Freckle Node¶
The Freckle Node is a custom-built rackmount compute node purpose-built for running Kubernetes workloads across homelab clusters. Each generation is designed around specific workload requirements, with minor revisions within a generation for chassis or thermal changes.
Generation 3¶
Generation 3 (2025) is a ground-up redesign driven by the need for Intel Arc iGPU support for hardware-accelerated H.265 and 4K transcoding (Plex/Jellyfin). These are the primary AMD64 workhorse nodes in the fairy-k8s01 cluster, running all non-inference workloads: home automation, media services, networking, auth, monitoring, and storage controllers.
Gen 3.1 (2026) is a minor revision that moves to a chassis with native U.2 drive mounting support — in Gen 3.0 the drives are just loose inside the chassis.
Gen 3.0¶
Bill of Materials¶
| Component | Part | Notes |
|---|---|---|
| Motherboard | Supermicro X14SAZ-TLN4F | LGA1851, dual 10G X550 + 2x 2.5G i226LM + IPMI |
| CPU | Intel Core Ultra 7 265K | 20C/20T, 125W TDP, Arc iGPU |
| RAM | DDR5 4x32GB | 128GB total, see note below |
| OS Disk | Samsung 980 Pro M.2 | Boot drive (JMD1 slot) |
| Ceph OSDs | 2x Samsung SZ1735 1.6TB U.2 | SLC, 30 DWPD, 250K rand write IOPS |
| MCIO Cable | 10Gtek MCIO x8 to 2x U.2 | SFF-TA-1016 to SFF-8639, 0.75m, PCIe 4.0 |
| NIC | Onboard Intel X550 10GBase-T | Dual-port, second port available for dedicated Ceph traffic |
| Chassis | Sliger CX2151a 2U | Single PCIe riser (double-width), SFX PSU |
| Fans | 4x Arctic P8 Max 80mm | Chassis fans |
| Rails | iStarUSA TC-RAIL-20 | 20" sliding rail kit |
| Cooler | Thermalright AXP90-X53 Full (copper) | Low-profile for 2U clearance, 145W TDP rating |
| PSU | Corsair SF750 SFX | 750W |
Key Design Points¶
Motherboard: The Supermicro X14SAZ-TLN4F was chosen for its combination of dual onboard Intel X550 10GBase-T, IPMI/BMC for remote management, and Intel Arc iGPU for hardware transcoding (Plex/Jellyfin).
Ceph OSD connectivity: The two U.2 drives connect via the JNVME1 MCIO connector (PCIe 4.0 x4+x4) using a breakout cable — no PCIe slot consumed. The Samsung SZ1735 drives are SLC with 30 DWPD endurance, chosen for Ceph write amplification tolerance.
RAM: Nodes use either Corsair CMK64GX5M2B6000Z40 or G.Skill F5-6000J4048F32GX2-FX5 kits (2x32GB each, two kits per node). Both are DDR5-6000 CL40 and run at 4400 MT/s when all four DIMM slots are populated.
Network: The onboard dual-port Intel X550 provides two 10GBase-T connections. One port handles primary cluster traffic, with the second available as a dedicated Ceph cluster network if needed.
Talos Extensions¶
| Extension | Purpose |
|---|---|
siderolabs/i915 |
Intel Arc iGPU support (media transcoding) |
siderolabs/intel-ucode |
CPU microcode updates |
siderolabs/iscsi-tools |
iSCSI client |
siderolabs/lldpd |
LLDP discovery |
siderolabs/mei |
Management Engine Interface |
Gen 3.1 Changes¶
The Gen 3.1 nodes share the same motherboard, RAM, Ceph drives, and MCIO cable as Gen 3.0. The differences are:
| Component | Gen 3.0 | Gen 3.1 |
|---|---|---|
| CPU | Core Ultra 7 265K (125W) | TBD — 265K or 265 non-K (65W) |
| Chassis | Sliger CX2151a | Sliger CX2151x |
Chassis¶
The Gen 3.1 nodes use the Sliger CX2151x. Note: three CX2130x chassis were originally ordered by mistake — contacting Sliger to change to CX2151x.
CPU¶
The CPU choice depends on thermal validation. The 265K (125W TDP) would make a fully homogeneous fleet with Gen 3.0, but needs to run cool enough in the CX2151x with 3–4 fans. If thermals are marginal, the 265 non-K (65W TDP) provides identical core count at lower power. Testing is scheduled for the first chassis delivery.
Status¶
- Chassis: delivered; cn02 built 2026-09-27 (BIOS 2.0, replaces the old compute02 as the third control-plane node). cn01-cn03 are all Gen 3.1 now.
- RAM: on hand
- CPUs: 265K thermal test on cn01 (Sliger CX2151, AXP90-X53 Full) hit the 105 °C Tjmax within a minute at stock power limits. The chassis' 66 mm cooler ceiling rules out a bigger heatsink, so the fix is a BIOS power-limit cap (see below) rather than the 65 W 265 non-K.
BIOS and BMC baseline¶
New X14SAZ boards ship with BIOS 2.0 (02/2026), whose defaults differ from the 1.1a boards in ways that break a Talos bring-up. Fix these before booting the Talos ISO; read/push them over Redfish once the BMC is licensed.
Settings that differ from BIOS 2.0 defaults¶
| Attribute | Value | Why |
|---|---|---|
PrimaryDisplay |
Auto |
2.0 defaults to IGFX, which hands the kernel an iGPU framebuffer. systemd-boot still shows on the BMC KVM, then the console goes black the moment Talos starts and never comes back. |
Re_SizeBARSupport |
Enabled |
matches cn01 |
SR_IOVSupport |
Enabled |
matches cn01; VF NICs for KubeVirt |
ACPISleepState |
Suspend Disabled |
server, never sleeps |
OnboardLAN1Support, OnboardLAN2Support |
Disabled |
the two i226 2.5G ports are unused; only the X550 pair (LAN3/LAN4 → eno3/eno4) is cabled |
PowerButtonFunction |
4 Seconds Override |
a brushed front button shouldn't instantly kill a Ceph node |
RestoreonACPowerLoss |
Power On |
nodes come back on their own after a PDU/UPS event |
IPv4HTTPSupport |
Enabled |
UEFI HTTP Boot of the signed Talos UKI (see Secure Boot below) |
IPv4PXESupport, IPv6PXESupport |
Disabled |
iPXE isn't Sidero-signed; PXE can't work under Secure Boot |
SecureBootEnable |
true |
set before first boot; the ISO enrollment below completes it |
UEFIBootOption_1 (BootOption_1 on 1.1a) |
UEFI Hard Disk:UEFI OS, _2–_9 Disabled |
boot from the installed disk only; no USB/network fallback. Stage after Talos is installed, or the install media won't boot |
TPMDeviceSelection |
dTPM |
Talos disk encryption seals to the discrete TPM |
SecureBootMode |
Custom |
Sidero's keys enrolled, see below |
PowerLimit1Override / PowerLimit1 |
Enabled / 125000 |
milliwatts. Caps the 265K at its 125 W TDP |
PowerLimit2Override / PowerLimit2 |
Enabled / 150000 |
stock PL2 is 250 W, which a 150 W-class low-profile cooler cannot sink |
cn02's attribute set is the reference (it was configured by hand to this
baseline on BIOS 2.0); diff a new node against it rather than trusting defaults.
Attribute names carry a per-BIOS-version suffix for some keys (e.g.
PowerLimit1_004E) and the BMC only refreshes its attribute set after the
host POSTs on the new BIOS, so push those after the first boot.
Reading and pushing BIOS settings over Redfish¶
Supermicro gates the BIOS endpoints behind a node-locked SFT-DCMS license.
Buy one per node up front (Supermicro Store); without it GET
/redfish/v1/Systems/1/Bios returns 403 Not licensed. With it:
# read
curl -sk -u "$USER:$PASS" https://<bmc>/redfish/v1/Systems/1/Bios | jq .Attributes
# stage changes (applied at next POST)
curl -sk -u "$USER:$PASS" -X PATCH -H 'Content-Type: application/json' \
https://<bmc>/redfish/v1/Systems/1/Bios/SD \
-d '{"Attributes":{"PrimaryDisplay":"Auto","PowerLimit1Override":"Enabled","PowerLimit1":125000}}'
# apply
curl -sk -u "$USER:$PASS" -X POST -H 'Content-Type: application/json' \
https://<bmc>/redfish/v1/Systems/1/Actions/ComputerSystem.Reset -d '{"ResetType":"ForceRestart"}'
Allowed values and units are in the registry at
https://<bmc>/registries/BiosAttributeRegistry.1.0.0.json. Redfish only
inventories the BMC's own NIC on these boards; host NIC MACs come from the
Talos dashboard or the switch, not the BMC.
BMC network mode: Dedicated, not Failover¶
Supermicro's default Failover mode lets the BMC take over a host LAN port via
NC-SI when its dedicated link drops. On the X14SAZ the shared port is one of
the X550 10G ports. During cn02's bring-up the BMC grabbed the switch port
at 100 Mbps while the host was down, and after switching the BMC to
Dedicated that switch port stayed dead (LED lit, controller reporting it
down) through a host cold cycle. Moving the cable to a fresh port linked at 10G
immediately. Set LAN Interface: Dedicated in the BMC before first boot.
Secure Boot key enrollment¶
The Talos secureboot ISO and installer are signed with Sidero's key. A fresh board only trusts Microsoft's, and Supermicro firmware rejects the image silently (black screen, no error). One-time per board:
- BIOS → Security → Secure Boot: mode
Custom, then reset to Setup Mode (erase keys). Leave Secure Boot enabled. - Boot the Talos secureboot ISO. Auto-enrollment only happens inside a
hypervisor, so press
Escat the systemd-boot menu and choose Enroll Secure Boot keys: auto. - It enrolls PK/KEK/db and reboots into the UKI under Secure Boot.
talosctl get securitystate on a booted node should report secureBoot: true
and bootedWithUKI: true.