Does anyone automate the generation of visio/architecture diagrams?
What tool do you use?
https://redd.it/g1j2m6
@r_devops
What tool do you use?
https://redd.it/g1j2m6
@r_devops
reddit
Does anyone automate the generation of visio/architecture diagrams?
What tool do you use?
GitHub actions vs Gitlab CI
I’m currently using GitLab and I like the CI experience. However with GitHub’s new announcement, they’re becoming more and more of a viable competitor to GitLab.
Has anyone had experience with GitHub actions and how they compare with GitLab’s CI?
If GitHub’s CI offering is a viable option I would switch in a heartbeat since GitLab’s UI is pretty unintuitive at times. GitHub’s code review commenting and many other UI features are just much easier to use overall.
https://redd.it/g1i9mc
@r_devops
I’m currently using GitLab and I like the CI experience. However with GitHub’s new announcement, they’re becoming more and more of a viable competitor to GitLab.
Has anyone had experience with GitHub actions and how they compare with GitLab’s CI?
If GitHub’s CI offering is a viable option I would switch in a heartbeat since GitLab’s UI is pretty unintuitive at times. GitHub’s code review commenting and many other UI features are just much easier to use overall.
https://redd.it/g1i9mc
@r_devops
reddit
GitHub actions vs Gitlab CI
I’m currently using GitLab and I like the CI experience. However with GitHub’s new announcement, they’re becoming more and more of a viable...
Working style for Devops
In your work, do you find yourself the only person on a project or are you usually paired up with someone on the job?
https://redd.it/g1hqyt
@r_devops
In your work, do you find yourself the only person on a project or are you usually paired up with someone on the job?
https://redd.it/g1hqyt
@r_devops
reddit
Working style for Devops
In your work, do you find yourself the only person on a project or are you usually paired up with someone on the job?
Why is inter-service TLS desirable?
I have a production load at the moment without TLS enabled between services nor between services an externally listening ingress. TLS terminates at the ingress from the client. Internal services have no public IP address. I am the only one with direct access to the cluster.
If it's a single cloud environment that can only be accessed locally does it matter? What are the risks / attack vectors? Or where can I learn more about it? Tell me why I'm an idiot.
https://redd.it/g1h41y
@r_devops
I have a production load at the moment without TLS enabled between services nor between services an externally listening ingress. TLS terminates at the ingress from the client. Internal services have no public IP address. I am the only one with direct access to the cluster.
If it's a single cloud environment that can only be accessed locally does it matter? What are the risks / attack vectors? Or where can I learn more about it? Tell me why I'm an idiot.
https://redd.it/g1h41y
@r_devops
reddit
Why is inter-service TLS desirable?
I have a production load at the moment without TLS enabled between services nor between services an externally listening ingress. TLS terminates...
What would you invest in learning, Openshift, Splunk , Infoblox?
I've doing K8S tools for the last 3 years and I am not sure which of those 3 ( openshift, splunk or infoblox) would add more value to my Skillset. At this point I don't want invest more effort in learning or mastering K8S and just want to jump into something else.
Openshift . Pros - easier to learn given my k8s exp and the $ rate is above devops rates . Cons - I don't see many jobs requiring it.
Splunk . Pros - very valuable $$$$ niche skill . Cons - Takes a lot in time/$$$$ wise to learn it .
Infoblox - I had some experience in the past , and I've seen a couple of roles in the market paying above market rate for this skillset .
What do you think ?
https://redd.it/g1c91b
@r_devops
I've doing K8S tools for the last 3 years and I am not sure which of those 3 ( openshift, splunk or infoblox) would add more value to my Skillset. At this point I don't want invest more effort in learning or mastering K8S and just want to jump into something else.
Openshift . Pros - easier to learn given my k8s exp and the $ rate is above devops rates . Cons - I don't see many jobs requiring it.
Splunk . Pros - very valuable $$$$ niche skill . Cons - Takes a lot in time/$$$$ wise to learn it .
Infoblox - I had some experience in the past , and I've seen a couple of roles in the market paying above market rate for this skillset .
What do you think ?
https://redd.it/g1c91b
@r_devops
reddit
What would you invest in learning, Openshift, Splunk , Infoblox?
I've doing K8S tools for the last 3 years and I am not sure which of those 3 ( openshift, splunk or infoblox) would add more value to my...
Infrastructure Automation with Terraform and Atlantis
If anyone out there is using Jenkins to automate Terraform , Atlantis is worth taking a look. I have been using Atlantis for quite sometime now and love it. Actively using to spin up production infrastructure. Here is my medium blog if anyone is interested
https://tech.boxed.com/infrastructure-automation-with-terraform-0-12-and-atlantis-1a5725ee247e
https://redd.it/g1ftgh
@r_devops
If anyone out there is using Jenkins to automate Terraform , Atlantis is worth taking a look. I have been using Atlantis for quite sometime now and love it. Actively using to spin up production infrastructure. Here is my medium blog if anyone is interested
https://tech.boxed.com/infrastructure-automation-with-terraform-0-12-and-atlantis-1a5725ee247e
https://redd.it/g1ftgh
@r_devops
Medium
Infrastructure Automation with Terraform 0.12 and Atlantis
Before (the days of) Atlantis …
WTF is wrong with full remote positions?
I eventually found a local office job that is currently 100% remote due to COVID, I'll go back to office after all this and will be fine.
But I'd like to discuss weird remote job market I had recent experience with.
About half a year ago I decided that it's damn cool to have fully remote position, primarily because it's possible to live in a cheap place, commute to next room and work in pajamas. Then I started my search, and it was pretty bad.
First - amazingly few positions are posted. There are more offline positions here, in Greater Detroit (that is not Bay Area guys), than remote positions in whole US.
Second - terrible conversion rate. I was getting around 1 tech interview for every 5-10 applications for traditional jobs. For online it was like 1 tech interview for 30-50 applications. It's completely crazy.
I have 15+ years of experience in system admin, both win and linux, last 4 is in DevOps/Cloud - theoretically my skills are in demand, that's not the problem I guess.
What's your experience?
https://redd.it/g1i7lo
@r_devops
I eventually found a local office job that is currently 100% remote due to COVID, I'll go back to office after all this and will be fine.
But I'd like to discuss weird remote job market I had recent experience with.
About half a year ago I decided that it's damn cool to have fully remote position, primarily because it's possible to live in a cheap place, commute to next room and work in pajamas. Then I started my search, and it was pretty bad.
First - amazingly few positions are posted. There are more offline positions here, in Greater Detroit (that is not Bay Area guys), than remote positions in whole US.
Second - terrible conversion rate. I was getting around 1 tech interview for every 5-10 applications for traditional jobs. For online it was like 1 tech interview for 30-50 applications. It's completely crazy.
I have 15+ years of experience in system admin, both win and linux, last 4 is in DevOps/Cloud - theoretically my skills are in demand, that's not the problem I guess.
What's your experience?
https://redd.it/g1i7lo
@r_devops
reddit
WTF is wrong with full remote positions?
I eventually found a local office job that is currently 100% remote due to COVID, I'll go back to office after all this and will be fine. But...
Reusing Serverless Environments in your CI Pipeline to Reduce Serverless Integration Test Runtime from 40 minutes to 7
Recently my team managed to reduce the time taken to run Integration Tests on our Serverless microservice via CI from 40 minutes to 7 minutes!
We used another Serverless microservice to manage the re use of Serverless envrionments and CircleCI’s parallelisation tools. Check out my article if you’re interested!
https://medium.com/serverless-transformation/reducing-your-serverless-integration-test-runtime-on-ci-from-40-minutes-to-7-a8982a47b655
https://redd.it/g19fdg
@r_devops
Recently my team managed to reduce the time taken to run Integration Tests on our Serverless microservice via CI from 40 minutes to 7 minutes!
We used another Serverless microservice to manage the re use of Serverless envrionments and CircleCI’s parallelisation tools. Check out my article if you’re interested!
https://medium.com/serverless-transformation/reducing-your-serverless-integration-test-runtime-on-ci-from-40-minutes-to-7-a8982a47b655
https://redd.it/g19fdg
@r_devops
Medium
Reducing Serverless Integration Test Runtime on CI — From 40 minutes to 7
Learn how a team reduced the CI time for their Serverless integration tests, the tools they used and what you can do to achieve the same.
CICD Pipeline for multiple services on AWS ECS with ECS ComposeX
[x-post](https://www.reddit.com/r/aws/comments/g0kezz/cicd_pipeline_for_multiple_services_on_aws_ecs/) from r/aws.
My first blog post of what I hope to be a regular series of articles around DevOps work. Feel free to submit any ideas on the [GH repo for the blog](https://github.com/lambda-my-aws/blog.ecs-composex.lambda-my-aws.io) and report any issues with [ECS ComposeX](https://github.com/lambda-my-aws/ecs_composex) or submit PRs.
Thanks!
https://redd.it/g198h5
@r_devops
[x-post](https://www.reddit.com/r/aws/comments/g0kezz/cicd_pipeline_for_multiple_services_on_aws_ecs/) from r/aws.
My first blog post of what I hope to be a regular series of articles around DevOps work. Feel free to submit any ideas on the [GH repo for the blog](https://github.com/lambda-my-aws/blog.ecs-composex.lambda-my-aws.io) and report any issues with [ECS ComposeX](https://github.com/lambda-my-aws/ecs_composex) or submit PRs.
Thanks!
https://redd.it/g198h5
@r_devops
reddit
CICD Pipeline for multiple services on AWS ECS with ECS ComposeX...
Posted in r/aws by u/JohnPreston72 • 4 points and 1 comment
How do you become certified in DevOps?
I am seeing positions that include text like the following: "A solid understanding of tools such as Chef, Python, PowerShell, Docker, Puppet, AWS CloudFormation, AWS, Ansible, and Kubernetes."
Let's say you learn some (or all) of these technologies at home, taking advantage of this time during pandemic.
How would you prove to prospective employers that you are capable with these technologies? Would you list on your resume the Udemy courses taken or books read, etc?
https://redd.it/g1brbc
@r_devops
I am seeing positions that include text like the following: "A solid understanding of tools such as Chef, Python, PowerShell, Docker, Puppet, AWS CloudFormation, AWS, Ansible, and Kubernetes."
Let's say you learn some (or all) of these technologies at home, taking advantage of this time during pandemic.
How would you prove to prospective employers that you are capable with these technologies? Would you list on your resume the Udemy courses taken or books read, etc?
https://redd.it/g1brbc
@r_devops
reddit
How do you become certified in DevOps?
I am seeing positions that include text like the following: "A solid understanding of tools such as Chef, Python, PowerShell, Docker, Puppet, AWS...
upgrading multiple repo's/Deploying multiple projects with a multi-repo Design?
Hey everyone,
currently just testing this because of curiosity.. switched from a single repository where all deployment files for each container/vm reside to a "per service" design. Reason for this is that i want to improve the automated deployment of new services, and i think that switching from a monorepo to multiple ones could help here.
Every repo now looks kinda like this (example from a webcrawler project):
├── crawler <- sourcecode
│ └── crawler.py
└── deployment <- deployment files
├── deploy-int.yml
├── deploy-prod.yml
├── inventory <- ansible inventory directory container variables for each host
│ ├── host_vars
│ │ ├── crawler.local
│ │ │ └── vars.yml
│ │ └── database.local
│ │ └── vars.yml
│ └── inventory <- inventory file
└── roles <- ansible roles, included as a submodule from another repo
I have to say that i like this design. I am creating new repos for services with cookiecutter, this made the deployment process a lot easier. Also, since every service has its own repo, its easy to find out how a certain service has been configured and deployed. Inside the deployment folder are all the files which are needed for ansible to spin up the needed containers/vms, and depending on which role i add to the deploy-xxx.yml files they are also provisioned like needed.
But i have one problem with this setup:
There are situations where i feel like a single repo with every service repo could be really handy.
For example, how would i deploy a whole "site" with this design? Lets say everything burns down and a new host system is already set up but no containers/vms have been deployed yet. What i want is to push a single big red button which says "DEPLOY IT ALL!" and every service gets deployed. With a monorepo, this is an easy task because all the inventory files are in the same directory. But how do i get those when each service has its own repo? Also, how do i keep them in sync?
Not saying that a whole infrastructure burns down regularly, but i want a solution for this just in case..
I think what i need is a master repo which includes all the service repos, but not sure how i should keep it up to date. Maybe a webhook inside the deployment process of new services could do the trick?
Has someone here been in a similar situation? Or can someone think of an better solution to this? Drone is being used as a ci/cd system, maybe a site deployment can be triggered from there somehow?
Any help and hints appreciated, thanks in advance! :)
Also, sorry for any wording or grammatical errors.
https://redd.it/g1572m
@r_devops
Hey everyone,
currently just testing this because of curiosity.. switched from a single repository where all deployment files for each container/vm reside to a "per service" design. Reason for this is that i want to improve the automated deployment of new services, and i think that switching from a monorepo to multiple ones could help here.
Every repo now looks kinda like this (example from a webcrawler project):
├── crawler <- sourcecode
│ └── crawler.py
└── deployment <- deployment files
├── deploy-int.yml
├── deploy-prod.yml
├── inventory <- ansible inventory directory container variables for each host
│ ├── host_vars
│ │ ├── crawler.local
│ │ │ └── vars.yml
│ │ └── database.local
│ │ └── vars.yml
│ └── inventory <- inventory file
└── roles <- ansible roles, included as a submodule from another repo
I have to say that i like this design. I am creating new repos for services with cookiecutter, this made the deployment process a lot easier. Also, since every service has its own repo, its easy to find out how a certain service has been configured and deployed. Inside the deployment folder are all the files which are needed for ansible to spin up the needed containers/vms, and depending on which role i add to the deploy-xxx.yml files they are also provisioned like needed.
But i have one problem with this setup:
There are situations where i feel like a single repo with every service repo could be really handy.
For example, how would i deploy a whole "site" with this design? Lets say everything burns down and a new host system is already set up but no containers/vms have been deployed yet. What i want is to push a single big red button which says "DEPLOY IT ALL!" and every service gets deployed. With a monorepo, this is an easy task because all the inventory files are in the same directory. But how do i get those when each service has its own repo? Also, how do i keep them in sync?
Not saying that a whole infrastructure burns down regularly, but i want a solution for this just in case..
I think what i need is a master repo which includes all the service repos, but not sure how i should keep it up to date. Maybe a webhook inside the deployment process of new services could do the trick?
Has someone here been in a similar situation? Or can someone think of an better solution to this? Drone is being used as a ci/cd system, maybe a site deployment can be triggered from there somehow?
Any help and hints appreciated, thanks in advance! :)
Also, sorry for any wording or grammatical errors.
https://redd.it/g1572m
@r_devops
reddit
upgrading multiple repo's/Deploying multiple projects with a...
Hey everyone, currently just testing this because of curiosity.. switched from a single repository where all deployment files for each...
Export amazon image into IBM cloud
Hello,
I've a VM running in AWS and want to move it to IBM Cloud. Is this supported yet? I would like to use the Amazon AMI to bring a new VM in IBM Cloud. TIA
https://redd.it/g188j1
@r_devops
Hello,
I've a VM running in AWS and want to move it to IBM Cloud. Is this supported yet? I would like to use the Amazon AMI to bring a new VM in IBM Cloud. TIA
https://redd.it/g188j1
@r_devops
reddit
Export amazon image into IBM cloud
Hello, I've a VM running in AWS and want to move it to IBM Cloud. Is this supported yet? I would like to use the Amazon AMI to bring a new VM in...
Grafana - aggregating traffic graphs
Hi,
I've got some Juniper routers doing streaming telemetry into Grafana (using OpenNTI), and have currently got traffic graphs in bps per interface.
I'd like to create a single aggregate traffic graph, showing the combined inbound/outbound values of say three interfaces.
Does anybody know how to do this?
https://redd.it/g149wf
@r_devops
Hi,
I've got some Juniper routers doing streaming telemetry into Grafana (using OpenNTI), and have currently got traffic graphs in bps per interface.
I'd like to create a single aggregate traffic graph, showing the combined inbound/outbound values of say three interfaces.
Does anybody know how to do this?
https://redd.it/g149wf
@r_devops
reddit
Grafana - aggregating traffic graphs
Hi, I've got some Juniper routers doing streaming telemetry into Grafana (using OpenNTI), and have currently got traffic graphs in bps per...
Telegraf/Prometheus/Grafana snmp monitoring
Hi,
I'm trying to do some SNMP monitoring for some a Cisco ASA device, I've figured out the SNMP part with Telegraf, but the next part is putting this into Prometheus, and then Grafana.
The SNMP data is being polled using an `snmp.table`, as there are multiple values in a list format.
Here is my telegraf.conf:
[agent]
hostname = "myhostname"
[global_tags]
[[inputs.snmp]]
agents = ["mydevice:161"]
version = 2
community = "mycommunitystring"
name = "snmp"
name_suffix = "_parsed"
[[inputs.snmp.field]]
name = "ike_tunnels"
oid = "iso.3.6.1.4.1.9.9.171.1.2.1.1.0"
[[inputs.snmp.field]]
name = "ipsec_tunnels"
oid = "iso.3.6.1.4.1.9.9.171.1.3.1.1.0"
[[inputs.snmp.field]]
name = "hostname"
oid = "iso.3.6.1.2.1.1.5.0"
is_tag = true
[[inputs.snmp.table]]
inherit_tags = ["hostname"]
name = "snmp"
[[inputs.snmp.table.field]]
name = "vpn_peer_ip"
oid = "iso.3.6.1.4.1.9.9.171.1.2.2.1.7"
conversion = "ipaddr"
[[outputs.prometheus_client]]
listen = myprometheusserver:9222"
metric_version = 2
This will output to this:
2020-04-14T08:43:23Z I! Starting Telegraf 1.14.0
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename ike_tunnels=43i,ipsec_tunnels=49i 1586853803000000000
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename vpn_peer_ip="1.1.1.1" 1586853803000000000
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename vpn_peer_ip="2.2.2.2" 1586853803000000000
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename vpn_peer_ip="3.3.3.3" 1586853803000000000
Prometheus will pick up the first data which includes `ike_tunnels` and `ipsec_tunnels` but it will skip the table data, which is a list of `vpn_peer_ip`, and I think that is because it is in the list format. See screenshot:
[Prometheus output screenshot](https://pasteboard.co/J3KhaqQ.png)
Meaning in grafana, I can query `snmp_parsed_ike_tunnels` and also `snmp_parsed_ipssec_tunnels` so why is it that I cannot capture the snmp table, assuming this would be `snmp_parsed_vpn_peer_ip`?
Now, I am not sure if my telegraf.conf is invalid/incorrect for what I want it to do, or does Prometheus not support this? I've spent quite a few days on this already, and I feel like I've run out of ideas, so looking for some help/direction.
Thanks.
https://redd.it/g123fn
@r_devops
Hi,
I'm trying to do some SNMP monitoring for some a Cisco ASA device, I've figured out the SNMP part with Telegraf, but the next part is putting this into Prometheus, and then Grafana.
The SNMP data is being polled using an `snmp.table`, as there are multiple values in a list format.
Here is my telegraf.conf:
[agent]
hostname = "myhostname"
[global_tags]
[[inputs.snmp]]
agents = ["mydevice:161"]
version = 2
community = "mycommunitystring"
name = "snmp"
name_suffix = "_parsed"
[[inputs.snmp.field]]
name = "ike_tunnels"
oid = "iso.3.6.1.4.1.9.9.171.1.2.1.1.0"
[[inputs.snmp.field]]
name = "ipsec_tunnels"
oid = "iso.3.6.1.4.1.9.9.171.1.3.1.1.0"
[[inputs.snmp.field]]
name = "hostname"
oid = "iso.3.6.1.2.1.1.5.0"
is_tag = true
[[inputs.snmp.table]]
inherit_tags = ["hostname"]
name = "snmp"
[[inputs.snmp.table.field]]
name = "vpn_peer_ip"
oid = "iso.3.6.1.4.1.9.9.171.1.2.2.1.7"
conversion = "ipaddr"
[[outputs.prometheus_client]]
listen = myprometheusserver:9222"
metric_version = 2
This will output to this:
2020-04-14T08:43:23Z I! Starting Telegraf 1.14.0
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename ike_tunnels=43i,ipsec_tunnels=49i 1586853803000000000
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename vpn_peer_ip="1.1.1.1" 1586853803000000000
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename vpn_peer_ip="2.2.2.2" 1586853803000000000
> snmp_parsed,agent_host=mydevicehostname,host=myhostname,hostname=ciscodevicename vpn_peer_ip="3.3.3.3" 1586853803000000000
Prometheus will pick up the first data which includes `ike_tunnels` and `ipsec_tunnels` but it will skip the table data, which is a list of `vpn_peer_ip`, and I think that is because it is in the list format. See screenshot:
[Prometheus output screenshot](https://pasteboard.co/J3KhaqQ.png)
Meaning in grafana, I can query `snmp_parsed_ike_tunnels` and also `snmp_parsed_ipssec_tunnels` so why is it that I cannot capture the snmp table, assuming this would be `snmp_parsed_vpn_peer_ip`?
Now, I am not sure if my telegraf.conf is invalid/incorrect for what I want it to do, or does Prometheus not support this? I've spent quite a few days on this already, and I feel like I've run out of ideas, so looking for some help/direction.
Thanks.
https://redd.it/g123fn
@r_devops
pasteboard.co
Pasteboard - Uploaded Image
Simple and lightning fast image sharing. Upload clipboard images with Copy & Paste and image files with Drag & Drop
Three-tier architecture: Log management
Hello,
I'm trying to understand log management tools. Can someone just explain how these stacks are built? Frontend is easy, but what about the database, the shiptool and the processing? What does Graylog do? What is the difference between EFK and ELK (okay, Logstash and Fluentd, but Logstash is again an independent log management solution).
I am happy about your answers :)
https://redd.it/g10mew
@r_devops
Hello,
I'm trying to understand log management tools. Can someone just explain how these stacks are built? Frontend is easy, but what about the database, the shiptool and the processing? What does Graylog do? What is the difference between EFK and ELK (okay, Logstash and Fluentd, but Logstash is again an independent log management solution).
I am happy about your answers :)
https://redd.it/g10mew
@r_devops
reddit
Three-tier architecture: Log management
Hello, I'm trying to understand log management tools. Can someone just explain how these stacks are built? Frontend is easy, but what about the...
Pipeline and architecture drawing tools
What tool do you use to draw and graph your automation pipelines and architectures?
https://redd.it/g1y4gb
@r_devops
What tool do you use to draw and graph your automation pipelines and architectures?
https://redd.it/g1y4gb
@r_devops
reddit
Pipeline and architecture drawing tools
What tool do you use to draw and graph your automation pipelines and architectures?
[Question] Running SaaS agent on K8s cluster
I'm working on a SaaS that helps K8s users with observability and management. It also provides correlated view across clusters. For that purpose there is a need for some agents to be running within the cluster and reporting metrics to the SaaS backend. The rest of the things is accessible through web site once the data reported to the SaaS service. The product uses read-only access to non sensitive cluster APIs.
I want to remove barriers for entry and simplify the use as much as possible. If you're a Kubernetes I'd appreciate your feedback on how would you like to run such SaaS service (assuming you know what it is and need it).
Have few options in mind. Please feel free to suggest anything beyond those:
1. SaaS web site uses a wizard and asks if you're a public cloud user. If in AWS/GCP/Azure will show instructions to create service account. The SaaS will then connect to client's account, get list of managed K8s cluster. User selects a cluster and the SaaS deploys necessary agents on the cluster using the namespace of the choice. For self managed k8s clusters, asks for ip address/credentials and does the same thing. No direct management, configuration and deployment is needed.
2. User deploys a helm chart which contains an operator that handles agent deployment and version updates. It has write access to its own namespace only. Deploy the operator once, the rest is automated for life.
3. User deploys, upgrades and configures agent manually. Can be involved.
https://redd.it/g1yfvs
@r_devops
I'm working on a SaaS that helps K8s users with observability and management. It also provides correlated view across clusters. For that purpose there is a need for some agents to be running within the cluster and reporting metrics to the SaaS backend. The rest of the things is accessible through web site once the data reported to the SaaS service. The product uses read-only access to non sensitive cluster APIs.
I want to remove barriers for entry and simplify the use as much as possible. If you're a Kubernetes I'd appreciate your feedback on how would you like to run such SaaS service (assuming you know what it is and need it).
Have few options in mind. Please feel free to suggest anything beyond those:
1. SaaS web site uses a wizard and asks if you're a public cloud user. If in AWS/GCP/Azure will show instructions to create service account. The SaaS will then connect to client's account, get list of managed K8s cluster. User selects a cluster and the SaaS deploys necessary agents on the cluster using the namespace of the choice. For self managed k8s clusters, asks for ip address/credentials and does the same thing. No direct management, configuration and deployment is needed.
2. User deploys a helm chart which contains an operator that handles agent deployment and version updates. It has write access to its own namespace only. Deploy the operator once, the rest is automated for life.
3. User deploys, upgrades and configures agent manually. Can be involved.
https://redd.it/g1yfvs
@r_devops
reddit
[Question] Running SaaS agent on K8s cluster
I'm working on a SaaS that helps K8s users with observability and management. It also provides correlated view across clusters. For that purpose...
Jenkins and running Projects/Builds as another user?
Hi everyone,
Quick question here. So, I built out our team's Jenkins instance about a year ago. We have an Ent Git that I use to push PowerShell scripts to and have Jenkins jobs that pull and run the scripts in Ent Git's remote repo. Simple enough and everything works great! But...
When I setup Jenkins, I have the service currently running with the "Log On" as my AD \_adm account that has Account Operator. I recently created a service account (srv\_jenkins) to have as the account in the Jenkins service "Log On". Worked just fine. I could log in to Jenkins web UI just fine. But wait... I go to run a job, specifically this job, like many of the ones, query AD/DNS/DHCP/other directory services or modify AD Objects. Well the job failed. I'm assuming that because the jobs run as the user account in the "Log On" tab for the Jenkins service? Is this correct?
If so, what is the work around, if I don't want my AD \_adm account to be running the Jenkins service, but need the jobs that would require Account Operator/Domain Admin to run the PowerShell scripts to run? Thanks!
https://redd.it/g1xs3b
@r_devops
Hi everyone,
Quick question here. So, I built out our team's Jenkins instance about a year ago. We have an Ent Git that I use to push PowerShell scripts to and have Jenkins jobs that pull and run the scripts in Ent Git's remote repo. Simple enough and everything works great! But...
When I setup Jenkins, I have the service currently running with the "Log On" as my AD \_adm account that has Account Operator. I recently created a service account (srv\_jenkins) to have as the account in the Jenkins service "Log On". Worked just fine. I could log in to Jenkins web UI just fine. But wait... I go to run a job, specifically this job, like many of the ones, query AD/DNS/DHCP/other directory services or modify AD Objects. Well the job failed. I'm assuming that because the jobs run as the user account in the "Log On" tab for the Jenkins service? Is this correct?
If so, what is the work around, if I don't want my AD \_adm account to be running the Jenkins service, but need the jobs that would require Account Operator/Domain Admin to run the PowerShell scripts to run? Thanks!
https://redd.it/g1xs3b
@r_devops
reddit
Jenkins and running Projects/Builds as another user?
Hi everyone, Quick question here. So, I built out our team's Jenkins instance about a year ago. We have an Ent Git that I use to push PowerShell...
One Size Fits None
As somebody who has been involved with many projects, included some "One Size Fits All" pipelines. I thought I'd document some problems I've ran into, as well as some things that help this transition. Hopefully this helps at least one of you in the same boat.
https://medium.com/devops-dudes/one-size-fits-none-22cf9a1725ba
https://redd.it/g1w1bo
@r_devops
As somebody who has been involved with many projects, included some "One Size Fits All" pipelines. I thought I'd document some problems I've ran into, as well as some things that help this transition. Hopefully this helps at least one of you in the same boat.
https://medium.com/devops-dudes/one-size-fits-none-22cf9a1725ba
https://redd.it/g1w1bo
@r_devops
Medium
One Size Fits None
Making a one size fits all CI/CD process will leave you with one size that fits none
Workflow for Kubernetes DevOps
[Workflow for Kubernetes DevOps that can evolve.](https://medium.com/@imarunrk/workflow-for-kubernetes-devops-15f0dbb560ff)
The developers, application/cluster operators, architects, and security team wants to contribute to the Kubernetes YAML continuously to keep the Infrastructure matching to the evolving organization strategy and policy, which demands a workflow. [Read More](https://medium.com/@imarunrk/workflow-for-kubernetes-devops-15f0dbb560ff)
https://redd.it/g229e4
@r_devops
[Workflow for Kubernetes DevOps that can evolve.](https://medium.com/@imarunrk/workflow-for-kubernetes-devops-15f0dbb560ff)
The developers, application/cluster operators, architects, and security team wants to contribute to the Kubernetes YAML continuously to keep the Infrastructure matching to the evolving organization strategy and policy, which demands a workflow. [Read More](https://medium.com/@imarunrk/workflow-for-kubernetes-devops-15f0dbb560ff)
https://redd.it/g229e4
@r_devops
Medium
Workflow for Kubernetes DevOps
The developers, application/cluster operators, architects, and security team wants to contribute to the Kubernetes YAML continuously to…