Cluster Infra
Cluster Infra
Per-service reference for the in-cluster systems R2-D2 itself runs on.
R2-D2 runs in an RKE2 cluster alongside other unrelated tenants. This section only covers systems R2-D2 itself depends on at runtime — not every chart in the cluster. If a system isn't reached by the dashboard, embedded by The Force, or backing a dashboard PVC / LB / ingress, it doesn't belong here.
Service map
flowchart TB
subgraph Dashboard["r2d2-fleet (Next.js)"]
Routes["/api/* route handlers"]
end
subgraph Data["R2-D2 data plane"]
TB[TrailBase]
RD[ReductStore]
end
subgraph Media["R2-D2 media plane"]
RS[Restreamer datarhei/core]
end
subgraph Telemetry["R2-D2 telemetry plane"]
TBMQ[TBMQ MQTT]
end
subgraph Storage["Cluster shared (R2-D2 consumes)"]
LH[Longhorn]
KV[kube-vip]
NB[Netbird overlay]
IG[nginx-ingress + Caddy + Traefik]
end
subgraph Auth["Auth"]
KC[Keycloak]
end
Routes --> TB
Routes --> RD
Routes --> RS
Routes --> KC
Routes -.-> NB
TBMQ -.->|topics| Routes
TB -.->|PVCs| LH
RD -.->|PVCs| LH
RS -.->|ingress| IG
Routes -.->|cluster DNS| IG
IG -.->|LB IPs| KVPages
| Page | What it covers |
|---|---|
| TrailBase | Application data store — schema, TS SDK, session cookies |
| ReductStore | Snapshot history + audit blob store |
| Restreamer | datarhei/core — the FFmpeg process supervisor |
| TBMQ | MQTT broker for Temple Archives feed-sync + HoloNet |
| Keycloak | R2-D2 theme, realm hardening, OIDC client |
| Longhorn | Block storage for R2-D2's PVCs — csi-attacher recovery |
| kube-vip | LoadBalancer VIP allocation + lease tuning |
| Ingress | nginx-ingress + Caddy + Traefik routing model |
| Netbird | Overlay VPN — daemon socket + dashboard probes |
What's intentionally not here
Systems that share the cluster with R2-D2 but aren't part of R2-D2 — Matrix's YugabyteDB cluster, the legacy CNPG generic-postgres, Harbor, Cilium, n8n, geoserver, peertube, the office tooling, the AI services, etc. They are operated by the same team but are independent tenants. Their docs live with their charts, not here.
Conventions used across these pages
- Each page links to its chart directory in the parent repo (e.g.
../trailbase/,../longhorn/,../kube-vip/) so the operator can find values files and overrides quickly. - Each page captures crystallized recipes for failure modes that have hit R2-D2 specifically. New recipes belong here once they've been validated.
- VIP / IP / port conventions live on the relevant page (e.g.
.200reservation rules on kube-vip; the Caddy → nginx convention on ingress).