Using the STACKIT Edge Cloud Discovery Service
Last updated on
Overview
Section titled “Overview”STACKIT Edge Cloud (STEC) is powered by Talos Linux. In a Talos cluster, nodes must discover each other so they can communicate and form a healthy Kubernetes cluster. Talos nodes register their network information with the discovery service, allowing all nodes in your cluster to find one another without manual network mapping.
STACKIT provides an alternative to the default Talos discovery service. This service is compatible with Talos and is hosted on STACKIT infrastructure.
Endpoints
Section titled “Endpoints”| Service | URL | Purpose |
|---|---|---|
| Web UI | https://discovery.edge.eu01.stackit.cloud | Inspect discovered nodes and cluster members in a browser. |
| API | https://api.discovery.edge.eu01.stackit.cloud | Publish and query discovery data for Talos nodes. |
How it works
Section titled “How it works”- Encryption on the node: Before sending data to the discovery service, Talos encrypts it locally:
- Node (affiliate) data is encrypted using AES-GCM.
- Endpoints are encrypted using AES in ECB mode, allowing the discovery service to remove duplicate endpoints from different sources without decrypting them.
- Aggregation and distribution: Each node sends its encrypted data along with the endpoints it discovers from peers to the discovery service. The service aggregates the data, removes duplicate endpoints, and sends updates to all connected peers in the cluster.
- Peer discovery and KubeSpan: Each node receives updates from the discovery service, decrypts the affiliate data locally, and uses it for cluster discovery and KubeSpan.
Data storage and privacy
Section titled “Data storage and privacy”- In-memory storage: Data is kept in memory with a Time-to-Live (TTL) set by the Talos client, and is periodically saved as snapshots to disk.
- Cluster isolation: The Cluster ID is used as a lookup key so that different clusters only see their own affiliates.
- End-to-end encryption: STACKIT cannot decrypt the information sent by the nodes.
In summary, the discovery service only knows:
- Client version
- Cluster ID
- Number of affiliates
- Encrypted data for each affiliate
- A list of encrypted endpoints
Configuring the Discovery Service in Talos
Section titled “Configuring the Discovery Service in Talos”If you are customizing your Talos machine configuration (for example, using a config patch during cluster creation), specify the STACKIT Discovery API endpoint based on your Talos version.
In Talos 1.14 and later, discovery service configuration uses standalone DiscoveryServiceConfig documents (see the Talos DiscoveryServiceConfig documentation.
Because the legacy .cluster.discovery block conflicts with DiscoveryServiceConfig, delete the .cluster.discovery block and define the DiscoveryServiceConfig document:
cluster: discovery: $patch: delete---apiVersion: v1alpha1kind: DiscoveryServiceConfigname: stackit-discoveryendpoint: https://api.discovery.edge.eu01.stackit.cloudIn Talos 1.13 and earlier, specify the STACKIT Discovery API endpoint under the cluster.discovery configuration block (see the Talos cluster discovery documentation):
cluster: discovery: enabled: true registries: kubernetes: disabled: true service: disabled: false endpoint: https://api.discovery.edge.eu01.stackit.cloudVerifying discovery with Web UI
Section titled “Verifying discovery with Web UI”You can view your cluster’s discovered nodes in your browser using the STACKIT Discovery Service web interface.
Prerequisites:
- You have talosctl installed.
- You have downloaded your talosconfig.
Steps:
-
Set your
TALOSCONFIGenvironment variable:Terminal window export TALOSCONFIG=your-edge-cluster.talosconfig.yaml -
Retrieve your cluster ID using
talosctl:Terminal window talosctl --nodes <NODE_IP> get infoReplace
<NODE_IP>with the IP address of one of your cluster nodes, and copy theCLUSTER IDvalue from the output. -
Open the Discovery Service Web UI:
https://discovery.edge.eu01.stackit.cloud -
Search for your cluster using your Cluster ID.
-
Inspect the cluster information known to the discovery service, including:
- Client version
- Cluster ID
- Number of affiliates
- Encrypted data for each affiliate
- List of encrypted endpoints
Verifying discovery with talosctl
Section titled “Verifying discovery with talosctl”You can check whether your nodes have successfully discovered each other using talosctl.
Prerequisites:
- You have talosctl installed.
- You have downloaded your talosconfig.
Steps:
-
Set your
TALOSCONFIGenvironment variable:Terminal window export TALOSCONFIG=your-edge-cluster.talosconfig.yaml -
Query discovered members from a node:
Terminal window talosctl --nodes <NODE_IP> get members -
View detailed discovery status:
Terminal window talosctl --nodes <NODE_IP> get discoverymembers