This message was deleted.
# harvester
a
This message was deleted.
a
Could you tell more details. run the VPN agent in Harvester so that Harvester is a VPN gateway ?
g
Yeah, I want to run the management network in Tailscale
@ancient-pizza-13099 Do you have any idea on how to do this?
a
Basically, an indepedent VPN gateway is the better practice, thus Harvester has no knowledge of VPN.
g
That's not possible, especially when one of the sellingpoints is "hybrid".
a
When you wanna Harvester to be part of the VPN network, namely, Harvester VIP needs to add anohter component to encode/decode VPN related stuff
At the moment, I don't know a simple solution yet.
g
So I need a NIC dedicated to the cluster which is impossible when on multi regions without a VPN
cannot setup a virtualmachine either
a
That is still difficult, Harvester VIP can float on a couple of (Let's say three) management NODE, and the VPN gateway needs to float as well, indeed, it should sit in front of kubeVIP
the disk size is not matching
manybe certain kind of side-car to KubeVIP can have VPN feature, but needs more investigation
g
i have not tried this myself but what about this? https://tailscale.com/kb/1236/kubernetes-operator/
👍 1
you could leverage 1.2.0+ and new baremetal workload feature capability to deploy this..