EC2 Node Topology — AWS us-west-2
AWS Network Topology & Traffic Flows
K8s ingress / service routing
Kubernetes Cluster Architecture — RKE2
GitOps & Automation Data Flow
Authentication & Identity Flow
Service Map & Deployment Boundaries
Identity Layer — ipa01 (EC2 private)
FreeIPA 4.12.2
ipa01.lab.internal
DNS (lab.internal zone)
:53
Internal CA / cert-manager
:443
HBAC · sudo rules · OTP
IPA UI
ns: awx — Automation
AWX Web (operator 3.2.1)
ClusterIP
GitLab CE 18.10.1 (native)
:8929 / :2222
GitLab Gitaly
repos on disk
Mirror → GitHub
jslocomb/homelab-k8s
ns: monitoring — Observability
Prometheus (kube-prom-stack)
:9090
node-exporter DaemonSet
:9100 all nodes
ServiceMonitor CRDs
all ns
SIEM — k8s-w02 (native)
Splunk Enterprise 10.2.1
:8000 web
UF Receiver
:9997 all nodes
idx: os_logs · k8s_audit
90d ret.
idx: secure · aide_alerts
90d ret.
ns: netbox — CMDB
NetBox v4.5.5
Helm ns:netbox
NetBox PostgreSQL
PVC 10GB
LDAP: django-auth-ldap
FreeIPA
AWX dynamic inventory src
custom py script
Security — Runtime & Integrity
Falco 0.43.0 DaemonSet
legacy eBPF
AIDE baselines
all 5 nodes
AIDE cron check
02:00 UTC daily
auditd → Splunk UF
all nodes
K8s audit log → Splunk UF
cp01
Cluster Infrastructure Services
ingress-nginx
RKE2 reuseport :443
cert-manager
FreeIPA CA issuer
AWS SGs replace firewall
no MetalLB needed
IaC & GitOps
Terraform
AWS VPC / EC2 / SGs
Ansible
OS hardening / config
Helm
AWX · NetBox · kube-prom
GitHub mirror
jslocomb/homelab-k8s
GovCloud transferable
IL2/IL4 compatible
Port Reference — AWS Security Group Rules
RKE2 / K8s Control Plane
6443TCPK8s API server (TLS)
9345TCPRKE2 supervisor API
2379TCPetcd client
2380TCPetcd peer
10250TCPkubelet API
8472UDPVXLAN (Canal/Flannel)
FreeIPA / Identity (ipa01)
53TCP/UDPDNS (lab.internal)
88TCP/UDPKerberos KDC
389TCPLDAP (StartTLS)
636TCPLDAPS (SSL)
443TCPIPA Web UI / CA
464TCP/UDPKerberos kpasswd
Native Services (non-K8s)
8929TCPGitLab CE web (k8s-w01)
2222TCPGitLab CE SSH (k8s-w01)
8000TCPSplunk web UI (k8s-w02)
8088TCPSplunk HEC ingest
8089TCPSplunk mgmt API
9997TCPSplunk UF receiver
Monitoring / Telemetry
9090TCPPrometheus
9093TCPAlertmanager
3000TCPGrafana (ClusterIP)
9100TCPnode-exporter /metrics
AWS Security Group Rules
22TCPSSH bastion → all (key-only)
ALLALLSG-private internal traffic
OUTBOUNDALLVia NAT Gateway (private)
443TCPIngress-nginx (K8s NodePort)
Security / Integrity
––Falco: eBPF syscall (in-kernel)
––AIDE: file integrity cron 02:00
––auditd → Splunk UF :9997
––K8s audit log → UF (cp01)