Skip to content

Using the STACKIT Edge Cloud Discovery Service

Last updated on

STACKIT Edge Cloud (STEC) is powered by Talos Linux. In a Talos cluster, nodes must discover each other so they can communicate and form a healthy Kubernetes cluster. Talos nodes register their network information with the discovery service, allowing all nodes in your cluster to find one another without manual network mapping.

STACKIT provides an alternative to the default Talos discovery service. This service is compatible with Talos and is hosted on STACKIT infrastructure.

  1. Encryption on the node: Before sending data to the discovery service, Talos encrypts it locally:
    • Node (affiliate) data is encrypted using AES-GCM.
    • Endpoints are encrypted using AES in ECB mode, allowing the discovery service to remove duplicate endpoints from different sources without decrypting them.
  2. Aggregation and distribution: Each node sends its encrypted data along with the endpoints it discovers from peers to the discovery service. The service aggregates the data, removes duplicate endpoints, and sends updates to all connected peers in the cluster.
  3. Peer discovery and KubeSpan: Each node receives updates from the discovery service, decrypts the affiliate data locally, and uses it for cluster discovery and KubeSpan.
  • In-memory storage: Data is kept in memory with a Time-to-Live (TTL) set by the Talos client, and is periodically saved as snapshots to disk.
  • Cluster isolation: The Cluster ID is used as a lookup key so that different clusters only see their own affiliates.
  • End-to-end encryption: STACKIT cannot decrypt the information sent by the nodes.

In summary, the discovery service only knows:

  • Client version
  • Cluster ID
  • Number of affiliates
  • Encrypted data for each affiliate
  • A list of encrypted endpoints

Configuring the Discovery Service in Talos

Section titled “Configuring the Discovery Service in Talos”

If you are customizing your Talos machine configuration (for example, using a config patch during cluster creation), specify the STACKIT Discovery API endpoint based on your Talos version.

In Talos 1.14 and later, discovery service configuration uses standalone DiscoveryServiceConfig documents (see the Talos DiscoveryServiceConfig documentation.

Because the legacy .cluster.discovery block conflicts with DiscoveryServiceConfig, delete the .cluster.discovery block and define the DiscoveryServiceConfig document:

cluster:
discovery:
$patch: delete
---
apiVersion: v1alpha1
kind: DiscoveryServiceConfig
name: stackit-discovery
endpoint: https://api.discovery.edge.eu01.stackit.cloud

You can view your cluster’s discovered nodes in your browser using the STACKIT Discovery Service web interface.

Prerequisites:

Steps:

  1. Set your TALOSCONFIG environment variable:

    Terminal window
    export TALOSCONFIG=your-edge-cluster.talosconfig.yaml
  2. Retrieve your cluster ID using talosctl:

    Terminal window
    talosctl --nodes <NODE_IP> get info

    Replace <NODE_IP> with the IP address of one of your cluster nodes, and copy the CLUSTER ID value from the output.

  3. Open the Discovery Service Web UI:

    https://discovery.edge.eu01.stackit.cloud
  4. Search for your cluster using your Cluster ID.

  5. Inspect the cluster information known to the discovery service, including:

    • Client version
    • Cluster ID
    • Number of affiliates
    • Encrypted data for each affiliate
    • List of encrypted endpoints

You can check whether your nodes have successfully discovered each other using talosctl.

Prerequisites:

Steps:

  1. Set your TALOSCONFIG environment variable:

    Terminal window
    export TALOSCONFIG=your-edge-cluster.talosconfig.yaml
  2. Query discovered members from a node:

    Terminal window
    talosctl --nodes <NODE_IP> get members
  3. View detailed discovery status:

    Terminal window
    talosctl --nodes <NODE_IP> get discoverymembers
  • Learn how to interact with your cluster using talosctl.
  • Connect to your Kubernetes cluster using kubectl.