your CNI if set to "local", so you will even be able to see the real source IPv4 of your clients. Be careful with this on non kube-vip services, as nodes without the targeted pods will not be able to serve the traffic. Kube-vip only promotes nodes to serve the vip, if it also serves the pod targeted by it (see its docs/config).

  • Multiple Kubernetes Services Using Same Port Without SNI
  • Sure! Kube-vip is your go. Just use shared virtual ipv4 adresses.

  • De-googling and privacy on Sony xperia
  • Google for Sony Open Devices. AOSP, but running on Sony devices. While I prefer LOS, SODP is always the beginning to port it from.

  • Is ansible worth learning to automate setting up servers?
  • Sorry, but I fear not. Ansible has a good getting started out there, but I think you'll learn the most just using it.

    Maybe a broad roadmap... Try to add systems. Test them via Ansible-Ping. Change some configs (add file, add line-in-file). Add handlers to react to changes by restarting services. Add host variables and customize behavior per host. Add templates...

  • Is ansible worth learning to automate setting up servers?
  • I think it is a great way to document what you have done too. Especially with larger setups this can be quite time-intensive.

    Then add that you may want to dynamically reconfigure your systems to interact with each other and then Ansibles template-rendering comes in really handy.

    Finally, it is standardized - so other peopke can work with it too (relevant in work context).

  • 54,000 = 0
  • Javasrcript. 0 == null == NaN.

  • Why does my machine sometimes instantly come on from sleep?
  • Run "sudo dmesg -w", put it to sleep and then look what the kernel tells you why he could not sleep.

  • am I reading this right, that my cpu just died?
  • Most common issue would be something with your system memory. I could imagine that this caused the timeout of your cpu, which waited for the startup code, which never arrived.

    In case you want to test that, swap your memory sticks around. Or tell the kernel to ignore that cpu (see command line arguments of the kernel).

  • Dad is a meerkat
  • Instant thought: "Ausgefressen - Moritz Matthies". Good stuff.

  • Omega - finishing from the Anomaly Desk
  • Yes, the expidition was certainly fun... But...

    My coop friend started it, which lead to my game crashing instantly. After restarting I was able to play, but to never return to my primary save, as it was bugged - including the terminal.

    I thought that finishing it could help (as the terminal mentioned "Unable to pause, complete expidition first"). Nope. 9hrs later same problem. In the end I had to merge the expidition-savegame with my primary save using the NMS savegame editor. With some help from a known good save I was even able to reconstruct the final terminal state (stating that I finished the expidition).

    What a mess.

  • Just Updated a D&D Website I've been building - would love feedback!
  • For a university project I've scraped a shitload of stuff from dndbeyond.com (primarly the homebrew section) - are you interested in that? I would have to dig if I still have the raw data available (were processed with some ai-model later).

  • Star Trek Resurgence Giveaway
  • Oh yes, I also played a lot of Star Trek Elite Force back then - I think I liked the first title more, likely because I'm more into VOY. I liked solving the riddles on the levels and trying for hours to find the secrets... What a good time!

  • By any chance, does someone know of a private FOSS app to use this kind of bluetooth LED glasses with? (One that is not on the Play Store)
  • The location permission is needed to activate BLE and scan for other devices using low energy. Android things...

  • [REQUEST] Mark As Read On Scroll
  • Indeed. IIRC this feature was also part of the Reddit version. Also the view option to hide read was there...

  • Block Network Access for Game?
  • IIRC it is based on Ubuntu, so yes.

  • Block Network Access for Game?
  • Uh, under Windows use NetLimiter. Under Linux? Try AppArmor based policies, otherwise... No idea.