Skip to content

test(tmachine): add K3s PostgreSQL and mTLS conformance installer - #4081

Draft
matthewgrossman wants to merge 6 commits into
mainfrom
3529-tmachine-k3s-postgres-mtls/mg
Draft

matthewgrossman wants to merge 6 commits into
mainfrom
3529-tmachine-k3s-postgres-mtls/mg

Conversation

@matthewgrossman

@matthewgrossman matthewgrossman commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Add a k3s-ha-tls tmachine installer: three K3s gateway replicas sharing PostgreSQL, chart-generated TLS, and a guest CLI registered with mTLS. It runs the existing conformance archive and provides the deployment prerequisite for migrating #3825's HA scenarios.

Related Issue

Refs #3529 (deployment prerequisite only).

Changes

  • Import the existing K3s installer, deploy the pinned PostgreSQL fixture, and apply the three-replica TLS Helm overlay.
  • Provision the client certificate bundle and replace the baseline CLI registration with HTTPS during installation. The TLS listener requires a client certificate; the fixture uses allowUnauthenticatedUsers for its application-level development user.
nix run .#tmachine -- test ubuntu-k3s k3s-ha-tls conformance

Testing

  • mise run pre-commit.
  • Ansible syntax check, Nix configuration parsing, and Helm rendering.
  • CI PostgreSQL/mTLS conformance passed at b6bd1508f, using the existing tmachine install/reboot/test lifecycle.
  • Branch E2E passed, including ordinary K3s conformance.

Checklist

  • Conventional Commit and DCO sign-off.
  • Latest revision passes live conformance. PR remains draft.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant