System update: Kubernetes, Service Status, and Next Steps

[email protected] (Doug Bell) Sat, 13 Dec 2025 11:42:06 -0600
Newsgroups perl.cpan.testers.discuss
Message-ID <[email protected]>
--Apple-Mail=_A7664FEB-780E-47BC-A94E-7F8BF91F3B04
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii

TL;DR: Set up your super-admin access to the Kubernetes cluster. Set up =
SOPS with an AGE key and send the public key to me.



We are now (mostly) running on a Kubernetes cluster made up of some old =
VMs I had lying around and the new systems provided by the Open Source =
Lab at Oregon State University[1]. These services are currently in the =
cluster:

* Legacy Metabase shim
* Backend reports processing
* API server

These services are being migrated hopefully this weekend, and then the =
systems running them will be joined to the Kubernetes cluster.

* Web frontend
* CPAN / BackPAN mirrors
* Telemetry and monitoring

I have updated the cpantesters-deploy Github project[2] with information =
about the Kubernetes setup: It's a pretty basic k3s deploy with Longhorn =
set up by a complete novice to Kubernetes (me). There's still a lot to =
do around this, including updating the Rexfile to automate system setup, =
and improving the system setup with firewall configuration, user =
accounts, and other such.=20

Next steps:

I will add user accounts to the Kubernetes server node I rebuilt from an =
old VM. These will be the same as the ones added to other systems. =46rom =
there you can reach the Kubernetes configuration so that you can use =
`kubectl` locally to manage the cluster. This file can be found on =
nact-pdx-001.cpantesters.org as root using `kubectl config view --minify =
--flatten`. Put this on your local machine as `.kube/config` and =
`kubectl` will now be able to use our cluster.

This is also a great opportunity to fix our secret management. I have a =
vague idea that SOPS[3] will be the best path forward, but am still open =
to suggestions. If there are no better ideas, I'll need y'all to set up =
SOPS and send me a public key I can add to our secrets file(s) so you =
can decrypt them.


This is probably the least anxious I've felt about our hosting situation =
in a decade: We have contacts for every system still in our network and =
I'm not worried that someone will find one of our systems in a forgotten =
cabinet, fail to find any record of it, and decide to pull the plug.

Thank you to everyone who has helped inventory, document, contact, =
procure, manage, and otherwise helped CPAN Testers get to where we are =
now. It isn't perfect, but we're in a much more stable place that can =
support our re-growth.



Doug Bell
[email protected]


1: Open Source Lab at Oregon State University: https://osuosl.org/
2: cpantesters-deploy Github project: =
https://github.com/cpan-testers/cpantesters-deploy
3: SOPS: https://getsops.io/=

--Apple-Mail=_A7664FEB-780E-47BC-A94E-7F8BF91F3B04
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; =
charset=3Dus-ascii"></head><body style=3D"overflow-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;"><div>TL;DR: =
Set up your super-admin access to the Kubernetes cluster. Set up SOPS =
with an AGE key and send the public key to =
me.</div><div><br></div><div><br></div><div><br></div><div>We are now =
(mostly) running on a Kubernetes cluster made up of some old VMs I had =
lying around and the new systems provided by the Open Source Lab at =
Oregon State University[1]. These services are currently in the =
cluster:</div><div><br></div><div>* Legacy Metabase shim</div><div>* =
Backend reports processing</div><div>* API =
server</div><div><br></div><div>These services are being migrated =
hopefully this weekend, and then the systems running them will be joined =
to the Kubernetes cluster.</div><div><br></div><div>* Web =
frontend</div><div>* CPAN / BackPAN mirrors</div><div>* Telemetry and =
monitoring</div><div><br></div><div>I have updated the =
cpantesters-deploy Github project[2] with information about the =
Kubernetes setup: It's a pretty basic k3s deploy with Longhorn set up by =
a complete novice to Kubernetes (me). There's still a lot to do around =
this, including updating the Rexfile to automate system setup, and =
improving the system setup with firewall configuration, user accounts, =
and other such.&nbsp;</div><div><br></div><div>Next =
steps:</div><div><br></div><div>I will add user accounts to the =
Kubernetes server node I rebuilt from an old VM. These will be the same =
as the ones added to other systems. =46rom there you can reach the =
Kubernetes configuration so that you can use `kubectl` locally to manage =
the cluster. This file can be found on nact-pdx-001.cpantesters.org as =
root using `kubectl config view --minify --flatten`. Put this on your =
local machine as `.kube/config` and `kubectl` will now be able to use =
our cluster.</div><div><br></div><div>This is also a great opportunity =
to fix our secret management. I have a vague idea that SOPS[3] will be =
the best path forward, but am still open to suggestions. If there are no =
better ideas, I'll need y'all to set up SOPS and send me a public key I =
can add to our secrets file(s) so you can decrypt =
them.</div><div><br></div><div><br></div><div>This is probably the least =
anxious I've felt about our hosting situation in a decade: We have =
contacts for every system still in our network and I'm not worried that =
someone will find one of our systems in a forgotten cabinet, fail to =
find any record of it, and decide to pull the =
plug.</div><div><br></div><div>Thank you to everyone who has helped =
inventory, document, contact, procure, manage, and otherwise helped CPAN =
Testers get to where we are now. It isn't perfect, but we're in a much =
more stable place that can support our =
re-growth.</div><div><br></div><div><br></div><br><div>
<div>Doug Bell</div><div>[email protected]</div><div><br></div><br =
class=3D"Apple-interchange-newline">

</div>

1: Open Source Lab at Oregon State University:&nbsp;<a =
href=3D"https://osuosl.org/">https://osuosl.org/</a><div>2: =
cpantesters-deploy Github project:&nbsp;<a =
href=3D"https://github.com/cpan-testers/cpantesters-deploy">https://github=
.com/cpan-testers/cpantesters-deploy</a></div><div>3: SOPS:&nbsp;<a =
href=3D"https://getsops.io/">https://getsops.io/</a></div></body></html>=

--Apple-Mail=_A7664FEB-780E-47BC-A94E-7F8BF91F3B04--