This page explains how to deploy the FRIDGE services to a FRIDGE tenancy. This process includes configuration for various components such as Argo Workflows, MinIO, network policies, and other infrastructure settings. It does not deploy the Kubernetes clusters within the FRIDGE tenancy; instead, it assumes that Kubernetes clusters have already been deployed.
Deployment¶
A FRIDGE consists of two Kubernetes clusters: an access cluster and an isolated cluster.
The access cluster hosts the Harbor container registry and the VPN agent (NetBird) by which connections to the FRIDGE can be made.
The isolated cluster hosts the FRIDGE services.
The deployment process uses Pulumi to manage the infrastructure as code.
Currently, FRIDGE is configured to support deployment on Azure Kubernetes Service (AKS) and on DAWN. The isolated cluster can also be deployed to a local k3s instance.
You will require appropriate Kubernetes contexts for both clusters.
The Hosting Organisation should provide you with the required credentials.
Access cluster¶
You will deploy the access cluster first, as it hosts the Harbor container registry and VPN agent required to access and subsequently deploy services into the isolated cluster.
Navigate to the infra/fridge/access-cluster/ folder.
Create a stack¶
The infra/fridge/access-cluster/ folder already contains a Pulumi project configuration file (Pulumi.yaml), so you do not need to run pulumi new to create a new project.
The Pulumi.yaml file defines the project name and a schema for the configurations for individual stacks.
To create a new stack, you can use the following command:
pulumi stack init <stack-name>Configure the stack¶
Each stack has its own configuration settings, defined in the Pulumi.<stack-name>.yaml files.
The configuration can be manually edited, or you can use the Pulumi CLI to set configuration values.
You can set individual configuration values for the stack using the following command:
pulumi config set <key> <value>Some of the configuration keys must be set as secrets, such as the MinIO access key and secret key.
Those must be set using the Pulumi CLI using the --secret flag.
For example, the following command sets the minio_root_password:
pulumi config set --secret minio_root_password <your-minio-secret-key>It is critical that you set all required configuration keys before deploying the stack. In particular, you will need to supply a setup up key for NetBird. The setup key will be used to register the NetBird agent in the cluster with the VPN mesh overlay network. For a guide to configuring NetBird, see the Configuring NetBird documentation.
For a complete list of configuration keys, see the Pulumi.yaml file.
Kubernetes context¶
Pulumi requires that the Kubernetes context is set for the stack.
This must match one of the Kubernetes contexts in your local kubeconfig.
You can check the available contexts with kubectl:
kubectl config get-contextsFor example, to set the Kubernetes context for the dawn stack, you can use:
pulumi config set kubernetes:context dawnDeploying with Pulumi¶
Ensure that you are able to connect to the Kubernetes API of the access cluster.
On AKS, the Kubernetes API is publicly accessible during development/testing, so no changes to your local kubeconfig are required.
On Dawn, you will need to set up an SSH connection to the bastion host on the access cluster’s local network.
Once you have set up the stack and its configuration, you can deploy the stack using the following command:
pulumi upIsolated cluster¶
You will deploy the isolated cluster next, as it hosts the FRIDGE services.
Navigate to the infra/fridge/isolated-cluster/ folder.
Two additional steps are required before deploying FRIDGE to the isolated cluster.
VPN access: You must run the deployment steps from a machine connected to the VPN mesh overlay network. The connecting machine must be part of a NetBird Group that has permission to communicate with the NetBird agent in the access cluster on TCP port 6443
Kubernetes context: You must modify the Kubernetes context for the isolated cluster stack to use the local port forwarded to the isolated cluster’s API server. We recommend that you make a dedicated copy of the
kubeconfigfile for the isolated cluster. Edit it to point tohttps://<netbird-fqdn-or-ip>:6443, as per the NetBird instructions Then, set the Kubernetes context for the stack using the Pulumi CLI:pulumi config set kubernetes:context <isolated-cluster-context>
Once the stack is configured and you have verified that you can connect to the isolated cluster’s Kubernetes API, you can deploy the isolated cluster stack using pulumi up.
Note that pulumi up can safely be repeated if any errors arise.
Sometimes errors during deployment are due to race conditions that Pulumi cannot mitigate, and a repeated attempt will be successful.