31 Commits

Author SHA1 Message Date
Cédric Verstraeten
62244cff93 Merge pull request #34 from uug-ai/public-release-1786356403
A new public release - 1786356403
2026-08-13 13:30:19 +02:00
Cédric Verstraeten
c7be7901ff feat(mongodb-configmap): add MongoDB connection behavior and TLS configuration options 2026-08-13 10:18:31 +00:00
Cédric Verstraeten
6f6e95ae7a docs(README): clarify cert-manager self-checks DNS configuration 2026-08-11 14:22:20 +00:00
Cédric Verstraeten
bdbb9ae538 feat(cert-manager): replace CRDs enabled flag with values file for configuration 2026-08-11 14:10:32 +00:00
Cédric Verstraeten
b44775ef2a feat(ingress): add public HTTPS ingress configuration with cert-manager support 2026-08-11 14:05:37 +00:00
Cédric Verstraeten
d888d7e243 feat(database-import): add DocumentDB import job and script with example data 2026-08-11 13:00:10 +00:00
Cédric Verstraeten
2150a146b9 Update .gitignore 2026-08-11 13:56:41 +02:00
Cédric Verstraeten
bf164c208b Force DocumentDB replacement on VPC change
AWS cannot move a DocumentDB subnet group or cluster to a different VPC. Include the VPC ID in the subnet group name and create it before destroy, and add a replace_triggered_by lifecycle rule so the cluster is recreated when the subnet group changes instead of failing on an unsupported in-place update.

Document the behaviour and the snapshot caveat in the module README.
2026-08-11 13:08:35 +02:00
Cédric Verstraeten
687a0019d8 Update .gitignore 2026-08-10 14:38:04 +02:00
uug4ai
ba4f0df8be A new public release - 1786356403 2026-08-10 10:06:44 +00:00
Cédric Verstraeten
bf5eb0187e Merge remote-tracking branch 'refs/remotes/origin/main' 2026-08-06 15:45:40 +00:00
Cédric Verstraeten
8c620ccf1f feat(aws): add Terraform module for Amazon EKS and DocumentDB setup 2026-08-06 12:21:27 +00:00
Cédric Verstraeten
245b276d80 Update factory image version to v2.0.4 2026-07-30 16:18:08 +02:00
Cédric Verstraeten
442137cab2 Update kerberos-hub-values.yaml 2026-07-22 09:02:05 +02:00
Cédric Verstraeten
1751c76aa5 Merge pull request #33 from kerberos-io/feat/case-share-email-template
feat(email): add case-share white-label template + values
2026-07-22 09:00:35 +02:00
Cédric Verstraeten
67c9ae9dd5 Update kerberos-factory-deployment.yaml 2026-06-30 17:29:56 +02:00
Kilian Boute
a8001b37dc feat(email): add case-share white-label template + values
Adds the Kerberos-branded share_case email template (html/txt) and wires
caseShare/caseShareTitle into the hub email template values so the case-share
invitation renders with the dedicated template instead of the recording-share
one.
2026-06-23 13:46:41 +00:00
Cédric Verstraeten
85feb1d574 Update container image source in deployment YAML 2026-06-23 09:46:46 +02:00
Cédric Verstraeten
63b6607c02 Update factory image version to v2.0.2 2026-06-23 09:17:29 +02:00
cedricve
1d5c492959 Update documentation to replace 'Kerberos Agents' with 'Agents' for consistency 2026-06-22 13:00:14 +00:00
cedricve
8f41e9c375 Refactor Factory references and update deployment configurations 2026-06-22 12:36:57 +00:00
Cédric Verstraeten
0c1520c936 Merge pull request #32 from kerberos-io/public-release-1781595581
A new public release - 1781595581
2026-06-16 09:48:22 +02:00
uug4ai
469ae03f9c A new public release - 1781595581 2026-06-16 07:39:42 +00:00
Cédric Verstraeten
258f750441 Merge pull request #30 from kerberos-io/public-release-1776688403
A new public release - 1776688403
2026-04-20 14:42:17 +02:00
uug4ai
0257f5f323 A new public release - 1776688403 2026-04-20 12:33:24 +00:00
Cédric Verstraeten
cdb907a980 Rename deployment and update image reference 2026-03-09 06:58:20 +01:00
Cédric Verstraeten
cc57d08499 Merge pull request #28 from kerberos-io/public-release-1772868774
A new public release - 1772868774
2026-03-07 09:34:36 +01:00
uug4ai
2c7065d439 A new public release - 1772868774 2026-03-07 07:32:55 +00:00
Cédric Verstraeten
bbd59806c4 Merge pull request #27 from kerberos-io/public-release-1772208444
A new public release - 1772208444
2026-03-02 12:02:45 +01:00
uug4ai
591873e4ed A new public release - 1772208444 2026-02-27 16:07:25 +00:00
Cédric Verstraeten
b01604242f Merge pull request #25 from kerberos-io/public-release-1771807234
A new public release - 1771807234
2026-02-23 01:41:27 +01:00
40 changed files with 2383 additions and 85 deletions

3
.gitignore vendored
View File

@@ -1 +1,2 @@
**/charts
**/charts
modules/amazon-eks-documentdb/tfplan

View File

@@ -1,6 +1,6 @@
### Optimized Data Filtering for Enhanced Bandwidth Efficiency and Relevance
Once your Kerberos Agents are properly connected and all recordings are stored in the Kerberos Vault, you may encounter additional challenges such as bandwidth limitations, storage constraints, and the need to efficiently locate relevant data. To accomplish this, we can configure an integration to filter the recordings, ensuring that only the relevant ones are retained.
Once your Agents are properly connected and all recordings are stored in the Kerberos Vault, you may encounter additional challenges such as bandwidth limitations, storage constraints, and the need to efficiently locate relevant data. To accomplish this, we can configure an integration to filter the recordings, ensuring that only the relevant ones are retained.
Assuming all configurations are correctly set and all Kubernetes deployments are operational, you can apply the `data-filtering-deployment.yaml` deployment. This deployment will schedule a pod that listens to the configured integration in Kerberos Vault and runs a YOLOv8 model to evaluate the recordings and match them against specified conditions.

View File

@@ -10,7 +10,7 @@
Kubernetes is an open-source platform for automating the deployment, scaling, and management of containerized applications. It provides features like automated deployment, self-healing, service discovery, and storage orchestration. Kubernetes is essential for modern cloud-native application development and operations.
In this tutorial, we will guide you through the installation of the Kerberos.io edge stack, which includes the Kerberos Agent, Kerberos Vault, and the Data Filtering Service. This setup enables the storage of recordings from multiple cameras at the edge, facilitating local data processing and ensuring secure and efficient management of video streams.
In this tutorial, we will guide you through the installation of the Kerberos.io edge stack, which includes the Agent, Kerberos Vault, and the Data Filtering Service. This setup enables the storage of recordings from multiple cameras at the edge, facilitating local data processing and ensuring secure and efficient management of video streams.
## Install Kubernetes on Ubuntu with kubeadm
@@ -112,7 +112,7 @@ Ensure that all nodes are in the Ready state and all pods are in the Running sta
## Dependencies
When installing the Kerberos.io stack, several dependencies are required for storage, such as a database (e.g., MongoDB) and a message broker (e.g., RabbitMQ) for asynchronous behavior. We will install these components before setting up the Kerberos Agents and Kerberos Vault.
When installing the Kerberos.io stack, several dependencies are required for storage, such as a database (e.g., MongoDB) and a message broker (e.g., RabbitMQ) for asynchronous behavior. We will install these components before setting up the Agents and Kerberos Vault.
### Clone repository
@@ -131,7 +131,7 @@ When you create a Kubernetes cluster using `kubeadm` on a bare metal machine
MinIO is a high-performance, distributed object storage system that is compatible with Amazon S3 cloud storage service. It is designed to handle large-scale data storage and retrieval, making it an ideal choice for modern cloud-native applications.
In the context of the Kerberos.io stack, MinIO will be used to store recordings from the Kerberos Agents. These recordings are crucial for surveillance and monitoring purposes, and having a reliable storage solution like MinIO ensures that the data is stored securely and can be accessed efficiently.
In the context of the Kerberos.io stack, MinIO will be used to store recordings from the Agents. These recordings are crucial for surveillance and monitoring purposes, and having a reliable storage solution like MinIO ensures that the data is stored securely and can be accessed efficiently.
```bash
git clone --depth 1 --branch v6.0.1 https://github.com/minio/operator.git && kubectl apply -k operator/
@@ -349,15 +349,15 @@ With the Kerberos Vault installed, we can proceed to configure the various compo
- Access key: XJoi2@bgSOvOYBy# (or generate new keys, but don't forget to update them in the next steps)
- Secret key: OGGqat4lXRpL@9XBYc8FUaId@5 (or generate new keys, but don't forget to update them in the next steps)
### Create a Kerberos Agent
### Create an Agent
After deploying the Kerberos Vault and configuring the necessary services for storage, database, and integration, you can proceed to deploy the Kerberos Agent with the appropriate configuration. Review the `kerberos-agent-deployment.yaml` file and adjust the relevant settings, such as the RTSP URL, to ensure proper functionality. As mentioned below note that you can opt for the [Kerberos Factory](https://github.com/kerberos-io/factory/tree/master/kubernetes) which gives you a UI to manage the creation of Kerberos Agents. **_(Please note if you generated new the keys in the previous Kerberos Vault account creation, you need to update those in the Kerberos Agent deployment)_**
After deploying the Kerberos Vault and configuring the necessary services for storage, database, and integration, you can proceed to deploy the Agent with the appropriate configuration. Review the `kerberos-agent-deployment.yaml` file and adjust the relevant settings, such as the RTSP URL, to ensure proper functionality. As mentioned below note that you can opt for the [Factory](https://github.com/kerberos-io/factory/tree/master/kubernetes) which gives you a UI to manage the creation of Agents. **_(Please note if you generated new the keys in the previous Kerberos Vault account creation, you need to update those in the Agent deployment)_**
```bash
kubectl apply -f kerberos-agent-deployment.yaml
```
Review the creation of the Kerberos Agent and review the logs of the container to validate the Kerberos Agent is able to connect to the IP camera, and if a recording is being created and transferred to the Kerberos Vault
Review the creation of the Agent and review the logs of the container to validate the Agent is able to connect to the IP camera, and if a recording is being created and transferred to the Kerberos Vault
```bash
kubectl get po -w -A
@@ -366,11 +366,11 @@ kubectl logs -f kerberos-agent...
To validate the Kerberos Vault and review any stored recordings, access the user interface at `http://localhost:30080` (after establishing the reverse tunnel).
### Create Kerberos Agents through Kerberos Factory
### Create Agents through Factory
Managing Kerberos Agents through seperate configuration files might feel cumbersome, especially for non-technical users. This is where Kerberos Factory comes into the picture. Kerberos Factory provides a visual view that allows you to rapidly connect cameras through a user interface, which allows users without any technical background about cameras and kubernetes create Kerberos Agents.
Managing Agents through seperate configuration files might feel cumbersome, especially for non-technical users. This is where Factory comes into the picture. Factory provides a visual view that allows you to rapidly connect cameras through a user interface, which allows users without any technical background about cameras and kubernetes create Agents.
Kerberos Factory also requires a mongodb, just like Kerberos Vault. Luckily you can reuse the mongodb installation we have deployed earlier, the only thing we'll need to do is to create another `configmap.yaml` in the `kerberos-factory` namespace.
Factory also requires a mongodb, just like Kerberos Vault. Luckily you can reuse the mongodb installation we have deployed earlier, the only thing we'll need to do is to create another `configmap.yaml` in the `kerberos-factory` namespace.
Create the `kerberos-factory` namespace.
@@ -378,7 +378,7 @@ Create the `kerberos-factory` namespace.
kubectl create namespace kerberos-factory
```
Apply the manifests, so the Kerberos Factory application is deployed and knows how to connect to the MongoDB.
Apply the manifests, so the Factory application is deployed and knows how to connect to the MongoDB.
```bash
kubectl apply -f ./mongodb-configmap.yaml -n kerberos-factory
@@ -386,7 +386,7 @@ kubectl apply -f ./kerberos-factory-deployment.yaml -n kerberos-factory
kubectl apply -f ./kerberos-factory-service.yaml -n kerberos-factory
```
To allow our Kerberos Factory to create Kubernetes resources we will need to apply an additional cluster role. This will allow our Kerberos Factory deployment to read and write resources to our Kubernetes cluster.
To allow our Factory to create Kubernetes resources we will need to apply an additional cluster role. This will allow our Factory deployment to read and write resources to our Kubernetes cluster.
```bash
kubectl apply -f ./kerberos-factory-clusterrole.yaml -n kerberos-factory
@@ -400,7 +400,7 @@ kubectl get po -w -A
### Optimized Data Filtering for Enhanced Bandwidth Efficiency and Relevance
Once your Kerberos Agents are properly connected and all recordings are stored in the Kerberos Vault, you may encounter additional challenges such as bandwidth limitations, storage constraints, and the need to efficiently locate relevant data. To accomplish this, we can configure an integration to filter the recordings, ensuring that only the relevant ones are retained.
Once your Agents are properly connected and all recordings are stored in the Kerberos Vault, you may encounter additional challenges such as bandwidth limitations, storage constraints, and the need to efficiently locate relevant data. To accomplish this, we can configure an integration to filter the recordings, ensuring that only the relevant ones are retained.
Assuming all configurations are correctly set and all Kubernetes deployments are operational, you can apply the `data-filtering-deployment.yaml` deployment. This deployment will schedule a pod that listens to the configured integration in Kerberos Vault and runs a YOLOv8 model to evaluate the recordings and match them against specified conditions.

View File

@@ -6,8 +6,8 @@ Deploying the Kerberos.io stack may initially appear to be a complex task due to
The Kerberos.io stack offers flexible installation options, supporting deployment in hybrid environments, fully in the cloud, or entirely at the edge. This deployment guide covers the installation of various Kerberos.io components. For detailed information on each component, please refer to their respective repositories.
- [Kerberos Agent](https://github.com/kerberos-io/agent)
- [Kerberos Factory](https://github.com/kerberos-io/factory)
- [Agent](https://github.com/kerberos-io/agent)
- [Factory](https://github.com/kerberos-io/factory)
- [Kerberos Vault](https://github.com/kerberos-io/vault)
- [Kerberos Hub](https://github.com/kerberos-io/hub)
@@ -27,11 +27,11 @@ Given these differences, we have created specific architectural frameworks for s
## Edge (self-hosted) deployment
Edge (self-hosted) deployments are typically used for camera processing and edge storage. In this setup, Kerberos Agents are deployed and connected to cameras, with recordings stored in the Kerberos Vault. Additionally, you may want to create integrations, such as [data filtering](https://github.com/uug-ai/data-filtering), to ensure only relevant recordings are retained, or set up custom notifications to your first or third-party platforms. In this edge scenario, hardware is being deployed in the local network to handle the workloads; for example AMD64 or ARM64 processors.
Edge (self-hosted) deployments are typically used for camera processing and edge storage. In this setup, Agents are deployed and connected to cameras, with recordings stored in the Kerberos Vault. Additionally, you may want to create integrations, such as [data filtering](https://github.com/uug-ai/data-filtering), to ensure only relevant recordings are retained, or set up custom notifications to your first or third-party platforms. In this edge scenario, hardware is being deployed in the local network to handle the workloads; for example AMD64 or ARM64 processors.
![Edge - self-hosted deployment](./assets/images/deployment-self-hosted.svg)
A key aspect of this deployment is the scaling of Kerberos Agents. Each camera is assigned a dedicated Kerberos Agent container, which is linked to a central Kerberos Vault. The Kerberos Vault stores metadata in MongoDB, recordings in Minio (or another S3-compliant object storage), and can generate events in a message broker like RabbitMQ. This approach enables you to develop custom applications/logic that can respond to the creation of new recordings.
A key aspect of this deployment is the scaling of Agents. Each camera is assigned a dedicated Agent container, which is linked to a central Kerberos Vault. The Kerberos Vault stores metadata in MongoDB, recordings in Minio (or another S3-compliant object storage), and can generate events in a message broker like RabbitMQ. This approach enables you to develop custom applications/logic that can respond to the creation of new recordings.
Based on your technology experience and preferences, you can choose from the following deployment guides:
@@ -64,3 +64,7 @@ The primary objective of maintaining a managed, public-facing deployment is to c
Based on your technology experience and preferences, you can choose from the following deployment guides:
- [[Medium] Install Kerberos.io on Kubernetes (AWS, GCP, Azure, etc.)](/README.k8s-managed.md)
Or provision the infrastructure yourself with infrastructure as code:
- [[AWS] Terraform: EKS cluster + Amazon DocumentDB](./modules/amazon-eks-documentdb/README.md)

View File

@@ -71,7 +71,7 @@ For more detailed instructions and troubleshooting, please refer to the official
## Dependencies
Before installing, several dependencies are required for storage, such as a database (e.g., MongoDB) and a message broker (e.g., RabbitMQ) for asynchronous behavior. We will install these components before setting up the Kerberos Agents and Kerberos Vault.
Before installing, several dependencies are required for storage, such as a database (e.g., MongoDB) and a message broker (e.g., RabbitMQ) for asynchronous behavior. We will install these components before setting up the Agents and Kerberos Vault.
One of the key advantages of MicroK8s is its out-of-the-box addons, which can be enabled with a single command. This eliminates the need for complex Helm charts or operators, simplifying the setup process. We will enable some common services, such as DNS, GPU support, and storage, to streamline the installation.
@@ -332,9 +332,9 @@ With the Vault installed, we can proceed to configure the various components. Cu
- Access key: XJoi2@bgSOvOYBy# (or generate new keys, but don't forget to update them in the next steps)
- Secret key: OGGqat4lXRpL@9XBYc8FUaId@5 (or generate new keys, but don't forget to update them in the next steps)
### Create a Agent
### Create an Agent
After deploying the Vault and configuring the necessary services for storage, database, and integration, you can proceed to deploy the Agent with the appropriate configuration. Review the `kerberos-agent-deployment.yaml` file and adjust the relevant settings, such as the RTSP URL, to ensure proper functionality. Please note that you can allow opt for the [Kerberos Factory](https://github.com/kerberos-io/factory/tree/master/kubernetes) which gives you a UI to manage the creation of Agents. Also please note if you generated new the keys in the previous Vault account creation, you need to update those in the Agent deployment.
After deploying the Vault and configuring the necessary services for storage, database, and integration, you can proceed to deploy the Agent with the appropriate configuration. Review the `kerberos-agent-deployment.yaml` file and adjust the relevant settings, such as the RTSP URL, to ensure proper functionality. Please note that you can allow opt for the [Factory](https://github.com/kerberos-io/factory/tree/master/kubernetes) which gives you a UI to manage the creation of Agents. Also please note if you generated new the keys in the previous Vault account creation, you need to update those in the Agent deployment.
```bash
kubectl apply -f kerberos-agent-deployment.yaml

142
base/factory/README.md Normal file
View File

@@ -0,0 +1,142 @@
# Factory — base manifests
This directory holds the raw Kubernetes manifests for **Factory**. Factory
is a web application that runs *inside* your cluster and uses the Kubernetes API to
deploy, configure and observe Agents (one Deployment + Service per camera).
> **Scope of this README.** At the top level of this repository Factory is normally
> installed through **Kustomize** (see [`overlays/`](../../overlays) and the
> [`README.kustomize.md`](../../README.kustomize.md)). This README documents the
> alternative: applying the manifests in this folder **directly with `kubectl`**,
> without Kustomize. Use it when you want to install only Factory, understand each
> object in isolation, or integrate these manifests into your own tooling.
## What gets deployed
| File | Kind | Purpose |
| ---- | ---- | ------- |
| [`kerberos-factory-deployment.yaml`](./kerberos-factory-deployment.yaml) | `Deployment` | The Factory web app/API (`uugai/factory`), container port `80`. |
| [`kerberos-factory-service.yaml`](./kerberos-factory-service.yaml) | `Service` | Exposes Factory on `NodePort` **30079** (a `LoadBalancer` variant is included, commented out). |
| [`kerberos-factory-clusterrole.yaml`](./kerberos-factory-clusterrole.yaml) | `ClusterRole` + `ClusterRoleBinding` | Grants the `default` ServiceAccount in `kerberos-factory` the API access Factory needs to manage Agents. |
The matching namespace (`kerberos-factory`) is defined one level up in
[`../namespaces/kerberos-factory.yaml`](../namespaces/kerberos-factory.yaml).
## Configuration (ConfigMap store + Kubernetes engine)
These manifests are configured to run Factory **without MongoDB**. Factory keeps its
own (global/template) configuration and delivers each Agent's configuration through
Kubernetes **ConfigMaps**, and schedules Agents with the **Kubernetes** engine. This
is controlled by two environment variables on the Deployment:
```yaml
- name: FACTORY_CONFIGURATION
value: "configmap" # store config in ConfigMaps (json | configmap | secret | mongodb)
- name: FACTORY_ENGINE
value: "kubernetes" # schedule agents as Deployments (kubernetes | docker | host)
```
On start-up Factory bootstraps two cluster ConfigMaps — `agent-global-config`
(settings every Agent inherits) and `agent-template-config` (the base used for new
Agents) — and creates a per-agent `<name>-config` ConfigMap for each Agent it
provisions. **This is why the ClusterRole includes `configmaps`** — without that
permission the bootstrap fails.
Other relevant environment variables:
| Variable | Default here | Meaning |
| -------- | ------------ | ------- |
| `KERBEROS_LOGIN_USERNAME` / `KERBEROS_LOGIN_PASSWORD` | `root` / `kerberos` | Factory UI login. **Change these for anything but a demo.** |
| `KERBEROS_AGENT_IMAGE` | `kerberos/agent:latest` | Image used when Factory creates an Agent. |
| `KERBEROS_AGENT_MEMORY_LIMIT` | `256Mi` | Default memory limit for created Agents. |
| `NAMESPACE` | `kerberos-factory` | Namespace Factory schedules Agents into. |
| `K8S_PROXY` | `http://localhost:80` | Internal proxy address Factory calls for the `/kubernetes` API. |
## Prerequisites
- A running Kubernetes cluster and a `kubectl` configured to reach it.
- Permission to create `ClusterRole`/`ClusterRoleBinding` (cluster-admin or equivalent).
## Deploy with `kubectl` (without Kustomize)
The manifest files do **not** hard-code a namespace (Kustomize injects it at the upper
level). When applying directly, target the namespace explicitly with `-n`.
```bash
# 1. Create the namespace (only needed if it does not exist yet)
kubectl apply -f ../namespaces/kerberos-factory.yaml
# 2. Create the RBAC. The ClusterRole/ClusterRoleBinding are cluster-scoped;
# the binding's subject already references the kerberos-factory namespace.
kubectl apply -f ./kerberos-factory-clusterrole.yaml
# 3. Deploy Factory and its service into the namespace
kubectl apply -n kerberos-factory -f ./kerberos-factory-deployment.yaml
kubectl apply -n kerberos-factory -f ./kerberos-factory-service.yaml
```
Or apply the whole folder at once (RBAC is cluster-scoped, the rest lands in the
namespace):
```bash
kubectl apply -f ../namespaces/kerberos-factory.yaml
kubectl apply -n kerberos-factory -f ./
```
Verify the rollout:
```bash
kubectl get pods,svc -n kerberos-factory
kubectl rollout status deployment/factory -n kerberos-factory
kubectl logs -n kerberos-factory deploy/factory
```
You should see log lines confirming the global and template Agent ConfigMaps were
bootstrapped.
## Access the UI
With the `NodePort` service, Factory is reachable on port **30079** of any node:
```bash
# Example: open http://<node-ip>:30079
kubectl get nodes -o wide # find a node IP
# Or port-forward without exposing a node port
kubectl port-forward -n kerberos-factory svc/factory-nodeport 8080:80
# then browse http://localhost:8080
```
Log in with the `KERBEROS_LOGIN_USERNAME` / `KERBEROS_LOGIN_PASSWORD` values above
(default `root` / `kerberos`).
To use a cloud `LoadBalancer` instead of a `NodePort`, uncomment the `factory-lb`
service at the bottom of [`kerberos-factory-service.yaml`](./kerberos-factory-service.yaml)
and comment out the `NodePort` service.
## Switching the configuration store
ConfigMap storage is recommended for a clean, database-free install, but Factory
supports other stores via `FACTORY_CONFIGURATION`:
- `configmap` *(default here)* — config in ConfigMaps, no MongoDB.
- `secret` — same as `configmap` but sensitive values are kept in Kubernetes Secrets
(add `secrets` to the ClusterRole resources for this mode).
- `json` — config in local JSON files on the pod, no MongoDB.
- `mongodb` — legacy behaviour: Factory and Agents read config from MongoDB. For this
you also need a reachable MongoDB and the corresponding `MONGODB_*` environment
variables (e.g. via a `mongodb` ConfigMap mounted with `envFrom`).
See the [Configuration & engines documentation](https://github.com/uug-ai/factory)
for the full model.
## Uninstall
```bash
kubectl delete -n kerberos-factory -f ./kerberos-factory-service.yaml
kubectl delete -n kerberos-factory -f ./kerberos-factory-deployment.yaml
kubectl delete -f ./kerberos-factory-clusterrole.yaml
# Optionally remove the agent ConfigMaps Factory created and the namespace
kubectl delete configmap -n kerberos-factory agent-global-config agent-template-config --ignore-not-found
kubectl delete -f ../namespaces/kerberos-factory.yaml
```

View File

@@ -4,7 +4,7 @@ metadata:
name: pods-list
rules:
- apiGroups: ["", "apps"]
resources: ["pods", "pods/log", "deployments", "services", "services/proxy", "endpoints", "nodes"]
resources: ["pods", "pods/log", "deployments", "services", "services/proxy", "endpoints", "nodes", "configmaps"]
verbs: ["get", "list", "create", "update", "delete", "watch"]
---
kind: ClusterRoleBinding

View File

@@ -18,13 +18,9 @@ spec:
labels:
app: factory
spec:
initContainers:
- name: wait-for-mongodb-before-starup
image: busybox
command: ["sh", "-c", "until nc -z mongodb.mongodb 27017 > /dev/null; do echo Waiting for master.; sleep 2; done;"]
containers:
- name: factory
image: "uugai/factory:v1.0.5"
image: ghcr.io/uug-ai/factory:v2.0.4
resources:
requests:
memory: 128Mi
@@ -34,9 +30,6 @@ spec:
cpu: 100m
ports:
- containerPort: 80
envFrom:
- configMapRef:
name: mongodb
env:
- name: GIN_MODE
value: release
@@ -53,6 +46,12 @@ spec:
# Do not touch this, unless you know what you are doing.
- name: NAMESPACE
value: "kerberos-factory"
# Store the factory and agent configuration in Kubernetes ConfigMaps
# (no MongoDB required) and schedule agents with the Kubernetes engine.
- name: FACTORY_CONFIGURATION
value: "configmap"
- name: FACTORY_ENGINE
value: "kubernetes"
- name: FACTORY_ENVIRONMENT
value: "kubernetes"
- name: K8S_PROXY

View File

@@ -1,6 +1,5 @@
namespace: kerberos-factory
resources:
- mongodb-configmap.yaml
- kerberos-factory-deployment.yaml
- kerberos-factory-service.yaml
- kerberos-factory-clusterrole.yaml

View File

@@ -1,18 +0,0 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: mongodb
data:
# This is the mongodb database where data will be stored, you might use a different name if you want.
MONGODB_DATABASE_STORAGE: "KerberosStorage"
MONGODB_DATABASE_FACTORY: "KerberosFactory"
MONGODB_DATABASE_HUB: "Kerberos"
# MongoDB URI (for example for a SaaS service like MongoDB Atlas)
# If uri is set, the below properties are not used (host, adminDatabase, username, password)
#MONGODB_URI: "mongodb+srv://xx:xx@kerberos-hub.xxx.mongodb.net/?retryWrites=true&w=majority&appName=xxx"
# If you do not wish to use the URI, you can specify the individual values.
MONGODB_HOST: "mongodb.mongodb"
MONGODB_DATABASE_CREDENTIALS: "admin"
MONGODB_USERNAME: "root"
MONGODB_PASSWORD: "yourpassword"

View File

@@ -42,10 +42,10 @@ mongodb:
username: "root"
password: "yourpassword"
# A MQTT broker (vernemq or other like mosquitto) is used to have a bi-directional
# communication between Kerberos Agents and Kerberos Hub.
# communication between Agents and Kerberos Hub.
# we recommend to use vernemq (as part of this installation), but a stand-alone mosquitto broker is also possible.
mqtt:
host: "mqtt.yourdomain.com" # this needs to be a public accessible DNS name (it's used to communicate between Kerberos Agents and Kerberos Hub)
host: "mqtt.yourdomain.com" # this needs to be a public accessible DNS name (it's used to communicate between Agents and Kerberos Hub)
port: "31443"
protocol: "wss"
username: "yourusername"
@@ -131,12 +131,14 @@ email:
forgotTitle: "Password reset Kerberos Hub. You forgot your password"
share: "share"
shareTitle: "[Action] You received a recording from Kerberos Hub"
caseShare: "share_case"
caseShareTitle: "[Action] A case has been shared with you on Kerberos Hub"
detection: "detection"
disabled: "disabled"
highupload: "highupload"
device: "device"
alertTitle: "[Alert] Kerberos Hub detected something an event"
deviceTitle: "[Device] A Kerberos Agent's status has been changed"
deviceTitle: "[Device] An Agent's status has been changed"
# Following are all the different deployments needed to make
# Kerberos hub properly working.
kerberoshub:
@@ -155,7 +157,7 @@ kerberoshub:
api:
repository: ghcr.io/uug-ai/hub-api
pullPolicy: IfNotPresent
tag: "v1.8.14"
tag: "v1.9.48"
replicas: 1
jwtSecret: "I1JcwzW3A0t_THIS-IS_NOT_A_SECRET_WJK9jnPkipbnVTpf0efMy" # change to a random value, this is for generating JWT tokens.
schema: "http"
@@ -238,10 +240,13 @@ kerberoshub:
frontend:
repository: ghcr.io/uug-ai/hub-frontend
pullPolicy: IfNotPresent
tag: "v1.8.0"
tag: "v1.13.0"
replicas: 1
schema: "http"
url: "yourdomain.com"
# The front-end but in read-only mode
demoEnabled: true
demoUrl: "app-demo.kerberos.io"
resources:
requests:
memory: 100Mi
@@ -277,8 +282,8 @@ kerberoshub:
posthog: # Posthog is used for auditing and user interaction logging
key: "xxx"
url: "https://posthog.domain.com"
# You can disable the Kerberos agent buttons, this make sense
# in a white-label setup, or where you are managing the Kerberos Agents for your customers.
# You can disable the Agent buttons, this make sense
# in a white-label setup, or where you are managing the Agents for your customers.
hideAddAgent: "true"
# Multi tenancy (domains)
# By default the Kerberos Hub allows multi-tenancy through the concept
@@ -348,17 +353,17 @@ kerberoshub:
organization: "github-organization"
team: "github-team"
cleanup:
repository: uugai/hub-cleanup
repository: ghcr.io/uug-ai/hub-cleanup
pullPolicy: IfNotPresent
tag: "v1.4.1"
tag: "v1.4.16"
resources:
requests:
memory: 50Mi
cpu: 50m
monitordevice:
repository: uugai/hub-monitor-device
repository: ghcr.io/uug-ai/hub-monitor-device
pullPolicy: IfNotPresent
tag: "v1.3.0"
tag: "v1.4.1"
resources:
requests:
memory: 50Mi
@@ -408,9 +413,9 @@ kerberoshub:
cpu: 50m
kerberospipeline:
event:
repository: uugai/hub-pipeline-event
repository: ghcr.io/uug-ai/hub-pipeline-event
pullPolicy: IfNotPresent
tag: "v1.2.0"
tag: "v1.3.1"
replicas: 1
resources:
requests:
@@ -422,7 +427,7 @@ kerberospipeline:
monitor:
repository: ghcr.io/uug-ai/hub-pipeline-monitor
pullPolicy: IfNotPresent
tag: "v1.3.9"
tag: "v1.3.11"
replicas: 1
resources:
requests:
@@ -434,7 +439,7 @@ kerberospipeline:
sequence:
repository: ghcr.io/uug-ai/hub-pipeline-sequence
pullPolicy: IfNotPresent
tag: "v1.6.11"
tag: "v1.6.23"
replicas: 1
resources:
requests:
@@ -458,7 +463,7 @@ kerberospipeline:
notify:
repository: ghcr.io/uug-ai/hub-pipeline-notification
pullPolicy: IfNotPresent
tag: "v1.3.0"
tag: "v1.3.17"
replicas: 1
resources:
requests:
@@ -498,7 +503,7 @@ kerberospipeline:
analysis:
repository: ghcr.io/uug-ai/hub-pipeline-analysis
pullPolicy: IfNotPresent
tag: "v1.7.7"
tag: "v1.8.4"
replicas: 1
resources:
requests:
@@ -510,7 +515,7 @@ kerberospipeline:
dominantColor:
repository: ghcr.io/uug-ai/hub-pipeline-dominantcolors
pullPolicy: IfNotPresent
tag: "v2.0.2"
tag: "v2.0.3"
replicas: 1
resources:
requests:
@@ -522,7 +527,7 @@ kerberospipeline:
thumbnail:
repository: ghcr.io/uug-ai/hub-pipeline-thumbnail
pullPolicy: IfNotPresent
tag: "v1.3.1"
tag: "v1.3.10"
replicas: 1
quality: "1" # 1 (best) - 31 (worst)
width: "600"
@@ -547,9 +552,9 @@ kerberospipeline:
cpu: 50m
sprite:
enabled: true # Enable or disable the sprite generation 'true' or 'false
repository: uugai/hub-pipeline-sprite
repository: ghcr.io/uug-ai/hub-pipeline-sprite
pullPolicy: IfNotPresent
tag: "v1.0.9"
tag: "v1.1.16"
replicas: 1
interval: "1" # Number of secondes between each thumbnail in the sprite
width: "240" # Should not be changed for the moment (hard coded in UI)
@@ -564,7 +569,7 @@ kerberospipeline:
export:
repository: ghcr.io/uug-ai/hub-pipeline-export
pullPolicy: IfNotPresent
tag: "v1.1.3"
tag: "v1.2.9"
replicas: 1
resources:
requests:

View File

@@ -1,22 +1,22 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: hub-yolov8
name: hub-pipeline-classifier
labels:
app: hub-yolov8
app: hub-pipeline-classifier
spec:
replicas: 1
selector:
matchLabels:
app: hub-yolov8
app: hub-pipeline-classifier
template:
metadata:
labels:
app: hub-yolov8
app: hub-pipeline-classifier
spec:
containers:
- name: hub-yolov8
image: uugai/hub-yolov8:latest
- name: hub-pipeline-classifier
image: ghcr.io/uug-ai/hub-pipeline-classifier:v1.5.5
#resources:
# limits:
# nvidia.com/gpu: 1 # requesting a single GPU

210
base/vault/README.md Normal file
View File

@@ -0,0 +1,210 @@
<!-- markdownlint-disable MD013 -->
# Vault base manifests
This directory holds the raw Kubernetes manifests for **Vault**. Vault receives
recordings from Kerberos Agents, stores recording metadata in MongoDB, and sends
recording bytes to storage providers configured through the Vault UI.
> **Scope of this README.** At the top level of this repository Vault is normally
> installed through **Kustomize** (see [`overlays/`](../../overlays) and
> [`README.kustomize.md`](../../README.kustomize.md)). This README documents the
> alternative: applying the manifests in this folder directly with `kubectl`.
> Use it when you want to install only Vault, inspect each object, or integrate
> these manifests into your own deployment tooling.
## What gets deployed
| File | Kind | Purpose |
| ---- | ---- | ------- |
| [`mongodb-configmap.yaml`](./mongodb-configmap.yaml) | `ConfigMap` | Supplies Vault's MongoDB connection, backend flavor, retry-write, and TLS settings. |
| [`kerberos-vault-deployment.yaml`](./kerberos-vault-deployment.yaml) | `Deployment` | Runs the Vault API and UI on container port `80`. |
| [`kerberos-vault-service.yaml`](./kerberos-vault-service.yaml) | `Service` | Exposes Vault on `NodePort` **30080**. A commented `LoadBalancer` variant is included. |
| [`data-filtering-deployment.yaml`](./data-filtering-deployment.yaml) | `Deployment` | Optional YOLO data-filtering worker. The default manifest requests one NVIDIA GPU. |
The matching `kerberos-vault` namespace is defined in
[`../namespaces/kerberos-vault.yaml`](../namespaces/kerberos-vault.yaml).
## Prerequisites
- A running Kubernetes cluster and `kubectl` configured to reach it.
- A MongoDB-compatible database reachable from the Vault pod.
- A storage provider such as MinIO, Amazon S3, Google Cloud Storage, or Azure
Blob Storage. Configure it in the Vault UI after deployment.
- An NVIDIA-capable node and device plugin only when deploying the optional
data-filtering worker with its default resource settings.
## MongoDB configuration
Vault imports every key from the `mongodb` ConfigMap through `envFrom`. The base
manifest connects to the in-cluster MongoDB service at `mongodb.mongodb`.
| Variable | Default here | Meaning |
| -------- | ------------ | ------- |
| `MONGODB_DATABASE_STORAGE` | `KerberosStorage` | Database where Vault stores recording metadata and configuration. |
| `MONGODB_URI` | unset | Complete MongoDB connection URI. When set, it takes precedence over component settings. |
| `MONGODB_HOST` | `mongodb.mongodb` | MongoDB host and optional port for component-based configuration. |
| `MONGODB_DATABASE_CREDENTIALS` | `admin` | Authentication database or auth source. |
| `MONGODB_USERNAME` / `MONGODB_PASSWORD` | `root` / `yourpassword` | Database credentials. Replace these demo values before deployment. |
| `MONGODB_FLAVOR` | `mongodb` | Backend compatibility mode: `mongodb` or `documentdb`. |
| `MONGODB_RETRY_WRITES` | `true` | Enables retryable writes for MongoDB. Vault always disables them for DocumentDB. |
| `MONGODB_TLS` | `false` | Enables TLS for the database connection. |
| `MONGODB_TLS_CA_FILE` | empty | Path to a mounted PEM CA bundle. A non-empty value also enables TLS. |
| `MONGODB_TLS_INSECURE_SKIP_VERIFY` | `false` | Disables certificate and hostname verification. Use only for isolated local testing. |
The ConfigMap also contains legacy Factory and Hub database names, but Vault uses
`MONGODB_DATABASE_STORAGE` for its own data.
> [!WARNING]
> ConfigMaps are not appropriate for production credentials. Move the MongoDB
> username, password, or credential-bearing URI to a Kubernetes `Secret` in a
> production deployment and expose those keys to the Vault container.
### MongoDB Atlas or another URI connection
Set `MONGODB_URI` in [`mongodb-configmap.yaml`](./mongodb-configmap.yaml). The
component settings are ignored when the URI is non-empty.
The Deployment's `wait-for-mongodb-before-starup` init container currently probes
the base service name `mongodb.mongodb:27017`. When using Atlas or another external
database, change that command to probe the external host and port, or replace it
with a readiness mechanism suitable for your environment. Otherwise Vault will
remain in `Init` even when its configured database is reachable.
### DocumentDB or MongoDB with a custom CA
For AWS DocumentDB, use a connection URI, set the flavor to `documentdb`, disable
retryable writes, and enable TLS:
```yaml
MONGODB_URI: "mongodb://<username>:<password>@<endpoint>:27017/?replicaSet=rs0&readPreference=secondaryPreferred&retryWrites=false"
MONGODB_FLAVOR: "documentdb"
MONGODB_RETRY_WRITES: "false"
MONGODB_TLS: "true"
MONGODB_TLS_CA_FILE: "/certs/global-bundle.pem"
MONGODB_TLS_INSECURE_SKIP_VERIFY: "false"
```
Create a Secret from the trusted CA bundle:
```bash
kubectl create namespace kerberos-vault --dry-run=client -o yaml | kubectl apply -f -
kubectl create secret generic mongodb-ca \
--from-file=global-bundle.pem \
-n kerberos-vault
```
Then add the Secret volume and mount to
[`kerberos-vault-deployment.yaml`](./kerberos-vault-deployment.yaml):
```yaml
spec:
template:
spec:
containers:
- name: vault
volumeMounts:
- name: mongodb-ca
mountPath: /certs
readOnly: true
volumes:
- name: mongodb-ca
secret:
secretName: mongodb-ca
```
Also update or remove the MongoDB wait init-container as described above. For
Amazon DocumentDB, the shared Vault database client defaults component-based
authentication to `SCRAM-SHA-1` and does not enable MongoDB Stable API.
## Vault configuration
Relevant environment variables are defined directly on the Vault Deployment:
| Variable | Default here | Meaning |
| -------- | ------------ | ------- |
| `KERBEROS_LOGIN_USERNAME` / `KERBEROS_LOGIN_PASSWORD` | `root` / `kerberos` | Vault UI login. Change these demo credentials. |
| `MQTTURI` | `tcp://mqtt.kerberos.io:1883` | MQTT broker used for on-demand forwarding. |
| `MQTT_USERNAME` / `MQTT_PASSWORD` | empty | Optional MQTT credentials. |
| `CONTINUOUS_FORWARDING` | `false` | Enables forwarding for a chained Vault setup. |
Storage providers, integrations, and Vault accounts are configured through the
UI after the pod starts. See [`README.configure.md`](../../README.configure.md).
## Deploy with kubectl without Kustomize
The manifest files do not hard-code a namespace because Kustomize normally
injects it. When applying them directly, target the namespace explicitly.
```bash
# 1. Create the namespace.
kubectl apply -f ../namespaces/kerberos-vault.yaml
# 2. Review the database settings, then create the ConfigMap.
kubectl apply -n kerberos-vault -f ./mongodb-configmap.yaml
# 3. Deploy Vault and expose it through NodePort.
kubectl apply -n kerberos-vault -f ./kerberos-vault-deployment.yaml
kubectl apply -n kerberos-vault -f ./kerberos-vault-service.yaml
```
Verify the rollout:
```bash
kubectl get pods,svc -n kerberos-vault
kubectl rollout status deployment/vault -n kerberos-vault
kubectl logs -n kerberos-vault deploy/vault
```
If the pod remains in `Init`, inspect the database wait container:
```bash
kubectl logs -n kerberos-vault deploy/vault \
-c wait-for-mongodb-before-starup
```
## Access the UI
With the `NodePort` service, Vault is reachable on port **30080** of any node:
```bash
kubectl get nodes -o wide
# Browse http://<node-ip>:30080
# Or use a local port-forward without exposing a node port.
kubectl port-forward -n kerberos-vault svc/vault-nodeport 8080:80
# Browse http://localhost:8080
```
Log in with the configured `KERBEROS_LOGIN_USERNAME` and
`KERBEROS_LOGIN_PASSWORD` values. The base defaults are `root` and `kerberos`.
To use a cloud `LoadBalancer`, uncomment the `vault-lb` service at the bottom of
[`kerberos-vault-service.yaml`](./kerberos-vault-service.yaml) and remove or
comment out the `NodePort` service.
## Optional data filtering
The data-filtering worker is independent of the Vault Deployment. Before applying
it, configure its queue, Vault credentials, model settings, and GPU resources in
[`data-filtering-deployment.yaml`](./data-filtering-deployment.yaml).
```bash
kubectl apply -n kerberos-vault -f ./data-filtering-deployment.yaml
kubectl rollout status deployment/data-filtering -n kerberos-vault
```
Clusters without an NVIDIA device plugin must remove the `nvidia.com/gpu`
requests and limits or leave this optional Deployment unapplied. See
[`README.extensions.md`](../../README.extensions.md) for the integration flow.
## Uninstall
```bash
kubectl delete -n kerberos-vault -f ./data-filtering-deployment.yaml --ignore-not-found
kubectl delete -n kerberos-vault -f ./kerberos-vault-service.yaml
kubectl delete -n kerberos-vault -f ./kerberos-vault-deployment.yaml
kubectl delete -n kerberos-vault -f ./mongodb-configmap.yaml
kubectl delete secret mongodb-ca -n kerberos-vault --ignore-not-found
kubectl delete -f ../namespaces/kerberos-vault.yaml
```

View File

@@ -24,7 +24,7 @@ spec:
command: ["sh", "-c", "until nc -z mongodb.mongodb 27017 > /dev/null; do echo Waiting for master.; sleep 2; done;"]
containers:
- name: vault
image: ghcr.io/uug-ai/vault:v1.2.4
image: ghcr.io/uug-ai/vault:v1.4.9
resources:
requests:
memory: 128Mi

View File

@@ -15,4 +15,16 @@ data:
MONGODB_HOST: "mongodb.mongodb"
MONGODB_DATABASE_CREDENTIALS: "admin"
MONGODB_USERNAME: "root"
MONGODB_PASSWORD: "yourpassword"
MONGODB_PASSWORD: "yourpassword"
# MongoDB-compatible backend and connection behavior.
# Use "documentdb" for AWS DocumentDB; retryable writes are always disabled
# by Vault for that flavor.
MONGODB_FLAVOR: "mongodb"
MONGODB_RETRY_WRITES: "true"
# TLS is disabled by default. A non-empty CA file path also enables TLS, but
# the referenced PEM bundle must be mounted into the Vault container.
MONGODB_TLS: "false"
MONGODB_TLS_CA_FILE: ""
MONGODB_TLS_INSECURE_SKIP_VERIFY: "false"

View File

@@ -225,7 +225,7 @@
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">One of your Kerberos Agents changed</h2>
padding-right: 0;">One of your Agents changed</h2>
<h2 style=" font-family: Inter;
font-size: 20px;
font-style: normal;
@@ -265,7 +265,7 @@
letter-spacing: 0em;
text-align: left;
color: #262424;
width: 480px">The status your Kerberos Agent changed</h3>
width: 480px">The status your Agent changed</h3>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
@@ -275,8 +275,8 @@
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">Kerberos Agents go offline due to a variety of reasons. The machine, node, micro controller on which your Kerberos Agent runs, gets corrupted or disconnected from the internet.
The camera itself is broken, damaged or in the worst case tampered. Have a look into your Kerberos Hub account for the latest recordings and/or verify the connection and status of your Kerberos Agent.</p>
margin-top: 12px;">Agents go offline due to a variety of reasons. The machine, node, micro controller on which your Agent runs, gets corrupted or disconnected from the internet.
The camera itself is broken, damaged or in the worst case tampered. Have a look into your Kerberos Hub account for the latest recordings and/or verify the connection and status of your Agent.</p>
<a style="text-decoration: none;color: none;" href="{{link}}">
<p style="font-family: Inter;

View File

@@ -286,7 +286,7 @@ Tomorrow your account will be reset, and recordings will be uploaded again to yo
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">If you are hitting your daily limits a lot, you might consider upgrading your Kerberos Hub subscription, or fine-tune your Kerberos Agents so they record less recordings.</p>
margin-top: 12px;">If you are hitting your daily limits a lot, you might consider upgrading your Kerberos Hub subscription, or fine-tune your Agents so they record less recordings.</p>
<a style="text-decoration: none;color: none;" href="{{link}}">
<p style="font-family: Inter;

View File

@@ -225,7 +225,7 @@
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">High upload detected by one or more Kerberos Agents</h2>
padding-right: 0;">High upload detected by one or more Agents</h2>
</td>
<td class="corner-td" align="right"></td>
</tr>

View File

@@ -0,0 +1,418 @@
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<meta
name="viewport"
content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1"
/>
<meta name="description" content="Kerberos.io Mailing">
<style type="text/css">
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Regular.woff?v=/dist/fonts/Inter-Regular.woff2?v=3.183.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-Medium.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-Medium.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff2?v=3.18") format("woff2"),
url("https://kerberos.io/dist/fonts/Inter-SemiBold.woff?v=3.18") format("woff");
}
@font-face {
font-family: 'Inter var';
font-weight: 100 900;
font-display: swap;
font-style: normal;
font-named-instance: 'Regular';
src: url("https://kerberos.io/dist/fonts/Inter-roman.var.woff2?v=3.18") format("woff2");
}
body{
background: #E5E5E5;
margin-top:0;
margin-bottom: 0;
margin-right: 0;
margin-left: 0;
padding-top: 0;
padding-left: 0;
padding-right: 0;
padding-bottom: 0;
font-family: 'Inter';
}
a, a:hover, a:active {
color: #262424;
text-decoration: none;
}
.corner-td{
width: 60px;
}
table {border-collapse:separate;max-width: 850px; margin: 0 auto; width: 100%;}
.ExternalClass p, .ExternalClass span, .ExternalClass font, .ExternalClass td {line-height: 100%;}
.ExternalClass {width: 100%;}
@media screen and (max-width:500px){
.tab-td{
padding-left: 10px!important;
}
.tab-td a h4{
font-size: 14px!important;
}
.corner-td{
width: 20px!important;
}
.company-name-td h3{
font-size: 16px!important;
}
table.header-table{
padding-top: 8px!important;
padding-right: 0px!important;
padding-bottom: 24px!important;
padding-left: 0px!important;
}
.colored-card-td h4{
font-size: 14px!important;
}
.colored-card-td h2{
font-size: 20px!important;
}
.colored-card-td a p{
font-size: 12px!important;
width: 143px!important;
}
.colored-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td{
padding-top: 24px!important;
padding-right: 24px!important;
padding-bottom: 24px!important;
padding-left: 24px!important;
}
.colorless-card-td h3{
font-size: 18px!important;
}
.colorless-card-td p{
font-size: 14px!important;
}
.colorless-card-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 24px!important;
margin-bottom: 24px!important;
}
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:600px) {
.footer-td{
display: table-row!important;
}
}
@media screen and (max-width:650px) {
.footer-table{
margin-left: 0px!important;
margin-right: 0px!important;
margin-top: 0px!important;
margin-bottom: 36px!important;
}
}
</style>
</head>
<body height="100%" width="100%">
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" height="36" class="header-table" style="padding-top: 36px ;padding-right: 0;padding-bottom: 36px;padding-left: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td width="48" height="36" align="left"><img alt="Kerberos.io" width="36" height="36" src="https://kerberos.io/images/email/kerberos.png"/></td>
<td height="36" align="left" class="company-name-td">
<h3 width="36" height="36" style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;">Kerberos.io</h3>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right">
<a style="text-decoration: none;color: none;" href={{tab1_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab1_title}}</h4>
</a>
</td>
<td height="36" width="36" style="padding-left: 36px;" class="tab-td" align="right" >
<a style="text-decoration: none;color: none;" href={{tab2_href}}>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 500;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: right;
color: #6D6666;">{{tab2_title}}</h4>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colored-card-td" bgcolor="#57356B" style="padding-left: 48px;padding-right: 48px;padding-top: 48px;padding-bottom: 48px;border-radius: 4px;background-color:#57356B;">
<h2 style=" font-family: Inter;
font-size: 24px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
padding-top: 12px;
margin-bottom: 0;
padding-bottom: 0;
padding-left: 0;
padding-right: 0;">A case has been shared with you</h2>
<h4 style="font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#b09fb9;">{{user}} shared a case with you</h4>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="colorless-card-table" style="margin-top: 36px;margin-bottom: 36px;margin-left: 0;margin-right: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<td class="colorless-card-td" bgcolor="#FFFFFF" style="background-color:#FFFFFF;padding-top: 36px;padding-right: 43px;padding-bottom: 25px;padding-left: 43px;border-radius: 4px;">
<h3 style=" font-family: Inter;
font-size: 20px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #262424;
width: 280px">Open the shared case</h3>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #6D6666;
margin-top: 12px;">{{user}} has shared a case with you. Click the button below to open it. You'll be asked to request a one-time verification code from the share page itself.<br/><br/>This link will expire in {{expiry}}.</p>
<a style="text-decoration: none;color: none;" href="{{url}}">
<p style="font-family: Inter;
font-size: 14px;
font-style: normal;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#FFFFFF;
background-color: #84559F;
padding-top: 6px;
padding-bottom: 6px;
padding-right: 16px;
padding-left: 16px;
width: 130px;
border-radius: 4px;
text-align: center;
cursor: pointer;">Open case -></p>
</a>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<table border="0" cellpadding="0" cellspacing="0" width="100%" bgcolor="E5E5E5" style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tr>
<td bgcolor="E5E5E5">
<table border="0" cellpadding="0" cellspacing="0" width="100%" class="footer-table" style="margin-top: 0;border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;" >
<tbody>
<tr>
<td class="corner-td" align="left"></td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td height="146" width="190" class="footer-td" style="margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">Get in touch</h4>
<a style="text-decoration: none;color: none;" href="mailto:support@kerberos.io">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">support@kerberos.io</p>
</a>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 16px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">9000 Ghent, BE</p>
<a style="text-decoration: none;color: none;" href="https://kerberos.io/">
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">https://kerberos.io</p>
</a>
</td>
</tr>
</tbody>
</table>
</td>
<!--[if mso | IE]>
<table role="presentation" border="0" cellpadding="0" cellspacing="0"><tr><td style="vertical-align:top;display:table-row !important">
<![endif]-->
<td class="footer-td" style="border-radius: 4px;padding-left: 0;padding-right: 0;padding-top: 0;padding-bottom: 0; margin-bottom: 12px;" valign="top" align="left">
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr>
<td>
<h4 style=" font-family: Inter;
font-size: 16px;
font-style: normal;
font-weight: 600;
line-height: 36px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color:#6D6666;">About Kerberos</h4>
<p style=" font-family: Inter;
font-size: 14px;
font-style: normal;
font-weight: 400;
line-height: 24px;
mso-line-height-rule:exactly;
letter-spacing: 0em;
text-align: left;
color: #A69D9D;">Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.</p>
<p style="margin-top: 12px;">
<a href="https://twitter.com/kerberosio" style="text-decoration: none;color: none;">
<img width="24" height="24" alt="Twitter" src="https://kerberos.io/images/email/twitter.png"/>
</a>
<a href="https://reddit.com/r/kerberos_io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Reddit" src="https://kerberos.io/images/email/reddit.png"/>
</a>
<a href="https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Youtube" src="https://kerberos.io/images/email/youtube.png"/>
</a>
<a href="https://github.com/kerberos-io" style="text-decoration: none;color: none;">
<img g width="24" height="24" alt="Github" src="https://kerberos.io/images/email/github.png"/>
</a>
</p>
</td>
</tr>
</tbody>
</table>
</td>
<td class="corner-td" align="right"></td>
</tr>
</tbody>
</table>
<table style="border-collaps:collaps; mso-table-lspace:0pt; mso-table-rspace:0pt;">
<tbody>
<tr style="height: 50px">
<td></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
</body>
</html>

View File

@@ -0,0 +1,21 @@
Kerberos.io
------------
A case has been shared with you
{{user}} shared a case with you
Open the shared case
{{user}} has shared a case with you. Open the link below to access it — you'll be asked to request a one-time verification code from the share page.
{{url}}
This link will expire in {{expiry}}.
Get in touch
------------
support@kerberos.io
9000 Ghent, BE
https://kerberos.io
About Kerberos
------------
Welcome to the revolutionary video analytics and video management platform. Open, modular, and extensible for everyone, anywhere.

View File

@@ -1 +1,57 @@
# Amazon DocumentDB
[Amazon DocumentDB](https://aws.amazon.com/documentdb/) is a managed, MongoDB
compatible database. It can be used as the metadata store for Kerberos Hub
instead of a self-hosted MongoDB.
## Things to know
- **Not reachable from outside its VPC.** DocumentDB has no public endpoint, so
the Kerberos Hub services must run inside (or be peered with) the same VPC.
- **TLS is enabled by default.** Clients must trust the Amazon RDS certificate
authority bundle:
`https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem`.
- **Not every MongoDB feature is available.** Retryable writes, the MongoDB
Stable API, geospatial queries/indexes and complex `$lookup` pipelines are
unsupported. Set `mongodb.flavor: "documentdb"` and
`mongodb.retryWrites: "false"` in the hub chart so those code paths are
disabled.
## Provisioning
The [`amazon-eks-documentdb`](../amazon-eks-documentdb/README.md) Terraform
stack creates a VPC, an EKS cluster and a DocumentDB cluster with TLS enforced,
and outputs a ready to paste `mongodb` values block for the hub helm chart.
## Connecting Kerberos Hub
Configure the database through `mongodb.uri` (not `mongodb.host`) and point the
chart at the CA bundle:
```bash
curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
kubectl create secret generic mongodb-ca --from-file=global-bundle.pem -n kerberos-hub
```
```yaml
mongodb:
flavor: "documentdb"
retryWrites: "false"
uri: "mongodb://<user>:<password>@<cluster>.docdb.amazonaws.com:27017/?replicaSet=rs0&readPreference=secondaryPreferred&retryWrites=false"
adminDatabase: "admin"
authenticationMechanism: "SCRAM-SHA-1"
tls:
enabled: true
existingSecret: "mongodb-ca"
caFileName: "global-bundle.pem"
mountPath: "/certs"
```
The chart mounts the bundle read-only into every workload that talks to
MongoDB and appends `tls=true&tlsCAFile=/certs/global-bundle.pem` to the
connection string.
## Related
- [`../amazon-eks-documentdb`](../amazon-eks-documentdb/README.md) — Terraform for EKS + DocumentDB
- [`../../overlays/documentdb`](../../overlays/documentdb) — Kustomize overlay using DocumentDB

View File

@@ -0,0 +1,13 @@
.terraform/
.terraform.lock.hcl
*.tfstate
*.tfstate.*
*.tfplan
crash.log
override.tf
override.tf.json
*_override.tf
*_override.tf.json
terraform.tfvars
*.auto.tfvars
hub-values.yaml

View File

@@ -0,0 +1,361 @@
# Amazon EKS + DocumentDB (Terraform)
Terraform stack that creates a **basic Kubernetes cluster (EKS) and a managed
MongoDB-compatible database (Amazon DocumentDB) on AWS**, wired together so
Kerberos Hub can be installed on it straight away.
It is primarily meant as a **reproducible test environment** for the DocumentDB
support in the [`hub` helm chart](https://github.com/kerberos-io/helm-charts),
in particular the `mongodb.tls.*` values that mount the Amazon RDS certificate
authority bundle. It is deliberately small and cheap, not a hardened production
landing zone.
## What it creates
```mermaid
flowchart LR
subgraph VPC["VPC (10.20.0.0/16)"]
subgraph Public["Public subnets"]
NAT[NAT gateway]
LB[Load balancers]
end
subgraph Private["Private subnets"]
NODES[EKS managed node group]
DOCDB[(DocumentDB cluster<br/>TLS enforced)]
end
end
EKSCP[EKS control plane] --- NODES
NODES -- "27017 / TLS" --> DOCDB
NODES --> NAT
```
| Component | Details |
| --------- | ------- |
| VPC | Public + private subnets across 3 availability zones, internet gateway, NAT gateway |
| EKS | Managed control plane, one managed node group, `coredns`, `kube-proxy`, `vpc-cni`, `eks-pod-identity-agent` and `aws-ebs-csi-driver` add-ons (IRSA role included) |
| DocumentDB | Cluster + instances in the private subnets, encryption **at rest** (KMS) and **in transit** (`tls=enabled`), subnet group, cluster parameter group |
| Security | A dedicated security group that only allows port `27017` from the EKS worker node security group (plus any extra CIDRs you pass in) |
> [!IMPORTANT]
> DocumentDB has **no public endpoint**. It can only be reached from inside the
> VPC, which is why the workloads that talk to it must run on this cluster (or
> you must tunnel through a bastion host / VPN).
> [!WARNING]
> This stack costs money while it exists (EKS control plane, NAT gateway, EC2
> nodes, DocumentDB instances and storage). Run `terraform destroy` when you are
> done.
## Prerequisites
- [Terraform](https://developer.hashicorp.com/terraform/downloads) >= 1.5
- [AWS CLI](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html) v2, authenticated with permissions to create VPC, EKS, IAM and DocumentDB resources
- `kubectl` and `helm`
## Usage
```bash
cd deployment/modules/amazon-eks-documentdb
cp terraform.tfvars.example terraform.tfvars
$EDITOR terraform.tfvars
terraform init
terraform plan
terraform apply
```
Creating the cluster and the database takes a while (EKS and DocumentDB are
both slow to provision).
### Replacing the VPC
AWS cannot move a DocumentDB subnet group or cluster between VPCs. The subnet
group name therefore includes the VPC ID, allowing Terraform to create a new
group and replace the cluster when the VPC changes instead of attempting an
unsupported in-place subnet update.
Discard any saved plan created before a VPC replacement or configuration
change, then create and apply a fresh one:
```bash
rm -f tfplan
terraform plan -out=tfplan
terraform apply tfplan
```
> [!WARNING]
> Replacing the VPC also replaces the DocumentDB cluster. If it contains data,
> create and verify a snapshot before applying the plan; a final snapshot
> preserves the old data but is not restored into the replacement cluster
> automatically.
State is kept locally by default. For anything shared, add a backend, for
example:
```hcl
terraform {
backend "s3" {
bucket = "my-terraform-state"
key = "kerberos-hub/eks-documentdb.tfstate"
region = "eu-west-1"
}
}
```
### Connect kubectl
```bash
$(terraform output -raw update_kubeconfig_command)
kubectl get nodes
```
## Installing Kerberos Hub against DocumentDB
### 1. Create the certificate authority secret
DocumentDB presents a certificate signed by the Amazon RDS certificate
authority, so every client needs the bundle:
```bash
kubectl create namespace kerberos-hub
curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
kubectl create secret generic mongodb-ca \
--from-file=global-bundle.pem \
-n kerberos-hub
```
### 2. Generate the values
```bash
terraform output -raw hub_values_snippet > hub-documentdb-values.yaml
```
Which produces something like:
```yaml
mongodb:
flavor: "documentdb"
retryWrites: "false"
uri: "mongodb://kerberos:...@kerberos-hub-docdb.cluster-xxxx.eu-west-1.docdb.amazonaws.com:27017/?replicaSet=rs0&readPreference=secondaryPreferred&retryWrites=false"
adminDatabase: "admin"
authenticationMechanism: "SCRAM-SHA-1"
tls:
enabled: true
existingSecret: "mongodb-ca"
caFileName: "global-bundle.pem"
mountPath: "/certs"
```
The chart mounts the bundle into every workload that talks to MongoDB, appends
`tls=true&tlsCAFile=/certs/global-bundle.pem` to the URI, and exposes
`MONGODB_TLS`, `MONGODB_TLS_CA_FILE` and `MONGODB_TLS_INSECURE_SKIP_VERIFY`
through the `mongodb-config` ConfigMap.
> [!NOTE]
> With DocumentDB you must configure the database through `mongodb.uri`, not
> through `mongodb.host` / `mongodb.username` / `mongodb.password`, so that the
> TLS parameters end up in the connection string that every service uses.
### 3. Install the chart
```bash
helm repo add kerberos https://charts.kerberos.io
helm install hub kerberos/hub \
--version 0.127.0 \
-n kerberos-hub \
-f your-hub-values.yaml \
-f hub-documentdb-values.yaml
```
The `hub_values_snippet` output contains credentials, so treat the generated
file as a secret and do not commit it.
### 4. Verify
```bash
kubectl logs -n kerberos-hub deploy/hub-api | head -50
kubectl exec -n kerberos-hub deploy/hub-api -- ls -l /certs
```
A one-off connectivity check from inside the cluster:
```bash
kubectl run mongosh --rm -it --restart=Never -n kerberos-hub \
--image=mongodb/mongodb-community-server:7.0-ubi8 \
--overrides='{"spec":{"volumes":[{"name":"ca","secret":{"secretName":"mongodb-ca"}}],"containers":[{"name":"mongosh","image":"mongodb/mongodb-community-server:7.0-ubi8","stdin":true,"tty":true,"command":["mongosh"],"args":["'"$(terraform output -raw mongodb_uri)"'&tls=true&tlsCAFile=/certs/global-bundle.pem"],"volumeMounts":[{"name":"ca","mountPath":"/certs"}]}]}}'
```
### 5. Import the example Hub data
This module has a separate DocumentDB import under [`database-import`](database-import).
It uses the chart-managed `mongodb-config`, mounts `mongodb-ca`, forces TLS with
the Amazon RDS CA bundle, and refuses to run unless the backend flavor is
`documentdb` with retryable writes disabled. Install Hub chart `0.127.0` or
newer before running it.
Run it after installing Hub:
```bash
./database-import/run.sh
```
The import is idempotent: it upserts two example users, one subscription and
five settings documents using fixed IDs, then verifies those records. It can be
rerun after deleting or replacing the DocumentDB cluster.
| Account | Password | Role |
| ------- | -------- | ---- |
| `example-user` | `example-password` | Hub owner |
| `example-application` | `example-password` | Admin application |
These are public example credentials. Do not use this seed data in a production
deployment.
## Public HTTPS ingress
The [`ingress`](ingress) package installs ingress-nginx behind an
internet-facing AWS Network Load Balancer, installs cert-manager, and creates
Let's Encrypt certificates for exactly these routes:
| Host | Service |
| ---- | ------- |
| `aws-app.kerberos.lol` | `hub-frontend-svc:80` |
| `aws-api.kerberos.lol` | `hub-api-svc:8081` |
Keep the Hub chart's global `ingress` value disabled. The module owns these two
Ingress resources so that enabling public access does not also expose the Hub
administration services.
Install the controllers and resources:
```bash
./ingress/install.sh
```
The cert-manager values use `1.1.1.1` and `8.8.8.8` for HTTP-01 self-checks.
This avoids waiting for the AWS VPC resolver if it cached an `NXDOMAIN` before
the public records were created. The override affects only cert-manager's ACME
self-checks; normal cluster DNS continues to use the VPC resolver.
The script prints the NLB hostname. Create both DNS records as CNAMEs pointing
to that hostname. You can retrieve it again with:
```bash
kubectl get service ingress-nginx-controller \
--namespace ingress-nginx \
--output jsonpath='{.status.loadBalancer.ingress[0].hostname}{"\n"}'
```
| DNS name | Type | Target |
| -------- | ---- | ------ |
| `aws-app.kerberos.lol` | CNAME | The ingress-nginx NLB hostname |
| `aws-api.kerberos.lol` | CNAME | The ingress-nginx NLB hostname |
cert-manager automatically retries its HTTP-01 challenges after DNS resolves;
do not delete pending CertificateRequests. Wait for both certificates:
```bash
kubectl wait --namespace kerberos-hub \
--for=condition=Ready certificate/aws-app-kerberos-lol-tls \
certificate/aws-api-kerberos-lol-tls \
--timeout=10m
```
Set Hub's public URLs with the non-secret values fragment after the certificates
are ready. Include the same private Hub and DocumentDB values used for the
original installation:
```bash
helm upgrade hub kerberos/hub \
--version 0.127.0 \
--namespace kerberos-hub \
--file your-hub-values.yaml \
--file hub-documentdb-values.yaml \
--file ingress/hub-public-values.yaml \
--atomic \
--wait
```
Verify both public endpoints:
```bash
curl --fail https://aws-api.kerberos.lol/health
curl --fail --output /dev/null https://aws-app.kerberos.lol/login
```
## Persistent volumes
The EBS CSI driver is installed, but EKS ships `gp2` as the default storage
class. To use `gp3` instead:
```bash
kubectl patch storageclass gp2 -p '{"metadata":{"annotations":{"storageclass.kubernetes.io/is-default-class":"false"}}}'
kubectl apply -f - <<'EOF'
apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
name: gp3
annotations:
storageclass.kubernetes.io/is-default-class: "true"
provisioner: ebs.csi.aws.com
volumeBindingMode: WaitForFirstConsumer
allowVolumeExpansion: true
parameters:
type: gp3
EOF
```
## Tear down
```bash
# Remove Kubernetes resources first so AWS load balancers and volumes are cleaned up.
kubectl delete -f ingress/hub-ingresses.yaml --ignore-not-found
helm uninstall hub -n kerberos-hub
kubectl delete -f ingress/cluster-issuer.yaml --ignore-not-found
helm uninstall cert-manager -n cert-manager
helm uninstall ingress-nginx -n ingress-nginx
terraform destroy
```
## Inputs
The defaults are tuned for a small test stack. See [variables.tf](variables.tf)
for the full list; the ones you are most likely to change:
| Variable | Default | Description |
| -------- | ------- | ----------- |
| `name` | `kerberos-hub` | Name prefix for every resource |
| `region` | `eu-west-1` | AWS region |
| `vpc_cidr` | `10.20.0.0/16` | VPC CIDR block |
| `single_nat_gateway` | `true` | One shared NAT gateway (cheaper, not highly available) |
| `kubernetes_version` | `1.31` | EKS control plane version |
| `cluster_endpoint_public_access_cidrs` | `["0.0.0.0/0"]` | Who may reach the Kubernetes API, **narrow this down** |
| `node_instance_types` | `["t3.large"]` | Worker node instance types |
| `node_desired_size` | `2` | Number of worker nodes |
| `docdb_instance_class` | `db.t3.medium` | DocumentDB instance class |
| `docdb_instance_count` | `1` | Number of DocumentDB instances |
| `docdb_username` | `kerberos` | Master username |
| `docdb_password` | generated | Master password, generated when unset |
| `docdb_tls` | `true` | Enforce TLS on the cluster |
| `docdb_allowed_cidrs` | `[]` | Extra CIDRs allowed on port 27017 |
## Outputs
| Output | Description |
| ------ | ----------- |
| `cluster_name`, `cluster_endpoint` | EKS cluster identity |
| `update_kubeconfig_command` | Ready to run `aws eks update-kubeconfig ...` |
| `vpc_id`, `private_subnet_ids` | Networking identifiers |
| `docdb_endpoint`, `docdb_reader_endpoint`, `docdb_port` | DocumentDB connection details |
| `docdb_username`, `docdb_password` | Master credentials (password is sensitive) |
| `mongodb_uri` | Connection string for `mongodb.uri` (sensitive) |
| `hub_values_snippet` | Ready to paste helm values including the TLS block (sensitive) |
## Related
- [`../amazon-documentdb`](../amazon-documentdb/README.md) — using DocumentDB as the Kerberos Hub metadata store
- [`../../overlays/documentdb`](../../overlays/documentdb) — Kustomize overlay that deploys Kerberos Hub against DocumentDB
- [`../../README.k8s-managed.md`](../../README.k8s-managed.md) — installing on managed Kubernetes

View File

@@ -0,0 +1,163 @@
const database = db.getSiblingDB('Kerberos');
function upsert(collection, id, values) {
const result = database.getCollection(collection).updateOne(
{ _id: ObjectId(id) },
{ $set: values },
{ upsert: true },
);
if (!result.acknowledged) {
throw new Error(`Upsert was not acknowledged for ${collection}/${id}`);
}
}
// Login: example-user / example-password
upsert('users', '57e1011e3178aa6c5cc774d1', {
username: 'example-user',
email: 'example-user@email.com',
password: '$2a$10$jwLcD/.UT/1WLK7ct1XuHewI3GQXwW3zerPhCCs7QDrReEuIHbVYi',
role: 'owner',
google2fa_enabled: false,
timezone: 'Europe/Brussels',
isActive: NumberLong('1'),
registerToken: '',
updated_at: ISODate('2020-06-14T05:01:35.000Z'),
created_at: ISODate('2016-09-20T09:27:58.811Z'),
amazon_secret_access_key: 'K6rRLBI1xxxCk3C1H',
amazon_access_key_id: 'AKIAxxxxxxG5Q',
card_brand: 'Visa',
card_last_four: '0000',
card_status: 'ok',
card_status_message: null,
});
// Admin login: example-application / example-password
upsert('users', '57e1011e3178aa6c5cc774d2', {
username: 'example-application',
email: 'example-application@email.com',
password: '$2a$10$jwLcD/.UT/1WLK7ct1XuHewI3GQXwW3zerPhCCs7QDrReEuIHbVYi',
role: 'application',
google2fa_enabled: false,
timezone: 'Europe/Brussels',
isActive: NumberLong('1'),
registerToken: '',
updated_at: ISODate('2020-06-14T05:01:35.000Z'),
created_at: ISODate('2016-09-20T09:27:58.811Z'),
});
upsert('subscriptions', '57e1011e3178aa6c5cc774d1', {
name: 'default',
stripe_id: 'sub_9ECyjjMz3R7etK',
stripe_plan: 'enterprise',
quantity: 1,
trial_ends_at: null,
ends_at: null,
user_id: '57e1011e3178aa6c5cc774d1',
updated_at: ISODate('2021-04-27T09:45:30.169Z'),
created_at: ISODate('2016-09-20T09:35:03.448Z'),
stripe_status: 'active',
});
upsert('settings', '5a72c509e17699d18ada9154', {
key: 'plan',
map: {
basic: {
level: NumberInt(1),
uploadLimit: NumberInt(100),
videoLimit: NumberInt(100),
usage: NumberInt(500),
analysisLimit: NumberInt(0),
dayLimit: NumberInt(3),
},
premium: {
level: NumberInt(2),
uploadLimit: NumberInt(500),
videoLimit: NumberInt(500),
usage: NumberInt(1000),
analysisLimit: NumberInt(0),
dayLimit: NumberInt(7),
},
gold: {
level: NumberInt(3),
uploadLimit: NumberInt(1000),
videoLimit: NumberInt(1000),
usage: NumberInt(3000),
analysisLimit: NumberInt(1000),
dayLimit: NumberInt(30),
},
business: {
level: NumberInt(4),
uploadLimit: NumberInt(99999999),
videoLimit: NumberInt(99999999),
usage: NumberInt(10000),
analysisLimit: NumberInt(1000),
dayLimit: NumberInt(30),
},
enterprise: {
level: NumberInt(5),
uploadLimit: NumberInt(99999999),
videoLimit: NumberInt(99999999),
usage: NumberInt(99999999),
analysisLimit: NumberInt(5000),
dayLimit: NumberInt(30),
},
},
});
upsert('settings', '63f346ec64011a574161cf99', {
key: 'classifications',
map: {
objects: [
{ text: 'Car', value: 'car', icon: 'car' },
{ text: 'Person', value: 'pedestrian', icon: 'pedestrian' },
],
},
});
upsert('settings', '5a43fa12d885eb7da57046b3', {
key: 'sequence',
map: { timeBetween: NumberInt(60) },
});
upsert('settings', '5a4d3a6bd885eb7da5e6b297', {
key: 'throttler',
map: { waitingTime: NumberInt(60) },
});
upsert('settings', '5a53d0a0d885eb7da53ed5a6', {
key: 'analysis',
map: { waitingTime: NumberInt(15) },
});
const importedUsers = database.users.countDocuments({
_id: {
$in: [
ObjectId('57e1011e3178aa6c5cc774d1'),
ObjectId('57e1011e3178aa6c5cc774d2'),
],
},
});
const importedSubscriptions = database.subscriptions.countDocuments({
_id: ObjectId('57e1011e3178aa6c5cc774d1'),
});
const importedSettings = database.settings.countDocuments({
_id: {
$in: [
ObjectId('5a72c509e17699d18ada9154'),
ObjectId('63f346ec64011a574161cf99'),
ObjectId('5a43fa12d885eb7da57046b3'),
ObjectId('5a4d3a6bd885eb7da5e6b297'),
ObjectId('5a53d0a0d885eb7da53ed5a6'),
],
},
});
if (importedUsers !== 2 || importedSubscriptions !== 1 || importedSettings !== 5) {
throw new Error(
`Import verification failed: users=${importedUsers}, `
+ `subscriptions=${importedSubscriptions}, settings=${importedSettings}`,
);
}
print('Imported 2 users, 1 subscription, and 5 settings records into Kerberos.');

View File

@@ -0,0 +1,81 @@
apiVersion: batch/v1
kind: Job
metadata:
name: hub-documentdb-import
labels:
app.kubernetes.io/name: hub-documentdb-import
spec:
activeDeadlineSeconds: 300
backoffLimit: 1
template:
metadata:
labels:
app.kubernetes.io/name: hub-documentdb-import
spec:
restartPolicy: Never
containers:
- name: import
image: mongo:7.0
imagePullPolicy: IfNotPresent
command:
- sh
- -ec
- |
flavor="$(printf '%s' "$MONGODB_FLAVOR" | tr '[:upper:]' '[:lower:]')"
retry_writes="$(printf '%s' "$MONGODB_RETRY_WRITES" | tr '[:upper:]' '[:lower:]')"
if [ "$flavor" != "documentdb" ]; then
echo "Refusing import: MONGODB_FLAVOR must be documentdb" >&2
exit 1
fi
if [ "$retry_writes" != "false" ]; then
echo "Refusing import: MONGODB_RETRY_WRITES must be false for DocumentDB" >&2
exit 1
fi
if [ ! -r /certs/global-bundle.pem ]; then
echo "Refusing import: /certs/global-bundle.pem is not readable" >&2
exit 1
fi
mongosh "$MONGODB_URI" \
--tls \
--tlsCAFile /certs/global-bundle.pem \
--quiet \
--file /scripts/hub-import.js
env:
- name: MONGODB_URI
valueFrom:
configMapKeyRef:
name: mongodb-config
key: MONGODB_URI
- name: MONGODB_FLAVOR
valueFrom:
configMapKeyRef:
name: mongodb-config
key: MONGODB_FLAVOR
- name: MONGODB_RETRY_WRITES
valueFrom:
configMapKeyRef:
name: mongodb-config
key: MONGODB_RETRY_WRITES
resources:
requests:
cpu: 10m
memory: 64Mi
volumeMounts:
- name: import-script
mountPath: /scripts
readOnly: true
- name: mongodb-tls
mountPath: /certs
readOnly: true
volumes:
- name: import-script
configMap:
name: hub-documentdb-import
- name: mongodb-tls
secret:
secretName: mongodb-ca
items:
- key: global-bundle.pem
path: global-bundle.pem

View File

@@ -0,0 +1,13 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
generatorOptions:
disableNameSuffixHash: true
configMapGenerator:
- name: hub-documentdb-import
files:
- hub-import.js
resources:
- job.yaml

View File

@@ -0,0 +1,54 @@
#!/usr/bin/env bash
set -euo pipefail
namespace="${NAMESPACE:-kerberos-hub}"
timeout="${TIMEOUT:-5m}"
job_name="hub-documentdb-import"
script_dir="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"
for command_name in kubectl; do
if ! command -v "$command_name" >/dev/null 2>&1; then
echo "Required command not found: $command_name" >&2
exit 1
fi
done
flavor="$(kubectl get configmap mongodb-config \
--namespace "$namespace" \
--output jsonpath='{.data.MONGODB_FLAVOR}')"
retry_writes="$(kubectl get configmap mongodb-config \
--namespace "$namespace" \
--output jsonpath='{.data.MONGODB_RETRY_WRITES}')"
ca_bundle="$(kubectl get secret mongodb-ca \
--namespace "$namespace" \
--output jsonpath='{.data.global-bundle\.pem}')"
if [[ "${flavor,,}" != "documentdb" ]]; then
echo "Refusing import: mongodb-config MONGODB_FLAVOR must be documentdb" >&2
exit 1
fi
if [[ "${retry_writes,,}" != "false" ]]; then
echo "Refusing import: mongodb-config MONGODB_RETRY_WRITES must be false" >&2
exit 1
fi
if [[ -z "$ca_bundle" ]]; then
echo "Refusing import: mongodb-ca/global-bundle.pem is missing" >&2
exit 1
fi
kubectl delete job "$job_name" \
--namespace "$namespace" \
--ignore-not-found=true \
--wait=true
kubectl apply --kustomize "$script_dir" --namespace "$namespace"
if ! kubectl wait \
--namespace "$namespace" \
--for=condition=complete \
--timeout="$timeout" \
"job/$job_name"; then
kubectl logs --namespace "$namespace" "job/$job_name" --all-containers=true || true
exit 1
fi
kubectl logs --namespace "$namespace" "job/$job_name" --all-containers=true

View File

@@ -0,0 +1,131 @@
###############################################################################
# DocumentDB
#
# The cluster is created with TLS (encryption in transit) and encryption at
# rest enabled. Clients must trust the Amazon RDS certificate authority bundle:
#
# curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
#
# For Kerberos Hub that bundle is mounted through the helm chart's
# `mongodb.tls` values, see the README next to this file.
###############################################################################
resource "random_password" "docdb" {
count = var.docdb_password == null ? 1 : 0
length = 32
special = true
# DocumentDB rejects '/', '"' and '@' in the master password. '@' and '/'
# would also break the MongoDB connection string.
override_special = "!#$%&*()-_=+[]{}<>:?"
}
locals {
docdb_password = var.docdb_password != null ? var.docdb_password : random_password.docdb[0].result
docdb_subnet_group_name = "${local.name}-docdb-${module.vpc.vpc_id}"
}
resource "aws_security_group" "docdb" {
name = "${local.name}-docdb"
description = "MongoDB wire protocol access to the Kerberos Hub DocumentDB cluster"
vpc_id = module.vpc.vpc_id
tags = merge(local.tags, { Name = "${local.name}-docdb" })
}
resource "aws_vpc_security_group_ingress_rule" "docdb_from_eks_nodes" {
security_group_id = aws_security_group.docdb.id
description = "DocumentDB from the EKS worker nodes"
referenced_security_group_id = module.eks.node_security_group_id
ip_protocol = "tcp"
from_port = 27017
to_port = 27017
}
resource "aws_vpc_security_group_ingress_rule" "docdb_from_cidrs" {
for_each = toset(var.docdb_allowed_cidrs)
security_group_id = aws_security_group.docdb.id
description = "DocumentDB from ${each.value}"
cidr_ipv4 = each.value
ip_protocol = "tcp"
from_port = 27017
to_port = 27017
}
resource "aws_docdb_subnet_group" "this" {
name = local.docdb_subnet_group_name
description = "Private subnets of the Kerberos Hub VPC"
subnet_ids = module.vpc.private_subnets
tags = local.tags
lifecycle {
create_before_destroy = true
}
}
resource "aws_docdb_cluster_parameter_group" "this" {
name = "${local.name}-docdb"
family = var.docdb_parameter_group_family
description = "Kerberos Hub DocumentDB parameters"
parameter {
name = "tls"
value = var.docdb_tls ? "enabled" : "disabled"
}
tags = local.tags
lifecycle {
create_before_destroy = true
}
}
resource "aws_docdb_cluster" "this" {
cluster_identifier = "${local.name}-docdb"
engine = "docdb"
engine_version = var.docdb_engine_version
port = 27017
master_username = var.docdb_username
master_password = local.docdb_password
db_subnet_group_name = aws_docdb_subnet_group.this.name
db_cluster_parameter_group_name = aws_docdb_cluster_parameter_group.this.name
vpc_security_group_ids = [aws_security_group.docdb.id]
storage_encrypted = true
kms_key_id = var.docdb_kms_key_id
backup_retention_period = var.docdb_backup_retention_period
preferred_backup_window = "02:00-04:00"
preferred_maintenance_window = "sun:04:30-sun:05:30"
enabled_cloudwatch_logs_exports = var.docdb_enabled_cloudwatch_logs_exports
deletion_protection = var.docdb_deletion_protection
skip_final_snapshot = var.docdb_skip_final_snapshot
final_snapshot_identifier = var.docdb_skip_final_snapshot ? null : "${local.name}-docdb-final"
tags = local.tags
lifecycle {
replace_triggered_by = [aws_docdb_subnet_group.this.name]
}
}
resource "aws_docdb_cluster_instance" "this" {
count = var.docdb_instance_count
identifier = "${local.name}-docdb-${count.index}"
cluster_identifier = aws_docdb_cluster.this.id
instance_class = var.docdb_instance_class
auto_minor_version_upgrade = true
tags = local.tags
}

View File

@@ -0,0 +1,70 @@
###############################################################################
# EKS
###############################################################################
module "eks" {
source = "terraform-aws-modules/eks/aws"
version = "~> 20.31"
cluster_name = local.name
cluster_version = var.kubernetes_version
cluster_endpoint_public_access = var.cluster_endpoint_public_access
cluster_endpoint_public_access_cidrs = var.cluster_endpoint_public_access_cidrs
# Give the identity running `terraform apply` cluster-admin, so that
# `aws eks update-kubeconfig` immediately works.
enable_cluster_creator_admin_permissions = true
vpc_id = module.vpc.vpc_id
subnet_ids = module.vpc.private_subnets
cluster_addons = {
coredns = {}
kube-proxy = {}
vpc-cni = {}
eks-pod-identity-agent = {}
aws-ebs-csi-driver = {
service_account_role_arn = module.ebs_csi_irsa.iam_role_arn
}
}
eks_managed_node_groups = {
default = {
instance_types = var.node_instance_types
capacity_type = "ON_DEMAND"
min_size = var.node_min_size
max_size = var.node_max_size
desired_size = var.node_desired_size
disk_size = var.node_disk_size
}
}
tags = local.tags
}
###############################################################################
# EBS CSI driver
#
# Kerberos Hub's supporting components (RabbitMQ, VerneMQ, MinIO, ...) claim
# persistent volumes, so the cluster needs a working CSI driver.
###############################################################################
module "ebs_csi_irsa" {
source = "terraform-aws-modules/iam/aws//modules/iam-role-for-service-accounts-eks"
version = "~> 5.44"
role_name = "${local.name}-ebs-csi"
attach_ebs_csi_policy = true
oidc_providers = {
main = {
provider_arn = module.eks.oidc_provider_arn
namespace_service_accounts = ["kube-system:ebs-csi-controller-sa"]
}
}
tags = local.tags
}

View File

@@ -0,0 +1,5 @@
crds:
enabled: true
extraArgs:
- --acme-http01-solver-nameservers=1.1.1.1:53,8.8.8.8:53

View File

@@ -0,0 +1,13 @@
apiVersion: cert-manager.io/v1
kind: ClusterIssuer
metadata:
name: letsencrypt-prod
spec:
acme:
privateKeySecretRef:
name: letsencrypt-prod-account-key
server: https://acme-v02.api.letsencrypt.org/directory
solvers:
- http01:
ingress:
ingressClassName: nginx

View File

@@ -0,0 +1,52 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: hub-frontend-ingress
namespace: kerberos-hub
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
ingressClassName: nginx
rules:
- host: aws-app.kerberos.lol
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: hub-frontend-svc
port:
number: 80
tls:
- hosts:
- aws-app.kerberos.lol
secretName: aws-app-kerberos-lol-tls
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: hub-api-ingress
namespace: kerberos-hub
annotations:
cert-manager.io/cluster-issuer: letsencrypt-prod
nginx.ingress.kubernetes.io/proxy-body-size: 200m
nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
ingressClassName: nginx
rules:
- host: aws-api.kerberos.lol
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: hub-api-svc
port:
number: 8081
tls:
- hosts:
- aws-api.kerberos.lol
secretName: aws-api-kerberos-lol-tls

View File

@@ -0,0 +1,7 @@
kerberoshub:
api:
schema: https
url: aws-api.kerberos.lol
frontend:
schema: https
url: aws-app.kerberos.lol

View File

@@ -0,0 +1,15 @@
controller:
config:
use-forwarded-headers: "true"
ingressClass: nginx
ingressClassResource:
default: false
enabled: true
name: nginx
service:
annotations:
service.beta.kubernetes.io/aws-load-balancer-cross-zone-load-balancing-enabled: "true"
service.beta.kubernetes.io/aws-load-balancer-scheme: internet-facing
service.beta.kubernetes.io/aws-load-balancer-type: nlb
externalTrafficPolicy: Local
type: LoadBalancer

View File

@@ -0,0 +1,43 @@
#!/usr/bin/env bash
set -euo pipefail
readonly SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
readonly INGRESS_NGINX_VERSION="4.15.1"
readonly CERT_MANAGER_VERSION="v1.21.1"
for command in helm kubectl; do
if ! command -v "${command}" >/dev/null 2>&1; then
echo "Missing required command: ${command}" >&2
exit 1
fi
done
helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx --force-update
helm repo add jetstack https://charts.jetstack.io --force-update
helm repo update ingress-nginx jetstack
helm upgrade --install ingress-nginx ingress-nginx/ingress-nginx \
--version "${INGRESS_NGINX_VERSION}" \
--namespace ingress-nginx \
--create-namespace \
--values "${SCRIPT_DIR}/ingress-nginx-values.yaml" \
--atomic \
--wait \
--timeout 15m
helm upgrade --install cert-manager jetstack/cert-manager \
--version "${CERT_MANAGER_VERSION}" \
--namespace cert-manager \
--create-namespace \
--values "${SCRIPT_DIR}/cert-manager-values.yaml" \
--atomic \
--wait \
--timeout 15m
kubectl apply --filename "${SCRIPT_DIR}/cluster-issuer.yaml"
kubectl wait --for=condition=Ready clusterissuer/letsencrypt-prod --timeout=2m
kubectl apply --filename "${SCRIPT_DIR}/hub-ingresses.yaml"
kubectl get service ingress-nginx-controller \
--namespace ingress-nginx \
--output jsonpath='Load balancer: {.status.loadBalancer.ingress[0].hostname}{"\n"}'

View File

@@ -0,0 +1,124 @@
###############################################################################
# Cluster
###############################################################################
output "region" {
description = "AWS region the stack is deployed in."
value = var.region
}
output "cluster_name" {
description = "Name of the EKS cluster."
value = module.eks.cluster_name
}
output "cluster_endpoint" {
description = "Endpoint of the Kubernetes API server."
value = module.eks.cluster_endpoint
}
output "update_kubeconfig_command" {
description = "Command to point kubectl at the new cluster."
value = "aws eks update-kubeconfig --region ${var.region} --name ${module.eks.cluster_name}"
}
output "vpc_id" {
description = "ID of the VPC. DocumentDB is only reachable from inside this VPC."
value = module.vpc.vpc_id
}
output "private_subnet_ids" {
description = "IDs of the private subnets hosting the worker nodes and DocumentDB."
value = module.vpc.private_subnets
}
###############################################################################
# DocumentDB
###############################################################################
output "docdb_endpoint" {
description = "Cluster (writer) endpoint of the DocumentDB cluster."
value = aws_docdb_cluster.this.endpoint
}
output "docdb_reader_endpoint" {
description = "Reader endpoint of the DocumentDB cluster."
value = aws_docdb_cluster.this.reader_endpoint
}
output "docdb_port" {
description = "Port the DocumentDB cluster listens on."
value = aws_docdb_cluster.this.port
}
output "docdb_username" {
description = "DocumentDB master username."
value = aws_docdb_cluster.this.master_username
}
output "docdb_password" {
description = "DocumentDB master password. Read it with: terraform output -raw docdb_password"
value = local.docdb_password
sensitive = true
}
output "docdb_security_group_id" {
description = "Security group guarding the DocumentDB cluster."
value = aws_security_group.docdb.id
}
output "docdb_tls_enabled" {
description = "Whether TLS is enforced on the DocumentDB cluster."
value = var.docdb_tls
}
###############################################################################
# Kerberos Hub wiring
###############################################################################
output "mongodb_uri" {
description = <<-EOT
Connection string for the Kerberos Hub helm chart (`mongodb.uri`).
The chart appends `tls=true` and `tlsCAFile=...` itself when
`mongodb.tls.enabled=true`, so no TLS parameters are included here.
Read it with: terraform output -raw mongodb_uri
EOT
value = format(
"mongodb://%s:%s@%s:%d/?replicaSet=rs0&readPreference=secondaryPreferred&retryWrites=false",
var.docdb_username,
urlencode(local.docdb_password),
aws_docdb_cluster.this.endpoint,
aws_docdb_cluster.this.port,
)
sensitive = true
}
output "hub_values_snippet" {
description = <<-EOT
Ready to paste values for the Kerberos Hub helm chart. Write it to a file with:
terraform output -raw hub_values_snippet > hub-documentdb-values.yaml
It expects the Amazon RDS CA bundle to be available as the `mongodb-ca` secret:
curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
kubectl create secret generic mongodb-ca --from-file=global-bundle.pem -n kerberos-hub
EOT
value = <<-EOT
mongodb:
# DocumentDB does not support geospatial queries, complex $lookup
# pipelines or retryable writes, hence the flavor and retryWrites below.
flavor: "documentdb"
retryWrites: "false"
uri: "mongodb://${var.docdb_username}:${urlencode(local.docdb_password)}@${aws_docdb_cluster.this.endpoint}:${aws_docdb_cluster.this.port}/?replicaSet=rs0&readPreference=secondaryPreferred&retryWrites=false"
adminDatabase: "admin"
authenticationMechanism: "SCRAM-SHA-1"
tls:
enabled: ${var.docdb_tls}
existingSecret: "mongodb-ca"
caFileName: "global-bundle.pem"
mountPath: "/certs"
EOT
sensitive = true
}

View File

@@ -0,0 +1,33 @@
# Copy to terraform.tfvars and adjust.
name = "kerberos-hub"
region = "eu-west-1"
environment = "test"
# Networking
vpc_cidr = "10.20.0.0/16"
availability_zone_count = 3
single_nat_gateway = true
# EKS
kubernetes_version = "1.31"
# Restrict this to your office or VPN range.
cluster_endpoint_public_access_cidrs = ["0.0.0.0/0"]
node_instance_types = ["t3.large"]
node_desired_size = 2
node_min_size = 2
node_max_size = 4
# DocumentDB
docdb_engine_version = "5.0.0"
docdb_parameter_group_family = "docdb5.0"
docdb_instance_class = "db.t3.medium"
docdb_instance_count = 1
docdb_username = "kerberos"
# Leave docdb_password unset to have one generated:
# terraform output -raw docdb_password
docdb_tls = true
# Throwaway test stack settings, flip these for anything long lived.
docdb_deletion_protection = false
docdb_skip_final_snapshot = true

View File

@@ -0,0 +1,194 @@
###############################################################################
# General
###############################################################################
variable "name" {
description = "Name prefix used for every resource created by this stack."
type = string
default = "kerberos-hub"
validation {
condition = can(regex("^[a-z][a-z0-9-]{2,30}$", var.name))
error_message = "The name must be lowercase, start with a letter and contain only letters, digits and dashes (3-31 characters)."
}
}
variable "region" {
description = "AWS region to deploy into."
type = string
default = "eu-west-1"
}
variable "environment" {
description = "Environment label applied as a tag (for example test, staging, production)."
type = string
default = "test"
}
variable "tags" {
description = "Extra tags merged into every resource."
type = map(string)
default = {}
}
###############################################################################
# Networking
###############################################################################
variable "vpc_cidr" {
description = "CIDR block of the VPC. DocumentDB is only reachable from within this VPC."
type = string
default = "10.20.0.0/16"
}
variable "availability_zone_count" {
description = "Number of availability zones to spread the subnets over. DocumentDB requires at least two."
type = number
default = 3
validation {
condition = var.availability_zone_count >= 2 && var.availability_zone_count <= 4
error_message = "availability_zone_count must be between 2 and 4."
}
}
variable "single_nat_gateway" {
description = "Use one shared NAT gateway instead of one per availability zone. Cheaper, but not highly available."
type = bool
default = true
}
###############################################################################
# EKS
###############################################################################
variable "kubernetes_version" {
description = "Kubernetes version of the EKS control plane."
type = string
default = "1.31"
}
variable "cluster_endpoint_public_access" {
description = "Expose the Kubernetes API server publicly. Keep it on for a test cluster, restrict it with cluster_endpoint_public_access_cidrs."
type = bool
default = true
}
variable "cluster_endpoint_public_access_cidrs" {
description = "CIDR blocks allowed to reach the public Kubernetes API endpoint. Narrow this to your office/VPN range."
type = list(string)
default = ["0.0.0.0/0"]
}
variable "node_instance_types" {
description = "Instance types of the managed node group."
type = list(string)
default = ["t3.large"]
}
variable "node_desired_size" {
description = "Desired number of worker nodes."
type = number
default = 2
}
variable "node_min_size" {
description = "Minimum number of worker nodes."
type = number
default = 2
}
variable "node_max_size" {
description = "Maximum number of worker nodes."
type = number
default = 4
}
variable "node_disk_size" {
description = "EBS volume size (GiB) of each worker node."
type = number
default = 50
}
###############################################################################
# DocumentDB
###############################################################################
variable "docdb_engine_version" {
description = "DocumentDB engine version."
type = string
default = "5.0.0"
}
variable "docdb_parameter_group_family" {
description = "Parameter group family matching the engine version (docdb5.0, docdb4.0, ...)."
type = string
default = "docdb5.0"
}
variable "docdb_instance_class" {
description = "Instance class of the DocumentDB instances."
type = string
default = "db.t3.medium"
}
variable "docdb_instance_count" {
description = "Number of DocumentDB instances. One is enough for a test stack, use two or more for failover."
type = number
default = 1
}
variable "docdb_username" {
description = "DocumentDB master username. 'admin' and other reserved words are rejected by AWS."
type = string
default = "kerberos"
}
variable "docdb_password" {
description = "DocumentDB master password. Leave null to generate one; read it afterwards with 'terraform output -raw docdb_password'."
type = string
default = null
sensitive = true
}
variable "docdb_tls" {
description = "Enforce TLS (encryption in transit) on the cluster. Keep this enabled; it is the configuration the hub chart's mongodb.tls values are meant for."
type = bool
default = true
}
variable "docdb_kms_key_id" {
description = "KMS key ARN for encryption at rest. Leave null to use the AWS managed key."
type = string
default = null
}
variable "docdb_backup_retention_period" {
description = "Number of days automated backups are retained."
type = number
default = 1
}
variable "docdb_deletion_protection" {
description = "Prevent the cluster from being deleted. Keep false for a throwaway test stack."
type = bool
default = false
}
variable "docdb_skip_final_snapshot" {
description = "Skip the final snapshot on destroy. Keep true for a throwaway test stack."
type = bool
default = true
}
variable "docdb_enabled_cloudwatch_logs_exports" {
description = "Log types exported to CloudWatch (audit, profiler)."
type = list(string)
default = []
}
variable "docdb_allowed_cidrs" {
description = "Extra CIDR blocks allowed to reach DocumentDB on port 27017, on top of the EKS worker nodes (for example a bastion subnet)."
type = list(string)
default = []
}

View File

@@ -0,0 +1,18 @@
terraform {
required_version = ">= 1.5.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 5.60"
}
random = {
source = "hashicorp/random"
version = ">= 3.6"
}
}
}
provider "aws" {
region = var.region
}

View File

@@ -0,0 +1,59 @@
locals {
name = var.name
tags = merge(
{
Project = "kerberos-hub"
Environment = var.environment
ManagedBy = "terraform"
Module = "deployment/modules/amazon-eks-documentdb"
},
var.tags,
)
azs = slice(data.aws_availability_zones.available.names, 0, var.availability_zone_count)
}
data "aws_availability_zones" "available" {
state = "available"
filter {
name = "opt-in-status"
values = ["opt-in-not-required"]
}
}
###############################################################################
# VPC
#
# DocumentDB has no public endpoint: it only listens inside the VPC. Both the
# EKS worker nodes and the DocumentDB instances therefore live in the private
# subnets, and the workers reach the internet (image pulls) through NAT.
###############################################################################
module "vpc" {
source = "terraform-aws-modules/vpc/aws"
version = "~> 5.13"
name = "${local.name}-vpc"
cidr = var.vpc_cidr
azs = local.azs
private_subnets = [for index in range(var.availability_zone_count) : cidrsubnet(var.vpc_cidr, 4, index)]
public_subnets = [for index in range(var.availability_zone_count) : cidrsubnet(var.vpc_cidr, 4, index + 8)]
enable_nat_gateway = true
single_nat_gateway = var.single_nat_gateway
enable_dns_hostnames = true
enable_dns_support = true
public_subnet_tags = {
"kubernetes.io/role/elb" = "1"
}
private_subnet_tags = {
"kubernetes.io/role/internal-elb" = "1"
}
tags = local.tags
}