Giter Club home page Giter Club logo

aliyun-devops-demo's Introduction

Aliyun DevOps Automation Demo

Build Status

Which is not in scope of the demo

  1. AD integration or any IdP integration is not part of the demo.

    • This involves many manual configuration steps and external tools which cannot be automated properly in a independent github repo
    • The outcome of the integration could be RAM(Resource Access Management) users or RAM roles that will be used for automating the cloud DevOps. You can consider this repo demo as the next step of the IdP/AD integration
  2. #TODO

Prerequisites (Manual Steps)

  1. You have already a valid, ready to use Alibaba Cloud or Aliyun account.

  2. You have activated the following services (if activation is required)

    • ECS (Elastic Compute Service)
    • Auto Scaling
    • ARMS (Application Real-time Monitoring Service)
    • KMS (Key Management Service)
    • Log Service
    • Domain Service
    • ACK (Managed Kubernetes)
    • ACR (Managed Container Registry)
  3. To be able to automate the complete story, you need to prepare a domain name in advance.

  4. You need to prepare a valid OSS Bucket for storing the terraform state optionally with a OTS table for locking ( One can achieve this by using terraform or aliyun cli but it is not in our demo scope)

  5. You need to prepare a valid RAM role in your account or in each of hierachical resource management accounts. In the demo, I use terraform code to simulate a RAM role creation during the account setup step.

  6. You need to prepare a RAM user with proper permission

Workflow

  1. Accounts Setup

    In this step, you have an empty account and you need to prepare the content below (Account Setup modules)

    • UAA (User Authentication and Authorization)
    • RAM roles for Service to Service authentication #TODO
    • RAM roles for ECS/pod assumption
  2. Managed Services Setup

    • K8s and its friends (VPC, VSwitch, Security Group, Log Service)
    • Database (schema, accounts, whitelists)
    • KMS
    • ...
  3. K8s AliCloud Native Services Setup

    • Kube2Ram
    • Ingress Controller
    • Managed Prometheus
    • Logging
    • external-dns
    • external-secret
  4. Solution

    • TODO

Demos

  1. Ingress and services working with LoadBalancer and external DNS
  2. Helm Charts
  3. Prometheus Alert Rule
  4. prometheus exporter with ServiceMonitor
  5. CloudMonitor metrics integration

Limitations

TBD

TODO list

  1. Alibaba Cloud Container Registry automation - waiting for ACR EE in Frankfurt

Workarounds

TBD

Extras

How to create helm chart

How to guide

aliyun-devops-demo's People

Contributors

yagrxu avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.