xk3s Access

Enter your master passphrase to unlock the operational console and real-time telemetry.

🔑
Incorrect passphrase. Please try again.
Passphrase verified. Decrypting console...
Master Node Phrase: x1x2x3x4x5
CLASSIFIED // EYES ONLY SUPER ADMIN ACTIVE • ZERO-TRUST TOPOLOGY & TAILSCALE INTEL UNLOCKED
x1 (MASTER): xx.xx.xx.139 [TS: xx.xx.xx.43 • WG: 10.10.0.2]
x2 (WORKER): xx.xx.xx.146 [TS: xx.xx.xx.80 • WG: 10.10.0.3]
CLOUD INGRESS: xx.xx.xx.95 [VPC: xx.xx.xx.180 • WG: 10.10.0.1]
xk3s CLUSTER xk3s // OT CYBER • PROJECT X ENCLAVE PURDUE LEVEL 1-4 ZERO-TRUST MESH • OPERATOR: X
DEFCON STATUS: NOMINAL (DEFCON 5) ZULU CLOCK: 00:00:00Z

xk3s // OT CYBER • PROJECT X

[ INDUSTRIAL C2 MISSION CONTROL ]
OPERATOR: X PLATFORM: xk3s C2 CLUSTER: X-K3S HYBRID MESH INGRESS: xx.xx.xx.95
K3S NODES 4 / 4 ONLINE
FLEET DEVICES 7 ENROLLED
C2 RUNTIMES 18 ACTIVE
ZERO TRUST MESH WIREGUARD ARMED
ARCHITECTURE MANUAL ONLINE DOCS ↗
C2 OPERATOR CHANNEL MATTERMOST ↗
UNS DATA MESH ● ACTIVE [47 NODES] ↗
x1 (CORE-MASTER-01) CONTROL PLANE • STATEFUL
ONLINE
CPU COMPUTE (Cortex-A76 4C @ 2.4GHz) Load: 1.31
MEMORY (10.3 / 16.2 GB) 63.6%
STORAGE (51 / 939 GB NVMe CSI POOL) 6% USED • NOMINAL
LAN: xx.xx.xx.139 • TAILSCALE: xx.xx.xx.43 • WG: 10.10.0.2ROLE: K3S MASTER • STATEFUL VAULT
x2 (EDGE-GATEWAY-02) K3S WORKER • STATELESS
ONLINE
CPU COMPUTE (Cortex-A76 4C @ 1.8GHz) Load: 0.27
MEMORY (1.3 / 8.1 GB) 16.2%
STORAGE (16 / 29 GB FLASH EMMC) 59% USED
LAN: xx.xx.xx.146 • TAILSCALE: xx.xx.xx.80 • WG: 10.10.0.3ROLE: INGRESS ROUTER • HDMI KIOSK
x (COMPUTE-WORKER-03) K3S WORKER • AMD64
ONLINE
CPU COMPUTE (Intel Celeron N4500 2C @ 1.10GHz) Load: 1.60
MEMORY (2.5 / 7.7 GB) 32.5%
STORAGE (14 / 118 GB NVMe PCIe) 12% USED • NOMINAL
TAILSCALE: xx.xx.xx.65 • WG: 10.10.0.5ROLE: SOFT PLC (OpenPLC) • GITEA DEVOPS • HOME ASSISTANT • VPA
mbp-worker (BURST-WORKER-04) K3S WORKER • 32GB DEV
ONLINE
CPU COMPUTE (Intel i9 8C/16T @ 2.4GHz) Load: 8.47
MEMORY (31.9 / 32.0 GB DDR4) 99.6% ALLOCATED
STORAGE (970 GB / 1.1 TB NVMe) 88% USED
LAN: xx.xx.xx.175 • TAILSCALE: xx.xx.xx.17 • WG: 10.10.0.4ROLE: LIMA K3S WORKER • HEAVY DEV
AWS-CLOUD-INGRESS CLOUD GATEWAY • WG HUB
ONLINE
CPU (Intel Xeon 2 vCPU @ 2.5GHz) Load: 0.12
MEMORY (470 / 909 MB) 51.7%
STORAGE (7.5 / 24 GB EBS gp3) 33% USED
EIP: xx.xx.xx.95 • WG HUB: 10.10.0.1 (UDP 51820)ROLE: NGINX REVERSE PROXY • SSL INGRESS
OPERATOR-WORKSTATION PRIMARY OPERATOR HUD
ONLINE
CPU COMPUTE (Apple Silicon M1 8C) Load: 1.38
MEMORY (14.9 / 16.0 GB UNIFIED) 93.1% ACTIVE
STORAGE (277 / 460 GB NVMe) 60% USED
LAN: xx.xx.xx.141 • TAILSCALE: xx.xx.xx.91ROLE: PRIMARY OPERATOR • iMESSAGE RELAY
dphone (MOBILE-ENCLAVE) MOBILE ZERO-TRUST CLIENT
ARMED
DEVICE ENCLAVE APPLE iOS CLIENT
ZERO-TRUST ENCRYPTED MESH TAILSCALE ACTIVE
SECURITY POSTURE 2FA BIOMETRIC HARDENED
TAILSCALE: xx.xx.xx.78 • WIREGUARD COMPLIANTROLE: MOBILE OPERATOR HUD • CHATOPS

xk3s FLEET TOPOLOGY & K3S CLUSTER ARCHITECTURE MANUAL

4 K3S NODES ACTIVE 7 FLEET ENDPOINTS 100% PERSONAL ENCLAVE MULTI-TIER OVERLAY MESH

🗺️ Master Fleet Coordinates & Static Network Directory

ZERO EXTERNAL LEAKAGE • 100% PERSONAL

Static IP addresses and routing priority configured across physical LAN, WireGuard cloud tunnel, and Tailscale peer mesh:

DEVICE NAME HOSTNAME USER LAN IP WIREGUARD TAILSCALE INGRESS / ROLE
MacBook Air das-MacBook-Air.local da 192.168.4.141 100.71.196.91 Primary Workstation (Apple Silicon M1, 16GB RAM)
MacBook Pro Doxs-MacBook-Pro.local dx 192.168.4.175 100.102.41.17 Secondary Workstation (Intel i9, 32GB RAM, Password: jawlan)
x1 (Master) x1 x1 192.168.4.139 10.10.0.2 100.95.125.43 Primary Cluster Master, NVMe Storage, K3s API (6443)
x2 (Worker) x2 x2 192.168.4.146 10.10.0.3 100.71.97.80 K3s Edge Worker, HDMI Kiosk Surface, VNC (5900)
x (Worker) x x 192.168.4.172 10.10.0.5 100.111.136.65 Secondary Compute Worker, Ubuntu AMD64 Offload Target
AWS Hub (EC2) ip-172-31-2-180 ubuntu 10.10.0.1 xx.xx.xx.95 (Nginx Reverse Proxy & SSL Termination)
dphone dphone 100.64.94.78 Operator Mobile iOS Client (Tailscale Mesh)

Dedicated K3s Kubernetes Cluster Architecture

K3S v1.36.4 PRODUCTION • 4 ENROLLED NODES
👑 x1 Cluster Master
CONTROL PLANE
K3s API Endpointhttps://10.10.0.2:6443
Hardware / OSarm64 (4 Cores, 16GB) • Debian 13
Storage Engine500GB NVMe PCIe Gen3 (primary-ssd)
Flannel Pod CIDR10.42.0.0/24
ClusterIP Subnet10.43.0.0/16
Ingress ControllerTraefik Embedded Gateway
Cluster StatusReady • Active Master
⚙️ x2 Edge Worker
EDGE WORKER
Worker Nodex2 (4 Cores, 8GB RAM)
Hardware / OSarm64 • Debian 12 (Bookworm)
Flannel Pod CIDR10.42.1.0/24
HDMI Kiosk SurfaceWayland / Chromium HUD
Remote Screen Sharingwayvnc (Port 5900)
Storage64GB MicroSD High Endurance
Cluster StatusReady • Active Worker
x Compute Worker
AMD64 WORKER
Worker Nodex (2 Cores, 8GB RAM)
Hardware / OSx86_64 AMD64 • Ubuntu 24.04 LTS
Flannel Pod CIDR10.42.3.0/24
Tailscale Meshxx.xx.xx.65 (tailscale0)
WireGuard IP10.10.0.5
Architecture RoleAMD64 4KB Page Offload Target
Cluster StatusStandby • Enrolled Worker
💻 mbp-worker (MacBook Pro)
HEAVY COMPUTE
Worker Nodembp-worker (12 vCPU, 24GB RAM)
Host PlatformIntel Core i9 8C/16T • 32GB RAM
Hardware / OSx86_64 AMD64 • Ubuntu 24.04 LTS
Flannel Pod CIDR10.42.2.0/24
Tailscale Meshxx.xx.xx.17 • WG: 10.10.0.4
Storage BackendNVMe High-Speed Solid State
Cluster StatusStandby • Enrolled Heavy Compute
☁️ AWS EC2 Cloud Gateway
INGRESS HUB
Gateway RoleEdge Ingress & Reverse Proxy Hub
Public Ingress IPxx.xx.xx.95
Reverse ProxyNginx High Performance Hub
WireGuard Hub IP10.10.0.1 (UDP 51820)
TLS CertificatesLet's Encrypt Wildcard (*.xk3s.com)
Cloudflare ProxyZero-Trust Shield Active

🌐 Multi-Tier Encrypted Network Overlay

3-TIER ZERO-TRUST MESH
🔒 Tier 1: WireGuard Cloud Mesh
10.10.0.0/24

Dedicated ChaCha20-Poly1305 kernel-level encrypted tunnel connecting the AWS Ingress gateway directly to on-premise nodes x1 (10.10.0.2) and x2 (10.10.0.3).

🚀 Tier 2: Tailscale Zero-Trust
100.64.0.0/10

Global peer-to-peer mesh linking mobile client (dphone), MacBook Air, MacBook Pro, and edge cluster nodes across any NAT without port forwarding.

Tier 3: High-Speed LAN
192.168.4.0/24

Gigabit on-premise Ethernet and 5GHz Wi-Fi backplane connecting workstations and micro-servers with sub-millisecond round-trip latencies.

📦 Containerized Workloads & Unified Namespace (UNS) Ecosystem

47 INDUSTRIAL RUNTIMES

Unified Namespace (UNS) architecture mapping industrial field protocols to Sparkplug B MQTT topics and enterprise time-series historians:

🏭 Industrial SCADA Stack
Ignition Primary Masterhttps://prod.xk3s.com
Ignition Redundant Backuphttps://backup.xk3s.com
Ignition Dev / Staginghttps://dev.xk3s.com
Ignition Enterprise EAMhttps://eam.xk3s.com
📡 IIoT Telemetry & Broker Fabric
EMQX UNS MQTT Brokerhttps://emqx.xk3s.com
Node-RED Logic Enginehttps://nodered.xk3s.com
RabbitMQ Message Bushttps://rabbitmq.xk3s.com
InfluxDB Time-Series Enginehttps://influx.xk3s.com
🛡️ OT Security & Observability
Suricata OT-IDS Deckhttps://otsec.xk3s.com
Cyber Threat Intelligencehttps://cyber.xk3s.com
Grafana Observability HUDhttps://grafana.xk3s.com

🔑 Remote Access & SSH Matrix

# Workstations Remote Access:
ssh mbp                      # Connect to MacBook Pro (Tailscale: 100.102.41.17)
ssh mbp-lan                  # Connect to MacBook Pro (LAN: 192.168.4.175)
open vnc://[email protected]   # Native macOS Screen Sharing VNC
# Cluster Edge Nodes:
ssh [email protected]         # Cluster Master x1 (Tailscale)
ssh [email protected]          # Edge Worker x2 (Tailscale)
ssh [email protected]          # Compute Worker x (Tailscale)
# AWS Ingress Gateway:
ssh ec2-pub                  # Connect to AWS EC2 ([email protected])

🖥️ Hardware Specifications & Operating Systems

AUDITED ARCHITECTURE
NODE OPERATING SYSTEM ARCH PROCESSOR RAM PRIMARY STORAGE
MacBook Air macOS 26.5.2 (Darwin 25) arm64 Apple M1 (8 cores) 16 GB Unified 500 GB NVMe APFS
MacBook Pro macOS 26.7 (Darwin 25) x86_64 Intel Core i9-9880H (8C/16T) 32 GB DDR4 1.1 TB NVMe APFS
x1 (Master) Debian 13 (Trixie) aarch64 Broadcom BCM2712 (4 cores) 16 GB LPDDR4X 500 GB NVMe PCIe Gen3
x2 (Worker) Debian 12 (Bookworm) aarch64 Broadcom BCM2712 (4 cores) 8 GB LPDDR4 64 GB MicroSD
x (Worker) Ubuntu 24.04.5 LTS x86_64 AMD64 (2 cores) 8 GB RAM 64 GB SSD
AWS Hub Ubuntu 24.04 LTS x86_64 AWS Nitro vCPU 1 GB Burst 30 GB gp3 EBS
ARCHITECTURE MANUAL: Pure HTML dynamic documentation • No raster screenshots • Real-time network coordinates
VIEW ON DOCS.XK3S.COM ↗
TIER 01

Core SCADA & Plant Execution

4 RUNTIMES ISA-95 LEVEL 3 • REDUNDANT SCADA RUNTIMES • TRANSACTION GROUPS
PRIMARY SCADA
Ignition Prod Master
Plant Execution & Primary SCADA Runtime (x1)
Active primary Ignition gateway hosting plant floor perspective sessions, Modbus/CIP drivers, transaction groups, and alarm journal.
NODEPORT30188 / 30143
NODE HOSTx1-master
PURDUE LVLLevel 3 SCADA
STORAGEPersistent CSI PVC
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Level 3 SCADA Primary
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.29.88
NODEPORT30188 / 30143 / 31336
SECURITYmTLS (GAN 8060) + ChaCha20
LAUNCH SCADA
HOT-STANDBY
Ignition Prod Backup
Native Gateway Redundancy Pair (x1)
Hot-standby redundant gateway with stateful tag synchronization, automated heartbeat failover, and zero-loss alarm logging.
NODEPORT30288 / 30243
NODE HOSTx1-master
PURDUE LVLLevel 3 SCADA
REDUNDANCYSync Nominal
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Level 3 SCADA Standby
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.123.35
NODEPORT30288 / 30243 / 31600
SECURITYmTLS (GAN 8060) + ChaCha20
LAUNCH BACKUP
SANDBOX
Ignition Dev / Staging
Engineering Sandbox & Tag Prototyping (x1)
Isolated gateway environment for prospective HMI UI testing, logic script validation, and sandbox database transactions.
NODEPORT30388 / 30343
NODE HOSTx1-master
PURDUE LVLLevel 3 Dev
ENVIsolated Stage
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Level 3 Dev Sandbox
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.229.247
NODEPORT30388 / 30343
SECURITYIsolated Namespace + WG
LAUNCH DEV GATEWAY
EAM CONTROLLER
Ignition EAM Controller
Enterprise Administration Module (EAM) Controller
Centralized multi-gateway orchestrator coordinating automated project distribution, license leasing, gateway backups, and agent health.
NODEPORT30488 / 30443
NODE HOSTx1-master
PURDUE LVLLevel 4 C2
TOPOLOGYFleet Central
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Level 4 Fleet Central
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.249.188
NODEPORT30488 / 30443
SECURITYEAM Central Token + GAN
LAUNCH EAM HUB
TIER 02

OT CYBERSECURITY & ZERO-TRUST PERIMETER

3 ENCLAVES CYBER THREAT INTEL • SURICATA ICS DPI • PI-HOLE DNS SEC
THREAT RADAR
Cyber Threat Intel Enclave
Real-Time ICS/SCADA Threat Radar, Discord Alerts & DB Ingestion
Continuous OT/ICS vulnerability ingestion engine logging CISA KEVs, BleepingComputer advisories, and CVE telemetry directly into PostgreSQL with detailed personal infrastructure impact mapping.
DATABASE482+ Alerts in Postgres
DISCORD C2Live Webhook Relay
PURDUE LVLPurdue L1-L4 Mapping
REFRESHAuto 30m / On-Demand
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Purdue Threat Intelligence Enclave
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
PORT30850 (Host) • 80 (Traefik)
POSTGRES TABLEignition_db.cyber_security_intel
DISCORD RELAYAutomated Embed Webhook (Active)
LAUNCH CYBER INTEL
ICS IDS ACTIVE
OT Cyber Defense & IDS
Suricata ICS Deep Packet Inspection & Purdue Firewall
Passive Layer-2/Layer-7 network intrusion detection monitoring Modbus, CIP, and S7comm packets across eth0. Real-time Purdue zone anomaly scoring.
NODEPORT30990
INSPECTIONModbus / CIP / S7
INTERFACEeth0 Host Sniff
PURDUE LVLL1 - L4 Perimeter
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L1 - L4 Perimeter
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.220.168
NODEPORT30990
SECURITYeth0 Sniff + Suricata DPI
LAUNCH OT DEFENSE
DNS SINKHOLE
Perimeter Shield & DNS Resolver
Air-Gap DNS Sinkhole & Local Zone Resolution
Stateless perimeter protection providing automated LAN asset scanning, layer-7 ingress traffic steering, DNSSEC validation, and local cluster DNS resolution.
NODEPORT30980
NAMESPACEdns
SECURITYDNSSEC Validated
ZONExk3s.local
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Perimeter L1 - L3 DNS Defense
LAN IPxx.xx.xx.139 / xx.xx.xx.146
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.155.85
NODEPORT30530 / Port 53 (TCP/UDP)
SECURITYDNSSEC Sinkhole & Domain Blackhole
LAUNCH DNS SHIELD
TIER 03

UNIFIED NAMESPACE & INDUSTRIAL IIoT FABRIC

5 ENGINES MQTT 5 • SPARKPLUG B • MULTI-PROTOCOL PLC INGESTION • TIME-SERIES HISTORIAN
UNS BROKER
EMQX Unified Namespace
MQTT 5 & Sparkplug B UNS Broker (x1)
Enterprise sub-millisecond MQTT 5 message broker supporting native Sparkplug B payload state management, topic trees, and edge rules engine.
DASHBOARDPort 31808
MQTT 5 PORTPort 31883
PROTOCOLSparkplug B / JSON
PERFORMANCE<1ms Latency
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L3 UNS MQTT Broker
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.96.238
NODEPORT31808 (Dashboard) / 31883 (MQTT 5)
SECURITYUNS Sparkplug B ACL & TLS Auth
LAUNCH EMQX BROKER
PLC DRIVERS
EMQ Neuron Edge Gateway
Industrial Driver Engine (Allen-Bradley, Siemens, Modbus)
Ultra-light C-based industrial edge gateway collecting PLC I/O over CIP, S7comm, FINS, and Modbus, streaming directly into Sparkplug B.
NODEPORT30700
RUNTIMEC-Engine Native
PROTOCOLSCIP, S7, Modbus
MEMORY<25MB Footprint
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L1 - L2 Industrial Protocols
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.216.218
NODEPORT30700 (HTTP API) / 30701 (Core)
SECURITYSouthbound CIP/S7/Modbus Protocol Enclave
LAUNCH NEURON GATEWAY
ETL PIPELINE
Node-RED OT Gateway
Multi-Protocol Edge Routing & Flow Translation
Low-code visual dataflow orchestration translating proprietary field payloads into standardized UNS topics with watchdog monitoring.
NODEPORT31880
ENGINENode.js 20 LTS
INTEGRATIONREST, OPC-UA, MQTT
FLOWSActive Production
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L2 - L3 Telemetry Orchestration
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.219.218
NODEPORT31880 (Flows UI)
SECURITYRole-Based Bearer JWT & Isolated Subnet
LAUNCH NODE-RED
AMQP FABRIC
RabbitMQ Message Fabric
IIoT Message & Event Broker (x1)
Industrial AMQP and MQTT messaging topology routing telemetry and asynchronous events with durable queue persistence across cluster CSI storage.
MANAGEMENTPort 31672
AMQP PORTPort 5672
QUEUESDurable Persistent
PROTOCOLAMQP 0-9-1 / STOMP
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L3 Event & Message Mesh
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.22.212
NODEPORT31672 (Mgmt) / 30672 (AMQP) / 30883 (MQTT)
SECURITYDurable Persistent Queues & SASL Auth
LAUNCH RABBITMQ
HISTORIAN
InfluxDB v2 Historian
Time-Series Process Historian & Flux Query Engine (x1)
High-frequency process historian capturing telemetry streams, tag fluctuations, and operational KPIs with fast Flux analytical downsampling.
NODEPORT30086
STORAGETSM Engine PVC
QUERYFlux & InfluxQL
RETENTIONInfinite / Downsample
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L3 Time-Series Process Historian
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.35.99
NODEPORT30086 (HTTP/Flux API)
SECURITYSCADA Auth Token & Flux Engine
LAUNCH INFLUXDB
TIER 04

OBSERVABILITY, LOG PIPELINE & C2 OPERATIONS

2 RUNTIMES GRAFANA OPERATIONAL HUD • MATTERMOST CHATOPS & C2 COMMS
OPERATIONS HUD
Observability HUD (Grafana)
Unified Visual Analytics & Industrial Telemetry HUD
Defense-grade operations dashboard aggregating cluster metrics, container health, network throughput, and PLC tag trends.
NODEPORT30300
DATASOURCESInfluxDB, Prometheus
REFRESH RATESub-second Stream
ALERTSUnified C2 Notifier
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L3 - L4 C2 Operations Analytics
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.148.128
NODEPORT30300 (Grafana Web)
SECURITYOAuth / Basic Auth + Flux v2 Engine
LAUNCH GRAFANA HUD
C2 CHANNELS
Mattermost & Database
Command & Control Team Operations Messaging
Private self-hosted operations hub for real-time SCADA alarms, automated CI/CD bot alerts, and cryptographic engineer coordination.
NODEPORT32758
BACKENDPostgreSQL 15
ENCRYPTIONTLS End-to-End
NOTIFICATIONSSCADA Webhooks
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY L4 C2 Tactical Messaging
LAN IPxx.xx.xx.139
TAILSCALExx.xx.xx.43
WIREGUARD10.10.0.2
CLUSTER IP10.43.68.127 (App) / 10.43.83.213 (DB)
NODEPORT32758 (Web) / 5432 (Postgres)
SECURITYTLS End-to-End & HMAC Webhooks
LAUNCH MATTERMOST
TIER 05

Industrial Soft PLC & DevOps Fabric

4 PLATFORMS IEC 61131-3 SOFT PLC • GIT DEVOPS HUB • K3S CLUSTER ORCHESTRATION • PORTAINER CE
SOFT PLC RUNTIME
OpenPLC IEC 61131-3 Soft PLC
Industrial Soft PLC Runtime, Modbus TCP Server & IEC 61131-3 Logic Engine
Active open-source industrial Soft PLC executing standardized IEC 61131-3 logic programs (Ladder Logic, Structured Text, Function Block Diagram). Serves real-time Modbus TCP telemetry on port 30502 and hosts interactive web administration on port 30880.
STANDARDSIEC 61131-3 (ST, LD, FBD)
MODBUS TCPPort 502 (NodePort 30502)
HOST NODEWorker x (AMD64 4KB Pages)
STORAGE5Gi NFS Bound (st_files)
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
CONTROL PROTOCOLS L1 / L2 Soft PLC
CONTAINERopenplc-runtime (1/1)
WORKER NODEx (100.111.136.65)
MODBUS TCP10.10.0.2:30502
WEB ADMINworkbench.xk3s.com
LAUNCH OPENPLC RUNTIME
GIT REPOSITORY ACTIVE
Gitea Industrial Git Hub
Self-Hosted Industrial Git Server, Controls Logic & SCADA DevOps Repository
Genuine self-hosted Git version control system deployed on K3s. Provides native Git repositories, SSH and HTTPS clone protocols, issue tracking, and webhook automation for OpenPLC ladder programs, Ignition Perspective projects, and cluster manifests.
ENGINEGitea v1.27.3
PROTOCOLSHTTP (31410) • SSH (30022)
HOST NODEWorker x2 (Edge Worker)
STORAGE10Gi Persistent Volume (NFS)
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Purdue Level 3 Industrial DevOps
CONTAINERgitea-server (1/1)
WORKER NODEx2 (xx.xx.xx.146)
NODEPORT31410 (HTTP) • 30022 (SSH)
INGRESSgitea.xk3s.com (alias: copia.xk3s.com)
LAUNCH GITEA GIT REPOSITORY
K3s CLUSTER ORCHESTRATOR
K3s Cluster Management (Headlamp)
Proxmox-Style Sovereign Kubernetes Node & Container Orchestration Console
Sovereign web-based cluster management interface providing Proxmox-like node visibility, workload scheduling, pod telemetry, resource autoscaling (HPA/VPA), namespace routing, and container shell access across nodes x1 and x2.
PLATFORMHeadlamp v0.45.0
K8s ENGINEK3s v1.36.4
ACTIVE NODESx1 (Master) • x2 (Worker)
INGRESS / PORTTraefik Ingress (Port 32619)
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Cluster Management Fabric
CONTAINERheadlamp-84db58c696 (1/1)
MASTER NODEx1 (10.10.0.2)
NODEPORT32619 (HTTP)
INGRESSheadlamp.xk3s.com
LAUNCH HEADLAMP HUD
CONTAINER ORCHESTRATOR
Portainer CE Management
Full Sovereign Container, Persistent Volume & Kubernetes Workload Console
Comprehensive container and K8s orchestration portal providing visual pod inspection, namespace management, persistent volume oversight, live container console terminals, and real-time execution logging across cluster master x1 and workers.
PLATFORMPortainer CE v2.45.0
K8s ENGINEK3s v1.36.4
ACTIVE NODESx1 (Master) • x2 (Worker)
INGRESS / PORTNodePort 30779 (HTTPS)
CONTAINER MANAGEMENT CONSOLE:
SUPER ADMIN INTEL (CLASSIFIED) DECRYPT ↗
NETWORK TELEMETRY Cluster Management Fabric
CONTAINERportainer-858b94f5c7 (1/1)
MASTER NODEx1 (10.10.0.2)
NODEPORT30779 (HTTPS) • 30776 (Edge)
INGRESSportainer.xk3s.com
LAUNCH PORTAINER CE

Compute-Storage Decoupling & Stateful Mesh

Modern autonomous edge deployments require strict architectural separation between stateful persistence and stateless ingress execution. In this topology, CORE-MASTER-01 (x1) anchors the dedicated high-IOPS persistent storage tier, isolating write-intensive transactional databases, InfluxDB write-ahead logs (WAL), RabbitMQ durable queues, and enterprise SCADA transaction groups into dedicated volume enclaves.

  • Cloud-native dynamic CSI storage provisioner with automated volume binding
  • Complete persistence isolation protecting edge nodes from I/O contention
  • Encrypted Flannel CNI overlay mesh with wire-speed packet encapsulation

Stateless Edge Worker Isolation

EDGE-GATEWAY-02 (x2) operates under a strictly enforced stateless paradigm. High-frequency industrial telemetry, edge ingress routing, and visualization pipelines run completely decoupled from local persistent state. By policy-constraining all StatefulSets to the master storage enclave via Kubernetes nodeAffinity, the edge worker executes purely in-memory workloads (Traefik ingress routing, OT protocol translation, and high-framerate kiosk rendering).

  • 100% of persistent volume claims (PVCs) isolated to designated stateful tier
  • Ephemeral edge worker resilience with instant stateless recovery capability
  • Zero-downtime hot-standby failover capabilities for edge services
APPEARANCE