System update: Kubernetes, Service Status, and Next Steps
[email protected] (Doug Bell) Sat, 13 Dec 2025 11:42:06 -0600
| Newsgroups | perl.cpan.testers.discuss |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail=_A7664FEB-780E-47BC-A94E-7F8BF91F3B04 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii TL;DR: Set up your super-admin access to the Kubernetes cluster. Set up = SOPS with an AGE key and send the public key to me. We are now (mostly) running on a Kubernetes cluster made up of some old = VMs I had lying around and the new systems provided by the Open Source = Lab at Oregon State University[1]. These services are currently in the = cluster: * Legacy Metabase shim * Backend reports processing * API server These services are being migrated hopefully this weekend, and then the = systems running them will be joined to the Kubernetes cluster. * Web frontend * CPAN / BackPAN mirrors * Telemetry and monitoring I have updated the cpantesters-deploy Github project[2] with information = about the Kubernetes setup: It's a pretty basic k3s deploy with Longhorn = set up by a complete novice to Kubernetes (me). There's still a lot to = do around this, including updating the Rexfile to automate system setup, = and improving the system setup with firewall configuration, user = accounts, and other such.=20 Next steps: I will add user accounts to the Kubernetes server node I rebuilt from an = old VM. These will be the same as the ones added to other systems. =46rom = there you can reach the Kubernetes configuration so that you can use = `kubectl` locally to manage the cluster. This file can be found on = nact-pdx-001.cpantesters.org as root using `kubectl config view --minify = --flatten`. Put this on your local machine as `.kube/config` and = `kubectl` will now be able to use our cluster. This is also a great opportunity to fix our secret management. I have a = vague idea that SOPS[3] will be the best path forward, but am still open = to suggestions. If there are no better ideas, I'll need y'all to set up = SOPS and send me a public key I can add to our secrets file(s) so you = can decrypt them. This is probably the least anxious I've felt about our hosting situation = in a decade: We have contacts for every system still in our network and = I'm not worried that someone will find one of our systems in a forgotten = cabinet, fail to find any record of it, and decide to pull the plug. Thank you to everyone who has helped inventory, document, contact, = procure, manage, and otherwise helped CPAN Testers get to where we are = now. It isn't perfect, but we're in a much more stable place that can = support our re-growth. Doug Bell [email protected] 1: Open Source Lab at Oregon State University: https://osuosl.org/ 2: cpantesters-deploy Github project: = https://github.com/cpan-testers/cpantesters-deploy 3: SOPS: https://getsops.io/= --Apple-Mail=_A7664FEB-780E-47BC-A94E-7F8BF91F3B04 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=us-ascii <html><head><meta http-equiv=3D"content-type" content=3D"text/html; = charset=3Dus-ascii"></head><body style=3D"overflow-wrap: break-word; = -webkit-nbsp-mode: space; line-break: after-white-space;"><div>TL;DR: = Set up your super-admin access to the Kubernetes cluster. Set up SOPS = with an AGE key and send the public key to = me.</div><div><br></div><div><br></div><div><br></div><div>We are now = (mostly) running on a Kubernetes cluster made up of some old VMs I had = lying around and the new systems provided by the Open Source Lab at = Oregon State University[1]. These services are currently in the = cluster:</div><div><br></div><div>* Legacy Metabase shim</div><div>* = Backend reports processing</div><div>* API = server</div><div><br></div><div>These services are being migrated = hopefully this weekend, and then the systems running them will be joined = to the Kubernetes cluster.</div><div><br></div><div>* Web = frontend</div><div>* CPAN / BackPAN mirrors</div><div>* Telemetry and = monitoring</div><div><br></div><div>I have updated the = cpantesters-deploy Github project[2] with information about the = Kubernetes setup: It's a pretty basic k3s deploy with Longhorn set up by = a complete novice to Kubernetes (me). There's still a lot to do around = this, including updating the Rexfile to automate system setup, and = improving the system setup with firewall configuration, user accounts, = and other such. </div><div><br></div><div>Next = steps:</div><div><br></div><div>I will add user accounts to the = Kubernetes server node I rebuilt from an old VM. These will be the same = as the ones added to other systems. =46rom there you can reach the = Kubernetes configuration so that you can use `kubectl` locally to manage = the cluster. This file can be found on nact-pdx-001.cpantesters.org as = root using `kubectl config view --minify --flatten`. Put this on your = local machine as `.kube/config` and `kubectl` will now be able to use = our cluster.</div><div><br></div><div>This is also a great opportunity = to fix our secret management. I have a vague idea that SOPS[3] will be = the best path forward, but am still open to suggestions. If there are no = better ideas, I'll need y'all to set up SOPS and send me a public key I = can add to our secrets file(s) so you can decrypt = them.</div><div><br></div><div><br></div><div>This is probably the least = anxious I've felt about our hosting situation in a decade: We have = contacts for every system still in our network and I'm not worried that = someone will find one of our systems in a forgotten cabinet, fail to = find any record of it, and decide to pull the = plug.</div><div><br></div><div>Thank you to everyone who has helped = inventory, document, contact, procure, manage, and otherwise helped CPAN = Testers get to where we are now. It isn't perfect, but we're in a much = more stable place that can support our = re-growth.</div><div><br></div><div><br></div><br><div> <div>Doug Bell</div><div>[email protected]</div><div><br></div><br = class=3D"Apple-interchange-newline"> </div> 1: Open Source Lab at Oregon State University: <a = href=3D"https://osuosl.org/">https://osuosl.org/</a><div>2: = cpantesters-deploy Github project: <a = href=3D"https://github.com/cpan-testers/cpantesters-deploy">https://github= .com/cpan-testers/cpantesters-deploy</a></div><div>3: SOPS: <a = href=3D"https://getsops.io/">https://getsops.io/</a></div></body></html>= --Apple-Mail=_A7664FEB-780E-47BC-A94E-7F8BF91F3B04--