πŸ—οΈ Garage Infrastructure

Multi-region S3-compatible object store Β· Geo-replicated across 3 datacenters

Garage v2.3.0 Β· dxflrs/garage
loading metrics… Β· refreshed on every page load

πŸ“Š Live Cluster Metrics

...
Total Bucket Data
...
Total Objects
...
Kubernetes Nodes
...
Replication
...
Garage Nodes
...
Max Queue Depth
...
Block Errors
...
Total Disk Used
across all regions
...
Total Disk Capacity
across all regions
mimir
Data Source
prometheus Β· server-side

πŸ“ˆ Cluster Charts

🟒 Storage Usage by Zone

πŸ”΅ Node Distribution

🟣 Capacity Distribution

🟠 Disk Utilization %

πŸ“ˆ Live Traffic & Health (Last 1 Hour)

🚦 S3 Request Rate

loading...

πŸ“€ Data Throughput

loading...

πŸ”„ Block Sync Catch-Up

loading...

⚠️ Block Errors & Queue

loading...

🌐 Multi-Region Topology with Tailscale Proxy Groups

Storage Node Gateway Node common-ingress (inbound) common-egress (outbound) Cross-Region RPC Tailscale VPN
Garage Multi-Region Topology β€” 3 datacenters with Tailscale VPN and GSLB round-robin Diagram showing three datacenter regions (Ottawa with 4 Talos nodes, Robbinsdale with 3 Talos nodes, St. Petersburg with 3 arm64+GPU nodes) connected via a Tailscale VPN backbone and common-ingress/common-egress Tailscale proxy groups. Each region contains storage pods and gateway pods. Cross-region RPC flows are shown as animated amber lines between regions. A GSLB round-robin DNS (s3.cdn.keiretsu.top) routes public S3 traffic via an Envoy Gateway. Traffic weights: Ottawa 33%, Robbinsdale 33%, St. Petersburg 34%. Replication factor is 2 with consistent mode. 🌐 Envoy Gateway public β€” s3.cdn.keiretsu.top (GSLB β†’ garage-gateway:3900) 🌐 Tailscale VPN Backbone β€” keiretsu.ts.net common-ingress ProxyGroup β€” 3 replicas Β· Tailscale VPN Inbound β†’ Service ingress-0 ingress-1 ingress-2 9 TS services ingress-0 ingress-1 ingress-2 8 TS services ingress-0 ingress-1 ingress-2 8 TS services common-egress ProxyGroup β€” 3 replicas Β· Service β†’ Tailscale (outbound RPC) egress-0 egress-1 egress-2 13 egress TS services egress-0 egress-1 egress-2 13 egress TS services egress-0 egress-1 egress-2 13 egress TS services Ottawa β†’ Robbinsdale RPC πŸ‡¨πŸ‡¦ Ottawa 4 Nodes (Talos) Β· Services & Media Storage Tier (common-ingress) asuka kaji rei shiro smb Gateway Tier gateway-0 gateway-1 RPC Templates (common-egress) ottawa-gw-{ordinal} robbinsdale-gw-{ordinal} stpetersburg-gw-{ordinal} via s3.cdn.keiretsu.top (33%) 🏠 Robbinsdale 3 Nodes (Talos) Β· Production Home Lab Storage Tier (common-ingress) stone tank titan smb Gateway Tier gateway-0 gateway-1 RPC Templates (common-egress) ottawa-gw-{ordinal} robbinsdale-gw-{ordinal} stpetersburg-gw-{ordinal} via s3.cdn.keiretsu.top (33%) πŸš€ St. Petersburg 3 Nodes (arm64+GPU) Β· AI/ML Storage (manual layout) spark-0 spark-1 orin-0 (cp) Gateway gateway-0 gateway-1 RPC Templates (common-egress) ottawa-gw-{ordinal} robbinsdale-gw-{ordinal} stpetersburg-gw-{ordinal} via s3.cdn.keiretsu.top (34%) GSLB Round-Robin Β· s3.cdn.keiretsu.top β†’ ottawa:33 robbinsdale:33 stpetersburg:34 👺 Public S3: Client β†’ s3.cdn.keiretsu.top (GSLB) β†’ Envoy Gateway public β†’ Gateway pod 👺 Replication: Gateway β†’ common-egress β†’ Tailscale VPN β†’ other region's common-ingress β†’ Storage pod Each cluster runs all 3 regions' gateway RPC endpoints as local egress services (13 via common-egress) Β· Tailscale VPN inbound via common-ingress

πŸ›οΈ Per-Cluster Breakdown

πŸ‡¨πŸ‡¦ Ottawa β€” Services & Media

K8s Nodes4 ...
Storage Pods5 (4 NVMe localpath + 1 SMB)
Gateway Pods2
common-ingress... replicas Β· 9 TS svcs
common-egress... replicas Β· 13 TS svcs (all regions)
... used...
asukakajirei shirosmb gw-0gw-1 ingressΓ—3egressΓ—3

🏠 Robbinsdale β€” Home Lab

K8s Nodes3 ...
Storage Pods4 (3 localpath + 1 SMB)
Gateway Pods2
common-ingress... replicas Β· 8 TS svcs
common-egress... replicas Β· 13 TS svcs (all regions)
... used...
stonetanktitan smb gw-0gw-1 ingressΓ—3egressΓ—3

πŸš€ St. Petersburg β€” AI/ML GPU Cluster

K8s Nodes3 ...
Storage3 localpath (spark-0, spark-1, orin-0)
Gateway Pods2
common-ingress... replicas Β· 8 TS svcs
common-egress... replicas Β· 13 TS svcs (all regions)
FederationRejoined 2026-06-04
... used...
Notearm64 GPU β€” timeouts expected
spark-0spark-1orin-0 gw-0gw-1 ingressΓ—3egressΓ—3

βš™οΈ Architecture

πŸ”‘ Replication & Consistency

  • β€’ Replication factor: 2 (read quorum=2)
  • β€’ Consistency mode: consistent β€” prevents restic AEAD corruption
  • β€’ Layout version v209 β€” auto-applied via GarageCluster CR

πŸ“₯ common-ingress (Tailscale VPN Inbound)

  • β€’ 3 replicas per cluster β€” Tailscale VPN traffic β†’ service
  • β€’ For Tailscale VPN clients accessing Garage S3/admin/web
  • β€’ Garage storage + gateway pods accept VPN inbound via this group
  • β€’ Not used for public S3 CDN traffic (that goes through Envoy Gateway)
  • β€’ 8–9 TS services per cluster with annotation: proxy-group: common-ingress
  • β€’ Migrated from standalone TS pods to proxy group (Jun 9)

πŸ“€ common-egress (Outbound RPC)

  • β€’ 3 replicas per cluster β€” outbound Tailscale connections
  • β€’ Each cluster runs all 3 regions' gateway RPC services (13 total)
  • β€’ Template: {zone}-gw-{ordinal}.keiretsu.ts.net:3901
  • β€’ Cross-region RPC flow: Garage β†’ common-egress β†’ VPN β†’ common-ingress β†’ peer

🌐 GSLB + Envoy Gateway β€” s3.cdn.keiretsu.top

  • β€’ K8GB round-robin DNS: s3.cdn.keiretsu.top β†’ 3 A records
  • β€’ Weights: ottawa 33%, robbinsdale 33%, stpetersburg 34%
  • β€’ GSLB β†’ Envoy Gateway public β†’ garage-gateway:3900
  • β€’ Tailscale VPN clients hit common-ingress proxy for S3 access
  • β€’ All 3 clusters healthy β€” GSLB CRs: garage-s3-cdn