k3s Single-Node - Issues
Lessons Learned
| Category | Lesson |
|---|---|
cloud-init |
|
SELinux |
k3s requires container-selinux package. Don’t disable SELinux - fix contexts instead. |
Cilium |
Must disable Flannel in k3s install ( |
Vault Agent |
Service account must have |
firewalld |
Rich rules needed for pod CIDR → host communication. |
Post-Deployment Status
| Item | Status |
|---|---|
k3s Cluster |
Operational, single-node |
DNS Records |
k3s-master-01 A record in BIND |
Monitoring |
Wazuh agent deployed |
Documentation |
2340-line runbook in domus-infra-ops |