The Mac control plane for the local AI stack: OTEL, two Cribl Edges, and a Cribl Stream, all in one OrbStack cluster.
orbstack-kubernetes is the Kustomize-based manifest set for a local Kubernetes cluster on
OrbStack. It runs the AI-development monitoring stack as five StatefulSets
in a single monitoring namespace: an OTEL Collector, two Cribl Edges (one cloud-managed, one
standalone), a local Cribl Stream, and a Cribl MCP server.
Architecture invariant
Edge → Stream → Splunk is the only allowed data path. The standalone Cribl Edge talks to the standalone Cribl Stream over HEC port 8088. It never talks directly to Splunk. Stream is the only component with Splunk egress. Network policies in the manifest set enforce this. No one can shortcut it.What runs in the cluster
Four
healthchecks.io CronJobs ping every 5 minutes as dead-man switches: pipeline-heartbeat, heartbeat-splunk, heartbeat-edge, heartbeat-otel.
How it fits
Secrets and overlays
Nix and direnv pre-inject secrets into the Claude Code session (SOPS-decrypted env vars).secrets.enc.yaml is the source of truth. secrets.enc.yaml.example is the template. Base
manifests in k8s/monitoring/ use the literal string PLACEHOLDER_HOME_DIR for hostPath volumes;
the base never replaces it. scripts/generate-overlay.sh produces the gitignored
k8s/overlays/local/ at deploy time.
Getting started
1
Activate the dev shell
cd ~/git/orbstack-kubernetes/main && direnv allow. Provides kubectl, kubectx, helm, kustomize, kubeconform, kube-linter, conftest, pluto, k9s, stern, kind, jq, yq.2
Seed the secrets file
cp secrets.enc.yaml.example secrets.enc.yaml && sops secrets.enc.yaml. Encrypt-on-save; never commit a plaintext copy.3
Deploy
make deploy-doppler. Generates the overlay, creates secrets, applies the kustomize bundle. Verify with make status.4
Run the tests
make test-all chains unit → smoke → pipeline → forwarding → sourcetypes. CI enforces the same chain on every PR.CI and the self-hosted runner
E2E tests run on a self-hosted ARM64 runner on the laptop while it is powered on. The runner is a stockmyoung34/github-runner:ubuntu-jammy container with
EPHEMERAL=1, managed by docker/actions-runner/docker-compose.yml. A macOS
LaunchAgent invokes make runner-foreground for boot persistence.
make runner-doctor is the deep health check. The runner requires OrbStack
running and Doppler authenticated.
That laptop runner is not the always-on Mac Studio fleet (mac-fleet,
GitHub group still named llm-runners). Studio jobs are Linux ARM64 inside
an Apple container. Pin them with apple-container so they cannot land here.
See CI/CD overview.
Related repos
cc-edge-the-mac-pack
The macOS-native Cribl Edge pack — captures host telemetry that this cluster does not.
Monitoring agents
Cross-stack view of every collector and where it runs.
LXC vs Docker decision tree
Why the homelab Edge is LXC and this one is K8s/OrbStack.
Source on GitHub
Full manifest set, Makefile, deployment scripts.