mirror of
https://github.com/kerberos-io/documentation.git
synced 2026-08-23 15:18:31 +00:00
finish documentaatioon
This commit is contained in:
@@ -2,12 +2,10 @@
|
||||
const preferDefault = m => m && m.default || m
|
||||
|
||||
exports.components = {
|
||||
"component---cache-dev-404-page-js": () => import("dev-404-page.js" /* webpackChunkName: "component---cache-dev-404-page-js" */),
|
||||
"component---src-pages-404-js": () => import("../src/pages/404.js" /* webpackChunkName: "component---src-pages-404-js" */),
|
||||
"component---src-architectures-mdx": () => import("../../src/architectures.mdx" /* webpackChunkName: "component---src-architectures-mdx" */),
|
||||
"component---src-enterprise-installation-mdx": () => import("../../src/enterprise/installation.mdx" /* webpackChunkName: "component---src-enterprise-installation-mdx" */),
|
||||
"component---src-index-mdx": () => import("../../src/index.mdx" /* webpackChunkName: "component---src-index-mdx" */),
|
||||
"component---src-enterprise-index-mdx": () => import("../../src/enterprise/index.mdx" /* webpackChunkName: "component---src-enterprise-index-mdx" */),
|
||||
"component---src-enterprise-installation-mdx": () => import("../../src/enterprise/installation.mdx" /* webpackChunkName: "component---src-enterprise-installation-mdx" */),
|
||||
"component---src-enterprise-releases-mdx": () => import("../../src/enterprise/releases.mdx" /* webpackChunkName: "component---src-enterprise-releases-mdx" */),
|
||||
"component---src-open-source-index-mdx": () => import("../../src/open-source/index.mdx" /* webpackChunkName: "component---src-open-source-index-mdx" */),
|
||||
"component---src-open-source-upgrade-mdx": () => import("../../src/open-source/upgrade.mdx" /* webpackChunkName: "component---src-open-source-upgrade-mdx" */),
|
||||
@@ -18,6 +16,8 @@ exports.components = {
|
||||
"component---src-open-source-license-mdx": () => import("../../src/open-source/license.mdx" /* webpackChunkName: "component---src-open-source-license-mdx" */),
|
||||
"component---src-open-source-releases-mdx": () => import("../../src/open-source/releases.mdx" /* webpackChunkName: "component---src-open-source-releases-mdx" */),
|
||||
"component---src-open-source-installation-mdx": () => import("../../src/open-source/installation.mdx" /* webpackChunkName: "component---src-open-source-installation-mdx" */),
|
||||
"component---src-open-source-machinery-mdx": () => import("../../src/open-source/machinery.mdx" /* webpackChunkName: "component---src-open-source-machinery-mdx" */)
|
||||
"component---src-open-source-machinery-mdx": () => import("../../src/open-source/machinery.mdx" /* webpackChunkName: "component---src-open-source-machinery-mdx" */),
|
||||
"component---cache-dev-404-page-js": () => import("dev-404-page.js" /* webpackChunkName: "component---cache-dev-404-page-js" */),
|
||||
"component---src-pages-404-js": () => import("../src/pages/404.js" /* webpackChunkName: "component---src-pages-404-js" */)
|
||||
}
|
||||
|
||||
|
||||
Binary file not shown.
@@ -5,12 +5,10 @@ const preferDefault = m => m && m.default || m
|
||||
|
||||
|
||||
exports.components = {
|
||||
"component---cache-dev-404-page-js": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/.docz/.cache/dev-404-page.js"))),
|
||||
"component---src-pages-404-js": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/.docz/src/pages/404.js"))),
|
||||
"component---src-architectures-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/architectures.mdx"))),
|
||||
"component---src-enterprise-installation-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/enterprise/installation.mdx"))),
|
||||
"component---src-index-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/index.mdx"))),
|
||||
"component---src-enterprise-index-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/enterprise/index.mdx"))),
|
||||
"component---src-enterprise-installation-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/enterprise/installation.mdx"))),
|
||||
"component---src-enterprise-releases-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/enterprise/releases.mdx"))),
|
||||
"component---src-open-source-index-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/index.mdx"))),
|
||||
"component---src-open-source-upgrade-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/upgrade.mdx"))),
|
||||
@@ -21,6 +19,8 @@ exports.components = {
|
||||
"component---src-open-source-license-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/license.mdx"))),
|
||||
"component---src-open-source-releases-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/releases.mdx"))),
|
||||
"component---src-open-source-installation-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/installation.mdx"))),
|
||||
"component---src-open-source-machinery-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/machinery.mdx")))
|
||||
"component---src-open-source-machinery-mdx": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/src/open-source/machinery.mdx"))),
|
||||
"component---cache-dev-404-page-js": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/.docz/.cache/dev-404-page.js"))),
|
||||
"component---src-pages-404-js": hot(preferDefault(require("/Users/i353408/Vagrant/www/repos/documentation/.docz/src/pages/404.js")))
|
||||
}
|
||||
|
||||
|
||||
@@ -1 +1 @@
|
||||
{"componentChunkName":"component---cache-dev-404-page-js","path":"/dev-404-page/","result":{"data":{"allSitePage":{"nodes":[{"path":"/404/"},{"path":"/404.html"},{"path":"/architectures"},{"path":"/"},{"path":"/enterprise/introduction"},{"path":"/enterprise/installation"},{"path":"/enterprise/releases"},{"path":"/opensource/introduction"},{"path":"/opensource/upgrade"},{"path":"/opensource/web"},{"path":"/cloud"},{"path":"/enterprise/license"},{"path":"/opensource/contribute"},{"path":"/opensource/license"},{"path":"/opensource/releases"},{"path":"/opensource/installation"},{"path":"/opensource/machinery"}]}},"pageContext":{"isCreatedByStatefulCreatePages":true}}}
|
||||
{"componentChunkName":"component---cache-dev-404-page-js","path":"/dev-404-page/","result":{"data":{"allSitePage":{"nodes":[{"path":"/architectures"},{"path":"/enterprise/installation"},{"path":"/"},{"path":"/enterprise/introduction"},{"path":"/enterprise/releases"},{"path":"/opensource/introduction"},{"path":"/opensource/upgrade"},{"path":"/opensource/web"},{"path":"/cloud"},{"path":"/enterprise/license"},{"path":"/opensource/contribute"},{"path":"/opensource/license"},{"path":"/opensource/releases"},{"path":"/opensource/installation"},{"path":"/opensource/machinery"},{"path":"/404/"},{"path":"/404.html"}]}},"pageContext":{"isCreatedByStatefulCreatePages":true}}}
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 1.6 MiB |
Binary file not shown.
|
After Width: | Height: | Size: 1.6 MiB |
@@ -10,28 +10,28 @@ Over the years Kerberos evolved into a mature and stable solution. Lots of peopl
|
||||
solution has its limitations, especially if you aim to scale it.
|
||||
|
||||
That being said, Kerberos Open Source is perfect when monitoring a limited set of surveillance cameras, but it doesn't scale well if you plan to monitor dozens or hundreds of surveillance cameras. Although Kerberos Open Source ships
|
||||
as a docker image, it has no high availability or fail over functionality. Due to these reasons we have developed Kerberos Enterprise, which is suitable for scaling against your ever growing video surveillance landscape, and makes them up and running in whatever situation.
|
||||
as a docker image, it has no high availability or fail over functionality. Due to these reasons we have developed Kerberos Enterprise, which is suitable for scaling against your ever growing video surveillance landscape, and keeps them up and running in whatever situation.
|
||||
|
||||
<div class='embed-container'><iframe src='https://player.vimeo.com/video/382090189?background=1' frameborder='0' webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></div>
|
||||
|
||||
## Kubernetes
|
||||
|
||||
To provide our customer with the high availability and fail over requirements they have, Kerberos Enterprise was built on top of Kubernetes (k8s). This container orchestrator, Kubernetes, allows us to scale a video surveillance landscape horizontally, and deliver a never-seen high available video surveillance system.
|
||||
To provide our customer with the high availability and fail over requirements they have, Kerberos Enterprise was built on top of Kubernetes (k8s). This container orchestrator allows us to scale a video surveillance landscape horizontally, and deliver a never-seen high available video surveillance system.
|
||||
|
||||

|
||||
|
||||
Kerberos Enterprise is installed inside a Kubernetes cluster. It will create pods/deployments for every surveillance camera you want to monitor. Kubernetes will scale and distrubute these pods across your nodes (VM's/Bare-metal machines).
|
||||
Kerberos Enterprise is installed inside a Kubernetes cluster. It will create pods/deployments for every surveillance camera you want to monitor. Kubernetes will scale and distrubute these pods across your nodes (VM's/Bare metal machines).
|
||||
|
||||
Nodes inside your cluster can fail or crash, Kubernetes will make sure the Kerberos pods running on the failed nodes will be deployed to healthy nodes, to make sure the monitoring of your video surveillance cameras continues seamlessly.
|
||||
Nodes inside your cluster can fail or crash, Kubernetes will make sure the Kerberos pods running on the failed nodes will be deployed to healthy node. This, to make sure the monitoring of your video surveillance cameras continues seamlessly.
|
||||
|
||||
By having the power to add nodes to your cluster, you can anticipate to the ever growing need of surveillance cameras. With the Kubernetes tools you can monitor your cluster and get into the details.
|
||||
By having the power to add nodes to your cluster, you can anticipate to the ever growing need of your surveillance cameras. With the Kubernetes tools you can monitor your cluster and get into the details.
|
||||
|
||||
## Cloud or on premise
|
||||
|
||||
You install Kerberos Enterprise inside a Kubernetes cluster, but there are not limitations where this cluster is running. This means that whatever security policy you have within your company, you can run it where you want: on-premise, public cloud, private cloud, etc.
|
||||
You install Kerberos Enterprise inside a Kubernetes cluster, but there are no limitations where this cluster will be actually running. This means that whatever security policy you have within your company, you can run it where you want: on-premise, public cloud, private cloud, etc.
|
||||
|
||||

|
||||
|
||||
## Licensing
|
||||
|
||||
Kerberos Enterprise is publicly available but requires a license key to operate correctly. A license key can be requested by contacting **cedric@verstraeten.io**, send an email to have more information about the pricing.
|
||||
Kerberos Enterprise is publicly available but **requires a license key** to operate correctly. A license key can be requested by contacting **cedric@verstraeten.io**, you can send an email to have more information about the pricing.
|
||||
|
||||
@@ -15,41 +15,23 @@ cloud providers (Digital Ocean, Scaleway, etc) or on-premise in your own private
|
||||
|
||||
# Installation
|
||||
|
||||
Before setting up Kerberos Enterprise, some configuration needs to happen. First thing that needs to happen is setting up the RBAC permissions (Role Based Access Control),
|
||||
we need to do this to query specific endpoints from the Kubernetes API. By default these endpoints are blocked, so we need
|
||||
to unblock them.
|
||||
Before setting up Kerberos Enterprise, some configuration needs to happen. First thing that we need to do is setting up the RBAC permissions (Role Based Access Control). We need to enable this to be able to query specific endpoints from the Kubernetes API. By default these endpoints are locked, so we need to unlock them.
|
||||
|
||||
First clone the configrations from our Github repo.
|
||||
|
||||
git clone https://github.com/kerberos-io/enterprise-factory
|
||||
|
||||
Next go into the directory and execute the first Kubernetes configuration file `clusterrole.yaml`.
|
||||
|
||||
cd enterprise-factory
|
||||
|
||||
kubectl create -f ./clusterrole.yaml
|
||||
|
||||
|
||||
clusterrole.yaml
|
||||
|
||||
kind: ClusterRole
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: pods-list
|
||||
rules:
|
||||
- apiGroups: ["", "apps"]
|
||||
resources: ["pods", "pods/log", "deployments", "services", "endpoints", "nodes"]
|
||||
verbs: ["get", "list", "create", "delete"]
|
||||
---
|
||||
kind: ClusterRoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
metadata:
|
||||
name: pods-list
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: default
|
||||
namespace: default
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: pods-list
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
|
||||
This will make several actions inside your cluster available. We need this to be able to create deployments from the factory web app.
|
||||
|
||||
## Helm
|
||||
|
||||
[**Helm**](https://helm.sh/) is a package manager for Kubernetes, it helps you setting up services more easily (this could be a MQTT broker, a database, etc).
|
||||
Next we will install a couple of dependencies which are required for Kerberos Enterprise. [**Helm**](https://helm.sh/) is a package manager for Kubernetes, it helps you setting up services more easily (this could be a MQTT broker, a database, etc).
|
||||
Instead of writing yaml files for every service we need, we use so called **Charts** (libraries), that you can reuse and configure the,
|
||||
with the appropriate settings.
|
||||
|
||||
@@ -70,62 +52,84 @@ Tiller is what they call the server component of Helm.
|
||||
|
||||
kubectl create serviceaccount tiller --namespace kube-system
|
||||
kubectl create -f ./tiller-clusterrolebinding.yaml
|
||||
|
||||
helm init --service-account tiller
|
||||
|
||||
tiller-clusterrolebinding.yaml
|
||||
|
||||
kind: ClusterRoleBinding
|
||||
apiVersion: rbac.authorization.k8s.io/v1beta1
|
||||
metadata:
|
||||
name: tiller-clusterrolebinding
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: tiller
|
||||
namespace: kube-system
|
||||
roleRef:
|
||||
kind: ClusterRole
|
||||
name: cluster-admin
|
||||
apiGroup: ""
|
||||
Now you have installed **Helm** inside your cluster we can move on by installing the dependencies.
|
||||
|
||||
## Traefik
|
||||
|
||||
[**Traefik**](https://containo.us/traefik/) is a reverse proxy and load balancer which allows you to
|
||||
expose your deployments more easily. Kerberos uses Traefik to expose it's APIs more easily. More info will follow.
|
||||
expose your deployments more easily. Kerberos uses Traefik to expose it's APIs more easily.
|
||||
|
||||
By executing following helm command, we will install traefik and link it to a specific DNS name. Open the traefik values file, and update the DNS name to your own domain.
|
||||
|
||||
dashboard:
|
||||
enabled: true
|
||||
--> domain: traefik.domain.com
|
||||
serviceType: NodePort
|
||||
rbac:
|
||||
enabled: true
|
||||
|
||||
Execute the `helm install` command.
|
||||
|
||||
helm install --name traefik -f ./traefik/values.yaml stable/traefik
|
||||
|
||||
./traefik/values.yaml
|
||||
After installation you should have an IP attached to traefik service, look for it by executing the `get service` command. You will see the ip address in the `EXTERNAL-IP` attribute.
|
||||
|
||||
dashboard:
|
||||
enabled: true
|
||||
domain: your.domain.com
|
||||
serviceType: NodePort
|
||||
rbac:
|
||||
enabled: true
|
||||
kubectl get svc
|
||||
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
kubernetes ClusterIP 10.0.0.1 <none> 443/TCP 36h
|
||||
--> traefik LoadBalancer 10.0.27.93 40.114.168.96 443:31623/TCP,80:31804/TCP 35h
|
||||
traefik-dashboard NodePort 10.0.252.6 <none> 80:31146/TCP 35h
|
||||
|
||||
Go to your DNS provider and link the domain you've configured in the first step `traefik.domain.com` to the IP address of the `EXTERNAL-IP` attribute.
|
||||
|
||||
When browsing to `traefik.domain.com`, you should see the traefik dashboard showing up.
|
||||
|
||||
## MongoDB
|
||||
|
||||
Kerberos Enterprise generates configurations for every surveillance camera that you want to monitor. These configuration files
|
||||
are stored centrally in a MongoDB database. Therefore we use Helm to install a MongoDB instance inside your cluster.
|
||||
|
||||
Have a look into the `mongodb/values.yaml` file, you will find plenty of configurations for your mongodb instance. You will also find the attribute where you can change the root password of mongodb.
|
||||
|
||||
helm install --name mongodb stable/mongodb --values ./mongodb/values.yaml
|
||||
|
||||
./mongodb/values.yaml
|
||||
|
||||
...
|
||||
|
||||
## Factory
|
||||
|
||||
Kerberos Enterprise is managed through ann application which we call the **Factory**. The Factory is responsible for initiating
|
||||
The last step is to install the factory service. Kerberos Enterprise is managed through an application which we call the **Factory**.
|
||||
|
||||
The Factory is responsible for initiating
|
||||
the deployments inside your cluster. These deployments is what we also call (similar to the Open Source version) the machinery.
|
||||
The Factory also provide you with the tools to update your machineries easily through a web interface, monitor them, etc. The factory
|
||||
is the central portal for managing Kerberos Enterprise inside your cluster.
|
||||
|
||||
The Factory comes as a web interface which provides you with a tool to update your machineries easily, monitor them, etc. The Factory is the central portal for managing Kerberos Enterprise inside your cluster.
|
||||
|
||||
Before installing the Factory service, open the `factory/kubernetes.yaml` configuration file. At the bottom file you will find two endpoints, similar to the traefik config file. Update the domain names to your own domain, and add these to your DNS server (pointing to the same IP as the traefik EXTERNAL-IP).
|
||||
|
||||
spec:
|
||||
rules:
|
||||
--> - host: factory.domain.com
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
backend:
|
||||
serviceName: factory
|
||||
servicePort: 80
|
||||
--> - host: api.factory.domain.com
|
||||
http:
|
||||
paths:
|
||||
- path: /
|
||||
backend:
|
||||
serviceName: factory
|
||||
servicePort: 8081
|
||||
|
||||
Once you have corrected the DNS names, install the Factory service inside your cluster.
|
||||
|
||||
kubectl apply -f ./factory/kubernetes.yaml
|
||||
|
||||
./factory/kubernetes.yaml
|
||||
|
||||
... link to yaml ...
|
||||
|
||||
# Test out configuration
|
||||
|
||||
@@ -143,28 +147,8 @@ It should look like this.
|
||||
mongodb-55566dc65c-xgmns 2/2 Running 0 4d13h
|
||||
traefik-7d566ccc47-mwslb 1/1 Running 0 4d12h
|
||||
|
||||
## DNS configuration
|
||||
|
||||
When deploying both Traefik and Factory you had to specify a domain. In this step we need to configure your DNS server. Look for the
|
||||
Traefik service, and copy its External IP.
|
||||
|
||||
$ kubectl get svc
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
factory ClusterIP 10.0.10.175 <none> 80/TCP,8081/TCP 4d13h
|
||||
kubernetes ClusterIP 10.0.0.1 <none> 443/TCP 4d15h
|
||||
mongodb ClusterIP 10.0.1.0 <none> 27017/TCP,9216/TCP 4d14h
|
||||
--> traefik LoadBalancer 10.0.10.97 34.66.138.141 443:31683/TCP,80:32053/TCP 4d14h
|
||||
traefik-dashboard NodePort 10.0.14.209 <none> 80:32044/TCP 4d14h
|
||||
|
||||
Add this External IP to your DNS server, so it will resolve your domains:
|
||||
|
||||
- traefik.domain.com (change to your domain)
|
||||
- factory.domain.com (change to your domain).
|
||||
- api.factory.domain.com (change to your domain).
|
||||
|
||||
## Access the system
|
||||
|
||||
Once everything is configured correctly your cluster and dns, you should be able to setup the Factory application. By navigating
|
||||
to the Factory domain in your browser you will see the Factory login page showing up.
|
||||
Once everything is configured correctly your cluster and DNS, you should be able to setup the Factory application. By navigating to the Factory domain `factory.domain.com` in your browser you will see the Factory login page showing up.
|
||||
|
||||

|
||||
|
||||
Reference in New Issue
Block a user