# maidn-talos-proxmox Standalone Talos-on-Proxmox IaC for Maidn. ## Layout - `terraform/` provisions Proxmox networking and VMs and generates `generated/talconfig.yaml` - `generated/` holds local generated Talos artifacts and should stay uncommitted ## Usage 1. Copy `terraform/terraform.examples.tfvars` to `terraform/terraform.tfvars` 2. Set Proxmox, cluster, and node values 3. Run: ```bash cd terraform terraform init terraform apply ``` 4. Generate secrets/config outside Terraform: ```bash cd ../generated talhelper gensecret > talsecret.sops.yaml sops -e -i talsecret.sops.yaml talhelper genconfig ``` 5. Bootstrap Talos and Flux: ```bash talosctl bootstrap --talosconfig=./clusterconfig/talosconfig --nodes= talosctl kubeconfig --talosconfig=./clusterconfig/talosconfig --nodes= . flux bootstrap git --url= --branch=main --path=./clusters/ ``` ## Image updates Keep Talos version and factory schematic in config. A repo automation job can resolve the matching installer/raw/iso artifacts and open a PR updating pins. If `talos_image_update_mode = "download"`, Terraform also stages the required Talos ISO onto every Proxmox node used by the cluster before VM creation. ## Maintenance See `docs/maintenance.md` for upgrades, certificate rotation, health checks, and backup basics.