<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hetzner on Janusworx</title><link>https://janusworx.com/tags/hetzner/</link><description>Recent content in Hetzner on Janusworx</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>feedback@janusworx.com (Mario Jason Braganza)</managingEditor><webMaster>feedback@janusworx.com (Mario Jason Braganza)</webMaster><copyright>© 2026, Mario Jason Braganza</copyright><lastBuildDate>Fri, 19 Dec 2025 18:00:00 +0530</lastBuildDate><atom:link href="https://janusworx.com/tags/hetzner/index.xml" rel="self" type="application/rss+xml"/><item><title>The Big Plan: Change My VM to Be Gitops Driven</title><link>https://janusworx.com/work/the-big-plan-change-my-vm-to-be-gitops-driven/</link><pubDate>Fri, 19 Dec 2025 18:00:00 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/work/the-big-plan-change-my-vm-to-be-gitops-driven/</guid><description>&lt;div class="admonition relative overflow-hidden rounded-lg border-l-4 my-3 px-4 py-3 shadow-sm" data-type="info"&gt;
 &lt;div class="flex items-center gap-2 font-semibold text-inherit"&gt;
 &lt;div class="flex shrink-0 h-5 w-5 items-center justify-center text-lg"&gt;&lt;span class="relative block icon"&gt;&lt;svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512"&gt;&lt;path fill="currentColor" d="M256 0C114.6 0 0 114.6 0 256s114.6 256 256 256s256-114.6 256-256S397.4 0 256 0zM256 128c17.67 0 32 14.33 32 32c0 17.67-14.33 32-32 32S224 177.7 224 160C224 142.3 238.3 128 256 128zM296 384h-80C202.8 384 192 373.3 192 360s10.75-24 24-24h16v-64H224c-13.25 0-24-10.75-24-24S210.8 224 224 224h32c13.25 0 24 10.75 24 24v88h16c13.25 0 24 10.75 24 24S309.3 384 296 384z"/&gt;&lt;/svg&gt;
&lt;/span&gt;&lt;/div&gt;
 &lt;div class="grow"&gt;
 Intended Audience
 &lt;/div&gt;
 &lt;/div&gt;&lt;div class="admonition-content mt-3 text-base leading-relaxed text-inherit"&gt;&lt;p&gt;Me!&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;&lt;em&gt;Update 2025-12-19: All done!&lt;/em&gt;&lt;/p&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

&lt;p&gt;I just finished a move from one Hetzner VM to another.&lt;br&gt;
The type of VMs are the same, in fact.&lt;br&gt;
It’s just that the new VM and all the software on it are entirely software driven. I kept logging my progress in my &lt;a href="https://janusworx.com/nm/" &gt;notes&lt;/a&gt;, copy pasting the plan from day to day and ticking things off.&lt;br&gt;
Now that it’s done and I &lt;em&gt;still&lt;/em&gt; want to &lt;a href="https://janusworx.com/nm/2025-12-12/" &gt;refer to it regularly&lt;/a&gt;, as the rest of the services come over, I wanted a place to keep it. And so this post, it is.&lt;/p&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h2 class="relative group"&gt;List of services that absolutely need to come over. Miscellaneous stuff later.
 &lt;div id="list-of-services-that-absolutely-need-to-come-over-miscellaneous-stuff-later" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#list-of-services-that-absolutely-need-to-come-over-miscellaneous-stuff-later" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; the main domain&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; french version of the website&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; the mastodon archive&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; the email distribution list&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; miniflux for rss feeds&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; joplin&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; baikal&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;discourse&lt;/del&gt; (no more discourse!)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; markdown editor (hedgedoc)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; anki&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; huginn&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; syncthing&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; IRC: theLounge + znc (see if we can make do with a single service now &lt;em&gt;(2025-12-15: we could!)&lt;/em&gt;)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; kanboard&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Certs, Move them over, or figure out a way to generate and renew them via Ansible&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h2 class="relative group"&gt;The Big Point of The Big Plan
 &lt;div id="the-big-point-of-the-big-plan" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-big-point-of-the-big-plan" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Save time and energy. Managing all the disparate services I use is taking more and more of my time. I need to claim that back, while being able to use said services.&lt;/li&gt;
&lt;li&gt;Be gitops driven. Managing stuff gets easier. Tearing down things and rebuilding them gets easier&lt;/li&gt;
&lt;li&gt;Have most everything I use, be in a Kubernetes cluster.&lt;/li&gt;
&lt;li&gt;Be pragmatic enough to know that everything cannot be in a Kubernetes cluster and will have to live in the root VM&lt;/li&gt;
&lt;li&gt;Have Flux CD manage everything in the cluster&lt;/li&gt;
&lt;li&gt;Have Ansible Pull manage everything in the VM, acting as my single node. The point of doing this is not idempotency, rather to have everything in code; something that I can comment and uncomment and manipulate at will, something I can update at will and something that is documented. Never again will Future Jason have to scratch his head about, just how to go about doing something. &lt;em&gt;(Long term note to self: Have the discipline to write tasks and drive everything with Ansible, despite the ease of “just doing it at the command line”)&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;The Big Plan (&lt;em&gt;Done!&lt;/em&gt; 🎉🎉🎉)
 &lt;div id="the-big-plan-done-" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#the-big-plan-done-" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The plan is to redo the cluster again and do my own instance of
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; K3s&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Sealed Secrets&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Flux CD&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Certmanager&lt;/del&gt; (Not using it)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; &lt;del&gt;Letsencrypt&lt;/del&gt; (using pre existing Letsencrypt certs)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get Traefik Ingress to work&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out a way to get certs automatically into the cluster&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;And once &lt;em&gt;that&lt;/em&gt; is done, figure out an app to move (Miniflux or Hedgedoc?); 2025-12-03: Kanboard it is!&lt;/li&gt;
&lt;li&gt;Begin by moving (lifting and shifting in popular parlance) Kanboard to the cluster
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Cert will probably be needed (Wildcard cert works now, just like it does without the cluster)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert a docker-compose to kubernetes manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to configure an app with code&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to store data and back it up&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out secrets, if there are any (for now sealed secrets ok, figure out vault and vault injection later)&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Learn how to tunnel through and reverse proxy&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Make Kubernetes manifests work with flux&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to automate deployment of manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to migrate there if there is any in an old app&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figue out how to automate updation of images in manual manifests&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get another app (Miniflux) deployed&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out what needs to happen as part of the lifecycle. What you want in the cluster, what stays out, do they intersect, how do updates of cluster happen? VM (node) updates as well?&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Then begin to think along the lines of Live Deploys. Prototype locally and once it works, migrate to production immediately&lt;/li&gt;
&lt;li&gt;&lt;input disabled="" type="checkbox"&gt; Convert Kubernetes manifests to Helm Charts (optional, based on energy)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Go live! Git is source of truth. Two repos.
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; One for the Main node and its update
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Terraform will provision node and install package, setup firewall&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Figure out how to get Terraform to get the node talking to the git forge&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Structure repo, copy every thing node related there, and make sure stuff gets updated periodically and if possible, idempotantly, via ansible pull and a systemd timer&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; The other one for k3s and flux
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Convert everything I have done locally to run on prod. Add more steps as you do them below&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;Unrelated. Long term. Optional. Just here so that I remember
 &lt;div id="unrelated-long-term-optional-just-here-so-that-i-remember" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#unrelated-long-term-optional-just-here-so-that-i-remember" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Get Moi publish script running&lt;/li&gt;
&lt;li&gt;&lt;input checked="" disabled="" type="checkbox"&gt; Redo Huginn Scenarios&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: The Big Plan: Change My VM to Be Gitops Driven
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;

&lt;br&gt;

P.S. Subscribe to my &lt;a href="https://janusworx.com/subscribe/" target="_blank" rel="noreferrer"&gt;mailing list!&lt;/a&gt;&lt;br&gt;
Forward these posts and letters to your friends and get them to subscribe!&lt;/p&gt;</description></item><item><title>2025-11-06 Notes aka The Plan for My New Hetzner VM</title><link>https://janusworx.com/nm/2025-11-06/</link><pubDate>Thu, 06 Nov 2025 08:03:54 +0530</pubDate><author>feedback@janusworx.com (Mario Jason Braganza)</author><guid>https://janusworx.com/nm/2025-11-06/</guid><description>
&lt;h2 class="relative group"&gt;Update: &lt;a href="https://janusworx.com/nm/2025-12-11/" &gt;2025-12-11&lt;/a&gt;
 &lt;div id="update-2025-12-11" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#update-2025-12-11" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://janusworx.com/nm/2025-12-11/" &gt;&lt;em&gt;I got it done!&lt;/em&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;Preamble
 &lt;div id="preamble" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#preamble" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;If this post is weird and stream of consciousness like, that’s by design.&lt;br&gt;
You are seeing a &lt;a href="https://janusworx.com/" &gt;notes and miscellanea&lt;/a&gt; post, in the work category.&lt;br&gt;
I want to be able to think through what I am doing. Mostly to clarify, document and explicitly state &lt;em&gt;&lt;strong&gt;what&lt;/strong&gt;&lt;/em&gt; I want. To avoid shifting goalposts (or rather to shift them intentionally, if need be.)&lt;br&gt;
I’ll be updating and revising this post as I think and learn and experience things&lt;/p&gt;

&lt;h2 class="relative group"&gt;Goals
 &lt;div id="goals" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#goals" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Think about and write what I want to get done with my hetzner&lt;/li&gt;
&lt;li&gt;For now, the how does not matter&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;What I want
 &lt;div id="what-i-want" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-i-want" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A VM running K3s, that I can deploy my Hugo website to, as well all the apps that I choose to run on Janusworx&lt;/li&gt;
&lt;li&gt;My main need with a cluster is the GitOps aspect. Not the scaling or redundancy.
I want infrastructure as code and automated updates, as much as possible.&lt;/li&gt;
&lt;li&gt;Everything goes through my Forgejo instance at home&lt;/li&gt;
&lt;li&gt;I write a post and it should deploy to the website somehow&lt;/li&gt;
&lt;li&gt;Apps that I put in there, either just my config files of already published images/deployments, or my own custom things, ought to be pushed to or pulled by the cluster and deployed. Upgrades should be a matter of manipulating code&lt;/li&gt;
&lt;li&gt;Secrets should be self hosted, via environment variables or some self hosted solution. Never at a third party service&lt;/li&gt;
&lt;/ul&gt;
&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;


&lt;h3 class="relative group"&gt;2025-11-06 09:35
 &lt;div id="2025-11-06-0935" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-11-06-0935" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Got tangled with Hugo in the morning.&lt;/li&gt;
&lt;li&gt;I think I got the basics down, the VM comes up. K3s in installed, but in what order do I move my apps over?&lt;/li&gt;
&lt;li&gt;Think I’ll the root domail last. And try beginning with the “simpler” apps first&lt;/li&gt;
&lt;li&gt;Begin with familiarising myself with Helm&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-11-06 10:06:&lt;/em&gt; Tea break&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-11-06 13:06:&lt;/em&gt; Lunch break&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;2025-11-06 16:00
 &lt;div id="2025-11-06-1600" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#2025-11-06-1600" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Back. Trying to port my dev terraform setup to production. It should &lt;em&gt;just&lt;/em&gt; work. But it does not.&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-11-06 16:59:&lt;/em&gt; Solved. I had somehow borked my Terraform state. Nuked it. And then things started working again&lt;/li&gt;
&lt;li&gt;Show stopper now. My GPG key has expired. Need to figure out how to sign my git commits with SSH now&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-11-06 18:26:&lt;/em&gt; I &lt;em&gt;think&lt;/em&gt; I’ve licked it. Both Github and Forgejo don’t seem to be complaining. Let’s see what else I’ve broken over the coming days&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2025-11-06 20:00:&lt;/em&gt; Done! My production cluster is up! &lt;em&gt;&lt;strong&gt;And&lt;/strong&gt;&lt;/em&gt; I can tear it down and build it up consistently. Now to work with it tomorrow.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;hr style='margin-left: auto; margin-right: auto; margin-bottom: 40px; margin-top: 50px; width:100px; border: none; background-color:rgb(238, 238, 238); color: rgb(238, 238, 238); height: 1px;'/&gt;

Feedback on this post?&lt;br&gt;
Mail me at &lt;a href="mailto:feedback@janusworx.com?subject=%22Feedback on post: 2025-11-06 Notes aka The Plan for My New Hetzner VM
%22" &gt;feedback at this domain&lt;/a&gt;.
&lt;br&gt;
&lt;/p&gt;</description></item></channel></rss>