Hi everyone,
Sharing my plan (already half implemented lol) to hear thoughts and suggestions before I complete it.
I doing it for the challenge and as part of preparing for CKS.
Hardware:
– Protecteli built running opnsense & Caddy
– Rpi 5 running stepca TinyCA
– Turinpi2 cluster (3x RK1 nodes) running talos
My end goal is:
– Using TinyCA for TLS and PKI
– Okta-like experience using Kanidm as IDM with Oauth2-proxy for OIDC/forward auth.
– mTLS (istio ambiant in the cluster, client certificates all over)
– Cillium eBPF capabilities (CNI + np)
– internal DNS using Adguard home dns rewrites
Client -> Caddy -> Kanidm App Portal -> Services
My current status that broke the whole thing was adding Istio Gateway, not sure why. Client certs and validation and currently skipped.
Should I do something’s different? Get dedicated hardware for Caddy + Kanidm? Or pick another reverse proxy instead? I hope to use the os-acme-client plugin to have opnsense ui also accessible via Kanidm, and manage Adguard rewrites using externaldns. I stick to gitops and also use kaniopto manage kanidm, is there a similar way to manage opnsense itself?
TIA
Source: r/homelab · by /u/zMynxx