Skip to content

test(tmachine): add K3s PostgreSQL and mTLS conformance installer - #4081

Draft
matthewgrossman wants to merge 3 commits into
mainfrom
3529-tmachine-k3s-postgres-mtls/mg
Draft

matthewgrossman wants to merge 3 commits into
mainfrom
3529-tmachine-k3s-postgres-mtls/mg

Conversation

@matthewgrossman

@matthewgrossman matthewgrossman commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Summary

Add a k3s-ha-tls tmachine installer: three K3s gateway replicas sharing PostgreSQL, chart-generated TLS, and a guest CLI registered with mTLS. It runs the existing conformance archive and provides the deployment prerequisite for migrating #3825's HA scenarios.

Related Issue

Refs #3529 (deployment prerequisite only).

Changes

  • Import the existing K3s installer, deploy the pinned PostgreSQL fixture, and apply the three-replica TLS Helm overlay.
  • Provision the client certificate bundle and replace the baseline CLI registration with HTTPS during installation. The TLS listener requires a client certificate; the fixture uses allowUnauthenticatedUsers for its application-level development user.
  • Reach the gateway through the Service ClusterIP introduced in test(tmachine): use K3s ClusterIP, wait for gateway, add failure diagnostics #4258. The chart's server certificate covers openshell.openshell.svc.cluster.local but not the ClusterIP, so the installer maps that name to the ClusterIP in the guest's /etc/hosts and registers https://openshell.openshell.svc.cluster.local:<port>.
  • Collect K3s diagnostics from every gateway Pod by label instead of only openshell-0, so the Deployment-based HA install is covered.
  • Add k3s-ha-tls to the core conformance matrix in Branch E2E, Release Dev, Release Tag, and the Integration Tests defaults, and note the lane in CI.md.
nix run .#tmachine -- test ubuntu-k3s k3s-ha-tls conformance

Testing

  • mise run pre-commit.
  • Ansible syntax check, Nix configuration parsing, and Helm rendering.
  • Local cold-boot conformance passed 3/3 on arm64 with 61d42102c images.
  • Branch E2E passed at 387026536, including the new k3s-ha-tls conformance lane alongside baseline k3s.

Checklist

  • Conventional Commit and DCO sign-off.
  • Latest revision passes live conformance. PR remains draft.

@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Drop the port-forward restart removed by the ClusterIP change, resolve the Service DNS name covered by the server certificate to the ClusterIP, bound each authenticated API wait attempt, and collect diagnostics from every gateway Pod.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
@matthewgrossman
matthewgrossman force-pushed the 3529-tmachine-k3s-postgres-mtls/mg branch from b6bd150 to e772f89 Compare October 9, 2026 20:34
Add the k3s-ha-tls installer to every core conformance matrix so Branch E2E, Release Dev, Release Tag, and manual Integration Tests cover three gateway replicas sharing PostgreSQL behind mTLS.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant