The deployment setup is orchestrated by ORCE and finally executed/operated by argoCD Applicationsets. Each applicationset deploys a layer of applications sorted by context.
Each Script prepares a different step of the cluster. Start with basic-cluster-init.sh to setup a basic cluster including network, storage and logging/monitoring.
To integrate the cluster bootstrap better in the orchestration engine, an installer provides an rest api for easier usage with kubernetes clusters. The ORCE can then decide if some features of the products are installed or not.
This layer has to be installed beforehand in the cluster without argo cd, to enable the basement for all other following componenents. All components must be installed in the order as declared.
Contains ArgoCD and all app projects
The network provides essential network components which are required to bootstrap the core functionality.
| Component | Purpose | Mandatory | Install Prio |
|---|---|---|---|
| Open Telemtry | The Open Telemetry stack installs standard tools like grafana, prometheus, alertmanager, loki, jeager, tempo und promtail. | ✅ | 0 |
The XFSC security has the task to provide essential security components. This components must be installed first. The layer consists of the following components:
| Component | Purpose | Mandatory | Install Prio |
|---|---|---|---|
| Kyverno | Kyverno is an zero trust component which evaluates pod starts and cluster setups by policy. It's later used for evaluating f.e. correct container signings. To enable label the namespace with image-signature-policy.xsfc.io/enabled=true | ❌ | 0 |
| OpenBao | Open Bao is used for all scenarios where a transit engine or other secret engines are required. | ✅ | 1 |
| External Secret Operator | Secret management of XFSC. Manages handling of cluster secrets. Can be connected to external stores but it's by default connected to openbao. | ✅ | 2 |
The installation of those components is made via helm install directly in the cluster to prepare the proper setup.
After the security, the application management is installed, because it is relying on external secret operator and openbao. The namepaces must be installed over the security namespace, because the service account for openbao is requried.
| Component | Purpose | Mandatory | Install Prio |
|---|---|---|---|
| Infra App Namespace | An namespace package for infrastructure. | ✅ | 0 |
| OCM App Namespace | An namespace package for OCM. | ✅ | 0 |
| Catalogue App Namespace | An namespace package for Catalogue. | ✅ | 0 |
| OCM W-Stack App Namespace | An namespace package for OCM-Stack. | ✅ | 0 |
| TSA App Namespace | An namespace package for TSA. | ✅ | 0 |
| DCS App Namespace | An namespace package for DCS. | ✅ | 0 |
| ORCE App Namespace | An namespace package for ORCE. | ✅ | 0 |
| Kubernetes Operator | The operator is an special xfsc operator and is installed first, to observe xfsc resources and injection requests for xfsc components. It has the task to decide, when an injection request has to be fullfilled or when a resource must be created (e.g. for databases, kyverno etc.) | ✅ | 1 |
The storage package provides essential storage components like cassandra, postgres and redis.
The network provides essential network components which are required to bootstrap the core functionality.
| Component | Purpose | Mandatory | Install Prio |
|---|---|---|---|
| Cert Manager | Cert Manager is used for let's encrypt certifcates. The package installs an DNS based resolver. | ✅ | 0 |
| Envoy Gateway | Envoy Gateway manages incoming traffic for the cluster using the Kubernetes Gateway API. | ✅ | 1 |
| BIND9 | BIND9 provides the authoritative DNS service and DNSSEC support for TRAIN trust zones. | ✅ | 2 |
| External DNS | External DNS manages the connection between ingress and dns. | ✅ | 3 |
The core layer consits basic tools which are required for operating the xfsc stack. This layer is installed via argo applicationset. The set contains the following:
| Component | Purpose | Mandatory | Install Prio |
|---|---|---|---|
| Nats | Nats is used as light weight message bus to provide for the application and eventing system. | ✅ | 3 |
| Universal Resolver | The universal resolver provides for applications the capability to resolve DIDs. | ✅ | 3 |