Containers are a great solution for consistent software deployments. When you start using containers in your environment, you and your team will quickly realise that you need a system which allows you to automate container operations. You need a system to keep your containers running when stuff breaks (which always happens, expect failure!), be able to scale up and down, and which is also extensible, so you can interact with it or built upon it to get the functionality you need. The most popular system for deploying, scaling and managing containerized applications is Kubernetes.
ksonnet is a framework for writing, sharing, and deploying Kubernetes application manifests. With its CLI, you can generate a complete application from scratch in only a few commands, or manage a complex system at scale.
Specifically, ksonnet allows you to:
Reuse common manifest patterns (within your app or from external libraries)
Customize manifests directly with powerful object concatenation syntax
Deploy app manifests to multiple environments
Diff across environments to compare two running versions of your app
Track the entire state of your app configuration in version controllable files
All of this results in a more iterative process for developing manifests, one that can be supplemented by continuous integration (CI).
Envoy is an L7 proxy and communication bus designed for large modern service oriented architectures. The project was born out of the belief that:
The network should be transparent to applications. When network and application problems do occur it should be easy to determine the source of the problem.tl;dr: this post explains how the new openstack-tempest-ci-live-booter package configures a machine to PXE boot a Debian Live system running on KVM in order to run functional testing of OpenStack. It may be of interest to you if you want to learn how to PXE boot a KVM virtual machine running Debian Live, even if you aren’t interested in OpenStack.
Tahoe-LAFS is a Free and Open decentralized cloud storage system. It distributes your data across multiple servers. Even if some of the servers fail or are taken over by an attacker, the entire file store continues to function correctly, preserving your privacy and security.
Kolla’s mission is to provide production-ready containers and deployment tools for operating OpenStack clouds.
This documentation is for the Kolla container images. The following subprojects are available to help deploy Kolla:
- kolla-ansible
- kolla-kubernetes
Minio is an object storage server released under Apache License v2.0. It is compatible with Amazon S3 cloud storage service. It is best suited for storing unstructured data such as photos, videos, log files, backups and container / VM images. Size of an object can range from a few KBs to a maximum of 5TB.
Minio server is light enough to be bundled with the application stack, similar to NodeJS, Redis and MySQL.
To give you a little bit of background when the OSD writes into his journal it uses D_SYNC and O_DIRECT. Writing with O_DIRECT bypasses the Kernel page cache, while D_SYNC ensures that the command won’t return until every single write is complete. So yes, basically the OSD forces all the writes to be flushed prior to start the next IO.
Simple yet Powerful Turnkey Solution to Build Clouds and Manage Data Center Virtualization
CoreDNS is a DNS server that chains middleware. Each middleware implements some DNS feature, like service discovery.
Service Discovery
CoreDNS integrates with Kubernetes via the Kubernetes middleware or directly with etcd with the etcd middleware.
Middlewares
Currently CoreDNS supports (among others) the following middlewares:
chaos: respond to CH class queries
dnssec: on-the-fly DNSSEC signing of records
etcd: SkyDNS replacement
file: serve DNS from a set of files
health: simple health check
kubernetes: use CoreDNS as a KubeDNS replacement
loadbalance: shuffle A and AAAA records
metrics: Prometheus metrics
pprof: Go profiling
proxy: forward queries to an upstream (recursive) server
rewrite: rewrite incoming queries
secondary: be a secondary nameserver and retrieve zones from a primary
"Classic" DNS fully supported
Serve DNS data from a set of files, DNSSEC signed or not.
Or just enable on-the-fly DNSSEC signing.
The content contained herein is correct as of January 2017, and represents the status quo as of the time it was written. Google’s security policies and systems may change going forward, as we continually improve protection for our customers.
An important ingredient in the Technology of Cyberspace is the ability to let any user communicate with any other user or service. How do we wire 5 billion people on the planet? That's an engineering problem - to design a network capable of handling such numbers over such a wide geographic area. We are going to talk about the engineering aspects of such network design for next two lectures.
OpenStack is on a six-month release cycle, with each release given a code name starting with consecutive letters of the alphabet. On October 7th, OpenStack Newton was released. Let's look at a few highlights from OpenStack's 2016 Newton release.
In addition to the usual enormous number of incremental improvements, the Newton release focused on ease of deployment and usability improvements, as well as improved container-management tools. It also added the Tacker project, for deploying and managing virtual network functions (NFV) on OpenStack.
Failure is inevitable. As engineers building and maintaining complex systems, we likely encounter failure in some form on a daily basis. Not every failure requires a postmortem, but if a failure impacts the bottom line of the business, it becomes important to follow a postmortem process. I say “follow a postmortem process” instead of “do a postmortem”, because a postmortem should have very specific goals designed to prevent future failures in your environment. Simply asking the five whys to try and determine the root cause is not enough.
Open vSwitch is a production quality, multilayer virtual switch licensed under the open source Apache 2.0 license. It is designed to enable massive network automation through programmatic extension, while still supporting standard management interfaces and protocols (e.g. NetFlow, sFlow, IPFIX, RSPAN, CLI, LACP, 802.1ag). In addition, it is designed to support distribution across multiple physical servers similar to VMware's vNetwork distributed vswitch or Cisco's Nexus 1000V.
Monasca is a open-source multi-tenant, highly scalable, performant, fault-tolerant monitoring-as-a-service solution that integrates with OpenStack. It uses a REST API for high-speed metrics processing and querying and has a streaming alarm engine and notification engine.