Bootstrap CLI for Maidn
Find a file
2026-07-31 19:34:03 +02:00
.vscode feat: add bootstrap workflow 2026-07-15 20:39:39 +02:00
cmd feat: create Forgejo registry token 2026-07-29 20:48:56 +02:00
docs feat: make bootstrap self-contained 2026-07-26 20:39:07 +02:00
internal fix: propagate delivery template updates 2026-07-31 19:32:45 +02:00
MaidnCLI@cc8fab6832 feat: add bootstrap workflow 2026-07-15 20:39:39 +02:00
.gitignore feat: make bootstrap self-contained 2026-07-26 20:39:07 +02:00
go.mod feat: restructure & secret setup 2025-10-26 00:43:31 +02:00
go.sum feat: restructure & secret setup 2025-10-26 00:43:31 +02:00
How2Auth.md feat: add bootstrap workflow 2026-07-15 20:39:39 +02:00
main.go feat: restructure & secret setup 2025-10-26 00:43:31 +02:00
README.md feat: make bootstrap self-contained 2026-07-26 20:39:07 +02:00

Commands

go mod init github.com/Pingu-Studio/MaidnCLI go get -u github.com/spf13/cobra@latest go get golang.org/x/term go mod tidy go get gopkg.in/yaml.v3

in powershell run

go install github.com/go-delve/delve/cmd/dlv@latest
dlv version

Commands

  • cicd-tool repo init --org <org> --flux-repo <repo> creates the manifests and Flux repos
  • cicd-tool bootstrap runs a shorter Forgejo-first wizard, asks for a Forgejo PAT, asks where local repos should be cloned, discovers Proxmox nodes/storage/networks, retries without losing entered answers when discovery fails, shows the latest Talos version, derives the standardized Talos factory URL, schematic, and required extensions automatically from the chosen version, writes terraform.tfvars, stages Talos images on Proxmox, and can execute Terraform, Talos bootstrap, and Flux bootstrap
  • cicd-tool bootstrap --config maidn-bootstrap.yaml skips the wizard and uses the saved config

Forgejo setup

For https://git.pingu.pw you need:

  • a user token with repo create/push rights
  • an owner target (Maidn org by default, or your own user/org)
  • git/ssh access from the machine running the CLI if you want SSH later
  • Flux bootstrap credentials for the repo URL that gets created

Cilium traffic network

Every Talos node needs a second static network for Cilium L2 announcements. It has no gateway; the primary network remains the default route. Configure the matching VLAN and a unique MAC address for each node:

cilium:
  trafficInterface: eth1
  loadBalancerStart: <first-reserved-address>
  loadBalancerEnd: <last-reserved-address>
talos:
  nodes:
    - networks:
        - # Primary management network
        - macAddress: <unique-mac>
          cidr: <traffic-subnet>
          ip: <node-traffic-address>
          vlanId: <opnsense-traffic-vlan>

https://192.168.0.15:8006 root@pam!maidn-test-key 2ce7bff1-ac98-4a45-8db4-186d49ae4159

test-org-test-key:147878348db3b8ab660b1af2799c3842705a31bc maidn-dev-work:fca448f2677362cc165eebb7859ce8f9f5e3735c

https://192.168.0.13:8006 root@pam!maidn-test-key 3773033f-552b-4572-83e9-cd16e8ac2e13