Machines
Machine management is the bridge between user-owned hardware and Satusky deployments. It is broader than renting capacity: the target system lets users discover, claim, group, observe, operate, and eventually decommission machines through one coherent control plane.
Current source-of-truth model
Section titled “Current source-of-truth model”| Concern | Best source of truth |
|---|---|
| machine discovery and management reachability | SideroLink |
| OS-level lifecycle and pre-Kubernetes state | Talos API |
| schedulability, capacity, allocatable resources | Kubernetes Node API |
| placement metadata | Kubernetes node labels |
| ownership, billing history, audit trail | backend database |
| live host/workload telemetry | Kubernetes metrics, Prometheus, and Talos where needed |
SideroLink and Talos
Section titled “SideroLink and Talos”SideroLink gives Talos machines a stable management address over a WireGuard overlay, including when machines sit behind NAT or firewalls. That makes discovery and lifecycle operations possible before ordinary app networking is useful.
Talos machine └── SideroLink identity / overlay address └── Satusky control planeCurrent CLI workflow
Section titled “Current CLI workflow”List owned inventory and inspect one machine by its machine ID or name:
1ctl machine list1ctl machine get worker-example1ctl machine inspect worker-examplemachine inspect combines stored inventory, hardware, labels, and Talos/Kubernetes status where available. A statically connected worker can be healthy even when the command warns that it is not present in SideroLink discovery; the remaining sections still describe the available sources.
Fetch bounded diagnostics:
1ctl machine logs worker-example --source kubernetes --tail 100 --since 10m1ctl machine events worker-example --tail 50An empty result means no matching logs or events were returned. It is not, by itself, evidence that the machine is unhealthy.
Rentable capacity and accounting history are separate views:
1ctl machine available --region MY --zone my-kul-1b --min-cpu 2 --min-memory 41ctl machine usage listControl-plane model
Section titled “Control-plane model”1ctl machine = fleet ownership and operations1ctl deploy = workload placement intentKubernetes = scheduling substrateInventory creation, updates, and deletion change control-plane records. Do not use them as substitutes for Kubernetes drain, Talos reconfiguration, or physical machine lifecycle procedures.
Labels and selectors
Section titled “Labels and selectors”This is the strategic center of machine-aware deployment.
machines declare what they areworkloads declare what they needUse the immutable machine ID for label changes:
MACHINE_ID=89905f5f769867452a7bd6c7505ab34d1ctl machine labels list "$MACHINE_ID"1ctl machine labels set "$MACHINE_ID" pool=production architecture=arm641ctl machine labels unset "$MACHINE_ID" pool1ctl machine labels keysUser keys are stored in the Satusky label namespace. Label removal aliases are delete and rm; the singular machine label alias is also accepted.
Most machine read commands support table and JSON output. machine labels list and machine labels keys currently render human-readable output even when --output json is supplied, so do not parse those commands as JSON.
Safe scripting
Section titled “Safe scripting”Supply every documented positional argument explicitly. Some machine subcommands currently print help and exit successfully when a required positional argument is omitted. Validate identifiers in the script rather than treating that help exit as an operation success.
Current gaps and target direction
Section titled “Current gaps and target direction”| Gap | Target |
|---|---|
| Discovery and claim are not part of the current CLI contract. | First-class tenant onboarding for new hardware. |
| Logs and events are point-in-time queries, not streaming telemetry. | Unified live and historical fleet diagnostics. |
| Placement language is narrower than the intended model. | General selectors become the foundation. |
| SideroLink/Talos details risk leaking too far upward. | Keep them diagnosable but beneath a clean machine UX. |