sloth-kubernetes

command module
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 27, 2025 License: MIT Imports: 1 Imported by: 0

README ยถ

๐Ÿฆฅ Sloth Kubernetes

Multi-Cloud Kubernetes Deployment Made Simple

Deploy production-ready Kubernetes clusters across DigitalOcean and Linode with embedded Pulumi + Salt + kubectl - zero external dependencies required

Go Version Test Coverage License

Pulumi Salt kubectl

Quick Start โ€ข Features โ€ข Documentation โ€ข CLI Reference โ€ข Examples


๐Ÿ“– Table of Contents


๐ŸŒŸ Overview

Sloth Kubernetes is a single-binary CLI tool that deploys production-grade Kubernetes clusters across multiple cloud providers with zero external dependencies. No Pulumi CLI, no Terraform, no complex setupโ€”just one binary and you're ready to deploy.

What Makes It Different?

Traditional Approach vs. Sloth Kubernetes:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                         TRADITIONAL APPROACH                             โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ“ฆ Install Tools:                                                       โ”‚
โ”‚     โ€ข Pulumi CLI (or Terraform)                                          โ”‚
โ”‚     โ€ข kubectl CLI                                                        โ”‚
โ”‚     โ€ข Salt CLI (or Ansible)                                              โ”‚
โ”‚     โ€ข Cloud provider CLIs (doctl, linode-cli)                            โ”‚
โ”‚     โ€ข Docker                                                             โ”‚
โ”‚     โ€ข Various plugins and dependencies                                   โ”‚
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ”ง Configure:                                                           โ”‚
โ”‚     โ€ข Pulumi backend (S3, cloud storage)                                 โ”‚
โ”‚     โ€ข kubectl contexts                                                   โ”‚
โ”‚     โ€ข Salt master/minion                                                 โ”‚
โ”‚     โ€ข Cloud provider credentials                                         โ”‚
โ”‚     โ€ข Version compatibility matrix                                       โ”‚
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ“ Manage:                                                              โ”‚
โ”‚     โ€ข Multiple CLI tool versions                                         โ”‚
โ”‚     โ€ข Conflicting dependencies                                           โ”‚
โ”‚     โ€ข Different configuration files                                      โ”‚
โ”‚     โ€ข Separate authentication for each tool                              โ”‚
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ’ป Deploy:                                                              โ”‚
โ”‚     1. pulumi up                                                         โ”‚
โ”‚     2. salt '*' test.ping                                                โ”‚
โ”‚     3. kubectl get nodes                                                 โ”‚
โ”‚     4. Switch contexts, update configs, troubleshoot...                  โ”‚
โ”‚                                                                           โ”‚
โ”‚  Result: โŒ Complex, error-prone, time-consuming                         โ”‚
โ”‚                                                                           โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

                                      โ†“โ†“โ†“

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                        SLOTH KUBERNETES APPROACH                         โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ“ฆ Install:                                                             โ”‚
โ”‚     โ€ข Download ONE binary (sloth-kubernetes)                             โ”‚
โ”‚     โ€ข That's it! โœ…                                                      โ”‚
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ”ง Configure:                                                           โ”‚
โ”‚     โ€ข Create ONE YAML file (cluster.yaml)                                โ”‚
โ”‚     โ€ข Set environment variables (cloud tokens)                           โ”‚
โ”‚                                                                           โ”‚
โ”‚  ๐Ÿ’ป Deploy & Manage:                                                     โ”‚
โ”‚     # Infrastructure (Pulumi embedded)                                   โ”‚
โ”‚     sloth-kubernetes deploy --config cluster.yaml                        โ”‚
โ”‚                                                                           โ”‚
โ”‚     # Node Management (Salt embedded)                                    โ”‚
โ”‚     sloth-kubernetes salt login                                          โ”‚
โ”‚     sloth-kubernetes salt ping                                           โ”‚
โ”‚     sloth-kubernetes salt cmd "uptime"                                   โ”‚
โ”‚                                                                           โ”‚
โ”‚     # Kubernetes Operations (kubectl embedded)                           โ”‚
โ”‚     sloth-kubernetes kubectl get nodes                                   โ”‚
โ”‚     sloth-kubernetes kubectl apply -f app.yaml                           โ”‚
โ”‚     sloth-kubernetes kubectl logs my-pod                                 โ”‚
โ”‚                                                                           โ”‚
โ”‚  Result: โœ… Simple, consistent, reliable                                 โ”‚
โ”‚                                                                           โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The Key Difference:

Traditional:  7 separate tools ร— 5 config files ร— 3 auth methods = ๐Ÿคฏ Complexity

Sloth K8s:    1 binary       + 1 YAML file    + env vars        = ๐Ÿ˜Œ Simplicity
Technology Stack
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                         Sloth Kubernetes Binary                             โ”‚
โ”‚                         (Single Unified CLI Tool)                           โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                              โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Command Layer (cmd/)                                              โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”‚    โ”‚
โ”‚  โ”‚  โ”‚deployโ”‚ โ”‚destroyโ”‚ โ”‚ nodes โ”‚ โ”‚ vpn  โ”‚ โ”‚ addons  โ”‚ โ”‚ kubectl โ”‚  โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                                        โ”‚    โ”‚
โ”‚  โ”‚  โ”‚ salt  โ”‚ โ”‚   pulumi   โ”‚                                        โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                                        โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ”‚                                    โ†“                                         โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Three Embedded Tools (Zero External Dependencies)                โ”‚    โ”‚
โ”‚  โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค    โ”‚
โ”‚  โ”‚                                                                     โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”     โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  1. Pulumi Automation โ”‚  โ”‚  2. Salt API Client          โ”‚     โ”‚    โ”‚
โ”‚  โ”‚  โ”‚     API (Embedded)    โ”‚  โ”‚     (Embedded)               โ”‚     โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โœ“ IaC without CLI    โ”‚  โ”‚  โœ“ Remote execution          โ”‚     โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โœ“ State management   โ”‚  โ”‚  โœ“ Configuration management  โ”‚     โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โœ“ Multi-cloud         โ”‚  โ”‚  โœ“ 100+ operations           โ”‚     โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜     โ”‚    โ”‚
โ”‚  โ”‚                                                                     โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  3. kubectl Client (Embedded)                             โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โœ“ Full kubectl functionality                             โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โœ“ All standard commands (get, apply, logs, exec)         โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โœ“ No separate installation needed                        โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ”‚                                    โ†“                                         โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Provider SDKs & Kubernetes Client                                 โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  DigitalOcean    โ”‚  โ”‚     Linode      โ”‚  โ”‚  Kubernetes API  โ”‚ โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข Droplets      โ”‚  โ”‚  โ€ข Instances    โ”‚  โ”‚  โ€ข Full API      โ”‚ โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข VPCs          โ”‚  โ”‚  โ€ข VPCs         โ”‚  โ”‚  โ€ข client-go     โ”‚ โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข Firewalls     โ”‚  โ”‚  โ€ข Firewalls    โ”‚  โ”‚  โ€ข kubectl pkg   โ”‚ โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                      โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                         Cloud Infrastructure                                 โ”‚
โ”‚                                                                              โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”         โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                 โ”‚
โ”‚  โ”‚   DigitalOcean       โ”‚         โ”‚      Linode          โ”‚                 โ”‚
โ”‚  โ”‚                      โ”‚โ—„โ”€โ”€โ”€VPNโ”€โ”€โ–บโ”‚                      โ”‚                 โ”‚
โ”‚  โ”‚  โ€ข VPCs              โ”‚         โ”‚  โ€ข VPCs              โ”‚                 โ”‚
โ”‚  โ”‚  โ€ข Droplets          โ”‚         โ”‚  โ€ข Instances         โ”‚                 โ”‚
โ”‚  โ”‚  โ€ข Load Balancers    โ”‚         โ”‚  โ€ข NodeBalancers     โ”‚                 โ”‚
โ”‚  โ”‚  โ€ข RKE2 Kubernetes   โ”‚         โ”‚  โ€ข RKE2 Kubernetes   โ”‚                 โ”‚
โ”‚  โ”‚  โ€ข Salt Minions      โ”‚         โ”‚  โ€ข Salt Minions      โ”‚                 โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜         โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                 โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โœจ Key Features

๐ŸŽฏ Zero External Dependencies

โœ… What You Need

  • Go 1.23+ (for building only)
  • Cloud provider API tokens
  • SSH access

โŒ What You DON'T Need

  • Pulumi CLI (embedded)
  • kubectl CLI (embedded)
  • Salt CLI (embedded)
  • Terraform
  • Docker (for deployment)
  • Ansible
  • Any other IaC tools
๐Ÿ”ง Three Powerful Tools in One Binary

Sloth Kubernetes embeds three complete CLI tools into a single binary:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                                                                  โ”‚
โ”‚  1๏ธโƒฃ  PULUMI AUTOMATION API                                      โ”‚
โ”‚      Infrastructure as Code without the Pulumi CLI              โ”‚
โ”‚                                                                  โ”‚
โ”‚      sloth-kubernetes deploy --config cluster.yaml              โ”‚
โ”‚      sloth-kubernetes pulumi stack output                       โ”‚
โ”‚      sloth-kubernetes destroy                                   โ”‚
โ”‚                                                                  โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                  โ”‚
โ”‚  2๏ธโƒฃ  SALT API CLIENT                                            โ”‚
โ”‚      Remote execution and configuration management              โ”‚
โ”‚                                                                  โ”‚
โ”‚      sloth-kubernetes salt login                                โ”‚
โ”‚      sloth-kubernetes salt ping                                 โ”‚
โ”‚      sloth-kubernetes salt cmd "uptime"                         โ”‚
โ”‚      sloth-kubernetes salt system disk                          โ”‚
โ”‚                                                                  โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                  โ”‚
โ”‚  3๏ธโƒฃ  KUBECTL CLIENT                                             โ”‚
โ”‚      Full Kubernetes cluster management                         โ”‚
โ”‚                                                                  โ”‚
โ”‚      sloth-kubernetes kubectl get nodes                         โ”‚
โ”‚      sloth-kubernetes kubectl apply -f deployment.yaml          โ”‚
โ”‚      sloth-kubernetes kubectl logs pod-name                     โ”‚
โ”‚      sloth-kubernetes kubectl exec -it pod-name -- bash         โ”‚
โ”‚                                                                  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Why This Matters:

  • โœ… One Binary to Rule Them All - Deploy, manage, and operate from a single tool
  • โœ… No Version Conflicts - All tools tested together and guaranteed compatible
  • โœ… Offline Capable - No need to download additional CLIs
  • โœ… Simplified CI/CD - Just copy one binary to your pipeline
  • โœ… Consistent Experience - Same CLI interface for all operations
๐ŸŒ True Multi-Cloud Support

Deploy a single Kubernetes cluster with nodes across multiple providers:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                    Your Kubernetes Cluster                       โ”‚
โ”‚                                                                  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”         โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”     โ”‚
โ”‚  โ”‚   DigitalOcean       โ”‚         โ”‚      Linode          โ”‚     โ”‚
โ”‚  โ”‚   Region: NYC3       โ”‚ โ—„โ”€โ”€โ”€โ”€โ”€โ–บ โ”‚   Region: US-East    โ”‚     โ”‚
โ”‚  โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค   VPN   โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค     โ”‚
โ”‚  โ”‚ โ€ข 1 Master Node      โ”‚         โ”‚ โ€ข 2 Master Nodes     โ”‚     โ”‚
โ”‚  โ”‚ โ€ข 2 Worker Nodes     โ”‚         โ”‚ โ€ข 1 Worker Node      โ”‚     โ”‚
โ”‚  โ”‚ โ€ข VPC: 10.10.0.0/16  โ”‚         โ”‚ โ€ข VPC: 10.11.0.0/16  โ”‚     โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜         โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜     โ”‚
โ”‚           โ†‘                                    โ†‘                 โ”‚
โ”‚           โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€ WireGuard Mesh โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                โ”‚
โ”‚                  (10.8.0.0/24)                                   โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Why Multi-Cloud?

  • ๐Ÿ›ก๏ธ High Availability - Survive provider outages
  • ๐Ÿ’ฐ Cost Optimization - Use best pricing per region
  • ๐ŸŒ Geographic Distribution - Reduce latency globally
  • ๐Ÿ”„ Avoid Vendor Lock-in - Freedom to choose
๐Ÿ” Automated Networking
Sequential 3-Phase Deployment
Phase 1: VPC Creation
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  โœ“ Create DigitalOcean VPC (10.10.0.0/16)             โ”‚
โ”‚  โœ“ Create Linode VPC (10.11.0.0/16)                   โ”‚
โ”‚  โœ“ Configure subnets and gateways                      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                         โ†“
Phase 2: WireGuard VPN
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  โœ“ Deploy VPN server (auto-created)                    โ”‚
โ”‚  โœ“ Generate encryption keys                            โ”‚
โ”‚  โœ“ Configure mesh networking                           โ”‚
โ”‚  โœ“ Enable cross-provider routing                       โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                         โ†“
Phase 3: Kubernetes Cluster
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  โœ“ Provision nodes (masters + workers)                 โ”‚
โ”‚  โœ“ Install RKE2 Kubernetes                             โ”‚
โ”‚  โœ“ Configure WireGuard on each node                    โ”‚
โ”‚  โœ“ Join nodes to cluster                               โ”‚
โ”‚  โœ“ Validate cluster health                             โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

All in One Command: sloth-kubernetes deploy --config cluster.yaml

๐Ÿš€ Production-Ready Kubernetes
RKE2 Distribution Features
โ”œโ”€ High Availability         # Odd-number master nodes (3, 5, 7)
โ”œโ”€ Automated Etcd Backups   # Scheduled snapshots with retention
โ”œโ”€ Secrets Encryption       # At-rest encryption for etcd
โ”œโ”€ Network Policies         # Calico/Cilium CNI support
โ”œโ”€ Security Hardening       # CIS benchmark compliance
โ”œโ”€ Rolling Updates          # Zero-downtime upgrades
โ””โ”€ Multi-CNI Support        # Calico, Cilium, Canal, Flannel
๐ŸŽฏ GitOps-Native
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Your Git Repository                                        โ”‚
โ”‚  https://github.com/yourorg/k8s-gitops                      โ”‚
โ”‚                                                              โ”‚
โ”‚  โ”œโ”€โ”€ argocd/                                                โ”‚
โ”‚  โ”‚   โ””โ”€โ”€ install.yaml      โ† ArgoCD self-manages itself     โ”‚
โ”‚  โ”œโ”€โ”€ apps/                                                  โ”‚
โ”‚  โ”‚   โ”œโ”€โ”€ cert-manager/                                      โ”‚
โ”‚  โ”‚   โ”œโ”€โ”€ ingress-nginx/                                     โ”‚
โ”‚  โ”‚   โ””โ”€โ”€ monitoring/                                        โ”‚
โ”‚  โ””โ”€โ”€ clusters/                                              โ”‚
โ”‚      โ””โ”€โ”€ production/                                        โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                         โ†“
         sloth-kubernetes addons bootstrap \
           --repo https://github.com/yourorg/k8s-gitops
                         โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Kubernetes Cluster                                         โ”‚
โ”‚  โ€ข ArgoCD auto-installed                                    โ”‚
โ”‚  โ€ข Watches Git repository                                   โ”‚
โ”‚  โ€ข Syncs all applications                                   โ”‚
โ”‚  โ€ข Self-healing and auto-sync                               โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โšก Quick Start

3 Minutes to Your First Cluster
# 1. Install sloth-kubernetes (10 seconds)
curl -fsSL https://raw.githubusercontent.com/chalkan3/sloth-kubernetes/main/install.sh | bash

# 2. Create config file (1 minute)
cat > cluster.yaml <<EOF
apiVersion: kubernetes-create.io/v1
kind: Cluster
metadata:
  name: my-first-cluster

spec:
  providers:
    digitalocean:
      enabled: true
      token: ${DIGITALOCEAN_TOKEN}
      region: nyc3
      vpc:
        create: true
        cidr: 10.10.0.0/16

  network:
    wireguard:
      create: true              # Auto-create VPN server
      provider: digitalocean
      meshNetworking: true

  kubernetes:
    distribution: rke2
    version: v1.28.5+rke2r1

  nodePools:
    - name: masters
      provider: digitalocean
      count: 3
      roles: [master]
      size: s-2vcpu-4gb

    - name: workers
      provider: digitalocean
      count: 3
      roles: [worker]
      size: s-2vcpu-4gb
EOF

# 3. Deploy! (5-10 minutes)
export DIGITALOCEAN_TOKEN="your-token-here"
sloth-kubernetes deploy --config cluster.yaml

# 4. Access your cluster
sloth-kubernetes kubeconfig > ~/.kube/config
kubectl get nodes

Expected Output:

NAME              STATUS   ROLES                  AGE   VERSION
do-master-1       Ready    control-plane,master   5m    v1.28.5+rke2r1
do-master-2       Ready    control-plane,master   5m    v1.28.5+rke2r1
do-master-3       Ready    control-plane,master   5m    v1.28.5+rke2r1
do-worker-1       Ready    worker                 4m    v1.28.5+rke2r1
do-worker-2       Ready    worker                 4m    v1.28.5+rke2r1
do-worker-3       Ready    worker                 4m    v1.28.5+rke2r1

๐ŸŽฏ Complete Workflow: Deploy to Production

See how all three embedded tools work together in a complete deployment:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  PHASE 1: INFRASTRUCTURE DEPLOYMENT (Pulumi)                                โ”‚
โ”‚โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes deploy --config cluster.yaml                            โ”‚
โ”‚                                                                              โ”‚
โ”‚  โœ“ Creating VPCs (DigitalOcean + Linode)                                    โ”‚
โ”‚  โœ“ Deploying WireGuard VPN mesh                                             โ”‚
โ”‚  โœ“ Provisioning 6 nodes (3 masters, 3 workers)                              โ”‚
โ”‚  โœ“ Installing RKE2 Kubernetes                                                โ”‚
โ”‚  โœ“ Configuring Salt minions                                                 โ”‚
โ”‚                                                                              โ”‚
โ”‚  ๐ŸŽ‰ Cluster deployed! (8m 32s)                                              โ”‚
โ”‚                                                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                    โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  PHASE 2: NODE MANAGEMENT (Salt API)                                        โ”‚
โ”‚โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes salt login                                              โ”‚
โ”‚  โœ“ Auto-detected bastion: 167.99.123.45                                     โ”‚
โ”‚  โœ“ Connected to 6 minions                                                   โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes salt ping                                               โ”‚
โ”‚  โœ… 6/6 minions responding                                                  โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes salt system disk                                        โ”‚
โ”‚  ๐Ÿ’พ Disk usage across all nodes displayed                                   โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes salt pkg install htop                                   โ”‚
โ”‚  โœ“ htop installed on 6 nodes                                                โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes salt service status rke2-server                         โ”‚
โ”‚  โœ… RKE2 running on all master nodes                                        โ”‚
โ”‚                                                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                    โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  PHASE 3: KUBERNETES OPERATIONS (kubectl)                                   โ”‚
โ”‚โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes kubeconfig > ~/.kube/config                             โ”‚
โ”‚  โœ“ Kubeconfig saved                                                         โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes kubectl get nodes                                       โ”‚
โ”‚  NAME              STATUS   ROLES          AGE   VERSION                    โ”‚
โ”‚  do-master-1       Ready    control-plane  8m    v1.28.5+rke2r1             โ”‚
โ”‚  do-master-2       Ready    control-plane  8m    v1.28.5+rke2r1             โ”‚
โ”‚  linode-master-1   Ready    control-plane  8m    v1.28.5+rke2r1             โ”‚
โ”‚  do-worker-1       Ready    worker         7m    v1.28.5+rke2r1             โ”‚
โ”‚  do-worker-2       Ready    worker         7m    v1.28.5+rke2r1             โ”‚
โ”‚  linode-worker-1   Ready    worker         7m    v1.28.5+rke2r1             โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes kubectl apply -f app.yaml                               โ”‚
โ”‚  deployment.apps/webapp created                                             โ”‚
โ”‚  service/webapp created                                                     โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes kubectl get pods                                        โ”‚
โ”‚  NAME                      READY   STATUS    RESTARTS   AGE                 โ”‚
โ”‚  webapp-7d4c9df8b-2x5kq   1/1     Running   0          30s                 โ”‚
โ”‚  webapp-7d4c9df8b-8hxqt   1/1     Running   0          30s                 โ”‚
โ”‚  webapp-7d4c9df8b-k9wnr   1/1     Running   0          30s                 โ”‚
โ”‚                                                                              โ”‚
โ”‚  $ sloth-kubernetes kubectl logs webapp-7d4c9df8b-2x5kq                    โ”‚
โ”‚  ๐Ÿš€ Application started successfully                                        โ”‚
โ”‚                                                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                                    โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  PHASE 4: ONGOING OPERATIONS (All Three Tools)                              โ”‚
โ”‚โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”‚
โ”‚                                                                              โ”‚
โ”‚  ๐Ÿ“ฆ Infrastructure Changes (Pulumi):                                        โ”‚
โ”‚     sloth-kubernetes nodes add --pool workers --count 2                     โ”‚
โ”‚     sloth-kubernetes pulumi stack output                                    โ”‚
โ”‚                                                                              โ”‚
โ”‚  ๐Ÿ”ง System Maintenance (Salt):                                              โ”‚
โ”‚     sloth-kubernetes salt pkg upgrade                                       โ”‚
โ”‚     sloth-kubernetes salt cmd "docker system prune -af"                     โ”‚
โ”‚     sloth-kubernetes salt service restart kubelet                           โ”‚
โ”‚                                                                              โ”‚
โ”‚  โ˜ธ๏ธ  Application Management (kubectl):                                      โ”‚
โ”‚     sloth-kubernetes kubectl scale deployment webapp --replicas=10          โ”‚
โ”‚     sloth-kubernetes kubectl rollout restart deployment/webapp              โ”‚
โ”‚     sloth-kubernetes kubectl top nodes                                      โ”‚
โ”‚                                                                              โ”‚
โ”‚  โœ… Production cluster fully operational!                                   โ”‚
โ”‚                                                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Key Benefits:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  One Binary, Three Complete Tool Sets                               โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                      โ”‚
โ”‚  ๐Ÿ—๏ธ  PULUMI                  ๐Ÿง‚ SALT                  โ˜ธ๏ธ  KUBECTL   โ”‚
โ”‚                                                                      โ”‚
โ”‚  Infrastructure              Node Management         K8s Management โ”‚
โ”‚  โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€             โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€         โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ โ”‚
โ”‚  โ€ข Deploy cluster            โ€ข Run commands          โ€ข Manage pods  โ”‚
โ”‚  โ€ข Manage state              โ€ข Install packages      โ€ข View logs    โ”‚
โ”‚  โ€ข Add/remove nodes          โ€ข Monitor systems       โ€ข Scale apps   โ”‚
โ”‚  โ€ข Configure VPCs            โ€ข Manage services       โ€ข Rollouts     โ”‚
โ”‚  โ€ข Setup VPN                 โ€ข Network diagnostics   โ€ข Debug issues โ”‚
โ”‚                                                                      โ”‚
โ”‚  When to use:                When to use:            When to use:   โ”‚
โ”‚  โ€ข Initial deployment        โ€ข Post-deployment       โ€ข Application  โ”‚
โ”‚  โ€ข Infrastructure changes    โ€ข System updates        โ€ข   operations โ”‚
โ”‚  โ€ข Scaling hardware          โ€ข Security audits       โ€ข Debugging    โ”‚
โ”‚  โ€ข Multi-cloud setup         โ€ข Batch operations      โ€ข Monitoring   โ”‚
โ”‚                                                                      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ“ฅ Installation

Install the latest version with a single command:

# Install latest version
curl -fsSL https://raw.githubusercontent.com/chalkan3/sloth-kubernetes/main/install.sh | bash

# Or install specific version
curl -fsSL https://raw.githubusercontent.com/chalkan3/sloth-kubernetes/main/install.sh | bash -s v1.0.0

Or download and run the script manually:

# Download install script
curl -fsSL -o install.sh https://raw.githubusercontent.com/chalkan3/sloth-kubernetes/main/install.sh

# Make it executable
chmod +x install.sh

# Run installer
./install.sh

# Or install specific version
./install.sh v1.0.0

The installer will:

  • โœ… Detect your OS and architecture automatically
  • โœ… Download the correct binary from GitHub Releases
  • โœ… Verify checksums for security
  • โœ… Install to /usr/local/bin
  • โœ… Make the binary executable
Method 2: Download Pre-built Binary

Download directly from GitHub Releases:

# Linux AMD64
curl -L https://github.com/chalkan3/sloth-kubernetes/releases/latest/download/sloth-kubernetes_Linux_x86_64.tar.gz -o sloth-kubernetes.tar.gz

# macOS Intel
curl -L https://github.com/chalkan3/sloth-kubernetes/releases/latest/download/sloth-kubernetes_Darwin_x86_64.tar.gz -o sloth-kubernetes.tar.gz

# macOS Apple Silicon
curl -L https://github.com/chalkan3/sloth-kubernetes/releases/latest/download/sloth-kubernetes_Darwin_arm64.tar.gz -o sloth-kubernetes.tar.gz

# Extract and install
tar -xzf sloth-kubernetes.tar.gz
chmod +x sloth-kubernetes
sudo mv sloth-kubernetes /usr/local/bin/
Method 3: Build from Source
# Clone repository
git clone https://github.com/chalkan3/sloth-kubernetes.git
cd sloth-kubernetes

# Build binary
go build -o sloth-kubernetes

# Install globally
sudo mv sloth-kubernetes /usr/local/bin/

# Verify installation
sloth-kubernetes version
Verify Installation
# Check version
sloth-kubernetes --version

# Show help
sloth-kubernetes --help
Prerequisites
Component Version Required For
Go 1.23+ Building from source
DigitalOcean API Token - DigitalOcean resources
Linode API Token - Linode resources (optional)
SSH Key Pair - Node access

๐Ÿ—๏ธ Architecture

System Architecture
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                      Sloth Kubernetes CLI                        โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚                                                                  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Command Layer (cmd/)                                  โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ” โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”‚    โ”‚
โ”‚  โ”‚  โ”‚deployโ”‚ โ”‚destroyโ”‚ โ”‚ nodes โ”‚ โ”‚ vpn  โ”‚ โ”‚ addons  โ”‚  โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ”‚                            โ†“                                     โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Configuration Layer (pkg/config/)                     โ”‚    โ”‚
โ”‚  โ”‚  โ€ข YAML parsing                                        โ”‚    โ”‚
โ”‚  โ”‚  โ€ข Validation                                          โ”‚    โ”‚
โ”‚  โ”‚  โ€ข Schema enforcement                                  โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ”‚                            โ†“                                     โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Orchestration Layer (internal/orchestrator/)          โ”‚    โ”‚
โ”‚  โ”‚                                                         โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”‚    โ”‚
โ”‚  โ”‚  โ”‚ SSH Keys    โ”‚โ†’ โ”‚  Bastion     โ”‚โ†’ โ”‚     VPC     โ”‚  โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ”‚    โ”‚
โ”‚  โ”‚         โ†“                                               โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”‚    โ”‚
โ”‚  โ”‚  โ”‚   Nodes     โ”‚โ†’ โ”‚  WireGuard   โ”‚โ†’ โ”‚    RKE2     โ”‚  โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ”‚    โ”‚
โ”‚  โ”‚         โ†“                                               โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                                       โ”‚    โ”‚
โ”‚  โ”‚  โ”‚     DNS     โ”‚                                       โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                                       โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ”‚                            โ†“                                     โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Pulumi Automation API (Embedded)                      โ”‚    โ”‚
โ”‚  โ”‚  โ€ข Infrastructure as Code                              โ”‚    โ”‚
โ”‚  โ”‚  โ€ข State management                                    โ”‚    โ”‚
โ”‚  โ”‚  โ€ข Resource tracking                                   โ”‚    โ”‚
โ”‚  โ”‚  โ€ข Diff/preview capabilities                           โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ”‚                            โ†“                                     โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”‚
โ”‚  โ”‚  Provider SDKs                                         โ”‚    โ”‚
โ”‚  โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  DigitalOcean    โ”‚    โ”‚      Linode           โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข Droplets      โ”‚    โ”‚  โ€ข Instances          โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข VPCs          โ”‚    โ”‚  โ€ข VPCs               โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข Firewalls     โ”‚    โ”‚  โ€ข Firewalls          โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ”‚  โ€ข DNS           โ”‚    โ”‚  โ€ข NodeBalancers      โ”‚   โ”‚    โ”‚
โ”‚  โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚    โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜    โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                              โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                    Cloud Infrastructure                          โ”‚
โ”‚                                                                  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”         โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”     โ”‚
โ”‚  โ”‚   DigitalOcean       โ”‚         โ”‚      Linode          โ”‚     โ”‚
โ”‚  โ”‚                      โ”‚โ—„โ”€โ”€โ”€VPNโ”€โ”€โ–บโ”‚                      โ”‚     โ”‚
โ”‚  โ”‚  โ€ข VPCs              โ”‚         โ”‚  โ€ข VPCs              โ”‚     โ”‚
โ”‚  โ”‚  โ€ข Droplets          โ”‚         โ”‚  โ€ข Instances         โ”‚     โ”‚
โ”‚  โ”‚  โ€ข Load Balancers    โ”‚         โ”‚  โ€ข NodeBalancers     โ”‚     โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜         โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
Deployment Flow
User Input (cluster.yaml)
          โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ 1. Load & Validate Configuration        โ”‚
โ”‚    โœ“ Parse YAML                         โ”‚
โ”‚    โœ“ Validate providers                 โ”‚
โ”‚    โœ“ Validate node distribution         โ”‚
โ”‚    โœ“ Check network configuration        โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
          โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ 2. Initialize Pulumi Stack              โ”‚
โ”‚    โœ“ Create/select stack                โ”‚
โ”‚    โœ“ Configure backend                  โ”‚
โ”‚    โœ“ Set config values                  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
          โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ 3. Phase 1: VPC Creation                โ”‚
โ”‚    โœ“ Create DigitalOcean VPC            โ”‚
โ”‚    โœ“ Create Linode VPC                  โ”‚
โ”‚    โœ“ Configure subnets                  โ”‚
โ”‚    โœ“ Setup routing tables               โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
          โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ 4. Phase 2: WireGuard VPN               โ”‚
โ”‚    โœ“ Deploy VPN server                  โ”‚
โ”‚    โœ“ Generate server keys               โ”‚
โ”‚    โœ“ Configure firewall rules           โ”‚
โ”‚    โœ“ Setup routing                      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
          โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ 5. Phase 3: Kubernetes Cluster          โ”‚
โ”‚    โœ“ Generate SSH keys                  โ”‚
โ”‚    โœ“ Create bastion host (optional)     โ”‚
โ”‚    โœ“ Deploy master nodes                โ”‚
โ”‚    โœ“ Deploy worker nodes                โ”‚
โ”‚    โœ“ Install RKE2                       โ”‚
โ”‚    โœ“ Configure WireGuard on nodes       โ”‚
โ”‚    โœ“ Join nodes to cluster              โ”‚
โ”‚    โœ“ Configure DNS                      โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
          โ†“
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ 6. Export Outputs                       โ”‚
โ”‚    โ€ข Cluster name                       โ”‚
โ”‚    โ€ข Kubeconfig                         โ”‚
โ”‚    โ€ข API endpoint                       โ”‚
โ”‚    โ€ข SSH private key                    โ”‚
โ”‚    โ€ข VPC IDs                            โ”‚
โ”‚    โ€ข VPN configuration                  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
          โ†“
    Production Cluster Ready! ๐ŸŽ‰

๐ŸŽฎ CLI Reference

Global Flags

All commands support these global flags:

Flag Short Default Description
--config -c ./cluster-config.yaml Path to configuration file
--stack -s production Pulumi stack name for multi-environment support
--verbose -v false Enable verbose output for debugging
--yes -y false Auto-approve without confirmation prompts
Command Overview
sloth-kubernetes
โ”œโ”€โ”€ deploy          Deploy a Kubernetes cluster
โ”œโ”€โ”€ destroy         Destroy a Kubernetes cluster
โ”œโ”€โ”€ status          Show cluster status and health
โ”œโ”€โ”€ kubeconfig      Get kubeconfig for kubectl access
โ”‚
โ”œโ”€โ”€ nodes           Node management
โ”‚   โ”œโ”€โ”€ list        List all cluster nodes
โ”‚   โ”œโ”€โ”€ add         Add nodes to existing pool
โ”‚   โ”œโ”€โ”€ remove      Remove node from cluster
โ”‚   โ”œโ”€โ”€ ssh         SSH into a node
โ”‚   โ””โ”€โ”€ upgrade     Upgrade Kubernetes version
โ”‚
โ”œโ”€โ”€ vpn             VPN management
โ”‚   โ”œโ”€โ”€ status      Show VPN mesh status
โ”‚   โ”œโ”€โ”€ peers       List VPN peers
โ”‚   โ”œโ”€โ”€ config      Get node WireGuard config
โ”‚   โ”œโ”€โ”€ test        Test VPN connectivity
โ”‚   โ””โ”€โ”€ join        Add machine to VPN
โ”‚
โ”œโ”€โ”€ addons          Addon management
โ”‚   โ”œโ”€โ”€ bootstrap   Bootstrap GitOps from repository
โ”‚   โ”œโ”€โ”€ list        List installed addons
โ”‚   โ””โ”€โ”€ install     Install specific addon
โ”‚
โ”œโ”€โ”€ config          Configuration utilities
โ”‚   โ”œโ”€โ”€ generate    Generate example config file
โ”‚   โ””โ”€โ”€ validate    Validate configuration file
โ”‚
โ”œโ”€โ”€ stacks          Stack management
โ”‚   โ”œโ”€โ”€ list        List all Pulumi stacks
โ”‚   โ”œโ”€โ”€ select      Switch active stack
โ”‚   โ””โ”€โ”€ delete      Delete a stack
โ”‚
โ”œโ”€โ”€ pulumi          ๐Ÿ†• Embedded Pulumi Automation API
โ”‚   โ””โ”€โ”€ [command]   Execute any Pulumi CLI command with backend config
โ”‚
โ”œโ”€โ”€ salt            ๐Ÿ†• Embedded Salt API Client (100+ operations)
โ”‚   โ”œโ”€โ”€ login       Login to Salt API using stack information
โ”‚   โ”œโ”€โ”€ ping        Test connectivity to all minions
โ”‚   โ”œโ”€โ”€ cmd         Execute shell commands on nodes
โ”‚   โ”œโ”€โ”€ grains      Get system information
โ”‚   โ”œโ”€โ”€ state       Execute Salt states
โ”‚   โ”œโ”€โ”€ pkg         Package management (install/remove/update)
โ”‚   โ”œโ”€โ”€ service     Service management (start/stop/restart/status)
โ”‚   โ”œโ”€โ”€ file        File operations (read/write/copy/remove)
โ”‚   โ”œโ”€โ”€ user        User management
โ”‚   โ”œโ”€โ”€ network     Network diagnostics and configuration
โ”‚   โ”œโ”€โ”€ system      System information and management
โ”‚   โ”œโ”€โ”€ docker      Docker container management
โ”‚   โ”œโ”€โ”€ kubernetes  Kubernetes operations via Salt
โ”‚   โ”œโ”€โ”€ security    Security auditing and hardening
โ”‚   โ””โ”€โ”€ custom      Execute custom Salt functions
โ”‚
โ”œโ”€โ”€ kubectl         ๐Ÿ†• Embedded kubectl Client (Full Functionality)
โ”‚   โ””โ”€โ”€ [any]       All standard kubectl commands supported
โ”‚       โ”œโ”€โ”€ get              Get resources
โ”‚       โ”œโ”€โ”€ apply            Apply configurations
โ”‚       โ”œโ”€โ”€ create           Create resources
โ”‚       โ”œโ”€โ”€ delete           Delete resources
โ”‚       โ”œโ”€โ”€ describe         Describe resources
โ”‚       โ”œโ”€โ”€ logs             View pod logs
โ”‚       โ”œโ”€โ”€ exec             Execute commands in containers
โ”‚       โ”œโ”€โ”€ port-forward     Forward ports to pods
โ”‚       โ”œโ”€โ”€ scale            Scale deployments
โ”‚       โ”œโ”€โ”€ rollout          Manage rollouts
โ”‚       โ”œโ”€โ”€ top              Display resource usage
โ”‚       โ””โ”€โ”€ ...              All kubectl commands available
โ”‚
โ””โ”€โ”€ version         Show version information

๐Ÿ“ฆ deploy

Deploy a complete Kubernetes cluster with VPC and VPN infrastructure.

Usage:

sloth-kubernetes deploy [flags]

Flags:

Flag Description
--config, -c Path to cluster configuration file
--stack, -s Pulumi stack name (default: "production")
--dry-run Preview changes without applying
--yes, -y Auto-approve without prompting
--verbose, -v Show detailed output

Examples:

# Basic deployment
sloth-kubernetes deploy --config cluster.yaml

# Preview changes before deploying (dry-run)
sloth-kubernetes deploy --config cluster.yaml --dry-run

# Deploy to specific stack
sloth-kubernetes deploy --config production.yaml --stack prod

# Auto-approve deployment (CI/CD)
sloth-kubernetes deploy --config cluster.yaml --yes

# Verbose output for debugging
sloth-kubernetes deploy --config cluster.yaml --verbose

Deployment Phases:

๐Ÿš€ Deploying cluster: production-cluster

Phase 1/3: VPC Creation
  โœ“ Creating DigitalOcean VPC (10.10.0.0/16)... Done
  โœ“ Creating Linode VPC (10.11.0.0/16)... Done

Phase 2/3: WireGuard VPN Setup
  โœ“ Deploying VPN server... Done
  โœ“ Generating encryption keys... Done
  โœ“ Configuring mesh networking... Done

Phase 3/3: Kubernetes Cluster
  โœ“ Generating SSH keys... Done
  โœ“ Creating master nodes (3)... Done
  โœ“ Creating worker nodes (3)... Done
  โœ“ Installing RKE2... Done
  โœ“ Configuring WireGuard on nodes... Done
  โœ“ Joining nodes to cluster... Done

โœ… Cluster deployed successfully!

๐Ÿ“Š Cluster Information:
  Name: production-cluster
  API Endpoint: 167.99.123.45:6443
  Kubernetes Version: v1.28.5+rke2r1

๐ŸŒ VPC Information:
  DigitalOcean VPC: vpc-abc123 (10.10.0.0/16)
  Linode VPC: vpc-def456 (10.11.0.0/16)

๐Ÿ” VPN Information:
  Server: 167.99.123.45:51820
  Subnet: 10.8.0.0/24

๐Ÿ“‹ Nodes:
  NAME              PROVIDER        ROLE     PUBLIC IP       VPN IP
  do-master-1       DigitalOcean    master   167.99.1.1      10.8.0.10
  do-master-2       DigitalOcean    master   167.99.1.2      10.8.0.11
  linode-master-1   Linode          master   172.104.1.1     10.8.0.12
  do-worker-1       DigitalOcean    worker   167.99.2.1      10.8.0.20
  do-worker-2       DigitalOcean    worker   167.99.2.2      10.8.0.21
  linode-worker-1   Linode          worker   172.104.2.1     10.8.0.22

โฑ  Total time: 8m 32s

Next steps:
  โ€ข Get kubeconfig: sloth-kubernetes kubeconfig
  โ€ข Check status: sloth-kubernetes status
  โ€ข Bootstrap GitOps: sloth-kubernetes addons bootstrap

๐Ÿ—‘๏ธ destroy

Destroy the entire cluster including all infrastructure.

Usage:

sloth-kubernetes destroy [flags]

Flags:

Flag Description
--stack, -s Pulumi stack name to destroy
--yes, -y Skip double confirmation
--force Force destroy even if resources are protected

Examples:

# Destroy with confirmation
sloth-kubernetes destroy --stack production

# Force destroy without confirmation (dangerous!)
sloth-kubernetes destroy --stack production --yes

# Destroy specific stack
sloth-kubernetes destroy --stack staging

Output:

โš ๏ธ  WARNING: This will destroy the entire cluster!

Cluster: production-cluster
Nodes: 6
VPCs: 2
Resources: 24

This action cannot be undone!

Type 'production-cluster' to confirm: production-cluster

๐Ÿ—‘๏ธ  Destroying cluster...
  โœ“ Removing nodes... Done
  โœ“ Destroying VPN server... Done
  โœ“ Deleting VPCs... Done
  โœ“ Cleaning up DNS records... Done

โœ… Cluster destroyed successfully
โฑ  Total time: 2m 15s

๐Ÿ“Š status

Display cluster health, node status, and resource information.

Usage:

sloth-kubernetes status [flags]

Flags:

Flag Description
--stack, -s Stack name
--format Output format: table, json, yaml
--watch, -w Watch mode (refresh every 5s)

Examples:

# Show status
sloth-kubernetes status

# JSON output
sloth-kubernetes status --format json

# Watch mode
sloth-kubernetes status --watch

# Specific stack
sloth-kubernetes status --stack staging

Output:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Cluster: production-cluster                                    โ”‚
โ”‚  Status: โœ… Healthy                                             โ”‚
โ”‚  Uptime: 3d 12h 45m                                             โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ“Š Cluster Info
  Kubernetes Version: v1.28.5+rke2r1
  API Endpoint: https://167.99.123.45:6443
  CNI: Calico

๐ŸŒ Network
  VPN Status: โœ… Active
  Mesh Peers: 6/6 connected

  DigitalOcean VPC: vpc-abc123 (10.10.0.0/16)
  Linode VPC: vpc-def456 (10.11.0.0/16)
  VPN Subnet: 10.8.0.0/24

๐Ÿ“‹ Nodes (6)

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ NAME             โ”‚ PROVIDER     โ”‚ ROLE   โ”‚ STATUS โ”‚ PUBLIC IP      โ”‚ VPN IP      โ”‚ UPTIME  โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚ DigitalOcean โ”‚ master โ”‚ โœ…     โ”‚ 167.99.1.1     โ”‚ 10.8.0.10   โ”‚ 3d 12h  โ”‚
โ”‚ do-master-2      โ”‚ DigitalOcean โ”‚ master โ”‚ โœ…     โ”‚ 167.99.1.2     โ”‚ 10.8.0.11   โ”‚ 3d 12h  โ”‚
โ”‚ linode-master-1  โ”‚ Linode       โ”‚ master โ”‚ โœ…     โ”‚ 172.104.1.1    โ”‚ 10.8.0.12   โ”‚ 3d 12h  โ”‚
โ”‚ do-worker-1      โ”‚ DigitalOcean โ”‚ worker โ”‚ โœ…     โ”‚ 167.99.2.1     โ”‚ 10.8.0.20   โ”‚ 3d 12h  โ”‚
โ”‚ do-worker-2      โ”‚ DigitalOcean โ”‚ worker โ”‚ โœ…     โ”‚ 167.99.2.2     โ”‚ 10.8.0.21   โ”‚ 3d 12h  โ”‚
โ”‚ linode-worker-1  โ”‚ Linode       โ”‚ worker โ”‚ โœ…     โ”‚ 172.104.2.1    โ”‚ 10.8.0.22   โ”‚ 3d 12h  โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ’ฐ Estimated Monthly Cost: $120/month

๐Ÿ”‘ kubeconfig

Retrieve kubeconfig for kubectl access.

Usage:

sloth-kubernetes kubeconfig [flags]

Flags:

Flag Description
--output, -o Output file (default: stdout)
--stack, -s Stack name
--merge Merge with existing kubeconfig

Examples:

# Print to stdout
sloth-kubernetes kubeconfig

# Save to file
sloth-kubernetes kubeconfig -o ~/.kube/config

# Merge with existing kubeconfig
sloth-kubernetes kubeconfig --merge -o ~/.kube/config

# Specific stack
sloth-kubernetes kubeconfig --stack production -o prod-kubeconfig.yaml

Usage:

# Get kubeconfig
sloth-kubernetes kubeconfig > ~/.kube/config

# Verify cluster access
kubectl get nodes
kubectl get pods --all-namespaces

๐Ÿ–ฅ๏ธ nodes

Manage cluster nodes (add, remove, SSH, upgrade).

nodes list

List all cluster nodes with detailed information.

Usage:

sloth-kubernetes nodes list [stack] [flags]

Flags:

Flag Description
--format Output format: table, json, yaml
--filter Filter by role, provider, or status

Examples:

# List all nodes
sloth-kubernetes nodes list

# List for specific stack
sloth-kubernetes nodes list production

# JSON output
sloth-kubernetes nodes list --format json

# Filter by role
sloth-kubernetes nodes list --filter role=master

# Filter by provider
sloth-kubernetes nodes list --filter provider=digitalocean

Output:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ NAME             โ”‚ PROVIDER     โ”‚ ROLE   โ”‚ PUBLIC IP       โ”‚ PRIVATE IP  โ”‚ SIZE         โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚ DigitalOcean โ”‚ master โ”‚ 167.99.1.1      โ”‚ 10.10.0.2   โ”‚ s-2vcpu-4gb  โ”‚
โ”‚ do-master-2      โ”‚ DigitalOcean โ”‚ master โ”‚ 167.99.1.2      โ”‚ 10.10.0.3   โ”‚ s-2vcpu-4gb  โ”‚
โ”‚ linode-master-1  โ”‚ Linode       โ”‚ master โ”‚ 172.104.1.1     โ”‚ 10.11.0.2   โ”‚ g6-standard-2โ”‚
โ”‚ do-worker-1      โ”‚ DigitalOcean โ”‚ worker โ”‚ 167.99.2.1      โ”‚ 10.10.0.10  โ”‚ s-2vcpu-4gb  โ”‚
โ”‚ do-worker-2      โ”‚ DigitalOcean โ”‚ worker โ”‚ 167.99.2.2      โ”‚ 10.10.0.11  โ”‚ s-2vcpu-4gb  โ”‚
โ”‚ linode-worker-1  โ”‚ Linode       โ”‚ worker โ”‚ 172.104.2.1     โ”‚ 10.11.0.10  โ”‚ g6-standard-2โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Total: 6 nodes (3 masters, 3 workers)
nodes add

Add nodes to an existing node pool (horizontal scaling).

Usage:

sloth-kubernetes nodes add [stack] [flags]

Flags:

Flag Description
--pool Node pool name to scale
--count Number of nodes to add
--yes, -y Auto-approve

Examples:

# Add 2 workers to pool
sloth-kubernetes nodes add --pool workers --count 2

# Add nodes with auto-approve
sloth-kubernetes nodes add --pool workers --count 3 --yes

Output:

๐Ÿš€ Adding 2 nodes to pool: workers

  โœ“ Updating Pulumi stack... Done
  โœ“ Creating nodes... Done
  โœ“ Installing RKE2... Done
  โœ“ Configuring WireGuard... Done
  โœ“ Joining to cluster... Done

โœ… Added 2 nodes successfully

New nodes:
  โ€ข do-worker-4 (167.99.2.4)
  โ€ข do-worker-5 (167.99.2.5)

โฑ  Total time: 4m 12s
nodes remove

Remove a node from the cluster.

Usage:

sloth-kubernetes nodes remove [stack] [node-name] [flags]

Flags:

Flag Description
--drain Drain node before removing
--force Force removal without draining
--yes, -y Auto-approve

Examples:

# Remove node with drain
sloth-kubernetes nodes remove production do-worker-5 --drain

# Force remove
sloth-kubernetes nodes remove production do-worker-5 --force --yes

Output:

โš ๏ธ  Removing node: do-worker-5

  โœ“ Draining node... Done (moved 12 pods)
  โœ“ Removing from cluster... Done
  โœ“ Deleting droplet... Done
  โœ“ Cleaning up WireGuard config... Done

โœ… Node removed successfully
nodes ssh

SSH into a cluster node.

Usage:

sloth-kubernetes nodes ssh [stack] [node-name] [flags]

Flags:

Flag Description
--bastion Use bastion host for access
--command, -c Execute command and exit
--user, -u SSH user (default: root)

Examples:

# SSH into node
sloth-kubernetes nodes ssh production do-master-1

# Execute command
sloth-kubernetes nodes ssh production do-master-1 -c "kubectl get nodes"

# Via bastion
sloth-kubernetes nodes ssh production do-worker-1 --bastion

# Custom user
sloth-kubernetes nodes ssh production do-worker-1 -u admin
nodes upgrade

Upgrade Kubernetes version on all nodes.

Usage:

sloth-kubernetes nodes upgrade [stack] [flags]

Flags:

Flag Description
--version Target Kubernetes version
--rolling Perform rolling upgrade (one node at a time)
--yes, -y Auto-approve

Examples:

# Upgrade to specific version
sloth-kubernetes nodes upgrade production --version v1.29.0+rke2r1 --rolling

# With auto-approve
sloth-kubernetes nodes upgrade production --version v1.29.0+rke2r1 --yes

๐Ÿ” vpn

Manage WireGuard VPN mesh network.

vpn status

Show VPN mesh status and connectivity.

Usage:

sloth-kubernetes vpn status [stack] [flags]

Examples:

# Show VPN status
sloth-kubernetes vpn status production

Output:

๐Ÿ” WireGuard VPN Status

Server: 167.99.123.45:51820
Subnet: 10.8.0.0/24
Mode: Mesh Networking

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ PEER             โ”‚ VPN IP      โ”‚ STATUS     โ”‚ LAST SEEN   โ”‚ TRANSFER   โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚ 10.8.0.10   โ”‚ โœ… Active  โ”‚ 5s ago      โ”‚ โ†“1.2GB โ†‘890MB โ”‚
โ”‚ do-master-2      โ”‚ 10.8.0.11   โ”‚ โœ… Active  โ”‚ 3s ago      โ”‚ โ†“980MB โ†‘750MB โ”‚
โ”‚ linode-master-1  โ”‚ 10.8.0.12   โ”‚ โœ… Active  โ”‚ 2s ago      โ”‚ โ†“1.1GB โ†‘820MB โ”‚
โ”‚ do-worker-1      โ”‚ 10.8.0.20   โ”‚ โœ… Active  โ”‚ 1s ago      โ”‚ โ†“2.3GB โ†‘1.2GB โ”‚
โ”‚ do-worker-2      โ”‚ 10.8.0.21   โ”‚ โœ… Active  โ”‚ 4s ago      โ”‚ โ†“1.8GB โ†‘980MB โ”‚
โ”‚ linode-worker-1  โ”‚ 10.8.0.22   โ”‚ โœ… Active  โ”‚ 6s ago      โ”‚ โ†“1.5GB โ†‘890MB โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Mesh Connectivity: 6/6 peers connected (100%)
vpn peers

List all VPN peers with connection details.

Usage:

sloth-kubernetes vpn peers [stack] [flags]

Flags:

Flag Description
--format Output format: table, json, yaml

Examples:

# List peers
sloth-kubernetes vpn peers production

# JSON output
sloth-kubernetes vpn peers production --format json
vpn config

Get WireGuard configuration for a specific node.

Usage:

sloth-kubernetes vpn config [stack] [node-name] [flags]

Flags:

Flag Description
--output, -o Output to file
--qr Generate QR code

Examples:

# Get config
sloth-kubernetes vpn config production do-worker-1

# Save to file
sloth-kubernetes vpn config production do-worker-1 -o wg0.conf

# Generate QR code (for mobile)
sloth-kubernetes vpn config production do-worker-1 --qr

Output:

[Interface]
PrivateKey = <generated-private-key>
Address = 10.8.0.20/24
DNS = 1.1.1.1, 8.8.8.8

[Peer]
PublicKey = <server-public-key>
Endpoint = 167.99.123.45:51820
AllowedIPs = 10.8.0.0/24, 10.10.0.0/16, 10.11.0.0/16
PersistentKeepalive = 25
vpn test

Test VPN connectivity between nodes.

Usage:

sloth-kubernetes vpn test [stack] [flags]

Examples:

# Test connectivity
sloth-kubernetes vpn test production

Output:

๐Ÿงช Testing VPN connectivity...

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ Peer-to-Peer Connectivity Test                          โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1 โ†’ do-master-2         โœ… 2ms               โ”‚
โ”‚ do-master-1 โ†’ linode-master-1     โœ… 45ms              โ”‚
โ”‚ do-master-2 โ†’ linode-worker-1     โœ… 48ms              โ”‚
โ”‚ linode-master-1 โ†’ do-worker-1     โœ… 43ms              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โœ… All peers reachable
๐Ÿ“Š Average latency: 34ms
vpn join

Add a local or remote machine to the VPN mesh.

Usage:

sloth-kubernetes vpn join [stack] [flags]

Flags:

Flag Description
--name Machine name
--output, -o Output config file

Examples:

# Join local machine
sloth-kubernetes vpn join production --name my-laptop -o wg0.conf

# Then on your machine:
sudo cp wg0.conf /etc/wireguard/
sudo wg-quick up wg0

๐ŸŽฏ addons

Manage cluster addons and GitOps automation.

addons bootstrap

Bootstrap ArgoCD from a Git repository for GitOps workflow.

Usage:

sloth-kubernetes addons bootstrap [flags]

Flags:

Flag Description
--repo Git repository URL
--branch Git branch (default: main)
--path Path in repository (default: /)
--yes, -y Auto-approve

Examples:

# Bootstrap from Git repository
sloth-kubernetes addons bootstrap \
  --repo https://github.com/yourorg/k8s-gitops \
  --branch main

# Custom path
sloth-kubernetes addons bootstrap \
  --repo https://github.com/yourorg/k8s-gitops \
  --path clusters/production

Output:

๐Ÿš€ Bootstrapping GitOps...

Repository: https://github.com/yourorg/k8s-gitops
Branch: main
Path: /

  โœ“ Installing ArgoCD... Done
  โœ“ Configuring repository access... Done
  โœ“ Creating root application... Done
  โœ“ Syncing applications... Done

โœ… GitOps bootstrapped successfully!

๐ŸŒ Access ArgoCD:
  kubectl port-forward svc/argocd-server -n argocd 8080:443
  URL: https://localhost:8080
  User: admin
  Password: (run: kubectl get secret argocd-initial-admin-secret -n argocd -o jsonpath="{.data.password}" | base64 -d)

๐Ÿ“‹ Applications syncing:
  โ€ข cert-manager
  โ€ข ingress-nginx
  โ€ข monitoring-stack
  โ€ข vault
addons list

List all installed addons.

Usage:

sloth-kubernetes addons list [flags]

Examples:

# List addons
sloth-kubernetes addons list

Output:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ ADDON               โ”‚ VERSION    โ”‚ STATUS     โ”‚ NAMESPACE  โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ argocd              โ”‚ v2.9.3     โ”‚ โœ… Synced  โ”‚ argocd     โ”‚
โ”‚ cert-manager        โ”‚ v1.13.3    โ”‚ โœ… Synced  โ”‚ cert-mgr   โ”‚
โ”‚ ingress-nginx       โ”‚ v1.9.5     โ”‚ โœ… Synced  โ”‚ ingress    โ”‚
โ”‚ prometheus          โ”‚ v2.48.0    โ”‚ โœ… Synced  โ”‚ monitoring โ”‚
โ”‚ grafana             โ”‚ v10.2.3    โ”‚ โœ… Synced  โ”‚ monitoring โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
addons install

Install a specific addon from catalog.

Usage:

sloth-kubernetes addons install [addon-name] [flags]

Examples:

# Install cert-manager
sloth-kubernetes addons install cert-manager

# Install with custom values
sloth-kubernetes addons install prometheus --values custom-values.yaml

โš™๏ธ config

Configuration file utilities.

config generate

Generate example configuration file.

Usage:

sloth-kubernetes config generate [flags]

Flags:

Flag Description
--type Config type: minimal, basic, advanced, multi-cloud
--output, -o Output file (default: stdout)

Examples:

# Generate minimal config
sloth-kubernetes config generate --type minimal > cluster.yaml

# Generate multi-cloud config
sloth-kubernetes config generate --type multi-cloud -o production.yaml

# Generate with VPC/VPN
sloth-kubernetes config generate --type advanced -o advanced.yaml
config validate

Validate configuration file.

Usage:

sloth-kubernetes config validate [flags]

Flags:

Flag Description
--file, -f Config file to validate

Examples:

# Validate config
sloth-kubernetes config validate -f cluster.yaml

Output:

โœ… Configuration valid

Cluster: production-cluster
Providers: DigitalOcean, Linode
Node Pools: 4 (2 master, 2 worker)
Total Nodes: 6
VPC: Auto-create (2)
VPN: Auto-create (WireGuard)

๐Ÿ“š stacks

Manage Pulumi stacks for multi-environment support.

stacks list

List all available stacks.

Usage:

sloth-kubernetes stacks list

Output:

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ STACK         โ”‚ ACTIVE     โ”‚ LAST UPDATE             โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ production    โ”‚ โœ…         โ”‚ 2025-01-15 14:30:22     โ”‚
โ”‚ staging       โ”‚            โ”‚ 2025-01-14 09:15:10     โ”‚
โ”‚ development   โ”‚            โ”‚ 2025-01-10 16:45:33     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ”ง pulumi

Execute Pulumi CLI commands with sloth-kubernetes backend configuration automatically loaded.

This command acts as a wrapper around the Pulumi CLI, ensuring that your sloth-kubernetes backend configuration (S3/MinIO) is properly loaded before executing any Pulumi command.

Usage:

sloth-kubernetes pulumi [command] [flags]

Common Commands:

Command Description
stack output Show stack outputs
stack export Export stack state to JSON
stack import Import stack state from JSON
stack ls List all stacks
preview Preview infrastructure changes
refresh Refresh stack state from cloud
config Manage stack configuration

Examples:

# Show all stack outputs
sloth-kubernetes pulumi stack output

# Show specific output with secrets
sloth-kubernetes pulumi stack output kubeConfig --show-secrets

# Export stack state for backup
sloth-kubernetes pulumi stack export --stack production > backup.json

# Import stack state
sloth-kubernetes pulumi stack import --stack production < backup.json

# Preview infrastructure changes
sloth-kubernetes pulumi preview

# Refresh stack state
sloth-kubernetes pulumi refresh

# List all stacks
sloth-kubernetes pulumi stack list

Requirements:

  • โœ… No Pulumi CLI required! Uses embedded Pulumi Automation API
  • All operations work directly through sloth-kubernetes binary

Notes:

  • Uses embedded Pulumi Automation API (no external CLI needed)
  • Backend configuration (S3/MinIO) is automatically loaded from sloth-kubernetes settings
  • Common Pulumi operations available without installing additional tools

๐Ÿง‚ salt

Execute remote commands and manage configuration on cluster nodes using the embedded Salt API client.

Salt provides 100+ operations across 22 categories for complete node management without SSH.

salt login

Automatically login to Salt API using your Pulumi stack information.

Usage:

sloth-kubernetes salt login [flags]

Flags:

Flag Description
--stack Pulumi stack name (auto-detects bastion IP)
--config Path to cluster config file
--skip-verify Skip connection verification

Examples:

# Login using current stack (auto-detects bastion)
sloth-kubernetes salt login

# Login to specific stack
sloth-kubernetes salt login --stack production

# Login with custom config
sloth-kubernetes salt login --config cluster.yaml

# Skip connection test
sloth-kubernetes salt login --skip-verify

Output:

๐Ÿ” Salt API Login

๐Ÿ“ฆ Loading Pulumi workspace...
๐Ÿ“š Using stack: production
โœ“ Using stack: production
๐Ÿ”„ Refreshing stack outputs...
๐Ÿ“Š Retrieving bastion information...
โœ“ Found bastion host: 167.99.123.45

๐ŸŒ Salt API URL: http://167.99.123.45:8000
๐Ÿ‘ค Username: saltapi
๐Ÿ”Œ Testing connection to Salt API...
โœ“ Successfully authenticated to Salt API

๐Ÿ“ก Testing minion connectivity...
โœ“ Connected to 6 minion(s)

โœ“ Configuration saved to ~/.sloth-kubernetes/salt-config.json

โœ… Login Complete!

You can now use Salt commands without additional configuration:

  sloth-kubernetes salt ping
  sloth-kubernetes salt cmd "uptime"
  sloth-kubernetes salt system disk

After Login: All subsequent salt commands automatically use the saved configuration. No need to specify API URL, credentials, or bastion IP.


salt ping

Test connectivity to all minions (nodes).

Usage:

sloth-kubernetes salt ping [flags]

Flags:

Flag Description
--target, -t Target pattern (default: "*" = all)
--timeout Command timeout in seconds

Examples:

# Ping all minions
sloth-kubernetes salt ping

# Ping specific minion
sloth-kubernetes salt ping -t "do-master-1"

# Ping by role
sloth-kubernetes salt ping -t "G@roles:master"

# Ping by provider
sloth-kubernetes salt ping -t "G@cloud:digitalocean"

Output:

๐Ÿ“ก Pinging Salt minions...

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ MINION           โ”‚ STATUS   โ”‚ RESPONSE   โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚ โœ…       โ”‚ True       โ”‚
โ”‚ do-master-2      โ”‚ โœ…       โ”‚ True       โ”‚
โ”‚ linode-master-1  โ”‚ โœ…       โ”‚ True       โ”‚
โ”‚ do-worker-1      โ”‚ โœ…       โ”‚ True       โ”‚
โ”‚ do-worker-2      โ”‚ โœ…       โ”‚ True       โ”‚
โ”‚ linode-worker-1  โ”‚ โœ…       โ”‚ True       โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โœ… 6/6 minions responding

salt cmd

Execute shell commands on cluster nodes.

Usage:

sloth-kubernetes salt cmd <command> [flags]

Flags:

Flag Description
--target, -t Target minions (default: "*")
--json Output in JSON format
--timeout Command timeout

Examples:

# Run command on all nodes
sloth-kubernetes salt cmd "uptime"

# Check disk space on workers
sloth-kubernetes salt cmd "df -h" -t "G@roles:worker"

# Get kernel version
sloth-kubernetes salt cmd "uname -r"

# Check memory usage
sloth-kubernetes salt cmd "free -h"

# List running containers
sloth-kubernetes salt cmd "crictl ps"

# JSON output
sloth-kubernetes salt cmd "hostname" --json

Output:

๐Ÿ”ง Executing command: uptime

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ MINION           โ”‚ OUTPUT                                      โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚  14:30:22 up 3 days,  4:15,  load: 0.52    โ”‚
โ”‚ do-master-2      โ”‚  14:30:22 up 3 days,  4:12,  load: 0.48    โ”‚
โ”‚ linode-master-1  โ”‚  14:30:23 up 3 days,  4:10,  load: 0.61    โ”‚
โ”‚ do-worker-1      โ”‚  14:30:22 up 3 days,  4:14,  load: 1.23    โ”‚
โ”‚ do-worker-2      โ”‚  14:30:23 up 3 days,  4:13,  load: 0.98    โ”‚
โ”‚ linode-worker-1  โ”‚  14:30:24 up 3 days,  4:11,  load: 1.45    โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โœ… Command executed on 6 minions

salt system

System information and diagnostics across 15+ sub-commands.

Available Commands:

sloth-kubernetes salt system disk      # Disk usage
sloth-kubernetes salt system memory    # Memory usage
sloth-kubernetes salt system cpu       # CPU information
sloth-kubernetes salt system uptime    # System uptime
sloth-kubernetes salt system kernel    # Kernel version
sloth-kubernetes salt system load      # Load average
sloth-kubernetes salt system processes # Running processes
sloth-kubernetes salt system network   # Network interfaces
sloth-kubernetes salt system date      # System date/time
sloth-kubernetes salt system timezone  # Timezone info
sloth-kubernetes salt system hostname  # Hostname
sloth-kubernetes salt system reboot    # Reboot nodes
sloth-kubernetes salt system shutdown  # Shutdown nodes

Examples:

# Check disk usage across all nodes
sloth-kubernetes salt system disk

# Memory usage
sloth-kubernetes salt system memory

# CPU information
sloth-kubernetes salt system cpu -t "do-*"

# System uptime
sloth-kubernetes salt system uptime

# Top processes
sloth-kubernetes salt system processes --top 10

Output (disk):

๐Ÿ’พ Disk Usage

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ MINION           โ”‚ SIZE    โ”‚ USED โ”‚ AVAIL  โ”‚ USE% โ”‚ MOUNTED ON  โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚ 80G     โ”‚ 35G  โ”‚ 41G    โ”‚ 46%  โ”‚ /           โ”‚
โ”‚ do-master-2      โ”‚ 80G     โ”‚ 32G  โ”‚ 44G    โ”‚ 42%  โ”‚ /           โ”‚
โ”‚ linode-master-1  โ”‚ 80G     โ”‚ 38G  โ”‚ 38G    โ”‚ 50%  โ”‚ /           โ”‚
โ”‚ do-worker-1      โ”‚ 160G    โ”‚ 89G  โ”‚ 63G    โ”‚ 59%  โ”‚ /           โ”‚
โ”‚ do-worker-2      โ”‚ 160G    โ”‚ 92G  โ”‚ 60G    โ”‚ 61%  โ”‚ /           โ”‚
โ”‚ linode-worker-1  โ”‚ 160G    โ”‚ 78G  โ”‚ 74G    โ”‚ 51%  โ”‚ /           โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

salt pkg

Package management (install, update, remove packages).

Available Commands:

sloth-kubernetes salt pkg install <package>    # Install package
sloth-kubernetes salt pkg remove <package>     # Remove package
sloth-kubernetes salt pkg update <package>     # Update package
sloth-kubernetes salt pkg upgrade              # Upgrade all packages
sloth-kubernetes salt pkg list                 # List installed packages
sloth-kubernetes salt pkg search <term>        # Search for packages
sloth-kubernetes salt pkg info <package>       # Package information

Examples:

# Install package on all nodes
sloth-kubernetes salt pkg install htop

# Install on specific nodes
sloth-kubernetes salt pkg install vim -t "G@roles:master"

# Update package
sloth-kubernetes salt pkg update nginx

# Upgrade all packages
sloth-kubernetes salt pkg upgrade

# Remove package
sloth-kubernetes salt pkg remove apache2

# List installed packages
sloth-kubernetes salt pkg list

# Search for package
sloth-kubernetes salt pkg search docker

salt service

Service management (start, stop, restart, status).

Available Commands:

sloth-kubernetes salt service start <service>      # Start service
sloth-kubernetes salt service stop <service>       # Stop service
sloth-kubernetes salt service restart <service>    # Restart service
sloth-kubernetes salt service status <service>     # Service status
sloth-kubernetes salt service enable <service>     # Enable at boot
sloth-kubernetes salt service disable <service>    # Disable at boot
sloth-kubernetes salt service list                 # List all services

Examples:

# Check RKE2 status on all nodes
sloth-kubernetes salt service status rke2-server

# Restart kubelet
sloth-kubernetes salt service restart kubelet

# Start Docker
sloth-kubernetes salt service start docker

# Enable service at boot
sloth-kubernetes salt service enable containerd

# List all running services
sloth-kubernetes salt service list --running

Output:

๐Ÿ”ง Service Status: rke2-server

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ MINION           โ”‚ STATUS    โ”‚ ENABLED โ”‚ UPTIME   โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ do-master-1      โ”‚ โœ… Active โ”‚ Yes     โ”‚ 3d 4h    โ”‚
โ”‚ do-master-2      โ”‚ โœ… Active โ”‚ Yes     โ”‚ 3d 4h    โ”‚
โ”‚ linode-master-1  โ”‚ โœ… Active โ”‚ Yes     โ”‚ 3d 4h    โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

salt docker

Docker container management.

Available Commands:

sloth-kubernetes salt docker ps                    # List containers
sloth-kubernetes salt docker images                # List images
sloth-kubernetes salt docker inspect <container>   # Inspect container
sloth-kubernetes salt docker logs <container>      # Container logs
sloth-kubernetes salt docker stats                 # Container stats
sloth-kubernetes salt docker prune                 # Clean up

Examples:

# List running containers
sloth-kubernetes salt docker ps

# List all containers (including stopped)
sloth-kubernetes salt docker ps --all

# Docker images
sloth-kubernetes salt docker images

# Container stats
sloth-kubernetes salt docker stats

# Clean up unused images
sloth-kubernetes salt docker prune -t "G@roles:worker"

salt kubernetes

Kubernetes-specific operations via Salt.

Available Commands:

sloth-kubernetes salt kubernetes pods              # List pods
sloth-kubernetes salt kubernetes nodes             # Node status
sloth-kubernetes salt kubernetes namespaces        # List namespaces
sloth-kubernetes salt kubernetes deployments       # List deployments
sloth-kubernetes salt kubernetes services          # List services
sloth-kubernetes salt kubernetes logs <pod>        # Pod logs
sloth-kubernetes salt kubernetes describe <resource> # Describe resource

Examples:

# Get all pods across cluster
sloth-kubernetes salt kubernetes pods

# Check node status
sloth-kubernetes salt kubernetes nodes

# List deployments
sloth-kubernetes salt kubernetes deployments -n default

# Get pod logs
sloth-kubernetes salt kubernetes logs nginx-123 -n default

salt network

Network diagnostics and configuration.

Available Commands:

sloth-kubernetes salt network ping <host>          # Ping host
sloth-kubernetes salt network traceroute <host>    # Traceroute
sloth-kubernetes salt network dig <domain>         # DNS lookup
sloth-kubernetes salt network interfaces           # Network interfaces
sloth-kubernetes salt network connections          # Active connections
sloth-kubernetes salt network stats                # Network statistics
sloth-kubernetes salt network speed                # Speed test

Examples:

# Test connectivity between nodes
sloth-kubernetes salt network ping 10.8.0.1

# Check network interfaces
sloth-kubernetes salt network interfaces

# DNS lookup
sloth-kubernetes salt network dig kubernetes.default.svc

# Active connections
sloth-kubernetes salt network connections

# Traceroute to external host
sloth-kubernetes salt network traceroute 8.8.8.8

salt security

Security auditing and hardening.

Available Commands:

sloth-kubernetes salt security audit               # Security audit
sloth-kubernetes salt security firewall            # Firewall status
sloth-kubernetes salt security ports               # Open ports
sloth-kubernetes salt security ssh-keys            # SSH keys
sloth-kubernetes salt security users               # User accounts
sloth-kubernetes salt security updates             # Available updates
sloth-kubernetes salt security vulnerabilities     # CVE scan

Examples:

# Full security audit
sloth-kubernetes salt security audit

# Check firewall status
sloth-kubernetes salt security firewall

# List open ports
sloth-kubernetes salt security ports

# Check for security updates
sloth-kubernetes salt security updates

Salt Targeting Patterns

Salt supports powerful targeting to execute commands on specific nodes:

# All minions (default)
sloth-kubernetes salt ping -t "*"

# Specific minion
sloth-kubernetes salt ping -t "do-master-1"

# Glob pattern
sloth-kubernetes salt ping -t "do-*"
sloth-kubernetes salt ping -t "*-master-*"

# Grain matching (metadata)
sloth-kubernetes salt cmd "uptime" -t "G@roles:master"
sloth-kubernetes salt cmd "uptime" -t "G@cloud:digitalocean"
sloth-kubernetes salt cmd "uptime" -t "G@os:Ubuntu"

# Compound targeting (AND/OR/NOT)
sloth-kubernetes salt cmd "uptime" -t "G@roles:worker and G@cloud:linode"
sloth-kubernetes salt cmd "uptime" -t "G@roles:master or G@roles:worker"

# List targeting
sloth-kubernetes salt cmd "uptime" -t "do-master-1,do-master-2,do-master-3"

โ˜ธ๏ธ kubectl

Execute kubectl commands using the embedded Kubernetes client.

Full kubectl functionality is available without needing a separate kubectl installation.

Usage:

sloth-kubernetes kubectl [kubectl-command] [flags]

All Standard kubectl Commands Supported:

Resource Management
# Get resources
sloth-kubernetes kubectl get nodes
sloth-kubernetes kubectl get pods
sloth-kubernetes kubectl get deployments
sloth-kubernetes kubectl get services
sloth-kubernetes kubectl get pods -A                    # All namespaces
sloth-kubernetes kubectl get pods -n kube-system        # Specific namespace
sloth-kubernetes kubectl get pods -o wide               # More details
sloth-kubernetes kubectl get pods -o json               # JSON output
sloth-kubernetes kubectl get pods -w                    # Watch mode

# Describe resources
sloth-kubernetes kubectl describe node do-master-1
sloth-kubernetes kubectl describe pod nginx-123
sloth-kubernetes kubectl describe deployment webapp

# Create resources
sloth-kubernetes kubectl create deployment nginx --image=nginx
sloth-kubernetes kubectl create namespace production
sloth-kubernetes kubectl create configmap app-config --from-file=config.yaml

# Apply configurations
sloth-kubernetes kubectl apply -f deployment.yaml
sloth-kubernetes kubectl apply -f https://example.com/manifest.yaml
sloth-kubernetes kubectl apply -k ./kustomize-dir

# Delete resources
sloth-kubernetes kubectl delete pod nginx-123
sloth-kubernetes kubectl delete deployment webapp
sloth-kubernetes kubectl delete -f deployment.yaml
Pod Operations
# View logs
sloth-kubernetes kubectl logs nginx-123
sloth-kubernetes kubectl logs nginx-123 -f                     # Follow logs
sloth-kubernetes kubectl logs nginx-123 --tail=100             # Last 100 lines
sloth-kubernetes kubectl logs nginx-123 --since=1h             # Last hour
sloth-kubernetes kubectl logs nginx-123 -c container-name      # Specific container

# Execute commands in pods
sloth-kubernetes kubectl exec nginx-123 -- ls /app
sloth-kubernetes kubectl exec nginx-123 -- cat /etc/hostname
sloth-kubernetes kubectl exec -it nginx-123 -- bash            # Interactive shell
sloth-kubernetes kubectl exec -it nginx-123 -c app -- sh       # Specific container

# Copy files to/from pods
sloth-kubernetes kubectl cp ./local-file nginx-123:/remote-path
sloth-kubernetes kubectl cp nginx-123:/remote-file ./local-path

# Port forwarding
sloth-kubernetes kubectl port-forward pod/nginx-123 8080:80
sloth-kubernetes kubectl port-forward svc/webapp 8080:80
sloth-kubernetes kubectl port-forward deployment/webapp 8080:80

# Attach to running container
sloth-kubernetes kubectl attach nginx-123 -i
Deployment Management
# Scale deployments
sloth-kubernetes kubectl scale deployment webapp --replicas=5
sloth-kubernetes kubectl scale deployment webapp --replicas=0  # Scale to zero

# Autoscale
sloth-kubernetes kubectl autoscale deployment webapp --min=2 --max=10 --cpu-percent=80

# Rollout management
sloth-kubernetes kubectl rollout status deployment/webapp
sloth-kubernetes kubectl rollout history deployment/webapp
sloth-kubernetes kubectl rollout undo deployment/webapp        # Rollback
sloth-kubernetes kubectl rollout restart deployment/webapp     # Restart

# Set image
sloth-kubernetes kubectl set image deployment/webapp app=nginx:1.19
Configuration & Secrets
# ConfigMaps
sloth-kubernetes kubectl create configmap app-config --from-file=config.yaml
sloth-kubernetes kubectl get configmap app-config -o yaml
sloth-kubernetes kubectl describe configmap app-config

# Secrets
sloth-kubernetes kubectl create secret generic db-password --from-literal=password=secret123
sloth-kubernetes kubectl create secret docker-registry regcred \
  --docker-server=registry.example.com \
  --docker-username=user \
  --docker-password=pass

sloth-kubernetes kubectl get secrets
sloth-kubernetes kubectl describe secret db-password
Cluster Information
# Cluster info
sloth-kubernetes kubectl cluster-info
sloth-kubernetes kubectl cluster-info dump

# API resources
sloth-kubernetes kubectl api-resources
sloth-kubernetes kubectl api-versions

# Node information
sloth-kubernetes kubectl top nodes
sloth-kubernetes kubectl top pods
sloth-kubernetes kubectl top pods -A

# Events
sloth-kubernetes kubectl get events
sloth-kubernetes kubectl get events --sort-by='.lastTimestamp'
sloth-kubernetes kubectl get events -w                          # Watch events
Troubleshooting
# Debug pod
sloth-kubernetes kubectl debug node/do-worker-1 -it --image=busybox
sloth-kubernetes kubectl debug pod/nginx-123 -it --image=busybox --copy-to=debug-pod

# Get pod YAML
sloth-kubernetes kubectl get pod nginx-123 -o yaml

# Explain resources
sloth-kubernetes kubectl explain pods
sloth-kubernetes kubectl explain deployment.spec

# Diff
sloth-kubernetes kubectl diff -f deployment.yaml

# Dry run
sloth-kubernetes kubectl apply -f deployment.yaml --dry-run=client
sloth-kubernetes kubectl create deployment test --image=nginx --dry-run=client -o yaml

Examples - Complete Workflow:

# 1. Check cluster nodes
sloth-kubernetes kubectl get nodes

# 2. Deploy application
cat <<EOF | sloth-kubernetes kubectl apply -f -
apiVersion: apps/v1
kind: Deployment
metadata:
  name: webapp
spec:
  replicas: 3
  selector:
    matchLabels:
      app: webapp
  template:
    metadata:
      labels:
        app: webapp
    spec:
      containers:
      - name: nginx
        image: nginx:1.19
        ports:
        - containerPort: 80
EOF

# 3. Expose as service
sloth-kubernetes kubectl expose deployment webapp --port=80 --type=LoadBalancer

# 4. Check status
sloth-kubernetes kubectl get deployments
sloth-kubernetes kubectl get pods
sloth-kubernetes kubectl get services

# 5. View logs
sloth-kubernetes kubectl logs -l app=webapp

# 6. Scale up
sloth-kubernetes kubectl scale deployment webapp --replicas=5

# 7. Update image
sloth-kubernetes kubectl set image deployment/webapp nginx=nginx:1.20

# 8. Check rollout
sloth-kubernetes kubectl rollout status deployment/webapp

# 9. Get service endpoint
sloth-kubernetes kubectl get svc webapp

Kubeconfig Auto-detection:

kubectl automatically detects kubeconfig from:

  1. --kubeconfig flag
  2. KUBECONFIG environment variable
  3. ~/.kube/config (default)
  4. Kubeconfig from Pulumi stack (via sloth-kubernetes kubeconfig)

Examples:

# Use default kubeconfig
sloth-kubernetes kubectl get nodes

# Use custom kubeconfig
sloth-kubernetes kubectl --kubeconfig=./my-config get nodes

# Set KUBECONFIG env var
export KUBECONFIG=~/.kube/production-config
sloth-kubernetes kubectl get nodes

# Get kubeconfig from stack and use it
sloth-kubernetes kubeconfig > ~/.kube/config
sloth-kubernetes kubectl get nodes

๐Ÿ“Œ version

Display version information.

Usage:

sloth-kubernetes version

Output:

Sloth Kubernetes v1.0.0

Build Information:
  Go Version: go1.23.1
  Commit: 2d605b4
  Built: 2025-01-15T10:30:00Z
  OS/Arch: darwin/arm64

Dependencies:
  Pulumi: v3.203.0
  Cobra: v1.10.1

๐Ÿ“‹ Configuration Guide

Configuration File Structure

Sloth Kubernetes uses Kubernetes-style YAML configuration:

apiVersion: kubernetes-create.io/v1
kind: Cluster

metadata:
  name: cluster-name
  environment: production
  labels:
    key: value

spec:
  providers: {}
  network: {}
  kubernetes: {}
  nodePools: []
  security: {}
  addons: {}
Complete Configuration Reference
๐Ÿ“ฆ Providers Configuration
providers:
  digitalocean:
    enabled: true
    token: ${DIGITALOCEAN_TOKEN}  # Environment variable
    region: nyc3                   # Default region
    monitoring: true               # Enable monitoring
    backups: false                 # Enable backups

    vpc:
      create: true                 # Auto-create VPC
      name: k8s-vpc-do
      cidr: 10.10.0.0/16
      region: nyc3
      enableDns: true
      tags:
        - kubernetes
        - production

  linode:
    enabled: true
    token: ${LINODE_TOKEN}
    region: us-east
    privateIp: true

    vpc:
      create: true
      name: k8s-vpc-linode
      cidr: 10.11.0.0/16
      region: us-east
      enableDns: true
      subnets:
        - label: k8s-subnet-1
          ipv4: 10.11.1.0/24

Supported Regions:

Provider Regions
DigitalOcean nyc1, nyc3, sfo3, ams3, sgp1, lon1, fra1, tor1, blr1, syd1
Linode us-east, us-west, eu-west, eu-central, ap-south, ap-northeast
๐ŸŒ Network Configuration
network:
  mode: wireguard              # VPN mode
  cidr: 10.8.0.0/16           # Cluster network CIDR
  podCidr: 10.244.0.0/16      # Pod network CIDR
  serviceCidr: 10.96.0.0/12   # Service network CIDR
  crossProviderNetworking: true
  enableNodePorts: true

  # WireGuard VPN Configuration
  wireguard:
    create: true                    # Auto-create VPN server
    provider: digitalocean          # Provider to host VPN
    region: nyc3
    size: s-1vcpu-1gb              # Server size
    image: ubuntu-22-04-x64
    name: wireguard-vpn-server

    # VPN Settings
    enabled: true
    port: 51820
    clientIpBase: 10.8.0
    subnetCidr: 10.8.0.0/24
    mtu: 1420
    persistentKeepalive: 25
    autoConfig: true
    meshNetworking: true           # Enable full mesh
    allowedIps:
      - 10.8.0.0/24               # VPN subnet
      - 10.10.0.0/16              # DO VPC
      - 10.11.0.0/16              # Linode VPC
    dns:
      - 1.1.1.1
      - 8.8.8.8

  # DNS Configuration
  dns:
    provider: digitalocean
    domain: k8s.example.com
    records:
      - name: api
        type: A
        ttl: 300
      - name: "*.apps"
        type: A
        ttl: 300
๐ŸŽฏ Kubernetes Configuration
kubernetes:
  distribution: rke2              # rke2 or k3s
  version: v1.28.5+rke2r1
  channel: stable                 # stable, latest, or specific version
  networkPlugin: calico           # calico, cilium, canal, flannel
  podCIDR: 10.42.0.0/16
  serviceCIDR: 10.43.0.0/16

  rke2:
    channel: stable
    clusterToken: your-secure-token  # Cluster join token

    # TLS SANs
    tlsSan:
      - api.k8s.example.com
      - 167.99.123.45

    # Disable default components
    disableComponents:
      - rke2-ingress-nginx         # Install via GitOps instead
      - rke2-metrics-server

    # Etcd Snapshots (Backups)
    snapshotScheduleCron: "0 */12 * * *"  # Every 12 hours
    snapshotRetention: 7                   # Keep 7 snapshots

    # Security
    secretsEncryption: true               # Encrypt secrets at rest

    # Profiles
    profiles:
      - cis-1.6                           # CIS benchmark compliance

    # Node taints (for masters)
    nodeTaints:
      - "node-role.kubernetes.io/control-plane:NoSchedule"

    # Additional server args
    serverArgs:
      - "--disable-cloud-controller"

    # Additional agent args
    agentArgs:
      - "--kubelet-arg=max-pods=200"

Available CNI Plugins:

Plugin Best For Features
Calico Production, Network Policies BGP routing, Network policies, Encryption
Cilium Advanced networking, eBPF eBPF-based, Service mesh, Security
Canal Calico + Flannel Simple, Reliable
Flannel Simple setups Basic overlay networking
๐Ÿ–ฅ๏ธ Node Pools Configuration
nodePools:
  # DigitalOcean Masters
  do-masters:
    provider: digitalocean
    region: nyc3
    size: s-2vcpu-4gb              # Droplet size
    image: ubuntu-22-04-x64        # OS image
    count: 1                       # Number of nodes
    role: master                   # master or worker

    # Kubernetes labels
    labels:
      node-role.kubernetes.io/master: "true"
      cloud-provider: digitalocean
      environment: production

    # Kubernetes taints
    taints:
      - key: node-role
        value: master
        effect: NoSchedule

    # DigitalOcean specific
    monitoring: true
    backups: false
    ipv6: false
    tags:
      - kubernetes
      - master

  # Linode Workers
  linode-workers:
    provider: linode
    region: us-east
    size: g6-standard-2            # Linode plan
    image: linode/ubuntu22.04
    count: 3
    role: worker

    labels:
      node-role.kubernetes.io/worker: "true"
      cloud-provider: linode
      workload: general

    taints: []

    # Linode specific
    privateIp: true
    backups: false
    tags:
      - kubernetes
      - worker

Instance Sizes:

Provider Size vCPU RAM Price/mo
DigitalOcean s-2vcpu-2gb 2 2GB $18
DigitalOcean s-2vcpu-4gb 2 4GB $24
DigitalOcean s-4vcpu-8gb 4 8GB $48
Linode g6-standard-1 1 2GB $12
Linode g6-standard-2 2 4GB $24
Linode g6-standard-4 4 8GB $48
๐Ÿ” Security Configuration
security:
  # SSH Configuration
  ssh:
    generateKeys: true             # Auto-generate SSH keys
    keyPath: ~/.ssh/k8s-cluster   # Key path
    allowedIPs:                    # SSH access whitelist
      - 0.0.0.0/0                  # All (VPN protected)

  # Bastion Host (Jump Server)
  bastion:
    enabled: true
    provider: digitalocean
    region: nyc3
    size: s-1vcpu-1gb
    allowedIPs:
      - 1.2.3.4/32                # Your IP only

  # RBAC
  rbac:
    enabled: true

  # Pod Security
  podSecurity:
    enabled: true
    defaultPolicy: restricted      # restricted, baseline, privileged

  # Network Policies
  networkPolicies:
    enabled: true
    defaultDeny: true

  # TLS/Certificates
  tls:
    autoGenerate: true
๐ŸŽฏ Addons Configuration
addons:
  # GitOps with ArgoCD
  gitops:
    enabled: true
    repository: https://github.com/yourorg/k8s-gitops
    branch: main
    path: addons/

    # ArgoCD configuration
    argocd:
      version: v2.9.3
      ha: true                     # High availability

  # Monitoring Stack
  monitoring:
    enabled: true
    prometheus:
      enabled: true
      retention: 15d
      storageSize: 50Gi

    grafana:
      enabled: true
      adminPassword: ${GRAFANA_PASSWORD}

    alertmanager:
      enabled: true

  # Storage
  storage:
    csi:
      digitalocean:
        enabled: true
      linode:
        enabled: true

    storageClasses:
      - name: fast
        provisioner: do-csi
        parameters:
          type: pd-ssd
      - name: standard
        provisioner: linode-csi
        parameters:
          type: pd-standard
Environment Variables

Sensitive values can be referenced using environment variables:

providers:
  digitalocean:
    token: ${DIGITALOCEAN_TOKEN}
  linode:
    token: ${LINODE_TOKEN}

addons:
  monitoring:
    grafana:
      adminPassword: ${GRAFANA_PASSWORD}

Setting environment variables:

export DIGITALOCEAN_TOKEN="dop_v1_xxxxx"
export LINODE_TOKEN="xxxxx"
export GRAFANA_PASSWORD="secure-password"

๐ŸŽจ Configuration Examples

Example 1: Minimal Single-Provider Cluster

Perfect for: Development, testing, small projects

apiVersion: kubernetes-create.io/v1
kind: Cluster
metadata:
  name: dev-cluster

spec:
  providers:
    digitalocean:
      enabled: true
      token: ${DIGITALOCEAN_TOKEN}
      region: nyc3

  kubernetes:
    distribution: rke2
    version: v1.28.5+rke2r1

  nodePools:
    - name: masters
      provider: digitalocean
      count: 3
      roles: [master]
      size: s-2vcpu-4gb

    - name: workers
      provider: digitalocean
      count: 3
      roles: [worker]
      size: s-2vcpu-4gb

Cost: ~$144/month Nodes: 6 (3 masters, 3 workers) Providers: 1 (DigitalOcean)


Example 2: Multi-Cloud Production Cluster

Perfect for: Production, high availability, geographic distribution

apiVersion: kubernetes-create.io/v1
kind: Cluster
metadata:
  name: production-cluster
  environment: production

spec:
  providers:
    digitalocean:
      enabled: true
      token: ${DIGITALOCEAN_TOKEN}
      region: nyc3
      vpc:
        create: true
        cidr: 10.10.0.0/16

    linode:
      enabled: true
      token: ${LINODE_TOKEN}
      region: us-east
      vpc:
        create: true
        cidr: 10.11.0.0/16

  network:
    wireguard:
      create: true
      provider: digitalocean
      meshNetworking: true

  kubernetes:
    distribution: rke2
    version: v1.28.5+rke2r1
    rke2:
      secretsEncryption: true
      snapshotScheduleCron: "0 */12 * * *"
      snapshotRetention: 7

  nodePools:
    # 1 DO master + 2 Linode masters = 3 masters (HA)
    do-masters:
      provider: digitalocean
      count: 1
      roles: [master]
      size: s-2vcpu-4gb

    linode-masters:
      provider: linode
      count: 2
      roles: [master]
      size: g6-standard-2

    # Workers across both providers
    do-workers:
      provider: digitalocean
      count: 2
      roles: [worker]
      size: s-2vcpu-4gb

    linode-workers:
      provider: linode
      count: 2
      roles: [worker]
      size: g6-standard-2

  security:
    bastion:
      enabled: true
    podSecurity:
      enabled: true
      defaultPolicy: restricted

Cost: ~$180/month Nodes: 7 (3 masters, 4 workers) Providers: 2 (DigitalOcean + Linode) HA: Yes (masters across providers)


Example 3: Advanced with Monitoring & GitOps

Perfect for: Enterprise, full observability, GitOps workflow

apiVersion: kubernetes-create.io/v1
kind: Cluster
metadata:
  name: enterprise-cluster
  environment: production

spec:
  providers:
    digitalocean:
      enabled: true
      token: ${DIGITALOCEAN_TOKEN}
      region: nyc3
      vpc:
        create: true
        cidr: 10.10.0.0/16

  network:
    wireguard:
      create: true
      provider: digitalocean
    dns:
      provider: digitalocean
      domain: k8s.example.com

  kubernetes:
    distribution: rke2
    version: v1.28.5+rke2r1
    networkPlugin: calico
    rke2:
      secretsEncryption: true
      profiles:
        - cis-1.6
      disableComponents:
        - rke2-ingress-nginx

  nodePools:
    masters:
      provider: digitalocean
      count: 3
      roles: [master]
      size: s-2vcpu-4gb

    workers:
      provider: digitalocean
      count: 5
      roles: [worker]
      size: s-4vcpu-8gb

  security:
    bastion:
      enabled: true
    podSecurity:
      enabled: true
      defaultPolicy: restricted
    networkPolicies:
      enabled: true

  addons:
    gitops:
      enabled: true
      repository: https://github.com/yourorg/k8s-gitops
      argocd:
        ha: true

    monitoring:
      enabled: true
      prometheus:
        retention: 30d
        storageSize: 100Gi
      grafana:
        enabled: true

Cost: ~$384/month Nodes: 8 (3 masters, 5 workers) Features: GitOps, Monitoring, CIS compliance, Bastion


๐Ÿš€ Deployment Workflow

Complete Deployment Example
# Step 1: Create configuration
cat > production.yaml <<EOF
apiVersion: kubernetes-create.io/v1
kind: Cluster
metadata:
  name: production

spec:
  providers:
    digitalocean:
      enabled: true
      token: ${DIGITALOCEAN_TOKEN}
      region: nyc3
      vpc:
        create: true
        cidr: 10.10.0.0/16

  network:
    wireguard:
      create: true
      provider: digitalocean

  kubernetes:
    distribution: rke2
    version: v1.28.5+rke2r1

  nodePools:
    masters:
      provider: digitalocean
      count: 3
      roles: [master]
      size: s-2vcpu-4gb
    workers:
      provider: digitalocean
      count: 3
      roles: [worker]
      size: s-2vcpu-4gb
EOF

# Step 2: Validate configuration
sloth-kubernetes config validate -f production.yaml

# Step 3: Preview deployment (dry-run)
sloth-kubernetes deploy --config production.yaml --dry-run

# Step 4: Deploy cluster
export DIGITALOCEAN_TOKEN="dop_v1_xxxxx"
sloth-kubernetes deploy --config production.yaml

# Step 5: Get kubeconfig
sloth-kubernetes kubeconfig > ~/.kube/config

# Step 6: Verify cluster
kubectl get nodes
kubectl get pods --all-namespaces

# Step 7: Check cluster status
sloth-kubernetes status

# Step 8: Bootstrap GitOps (optional)
sloth-kubernetes addons bootstrap \
  --repo https://github.com/yourorg/k8s-gitops

# Step 9: Deploy your applications
kubectl apply -f your-app.yaml

๐ŸŒ Network Architecture

VPN Mesh Topology
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚                    WireGuard Mesh Network                        โ”‚
โ”‚                      (10.8.0.0/24)                               โ”‚
โ”‚                                                                  โ”‚
โ”‚                  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                       โ”‚
โ”‚                  โ”‚   VPN Server         โ”‚                       โ”‚
โ”‚                  โ”‚   167.99.123.45:51820โ”‚                       โ”‚
โ”‚                  โ”‚   IP: 10.8.0.1       โ”‚                       โ”‚
โ”‚                  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜                       โ”‚
โ”‚                             โ”‚                                    โ”‚
โ”‚              โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”                    โ”‚
โ”‚              โ”‚              โ”‚              โ”‚                     โ”‚
โ”‚    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”  โ”Œโ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”         โ”‚
โ”‚    โ”‚ DigitalOcean   โ”‚  โ”‚ Linode   โ”‚  โ”‚ DigitalOcean โ”‚         โ”‚
โ”‚    โ”‚ VPC            โ”‚  โ”‚ VPC      โ”‚  โ”‚ Nodes        โ”‚         โ”‚
โ”‚    โ”‚ 10.10.0.0/16   โ”‚  โ”‚10.11.0.0 โ”‚  โ”‚              โ”‚         โ”‚
โ”‚    โ”‚                โ”‚  โ”‚    /16   โ”‚  โ”‚              โ”‚         โ”‚
โ”‚    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜         โ”‚
โ”‚                                                                  โ”‚
โ”‚  All nodes communicate via encrypted WireGuard tunnel           โ”‚
โ”‚  โ€ข Full mesh: Every node can reach every other node            โ”‚
โ”‚  โ€ข Encrypted: All traffic encrypted with modern crypto         โ”‚
โ”‚  โ€ข Low latency: Direct peer-to-peer connections                โ”‚
โ”‚  โ€ข Cross-cloud: Transparent routing between providers          โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
Network Flow
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Pod-to-Pod Communication (Cross-Provider)                       โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Pod A (DO)                                          Pod B (Linode)
  โ†“                                                       โ†‘
Calico CNI (10.42.0.10)                    Calico CNI (10.42.1.20)
  โ†“                                                       โ†‘
Node A (DO)                                        Node B (Linode)
Private IP: 10.10.0.5                        Private IP: 10.11.0.8
VPN IP: 10.8.0.10                            VPN IP: 10.8.0.12
  โ†“                                                       โ†‘
  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บ WireGuard Tunnel โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
             (Encrypted, 10.8.0.0/24)

โœ… Encrypted end-to-end
โœ… No public internet exposure
โœ… Cross-provider routing
โœ… Pod network isolation
Security Layers
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  Layer 7: Application Layer                                     โ”‚
โ”‚  โ€ข Kubernetes Network Policies                                  โ”‚
โ”‚  โ€ข Pod Security Policies                                        โ”‚
โ”‚  โ€ข RBAC Authorization                                           โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  Layer 4-6: Transport/Session Layer                             โ”‚
โ”‚  โ€ข WireGuard VPN (ChaCha20 encryption)                          โ”‚
โ”‚  โ€ข TLS for Kubernetes API                                       โ”‚
โ”‚  โ€ข Encrypted etcd storage                                       โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  Layer 3: Network Layer                                         โ”‚
โ”‚  โ€ข Private VPCs (isolated networks)                             โ”‚
โ”‚  โ€ข Firewall rules (UFW)                                         โ”‚
โ”‚  โ€ข Security groups                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  Layer 2: Data Link Layer                                       โ”‚
โ”‚  โ€ข Provider network isolation                                   โ”‚
โ”‚  โ€ข VLAN separation                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  Layer 1: Physical Layer                                        โ”‚
โ”‚  โ€ข Provider datacenter security                                 โ”‚
โ”‚  โ€ข Physical network isolation                                   โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

๐Ÿ’ผ Use Cases

1. High Availability Production Cluster

Scenario: You need a highly available Kubernetes cluster that can survive a cloud provider outage.

Solution:

  • Deploy masters across multiple providers
  • Use WireGuard mesh for seamless communication
  • Implement automated etcd backups
nodePools:
  do-masters:
    provider: digitalocean
    count: 1
    roles: [master]

  linode-masters:
    provider: linode
    count: 2
    roles: [master]

Benefits:

  • โœ… Survive entire provider outage
  • โœ… Automatic failover
  • โœ… Geographic distribution

2. Cost-Optimized Cluster

Scenario: You want to optimize costs by using the cheapest regions/instances.

Solution:

  • Mix and match providers
  • Use smaller instances for non-critical workloads
  • Scale workers independently
nodePools:
  linode-workers:
    provider: linode
    size: g6-standard-1  # Cheaper than DO
    count: 5

3. Development/Staging Environment

Scenario: Quick cluster for testing without complex setup.

Solution:

  • Single provider
  • Minimal configuration
  • Fast deployment
sloth-kubernetes config generate --type minimal > dev.yaml
sloth-kubernetes deploy --config dev.yaml

4. GitOps-First Infrastructure

Scenario: Fully automated infrastructure with GitOps workflow.

Solution:

  • Bootstrap ArgoCD automatically
  • Self-managing applications
  • Git as source of truth
# Deploy cluster
sloth-kubernetes deploy --config cluster.yaml

# Bootstrap GitOps
sloth-kubernetes addons bootstrap \
  --repo https://github.com/yourorg/k8s-gitops

# All applications auto-sync from Git

๐Ÿ”ง Advanced Topics

State Management

Sloth Kubernetes uses Pulumi for state management. By default, state is stored locally in ~/.pulumi/.

Local State (Default)
# State stored in: ~/.pulumi/stacks/
ls ~/.pulumi/stacks/
Remote State (S3)
# Set S3 backend
export PULUMI_BACKEND_URL="s3://my-bucket/sloth-kubernetes"

# Deploy
sloth-kubernetes deploy --config cluster.yaml
Remote State (Azure Blob)
export PULUMI_BACKEND_URL="azblob://my-container"
export AZURE_STORAGE_ACCOUNT="mystorageaccount"
export AZURE_STORAGE_KEY="xxxxx"
Remote State (Google Cloud Storage)
export PULUMI_BACKEND_URL="gs://my-bucket/sloth-kubernetes"

Multi-Environment Management

Manage multiple clusters (dev, staging, production) with stacks:

# Development
sloth-kubernetes deploy --config dev.yaml --stack dev

# Staging
sloth-kubernetes deploy --config staging.yaml --stack staging

# Production
sloth-kubernetes deploy --config production.yaml --stack production

# List all stacks
sloth-kubernetes stacks list

# Switch between environments
kubectl config use-context dev
kubectl config use-context production

Bastion Host (Jump Server)

For enhanced security, use a bastion host:

security:
  bastion:
    enabled: true
    provider: digitalocean
    region: nyc3
    size: s-1vcpu-1gb
    allowedIPs:
      - 1.2.3.4/32  # Your IP only

SSH via bastion:

# Direct SSH (blocked)
ssh root@do-worker-1  # โŒ Blocked

# Via bastion
sloth-kubernetes nodes ssh production do-worker-1 --bastion  # โœ… Works

Custom RKE2 Configuration

Advanced RKE2 options:

kubernetes:
  rke2:
    # Custom registry
    privateRegistries:
      - url: registry.example.com
        username: ${REGISTRY_USER}
        password: ${REGISTRY_PASS}

    # Custom manifests (installed on bootstrap)
    customManifests:
      - https://raw.githubusercontent.com/yourorg/manifests/main/custom.yaml

    # SELinux
    selinux: true

    # Additional mount points
    extraMounts:
      - source: /host/path
        destination: /container/path
        type: bind
        options:
          - rbind
          - rw

Monitoring Integration

Complete observability stack:

addons:
  monitoring:
    enabled: true

    prometheus:
      enabled: true
      retention: 30d
      storageSize: 100Gi
      storageClass: fast
      replicas: 2

    grafana:
      enabled: true
      adminPassword: ${GRAFANA_PASSWORD}
      persistence:
        enabled: true
        size: 10Gi
      dashboards:
        - https://grafana.com/api/dashboards/12345/revisions/1/download

    alertmanager:
      enabled: true
      config:
        route:
          receiver: 'slack'
        receivers:
          - name: 'slack'
            slack_configs:
              - api_url: ${SLACK_WEBHOOK}
                channel: '#alerts'

๐Ÿงช Testing

Run Tests
# All tests
go test ./...

# Specific package
go test ./pkg/config

# With coverage
go test ./pkg/config -cover

# Verbose
go test ./pkg/config -v

# Generate coverage report
go test ./pkg/config -coverprofile=coverage.out
go tool cover -html=coverage.out
Test Coverage

Current test coverage: 46.1% (71 tests)

Package Coverage Tests
pkg/config 53.4% 56
pkg/vpc 2.1% 9
pkg/vpn 7.7% 14

See TESTS_COVERAGE_REPORT.md for detailed coverage report.


๐Ÿ” Troubleshooting

Common Issues
โŒ Deployment fails: "token is invalid"

Cause: Invalid or expired API token

Solution:

# Verify token
export DIGITALOCEAN_TOKEN="dop_v1_xxxxx"
curl -X GET "https://api.digitalocean.com/v2/account" \
  -H "Authorization: Bearer $DIGITALOCEAN_TOKEN"

# If invalid, generate new token at:
# https://cloud.digitalocean.com/account/api/tokens
โŒ WireGuard connection fails

Cause: Firewall blocking UDP port 51820

Solution:

# Check VPN status
sloth-kubernetes vpn status

# Test connectivity
sloth-kubernetes vpn test

# Verify firewall rules on VPN server
ssh root@vpn-server
ufw status
ufw allow 51820/udp
โŒ kubectl: "Unable to connect to server"

Cause: Kubeconfig not set or incorrect

Solution:

# Get fresh kubeconfig
sloth-kubernetes kubeconfig > ~/.kube/config

# Verify
kubectl cluster-info
kubectl get nodes

# Check API endpoint
grep server ~/.kube/config
โŒ Nodes not joining cluster

Cause: Network connectivity or RKE2 installation issue

Solution:

# SSH into node
sloth-kubernetes nodes ssh production do-worker-1

# Check RKE2 status
systemctl status rke2-agent

# Check logs
journalctl -u rke2-agent -f

# Verify WireGuard
wg show
ping 10.8.0.1  # VPN server
โŒ Out of disk space on nodes

Cause: Container images filling disk

Solution:

# SSH into node
sloth-kubernetes nodes ssh production do-worker-1

# Clean up Docker images
crictl rmi --prune

# Check disk usage
df -h
du -sh /var/lib/rancher/rke2
Debug Mode

Enable verbose output for debugging:

# Verbose deployment
sloth-kubernetes deploy --config cluster.yaml --verbose

# Very verbose (includes Pulumi debug)
export PULUMI_DEBUG_COMMANDS=true
sloth-kubernetes deploy --config cluster.yaml --verbose
Logs

Check logs for issues:

# RKE2 server logs (master)
ssh root@master-1
journalctl -u rke2-server -f

# RKE2 agent logs (worker)
ssh root@worker-1
journalctl -u rke2-agent -f

# WireGuard logs
journalctl -u wg-quick@wg0 -f

โ“ FAQ

Do I need Pulumi CLI installed?

No! Sloth Kubernetes uses Pulumi Automation API, which is a Go library that embeds all Pulumi functionality into the binary. No external CLI needed.

Where is the infrastructure state stored?

By default, state is stored locally in ~/.pulumi/stacks/. You can configure remote backends (S3, Azure Blob, GCS, Pulumi Cloud) using the PULUMI_BACKEND_URL environment variable.

Can I use my existing VPC?

Yes! Set create: false and provide the VPC ID:

providers:
  digitalocean:
    vpc:
      create: false
      id: "vpc-existing-id"
Do I need a pre-existing WireGuard server?

No! Set create: true in the WireGuard configuration and Sloth Kubernetes will automatically deploy and configure a VPN server for you.

Can I add more nodes after initial deployment?

Yes! Use the nodes add command:

sloth-kubernetes nodes add --pool workers --count 2
How do I upgrade Kubernetes version?

Update the version in your config file and redeploy:

kubernetes:
  version: v1.29.0+rke2r1  # Updated version
sloth-kubernetes deploy --config cluster.yaml

Or use the upgrade command:

sloth-kubernetes nodes upgrade --version v1.29.0+rke2r1 --rolling
What happens if one cloud provider goes down?

If you've distributed your master nodes across multiple providers (recommended), your cluster will continue to function. Pods on the affected provider's nodes will be rescheduled to healthy nodes on other providers automatically.

How much does it cost?

Cost depends on your configuration:

  • Minimal (6 nodes, DO only): ~$144/month
  • Multi-cloud (7 nodes): ~$180/month
  • Enterprise (8+ nodes): ~$384/month+

VPN server adds minimal cost (~$6/month for s-1vcpu-1gb).

Can I use this in production?

Yes! Sloth Kubernetes is designed for production use with:

  • High availability (multi-master)
  • Automated backups (etcd snapshots)
  • Security hardening (CIS profiles, secrets encryption)
  • Multi-cloud resilience
  • GitOps support
How do I backup my cluster?

RKE2 automatically creates etcd snapshots based on your configuration:

kubernetes:
  rke2:
    snapshotScheduleCron: "0 */12 * * *"  # Every 12 hours
    snapshotRetention: 7                   # Keep 7 snapshots

Snapshots are stored on master nodes at /var/lib/rancher/rke2/server/db/snapshots/.


๐Ÿค Contributing

Contributions are welcome! Please follow these steps:

1. Fork the Repository
git clone https://github.com/yourusername/sloth-kubernetes.git
cd sloth-kubernetes
2. Create Feature Branch
git checkout -b feature/amazing-feature
3. Make Changes
# Make your changes
vim pkg/something/new.go

# Add tests
vim pkg/something/new_test.go

# Run tests
go test ./...
4. Commit Changes
git add .
git commit -m "Add amazing feature"
5. Push and Create PR
git push origin feature/amazing-feature

Then open a Pull Request on GitHub.

Development Setup
# Install dependencies
go mod download

# Run tests
go test ./...

# Run linters
golangci-lint run

# Build
go build -o sloth-kubernetes
Code Style
  • Follow standard Go conventions
  • Write tests for new features
  • Document public APIs
  • Keep commits atomic and descriptive

๐Ÿ“„ License

MIT License - see LICENSE file for details.


๐Ÿ™ Acknowledgments

Sloth Kubernetes is built on top of excellent open-source projects:

Embedded Tools:

  • Pulumi - Infrastructure as Code framework (embedded via Automation API)
  • SaltStack - Configuration management and remote execution (embedded client)
  • kubectl - Kubernetes command-line tool (embedded via client-go)

Core Technologies:

  • RKE2 - Production-ready Kubernetes distribution
  • WireGuard - Fast, modern VPN protocol
  • Calico - Kubernetes networking and security

Development Tools:

  • Cobra - CLI framework for Go
  • client-go - Official Kubernetes Go client

GitOps & Addons:

  • ArgoCD - GitOps continuous delivery

Special thanks to the open-source community for making projects like this possible.


๐Ÿ“š Additional Documentation


๐Ÿ“ง Support & Community


๐Ÿฆฅ Sloth Kubernetes - Deploy Kubernetes clusters, slowly but surely

Made with โค๏ธ by the open-source community

โญ Star us on GitHub โ€ข ๐Ÿ“– Read the docs โ€ข ๐Ÿš€ Get started

Documentation ยถ

The Go Gopher

There is no documentation for this package.

Directories ยถ

Path Synopsis
cmd
internal
pkg
config
Package config provides comprehensive configuration types for the kubernetes-create cluster
Package config provides comprehensive configuration types for the kubernetes-create cluster
dns
vpc
vpn

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL