Post #4316773
2026-07-25 19:03 UTC
@thedoctor@polymaths.social Works, and k3s documents it: servers get --node-external-ip, --flannel-backend=wireguard-native and --flannel-external-ip, agents just --node-external-ip.
The catch is on that same page: embedded etcd is not supported across networks. Agents can be spread out, servers cannot. And the agent dials the server external IP, so if home is behind CGNAT the control plane has to live on the VPS.
Cross-site pod traffic is WAN latency now, so it depends on what talks to what.
Replies (0)
No replies.