# Openziti on Talos cluster

**URL:** <https://openziti.discourse.group/t/openziti-on-talos-cluster/4047>\
**Category:** General Questions\
**Created:** [March 2, 2025, 10:45pm UTC](https://openziti.discourse.group/t/openziti-on-talos-cluster/4047 "2025-03-02T22:45:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![brandi](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@brandi](https://openziti.discourse.group/u/brandi)\
**Post date:** [March 2, 2025, 10:45pm UTC](https://openziti.discourse.group/t/openziti-on-talos-cluster/4047/1 "2025-03-02T22:45:07Z")

</div>

Hey,

I've a homelab Talos cluster with a bunch of SSFs. I wanna be able to access K8S API and my services remotely.

From [this doc](https://openziti.io/docs/reference/tunnelers/kubernetes/kubernetes-daemonset/#installation-using-a-existing--pre-created-secret), I understand that I can deploy a Daemonset with an OpenZiti tunneler.

So this could solve the "access services remotely". But how can I access the API through Openziti If I cannot deploy a tunneler on the host directly ?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [March 3, 2025, 12:01pm UTC](https://openziti.discourse.group/t/openziti-on-talos-cluster/4047/2 "2025-03-03T12:01:50Z")

</div>

Hi @brandi,

If I'm not mistaken, I believe the k8s API is available from within the cluster itself by default. You don't need to deploy a tunneler on the host via daemonset. You just need to deploy any OpenZiti tunneler in the kubernetes cluster. You could do that with a daemonset or just a regular pod.

Regardless of how you deploy OpenZiti though, are you confused as to how you'd create the service itself? As in, what the host config would look like? I am not sure I understand your question fully.

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [March 3, 2025, 4:50pm UTC](https://openziti.discourse.group/t/openziti-on-talos-cluster/4047/3 "2025-03-03T16:50:58Z")

</div>

> [@TheLumberjack](#):
>
> just a regular pod

Here's some specifics for the "just a regular pod" approach.

One way is to deploy a Ziti router: [Install the Router in Kubernetes | OpenZiti](https://openziti.io/docs/guides/deployments/kubernetes/kubernetes-router). Then you can host Ziti services with that router's tunneler identity.

Another way is to deploy a Ziti tunneler in hosting mode as a reverse proxy: [Deploy a Hosting Tunneler in Kubernetes | OpenZiti](https://openziti.io/docs/reference/tunnelers/kubernetes/kubernetes-host). The `ziti-host` chart runs `ziti-edge-tunnel run-host`, which is a run mode that only hosts Ziti services.

---

<div class="post-metadata">

**Author:** ![brandi](https://avatars.discourse-cdn.com/v4/letter/b/45deac/32.png) [@brandi](https://openziti.discourse.group/u/brandi)\
**Post date:** [March 3, 2025, 5:35pm UTC](https://openziti.discourse.group/t/openziti-on-talos-cluster/4047/4 "2025-03-03T17:35:05Z")

</div>

Hi

> [@TheLumberjack](#):
>
> If I'm not mistaken, I believe the k8s API is available from within the cluster itself by default.

Yeah basically that's my question, how can we configure an Openziti service to access the K8S API, how should the host.v1 be configured?

Also for apps hosted on K8S, if it's a pod running a private router or a tunneler with, should Openziti host.v1 config point directly to the K8S services ?

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [March 3, 2025, 5:48pm UTC](https://openziti.discourse.group/t/openziti-on-talos-cluster/4047/5 "2025-03-03T17:48:35Z")

</div>

Tunneled Ziti services need a "host config" to set the target address for the tunneler to send packets exiting the Ziti service.

`host.v1` example:

```json
{
  "address": "kubernetes.default.svc.cluster.local",
  "port": 443,
  "protocol": "tcp"
}

```

based on [Tunneler Config Type host.v1 | OpenZiti](https://openziti.io/docs/learn/core-concepts/config-store/config-type-host-v1)

You could then use any of that Kubernetes API server's existing DNS SANs as the Ziti service intercept address in your `intercept.v1`.

```json
{
    "protocols": [
        "tcp"
    ],
    "addresses": [
        "kubernetes.default.svc"
    ],
    "portRanges": [
        {
            "low": 443,
            "high": 443
        }
    ]
}

```

Depending on your K8S distribution, you may be able to add a DNS SAN and use that for your Ziti service intercept.
