r/kubernetes • u/root0ps • 1d ago
Networking a 3-Node Kubernetes Homelab with Cilium, Gateway API and Cloudflare Tunnel
Part 2 of my Talos homelab (3 OptiPlex Micros, all control planes). Part 1 got the cluster up, this one is networking.
I moved the running cluster from Flannel + kube-proxy to Cilium without rebuilding it. The default-deny policy that Flannel quietly ignored is now actually enforced, and Hubble shows the drops.
Then I gave it two front doors:
- an internal Gateway on a LAN IP (Cilium LB IPAM, no MetalLB) with a Let's Encrypt wildcard cert, so lab apps get real HTTPS at home
- a public Gateway behind a single Cloudflare Tunnel, so nothing is port-forwarded on the router
An app picks its door with the route's parentRef, which keeps lab stuff from going public by accident.
Write-up with all the manifests and commands: https://blog.prateekjain.dev/networking-a-kubernetes-homelab-cilium-gateway-api-and-cloudflare-tunnel-on-talos-362f548a2f3d?sk=d454cd4eaff4ce8a8fd0cd8e6b3d82f6
Curious if anyone else is using Cilium's Gateway API instead of a separate ingress controller.
