MetalLB

Hands out real LAN addresses to services in L2 mode, no cloud load balancer required

MetalLB hands out LoadBalancer addresses from a small pool on the LAN. Traefik and other entry points take their addresses from this pool. It runs in L2 mode, which speaks plain ARP and needs no special router capability.

ArgoCD configuration

Excerpt from argocd-apps/values.yaml in the argocd-apps chart, with annotations added for this site:

metallb:
  # true
  application: true
  project: k3s-services
  # false: IP pool changes can re-address the edge
  autoSync: false

Chart values

The full metallb/values.yaml from the service's own chart:

# Empty file

Manifests & templates

templates/configuration.yaml

MetalLB IPAddressPool and L2Advertisement: the address pool MetalLB hands out. This is the real MetalLB config; the chart values stay empty on purpose.

Show manifest
apiVersion: metallb.io/v1beta1
kind: IPAddressPool
metadata:
  name: opi5-cluster-ip-address-pool
  namespace: {{ .Release.Namespace }}
spec:
  addresses:
  - 192.168.1.5-192.168.1.10

---

apiVersion: metallb.io/v1beta1
kind: L2Advertisement
metadata:
  name: opi5-cluster-l2-advertisement
  namespace: {{ .Release.Namespace }}
spec:
  ipAddressPools:
  - opi5-cluster-ip-address-pool

Trade-offs

Decision. L2 mode

Alternative. BGP mode

Why. There is no BGP-capable router in the lab; L2 mode only needs same-subnet adjacency, which the cluster already has.

← Back to Platform & Infrastructure · All service groups