Skip to content

Prerequisites for Bare-Metal K3s Homelab

Before provisioning the bare-metal K3s cluster, set up your local operator workstation and verify target node access.

Ensure your local workstation has the necessary automation and Kubernetes management tools installed:

Terminal window
brew install ansible kubectl helm pre-commit
Terminal window
sudo apt-get update && sudo apt-get install -y curl git ansible kubectl helm pre-commit

Alternatively, run the repo’s containerized workstation environment:

Terminal window
./scripts/dev-container.sh up
./scripts/dev-container.sh shell

Ansible manages bare-metal nodes over SSH. Generate an SSH key pair if you do not already have one:

Terminal window
ssh-keygen -t ed25519 -C "homelab-admin"

Copy your public key to the target node legion (100.66.139.118 or your LAN IP):

Terminal window
ssh-copy-id sudhanva@100.66.139.118

Verify passwordless sudo on the target host by adding the user to sudoers:

Terminal window
sudo usermod -aG sudo sudhanva
echo "sudhanva ALL=(ALL) NOPASSWD:ALL" | sudo tee /etc/sudoers.d/sudhanva

Have the following credentials ready for platform integration:

  • Tailscale: An OAuth client secret with permissions to manage Tailscale devices and Kubernetes operator resources.
  • Cloudflare: An API token with Zone.DNS edit permissions for your managed domain (sudhanva.me).
  • GitHub: A personal access token for Git authentication and ArgoCD Image Updater write-back.

Once your workstation tools and target host SSH access are verified, proceed to: