Compare commits

..

95 Commits

Author SHA1 Message Date
Cedric Verstraeten
1c82f8ae7a Update Dockerfile 2024-09-30 21:50:52 +02:00
Cedric Verstraeten
f1fb359efa Merge branch 'master' of https://github.com/kerberos-io/documentation 2024-09-30 21:45:58 +02:00
Cedric Verstraeten
4fdcdbdce6 add workflows 2024-09-30 21:45:47 +02:00
Cédric Verstraeten
e2d06b29dd Merge pull request #49 from kerberos-io/tannyle289-patch-1
Update index.md
2024-07-25 10:24:59 +02:00
TannyLe
8eeb48bdba Update index.md
fix minor typo
2024-07-23 16:57:53 +02:00
TannyLe
01422f0d30 Update index.md
fix minor typo
2024-07-23 16:47:45 +02:00
Cedric Verstraeten
23f484e045 Kerberos Hub: force SSO documentation 2024-05-15 13:03:29 +02:00
Cedric Verstraeten
ca117c7aae moved introduction videos to different youtube channel 2024-05-13 10:52:49 +02:00
Cedric Verstraeten
efd128f4d9 publish documentation 2024-04-24 16:20:37 +02:00
Cedric Verstraeten
20c98257a8 add example gif: show how SSO looks like 2024-02-13 12:57:51 +01:00
Cedric Verstraeten
e23e036719 add sso docs 2024-02-13 11:58:57 +01:00
Cedric Verstraeten
937e86174f delete announcement, not longer relevant 2024-01-05 09:32:45 +01:00
Cedric Verstraeten
b9111ca4ff email templates allow you to build custom emails with variables 2023-08-08 21:27:10 +02:00
Cedric Verstraeten
fccc679135 add introduction 2023-07-24 07:29:22 +02:00
Cedric Verstraeten
e91bed43a7 small tweaks 2023-07-23 22:18:32 +02:00
Cedric Verstraeten
66a17b5978 add deployment image 2023-07-23 21:29:25 +02:00
Cedric Verstraeten
d99b1f306f improve docs for Kerberos Hub integration 2023-05-18 21:12:07 +02:00
Cédric Verstraeten
b9fe7fbc93 Update index.md 2023-05-05 08:26:38 +02:00
Cedric Verstraeten
9f3239d273 update links! 2023-05-05 08:20:24 +02:00
Cedric Verstraeten
4d03dd2794 remove api uril 2023-05-03 20:05:14 +02:00
Cedric Verstraeten
f661e75d7f hide recycling 2023-05-03 19:12:43 +02:00
Cedric Verstraeten
80ce2fc36e updates 2023-05-03 19:02:39 +02:00
Cédric Verstraeten
ac940f5548 Merge pull request #48 from Livingdead1989/patch-1 2023-04-08 18:40:14 +02:00
Steven Smith
e895d632a6 Update index.md
Corrected hyperlink typo in the protocol preventing users from using the link.
2023-04-08 16:26:48 +01:00
Cedric Verstraeten
c400ec136b add youtube end-to-end video 2023-02-21 15:45:46 +01:00
Cedric Verstraeten
3cbdcc3246 Update index.md 2022-12-18 14:27:34 +01:00
Cedric Verstraeten
10524122f6 Merge branch 'master' of https://github.com/kerberos-io/documentation 2022-12-18 14:27:00 +01:00
Cedric Verstraeten
f01f79edba expand glossary 2022-12-18 14:26:58 +01:00
Cédric Verstraeten
96515cd1d7 Merge pull request #44 from baberlevi/patch-1
typo correction
2022-12-18 08:09:29 +01:00
Cedric Verstraeten
10a1d55af0 more tweaks 2022-12-17 23:30:09 +01:00
Levi Baber
19b96e0ca5 typo correction 2022-12-17 15:20:52 -06:00
Cedric Verstraeten
b43d80ef9d advance deployments page 2022-12-16 16:15:47 +01:00
Cedric Verstraeten
0ff848ebf5 example deployments, more to be added of course 2022-12-15 23:14:27 +01:00
Cedric Verstraeten
911ce63702 improve "how it works page" 2022-12-15 16:51:02 +01:00
Cedric Verstraeten
ac1a29e261 tweaking the introduction pages, so it is better aligned 2022-12-15 08:22:08 +01:00
Cedric Verstraeten
91ae61076b small modifications prologue + starting to update illustrations 2022-12-14 19:38:26 +01:00
Cédric Verstraeten
ff2da6e248 Merge pull request #42 from dapeleg-dn/patch-1
Update index.html - add info about default and custom login options
2022-12-10 22:10:17 +01:00
David Peleg
6150cb52ca Update index.html
Add info about initial login username and password. 
Add info about configuring using environment variables, with custom username and password example.
2022-12-10 23:06:13 +02:00
Cedric Verstraeten
6f1e84e58e add depcrated message 2022-12-06 08:23:57 +01:00
Cedric Verstraeten
15e4816c8f get rid of release date Kerberos Agent, its here 2022-12-05 09:43:25 +01:00
Cedric Verstraeten
5767734ab5 make quote block 2022-12-05 09:41:55 +01:00
Cedric Verstraeten
31c50d38d1 Merge branch 'master' of https://github.com/kerberos-io/documentation 2022-12-05 09:34:38 +01:00
Cedric Verstraeten
9b711dd6f1 integrate github installation guides 2022-12-05 09:34:27 +01:00
Cédric Verstraeten
2bf185f384 Merge pull request #37 from eknowlton/patch-1
Updated link to Docker Volume Reference
2022-09-21 16:14:10 +02:00
Ethan Knowlton
deef2e1104 Updated link to Docker Volume Reference
Seems like a moving target but I noticed this was off by a few lines while trying out Kerberos.io.
2022-09-21 10:12:07 -04:00
Thomas Quandalle
f6fc8d0d39 fix 2022-08-09 20:31:09 +02:00
Thomas Quandalle
73f3e1e881 remove lock 2022-08-09 14:27:37 +02:00
Thomas Quandalle
d40dc5be7b add extended 2022-08-09 14:22:41 +02:00
Thomas Quandalle
88caca0aa0 move hugo to 0.81 2022-08-09 14:02:11 +02:00
Thomas Quandalle
03625c9e04 fix hugo version 2022-08-09 13:55:05 +02:00
Thomas Quandalle
0c5e6c47f2 lower version hugo 2022-08-09 13:53:16 +02:00
Thomas Quandalle
fec48aac86 install hugo from source 2022-08-09 13:46:29 +02:00
Thomas Quandalle
3b1ab12f14 add hugo 2022-08-09 13:34:18 +02:00
Thomas Quandalle
d251575d94 Update Dockerfile 2022-08-09 13:32:06 +02:00
Thomas Quandalle
457e6af437 add rimraf 2022-08-09 12:18:07 +02:00
Thomas Quandalle
aeda4c598b upgrade to node 18 2022-08-09 12:15:13 +02:00
Thomas Quandalle
8def470899 upgrade node base image 2022-08-09 12:11:05 +02:00
Thomas Quandalle
b4235a80ab do a local build in multi-stage 2022-08-09 12:08:33 +02:00
Thomas Quandalle
d4af376ad5 add docker build on github, get rid of gitlab 2022-08-09 12:00:11 +02:00
Thomas Quandalle
5631947474 add roles documentation 2022-08-09 11:28:17 +02:00
Thomas Quandalle
51194d917e add SVG's 2022-07-19 20:32:10 +02:00
Thomas Quandalle
3eb853c80e add welcome page for onboarding Kerberos Hub 2022-07-19 17:08:57 +02:00
Thomas Quandalle
9e8b62771b update docs 2022-07-18 17:57:10 +02:00
Cédric Verstraeten
a7ee84257d Update index.md 2022-06-07 11:41:58 +02:00
Thomas Quandalle
b0e77d884c fix typo 2022-06-07 09:16:25 +02:00
Thomas Quandalle
d7e026a49f add email templates docs 2022-06-07 08:45:10 +02:00
Thomas Quandalle
d1676daee3 Describing domain feature, and how to use, configure it. 2022-05-06 15:36:56 +02:00
Thomas Quandalle
dc47799a4f Remove spaces 2022-05-04 21:44:56 +02:00
Cédric Verstraeten
777c6a8102 Update index.md 2022-05-04 21:43:18 +02:00
Cédric Verstraeten
ce86090617 add onvif documentation, and instruction for Kerberos Hub 2022-05-04 21:38:32 +02:00
Cédric Verstraeten
47e7391ab1 add onvif / ptz docs 2022-04-25 15:28:12 +02:00
Cédric Verstraeten
8271a276e3 add analytics section 2022-04-24 22:52:31 +02:00
Cédric Verstraeten
33655103da fix 2022-04-20 21:29:10 +02:00
Cédric Verstraeten
debc147dd7 Create index.md 2022-04-20 21:07:10 +02:00
cedricve
c12cdb9433 add archiving section 2022-04-11 09:48:43 +02:00
Cédric Verstraeten
50fe92e11e Merge pull request #28 from Nanaki59/patch-1 2022-03-22 07:49:49 +01:00
Nanaki59
a02f8e8eb8 Fix installation issues on Raspbian Bullseye
Hi,

I'm proposing the fixes I had to apply to be able to use Kerberos.io with Raspberry Pi OS Bullseye 32 bits.

Adrien
2022-03-22 00:13:02 +01:00
cedricve
6651caf296 Update menus.toml 2022-03-21 20:47:56 +01:00
cedricve
1976303d81 Create youtube-vault-kerberosio.png 2022-03-19 20:54:02 +01:00
cedricve
c3e2743afb add images 2022-03-19 20:53:53 +01:00
cedricve
9de918a1e2 add recordings to factory and vault 2022-03-19 20:49:23 +01:00
cedricve
9cdb326dd8 update svg's 2022-03-14 21:30:20 +01:00
cedricve
c45c64b3bb Update factory-edge.svg 2022-03-14 21:29:19 +01:00
cedricve
aad78d2ca0 Update factory-edge-cloud.svg 2022-03-14 21:28:49 +01:00
cedricve
d9f11bf642 add white labeling section 2022-03-10 15:24:06 +01:00
cedricve
657a88e723 add introduction video 2022-03-08 10:18:12 +01:00
Cédric Verstraeten
1a8af99606 Update index.md 2022-02-23 22:13:43 +01:00
Cédric Verstraeten
e85c25ecc3 Update index.md 2022-02-23 22:13:19 +01:00
Cédric Verstraeten
ac89dc2abd Merge pull request #27 from anoopmundathan/patch-1 2022-02-07 07:11:34 +01:00
Anoop Mundathan
ccd31c6f84 Update index.md 2022-02-07 05:55:51 +00:00
cedricve
3de77068bd Merge branch 'master' of https://github.com/kerberos-io/documentation 2021-12-25 22:51:50 +01:00
cedricve
6884528207 add configmap mongodb to vault + change password 2021-12-25 22:51:47 +01:00
Iván Ruiz García
03721cc432 Update index.md 2021-12-25 20:22:27 +01:00
Iván Ruiz García
91b960babe Update index.md 2021-12-25 19:55:31 +01:00
cedricve
d241aa6e01 add webhook documentation 2021-12-20 09:50:40 +01:00
192 changed files with 32858 additions and 43943 deletions

31
.github/workflows/create-pr.yaml vendored Normal file
View File

@@ -0,0 +1,31 @@
name: Build pull request
on:
pull_request:
types: [opened, synchronize]
jobs:
build-pull-request:
runs-on: ubuntu-latest
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- name: Checkout repository
uses: actions/checkout@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Log in to Docker Hub
uses: docker/login-action@v1
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- uses: actions/setup-node@v1 #this installs node and npm for us
with:
node-version: "10.x"
# Build the Angular application to the dist folder
- name: Build Angular application
run: |
cd kerberos.ng
npm install
npm run build
# Build the Docker image with the latest tag and the release tag
- name: Build Docker image
run: |
docker build -t uugai/kerberos-documentation:latest .

53
.github/workflows/create-release.yml vendored Normal file
View File

@@ -0,0 +1,53 @@
name: Create a new release
on:
release:
types: [created]
workflow_dispatch:
inputs:
tag:
description: "Tag for the Docker image"
required: true
default: "test"
jobs:
build-and-push:
runs-on: ubuntu-latest
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- name: Checkout repository
uses: actions/checkout@v2
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v1
- name: Log in to Docker Hub
uses: docker/login-action@v1
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
# Build the Docker image with the latest tag and the release tag
- name: Build and push Docker image with latest tag
uses: docker/build-push-action@v2
if: github.event.inputs.tag != 'test'
with:
context: .
push: true
tags: uugai/kerberos-documentation:latest
- name: Build and push Docker image with release tag
uses: docker/build-push-action@v2
if: github.event.inputs.tag != 'test'
with:
context: .
push: true
tags: uugai/kerberos-documentation:${{ github.event.inputs.tag || github.ref_name }}
# After we build the Docker image, we create a pull request to update the GitOps repository
# This will allow us to update the Helm chart with the new Docker image tag.
- name: Create GitOps Pull Request
uses: cedricve/gitops-pullrequest-action@master
with:
github-token: ${{ secrets.TOKEN }}
gitops-repo: "uug-ai/gitops"
gitops-file: "environments/staging/doc.kerberos.io/deployment.yaml"
gitops-pr-branch: "release-kerberos-documentation-${{ github.event.inputs.tag || github.ref_name }}"
gitops-key: ".spec.template.spec.containers[0].image"
gitops-value: "uugai/kerberos-documentation:${{ github.event.inputs.tag || github.ref_name }}"
commit-email: "gitops@uug.ai"
commit-name: "GitOps - UUG.AI"
commit-message: "A new release for Kerberos documentation - ${{ github.event.inputs.tag || github.ref_name }}"

View File

@@ -1,37 +0,0 @@
name: github pages
on:
push:
branches:
- master
- develop
pull_request:
jobs:
deploy:
runs-on: ubuntu-18.04
steps:
- uses: actions/checkout@v2
with:
submodules: recursive # Fetch Hugo themes (true OR recursive)
fetch-depth: 1 # Fetch all history for .GitInfo and .Lastmod
- name: Setup Hugo
uses: peaceiris/actions-hugo@v2
with:
hugo-version: 'latest'
extended: true
- name: Install npm packages
run: |
npm install # reads info from package.js
- name: Build
run: hugo --minify --environment production # uses default config/_default/* files + merges with config/production ones
- name: Deploy
uses: peaceiris/actions-gh-pages@v3
if: github.ref == 'refs/heads/move-to-hugo-doks'
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
publish_dir: ./public

19
.github/workflows/pr-description.yml vendored Normal file
View File

@@ -0,0 +1,19 @@
name: Autofill PR description
on: pull_request
jobs:
openai-pr-description:
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@v4
- name: Autofill PR description if empty using OpenAI
uses: cedricve/azureopenai-pr-description@master
with:
github_token: ${{ secrets.TOKEN }}
openai_api_key: ${{ secrets.OPENAI_API_KEY }}
azure_openai_api_key: ${{ secrets.AZURE_OPENAI_API_KEY }}
azure_openai_endpoint: ${{ secrets.AZURE_OPENAI_ENDPOINT }}
azure_openai_version: ${{ secrets.AZURE_OPENAI_VERSION }}
overwrite_description: true

View File

@@ -1,72 +0,0 @@
image: monachus/hugo
variables:
GIT_SUBMODULE_STRATEGY: recursive
ARTIFACT_NAME: documentation
REPO_NAME: kerberos-io/${ARTIFACT_NAME}
REPO_DIR: gitlab.com/${REPO_NAME}
CI_VERSION: "1.0.${CI_PIPELINE_ID}"
DOCKER_HOST: tcp://localhost:2375
NAMESPACE: kerberos
REGISTRY: registry.gitlab.com/kerberos-io/${ARTIFACT_NAME}
stages:
- build-staging # Staging environment -> develop
- build-production # Production environment -> master
- docker # All branches
- kubernetes-staging # Staging environment -> develop
- kubernetes-production # Production environment -> master
build-staging:
image: node:10.22.1
stage: build-staging
script:
- yarn
- yarn run build-staging
artifacts:
paths:
- public
except:
- master
build-production:
image: node:10.22.1
stage: build-production
script:
- yarn
- yarn run build
artifacts:
paths:
- public
only:
- master
docker:
image: docker:stable
stage: docker
services:
- docker:18.09.7-dind
script:
- docker login -u ${gitlab_id} -p ${gitlab_token} $CI_REGISTRY
- docker build --build-arg gitlab_id=${gitlab_id} --build-arg gitlab_token=${gitlab_token} -t $CI_REGISTRY/$REPO_NAME:$CI_VERSION .
- docker push $CI_REGISTRY/$REPO_NAME:$CI_VERSION
kubernetes-staging:
image: registry.cn-hangzhou.aliyuncs.com/haoshuwei24/kubectl:1.16.6
stage: kubernetes-staging
environment:
name: staging
script:
- kubectl patch deployment kerberos-documentation --patch="{\"spec\":{\"template\":{\"spec\":{\"containers\":[{\"name\":\"kerberos-documentation\",\"image\":\"${REGISTRY}:${CI_VERSION}\"}]}}}}" -n kerberos-ecosystem
except:
- master
kubernetes-production:
image: registry.cn-hangzhou.aliyuncs.com/haoshuwei24/kubectl:1.16.6
stage: kubernetes-production
environment:
name: production
script:
- kubectl patch deployment kerberos-documentation --patch="{\"spec\":{\"template\":{\"spec\":{\"containers\":[{\"name\":\"kerberos-documentation\",\"image\":\"${REGISTRY}:${CI_VERSION}\"}]}}}}" -n kerberos-ecosystem
only:
- master

5
.idea/.gitignore generated vendored
View File

@@ -1,5 +0,0 @@
# Default ignored files
/shelf/
/workspace.xml
# Editor-based HTTP Client requests
/httpRequests/

View File

@@ -1,12 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<module type="WEB_MODULE" version="4">
<component name="NewModuleRootManager">
<content url="file://$MODULE_DIR$">
<excludeFolder url="file://$MODULE_DIR$/.tmp" />
<excludeFolder url="file://$MODULE_DIR$/temp" />
<excludeFolder url="file://$MODULE_DIR$/tmp" />
</content>
<orderEntry type="inheritedJdk" />
<orderEntry type="sourceFolder" forTests="false" />
</component>
</module>

4
.idea/encodings.xml generated
View File

@@ -1,4 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="Encoding" addBOMForNewFiles="with NO BOM" />
</project>

View File

@@ -1,6 +0,0 @@
<component name="InspectionProjectProfileManager">
<profile version="1.0">
<option name="myName" value="Project Default" />
<inspection_tool class="Eslint" enabled="true" level="WARNING" enabled_by_default="true" />
</profile>
</component>

6
.idea/misc.xml generated
View File

@@ -1,6 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="JavaScriptSettings">
<option name="languageLevel" value="JSX" />
</component>
</project>

8
.idea/modules.xml generated
View File

@@ -1,8 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="ProjectModuleManager">
<modules>
<module fileurl="file://$PROJECT_DIR$/.idea/documentation.iml" filepath="$PROJECT_DIR$/.idea/documentation.iml" />
</modules>
</component>
</project>

6
.idea/vcs.xml generated
View File

@@ -1,6 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<project version="4">
<component name="VcsDirectoryMappings">
<mapping directory="$PROJECT_DIR$" vcs="Git" />
</component>
</project>

20
.vscode/launch.json vendored Normal file
View File

@@ -0,0 +1,20 @@
{
// Use IntelliSense to learn about possible attributes.
// Hover to view descriptions of existing attributes.
// For more information, visit: https://go.microsoft.com/fwlink/?linkid=830387
"version": "0.2.0",
"configurations": [
{
"name": "Launch via NPM",
"request": "launch",
"runtimeArgs": [
"start"
],
"runtimeExecutable": "npm",
"skipFiles": [
"<node_internals>/**"
],
"type": "node"
}
]
}

BIN
.yarn/install-state.gz Normal file

Binary file not shown.

1
.yarnrc.yml Normal file
View File

@@ -0,0 +1 @@
nodeLinker: node-modules

View File

@@ -1,7 +1,15 @@
FROM node:12.18.3
# Build the documentation website
RUN mkdir -p /app
WORKDIR /app
ADD . /app
RUN yarn && yarn run build
FROM nginx:alpine FROM nginx:alpine
COPY nginx.conf /etc/nginx/nginx.conf COPY nginx.conf /etc/nginx/nginx.conf
COPY public /usr/share/nginx/html COPY --from=0 /app/public /usr/share/nginx/html
EXPOSE 80 EXPOSE 80
CMD ["nginx", "-g", "daemon off;"] CMD ["nginx", "-g", "daemon off;"]

View File

@@ -1,3 +1 @@
docker build -t documentation . docker buildx build --platform linux/amd64 -t kerberos/documentation:1.15 --push .
docker tag documentation kerberos/documentation:1.14
docker push kerberos/documentation:1.14

View File

@@ -1,46 +1,51 @@
[[docs]] [[docs]]
name = "Prologue" name = "Prologue"
weight = 10 weight = 9
identifier = "prologue" identifier = "prologue"
url = "/prologue/" url = "/prologue/"
[[opensource]] [[machinelearning]]
name = "Opensource" name = "Machine learning"
weight = 11 weight = 10
identifier = "opensource" identifier = "machinelearning"
url = "/opensource/" url = "/machinelearning/"
[[agent]] [[agent]]
name = "Agent" name = "Agent"
weight = 12 weight = 11
identifier = "agent" identifier = "agent"
url = "/agent/" url = "/agent/"
[[enterprise]] [[enterprise]]
name = "Enterprise" name = "Enterprise"
weight = 13 weight = 12
identifier = "enterprise" identifier = "enterprise"
url = "/enterprise/" url = "/enterprise/"
[[factory]] [[factory]]
name = "Factory" name = "Factory"
weight = 14 weight = 13
identifier = "factory" identifier = "factory"
url = "/factory/" url = "/factory/"
[[vault]] [[vault]]
name = "Vault" name = "Vault"
weight = 15 weight = 14
identifier = "vault" identifier = "vault"
url = "/vault/" url = "/vault/"
[[hub]] [[hub]]
name = "Hub" name = "Hub"
weight = 16 weight = 15
identifier = "hub" identifier = "hub"
url = "/hub/" url = "/hub/"
[[opensource]]
name = "Open Source (deprecated)"
weight = 16
identifier = "opensource"
url = "/opensource/"
[[main]] [[main]]
name = "Homepage" name = "Homepage"
url = "https://kerberos.io" url = "https://kerberos.io"
@@ -59,6 +64,13 @@
post = "v0.1.0" post = "v0.1.0"
weight = 20 weight = 20
[[social]]
name = "Youtube"
pre = "<svg width=\"29\" height=\"20\" viewBox=\"0 0 29 20\" fill=\"none\" xmlns=\"http://www.w3.org/2000/svg\"><path d=\"M27.311 1.71686C26.2852 0.497419 24.3912 0 20.7742 0H7.64427C3.94443 0 2.01837 0.529505 0.996397 1.82778C0 3.09361 0 4.9587 0 7.54004V12.4601C0 17.4609 1.18222 20 7.64427 20H20.7743C23.911 20 25.6491 19.5611 26.7735 18.4849C27.9267 17.3814 28.4187 15.5795 28.4187 12.4601V7.54004C28.4187 4.8178 28.3416 2.9417 27.311 1.71686ZM18.2449 10.6793L12.2827 13.7954C12.1494 13.865 12.0036 13.8996 11.858 13.8996C11.6932 13.8996 11.5287 13.8552 11.3831 13.767C11.1088 13.6008 10.9413 13.3035 10.9413 12.9829V6.77072C10.9413 6.45059 11.1083 6.15357 11.3821 5.98728C11.6559 5.82098 11.9965 5.80961 12.2806 5.95721L18.2428 9.0532C18.5461 9.21069 18.7366 9.52385 18.7371 9.86552C18.7375 10.2075 18.5478 10.5211 18.2449 10.6793Z\" fill=\"black\"/></svg>"
url = "https://www.youtube.com/channel/UCnd9q7iRNNw4W95eQwQuECA"
post = "v0.1.0"
weight = 30
[[social]] [[social]]
name = "Reddit" name = "Reddit"
pre = "<svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-message-circle\"><path d=\"M21 11.5a8.38 8.38 0 0 1-.9 3.8 8.5 8.5 0 0 1-7.6 4.7 8.38 8.38 0 0 1-3.8-.9L3 21l1.9-5.7a8.38 8.38 0 0 1-.9-3.8 8.5 8.5 0 0 1 4.7-7.6 8.38 8.38 0 0 1 3.8-.9h.5a8.48 8.48 0 0 1 8 8v.5z\"></path></svg>" pre = "<svg xmlns=\"http://www.w3.org/2000/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" class=\"feather feather-message-circle\"><path d=\"M21 11.5a8.38 8.38 0 0 1-.9 3.8 8.5 8.5 0 0 1-7.6 4.7 8.38 8.38 0 0 1-3.8-.9L3 21l1.9-5.7a8.38 8.38 0 0 1-.9-3.8 8.5 8.5 0 0 1 4.7-7.6 8.38 8.38 0 0 1 3.8-.9h.5a8.48 8.48 0 0 1 8 8v.5z\"></path></svg>"
@@ -67,12 +79,12 @@
[[footer]] [[footer]]
name = "Agent" name = "Agent"
url = "https://kerberos.io/product/open-source/" url = "https://kerberos.io/product/agent/"
weight = 10 weight = 10
[[footer]] [[footer]]
name = "Factory" name = "Factory"
url = "https://kerberos.io/product/enterprise-agent/" url = "https://kerberos.io/product/factory/"
weight = 11 weight = 11
[[footer]] [[footer]]

View File

@@ -13,36 +13,54 @@ weight: 100
toc: true toc: true
--- ---
The **Kerberos.io** project, pronounced as `/kuh buh ruhs dot ai o/`, is a video analytics and video management platform, which was initiated back in 2014. Over the years it has evolved into a stable and feature-rich video platform, which is used for management and analytics such as machine learning. The **Kerberos.io** project, pronounced as `/kuh buh ruhs dot ai o/`, is a video analytics and video management platform, which was initiated back in 2014. Over the years it has evolved into a stable and feature-rich video platform, which is used for video management and analytics such as machine learning.
To set the expectations of what is possible and how, it's recommended to have a look [at the architectures page](/prologue/deployments/) to find the best, or most reasonable architecture for your use case. [![An Introduction to Kerberos.io](youtube-introduction-kerberosio.png)](https://www.youtube.com/watch?v=HkMJHCsRd9M "An Introduction to Kerberos.io")
## Kerberos.io Next to being stable and feature-rich, Kerberos.io's main differentiator is scale. It helps you moving from a small home deployment to a large scale enterprise deployment. To illustrate the art of the possible, we recommend to have a look [at the deployments page](/prologue/deployments/) to find out the most suitable architecture for your use case.
Many people are confused, and don't understand why this project is called Kerberos.io. If you've been in the IT world for a while you will notice that Kerberos is already used for the authentication protocol [Kerberos](https://en.wikipedia.org/wiki/Kerberos_(protocol)). ## The name: Kerberos.io
We believe that the name Kerberos.io makes sense for this project as well, with a strong emphasize on the suffix **.io**, which stands for input and output devices (e.g. any type of camera). Kerberos.io can be seen as a kind of security protocol for images and recordings. Many people are confused, and don't understand why this project is called Kerberos.io. If you've been in the IT world for a while you will notice that Kerberos is already used for the authentication protocol [Kerberos](<https://en.wikipedia.org/wiki/Kerberos_(protocol)>).
## Why Kerberos.io After all those years, we still believe that the name Kerberos.io makes sense for this project. With a strong emphasize on the suffix **.IO**, which stands for any **(I) input** of camera, and any **(O) output** such as a webhook, bash script, mqtt, etc. Kerberos itself is keeping an eye, using the configured input, and triggers the required outputs.
Kerberos.io initiated as a side project, due to inspiration and motivation in the space of video analytics, computer vision and machine learning. Its first focus was video surveillance only, as nowadays burglary or attacks are very common in this world.
Due to this, our first mission is to provide every human being on this planet with a solution, a video platform, to protect its families, friends, homes or anything else which you think is important.
Our second mission is to make this video platform affordable and Open Source (MIT), and develop it in such a way, that it's using the latest technologies, to create a seamless, never-seen and delicious user experience.
While we moved forward our third mission is to scale, and make Kerberos reach far beyond a traditional video platform. With the rise of [Kerberos Enterprise Suite](/enterprise/first-things-first), we now focus on large scale deployments (covering thousands of cameras), and video analytics through machine learning.
## What is Kerberos.io ## What is Kerberos.io
Kerberos.io is a video analytics and monitoring platform, that is focussing on both end-consumer and enterprises. It comes with modular solutions to support small deployments, a couple of camera streams and larger deployments, with multiple sites and thousands of camera streams. [Kerberos.io](/prologue/how/) is a video analytics and monitoring platform for everyone, from a traditional user to a multinational corporation, we have different solutions and components to help you grow.
{{< figure src="kerberos-agent-edge.svg" alt="A Kerberos Agent is monitoring a single camera stream." caption="A Kerberos Agent is monitoring a single camera stream." class="stretch">}} Within the portfolio of [Kerberos.io](/prologue/how/) you leverage more or less components depending on the stage you are in, there is no need to overcomplicate things.
With Kerberos.io you start small with one or more [Kerberos Agents](/opensource/first-things-first/), and grow over time while introducing more and more components like [Kerberos Factory](/factory/first-things-first/), [Kerberos Vault](/vault/first-things-first/) and [Kerberos Hub](/hub/first-things-first/), which is also referred to as the [Kerberos Enterprise Suite](/enterprise/first-things-first/). Kerberos.io is shipped through the concept of container technology such as Docker and Kubernetes, and implements the ideas of bring your own cloud, bring your own storage and bring your own technology. {{< figure src="overview.svg" alt="The Kerberos.io solution stack" caption="The Kerberos.io solution stack" class="stretch">}}
{{< figure src="./kerberos-global.svg" alt="A scalable video platform for an ever-growing video landscape." caption="A scalable video platform for an ever-growing video landscape." class="stretch">}} The backbone of the Kerberos.io ecosystem is the [Kerberos Agent](/agent/first-things-first/). This [Kerberos Agent](/agent/first-things-first/), installed [through various possibilities](https://github.com/kerberos-io/agent#how-to-run-and-deploy-a-kerberos-agent), is deployed to a compute - VM, baremetal, Kubernetes cluster or other - of choice and connected to a camera stream you control.
The whole idea is that any solution you will find at Kerberos.io, is extensible and allows you to integrate by default. For example, you decide where to deploy the solutions (edge/cloud/hybrid), what storage you want (edge/cloud/hybrid), how to integrate it with other third-party solutions, etc. Every solution you'll find in the Kerberos.io space, ships Swagger APIs by default, and will allow you to build your own applications or integrations. {{< figure src="introduction-kerberos-io.svg" alt="A Kerberos Agent is monitoring a single camera stream." caption="A Kerberos Agent is monitoring a single camera stream." class="stretch">}}
With [Kerberos.io](/prologue/how/) you start small, with just one or more [Kerberos Agents](/agent/first-things-first/), and grow over time while introducing more and more components like [Kerberos Factory](/factory/first-things-first/), [Kerberos Vault](/vault/first-things-first/) and [Kerberos Hub](/hub/first-things-first/); which we refer to as the [Kerberos Enterprise Suite](/enterprise/first-things-first/). Each solution is shipped through the concept of containers and can be leveraged by using Docker, Docker compose, Kubernetes, OpenShift, Terraform, Ansible, and many more.
{{< figure src="./introduction-enterprise.svg" alt="A scalable video platform for an ever-growing video landscape." caption="A scalable video platform for an ever-growing video landscape." class="stretch">}}
As previously mentioned, the [Kerberos Enterprise Suite](/enterprise/first-things-first) brings additional components into the picture which help you build a more scalable and resilient video landscape through concepts such as Kubernetes, bring you own storage, bring your own cloud, single-pane of glass, live streaming, machine learning, etc.
## Why Kerberos.io
Kerberos.io initiated as a side project, due to inspiration and motivation in the space of video analytics, computer vision and machine learning. Its first focus was video surveillance only, as nowadays burglary and attacks are very common in this world.
Over time we have grown an amazing commmunity, collaborated with lots of international companies and received a lot of kudos for the work we've done. To consolidate our efforts, [we have written down our mission statement](/prologue/mission/), which explains why this projects exists.
## Integration and extension
The majority of video management platforms out there are owned by multinational manufacturers that are building closed systems which are unaccessible in any programmatical way; such as an API. This forces anyone to create unsupported workarounds, which become outdated very quickly.
The whole idea behind Kerberos.io is to challenge previous statement.
> We want open and integratable systems for anyone and anywhere. You generate the data, you own the data.
The response of Kerberos.io is, that any solution you'll find in our portfolio allows you to integrate and extend by default, no workaround, the data belongs to you. We expose Swagger APIs by default, to extract all the data you desire.
You decide where (cloud, self-hosted) and how (Docker, Kubernetes, OpenShift, Terraform, etc) to deploy our solutions, what storage you prefer (local SSE, S3, etc) and how to integrate it with other third-party solutions (Kafka, SQS, etc).
## Machine learning
Machine learning and Artificial Intelligence is a critical component of the Kerberos.io ecosystem. Within Kerberos Vault you can integrate your own machine learning models, and run them at scale. [Learn more about how we support](/vault/machine-learning/) machine learning use cases. Machine learning and Artificial Intelligence is a critical component of the Kerberos.io ecosystem. Within Kerberos Vault you can integrate your own machine learning models, and run them at scale. [Learn more about how we support](/vault/machine-learning/) machine learning use cases.

View File

@@ -1,53 +0,0 @@
---
title: "Announcement"
description: "A Kerberos Agent with more features, better performance, and great UX."
lead: "A Kerberos Agent with more features, better performance, and great UX."
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
agent:
parent: "agent"
weight: 300
toc: true
---
Kerberos Agent is the next generation of Kerberos.io, and is the successor of Kerberos Open Source (v1/v2). More specifically it will replace and merge the [machinery](https://github.com/kerberos-io/machinery) and [web](https://github.com/kerberos-io/web) repositories. A switch in technologies and architecture has been made. Kerberos Agent is still under active development, and not yet released. The progress can be followed at the [develop branch](https://github.com/kerberos-io/opensource/tree/develop) and [project overview](https://github.com/kerberos-io/opensource/projects/1).
## What is changing?
Bottom line, we are rebuilding the project from scratch using a different technology stack. We are saying goodbye to C++, PHP (Laravel), BackboneJS and saying hello to Golang and React. Despite the technology changes, we are also changing the architecture which was put in place a couple of years ago. The biggest change is to run the show inside a single repository, and no longer over seperate repos (machinery and web). Read more about this in the FAQ.
{{< figure src="opensource-to-agent.svg" alt="The Kerberos Agent is a complete new rewrite of the Kerberos Open Source version 1 and 2." caption="The Kerberos Agent is a complete new rewrite of the Kerberos Open Source version 1 and 2." class="stretch">}}
## FAQ
### 1. Why a mono repo?
We have noticed in the past (v1 and v2) that splitting the repositories (machinery and web), created a lot of confusion within our community. People didn't understand the different versions and so on. This caused a lack of collaboration, and made it impossible for some people to collaborate and contribute.
Having a mono repo, which is well-organised, simplifies the entry point for new people who would like to use, understand and/or contribute to Kerberos Agent.
### 2. Why a change in technologies?
In previous versions (v1 and v2) we used technologies like C++, PHP and BackboneJS. 7 years ago this was still acceptable, however time has changed and new technologies such as React and Golang became very popular.
Due to previous reason we have decided to rebuild the Kerberos Open Source technology from scratch, taking into account all the feedback we acquired over the years. Having these technologies available, we will enable more people to contribute and use our technology.
### 3. How is the Kerberos Enterprise Suite involved?
We started the developments of the Kerberos Enterprise Suite a year ago (January, 2020), our focus here was scalability, fast development and easy deployment. We noticed that with technologies such as Golang and React, we can still provide a highly performant video surveillance system.
The Kerberos Agent which is currently part of the Kerberos Enterprise Suite will be open sourced and become the one and only engine for video stream capturing, motion detection, etc.
The Kerberos Agent will be used both in the open source as the B2B communities. Other solutions such as Factory, Vault and Hub will be made available through different licensing.
### 4. When are we going to be able to install the first version?
We plan to ship the **first version by the end of Q1**, afterwards we will add more and more features as usual.
### 5. Change in License
Kerberos Agent is now available under the MIT license.

File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 81 KiB

File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 77 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 124 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 107 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 117 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 169 KiB

View File

@@ -0,0 +1,30 @@
---
title: "Encryption"
description: "End-to-end encryption to keep your recordings secure."
lead: "End-to-end encryption to keep your recordings secure."
date: 2023-04-09T21:45:00+00:00
lastmod: 2023-04-09T21:45:00+00:00
draft: true
images: []
menu:
agent:
parent: "agent"
weight: 204
toc: true
---
Kerberos Agent main goal is to make recordings and store them somewhere so you can access them. Next to "just" storing them, storing them securely is even more important, due to these we have integrated different levels of security in the Kerberos.io stack.
![Encryption diagram](./encryption.svg)
## Encryption from Kerberos Agent to Kerberos Vault
![Encryption Kerberos Agent to Kerberos Vault](./encryption-agent-vault.svg)
## Decryption from Kerberos Vault to Kerberos Hub
![Encryption Kerberos Vault to Kerberos Hub](./encryption-vault-hub.svg)
## Encryption from Kerberos Agent to Kerberos Hub
![Encryption Kerberos Agent to Kerberos Hub](./encryption-agent-hub.svg)

View File

@@ -0,0 +1,28 @@
---
title: "First things first"
description: "An agent with a mind for scale"
lead: "An agent with a mind for scale"
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
agent:
parent: "agent"
weight: 201
toc: true
---
The Kerberos Agent is an isolated and scalable video management agent with a strong focus on user experience, scalability, resilience, extension and integration. It is the backbone of the entire Kerberos.io ecosystem, and is used as a foundation for small deployments to production level deployments with thousands of cameras.
Next to the Kerberos Agent, Kerberos.io provides many other tools such as [Kerberos Factory](/factory/first-things-first), [Kerberos Vault](/vault/first-things-first) and [Kerberos Hub](/hub/first-things-first) to provide additional capabilities: bring your own cloud, bring your own storage, central overview, live streaming, machine learning etc.
As [explained before](/prologue/how/), there is no need to install all those components from the start. Usually you just start with a few Kerberos Agents, scale over time, and add additional components to support additional use cases.
## Introduction
So by now you'll understand that Kerberos.io [applies the concept of agents](/prologue/how/). An agent is running next to (or on) your camera, and is processing a single camera feed. It applies motion based or continuous recording and make those recordings available through a user friendly web interface. A Kerberos Agent allows you to connect to other cloud services or integrates with custom applications.
![Kerberos Agent overview](kerberos-agent-overview.gif)
We'll provide a more detailed explanation of the Kerberos Agent, but it's important to know that the [Kerberos Agent GitHub repository](https://github.com/kerberos-io/agent) contains the most accurate and latest information. You can find [a brief list of features and functions here](https://github.com/kerberos-io/agent#a-world-of-kerberos-agents).

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.0 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 866 KiB

View File

@@ -0,0 +1,54 @@
---
title: "Getting Started"
description: ""
lead: ""
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
agent:
parent: "agent"
weight: 202
toc: true
---
Once you've installed one ore more Kerberos Agents, you should have access to the Kerberos Agent user interface. The interface allows you to interact with the Kerberos Agent, and more specifically configure the camera stream, setup a cloud connection, watch recordings and live views, etc.
Having a UI in place, it is important to note that Kerberos Agent also ships numerous APIs, that allow you to automate the configuration. The APIs are exposed as, Swagger documentation, and can be used for configuration of Kerberos Agent but also development of custom applications or business logic.
## Login page
Once you open a browser, and navigate to the Kerberos Agent user app (see installation for the URL), you will land on the login page.
{{< figure src="login.gif" alt="After successful installation you should be able to access the login page." caption="After successful installation you should be able to access the login page." class="stretch">}}
The default username and password of the Kerberos Agent app is:
- username: **root**
- password: **root**
> The username and password can be changed [by setting an environment variable](https://github.com/kerberos-io/agent#configure-with-environment-variables).
## Dashboard
On the dashboard page, you'll find a summary of the most relevant information and insights.
{{< figure src="dashboard.gif" alt="All relevant information on a single pane of glass" caption="All relevant information on a single pane of glass" class="stretch">}}
## Media
At the media page you'll find all your past and future recordings. It shows the recordings in a latest to oldest view and allowxs you to filter and browse through your recordings.
{{< figure src="media.gif" alt="All your recordings in a single place." caption="All your recordings in a single place." class="stretch">}}
## Settings
The settings page allows you to modify the Kerberos Agent configuration. While configuring you will find different settings such as:
- general (name, timezone, etc)
- camera (which main stream and/or sub stream)
- streaming
- persistence
{{< figure src="settings.gif" alt="Configure your Kerberos Agent." caption="Configure your Kerberos Agent." class="stretch">}}

Binary file not shown.

After

Width:  |  Height:  |  Size: 1012 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 136 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.4 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 520 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 245 KiB

View File

@@ -0,0 +1,27 @@
---
title: "Installation"
description: "Run Kerberos Agents everywhere"
lead: "Run Kerberos Agents everywhere"
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
agent:
parent: "agent"
weight: 202
toc: true
---
As described before a Kerberos Agent is a container, which can be deployed through various ways and automation tools such as docker, docker compose, kubernetes and the list goes on. To simplify your life we have come with concrete and working examples of deployments to help you speed up your Kerberos.io journey.
We have documented the different deployment models in the [Kerberos Agent GitHub repository](https://github.com/kerberos-io/agent/tree/master/deployments). There you'll learn and find how to deploy using:
- [Docker](https://github.com/kerberos-io/agent/tree/master/deployments#1-docker)
- [Docker Compose](https://github.com/kerberos-io/agent/tree/master/deployments#2-docker-compose)
- [Kubernetes](https://github.com/kerberos-io/agent/tree/master/deployments#3-kubernetes)
- [Red Hat OpenShift with Ansible](https://github.com/kerberos-io/agent/tree/master/deployments#4-red-hat-ansible-and-openshift)
- [Terraform](https://github.com/kerberos-io/agent/tree/master/deployments#5-terraform)
- [Salt](https://github.com/kerberos-io/agent/tree/master/deployments#6-salt)
By default your Kerberos Agents will store all its configuration and recordings inside the container. To help you automate and have a more consistent data governance, you can [attach volumes](https://github.com/kerberos-io/agent#configure-and-persist-with-volume-mounts) to configure and persist data of your Kerberos Agents, and/or configure each Kerberos Agent [through environment variables](https://github.com/kerberos-io/agent#configure-with-environment-variables).

View File

@@ -15,7 +15,9 @@ toc: true
Kerberos Enterprise Suite is a consequence of supporting enterprises and customers for more than 7 years in the video analytics and video streaming industry. Kerberos Enterprise Suite is a collection of best practices supporting the ever-growing needs of enterprises rolling out huge amounts of video streams, requiring extreme flexibility in terms of deployment and customization, and putting strong focus on video analytics and more specific machine learning and AI. Kerberos Enterprise Suite is a consequence of supporting enterprises and customers for more than 7 years in the video analytics and video streaming industry. Kerberos Enterprise Suite is a collection of best practices supporting the ever-growing needs of enterprises rolling out huge amounts of video streams, requiring extreme flexibility in terms of deployment and customization, and putting strong focus on video analytics and more specific machine learning and AI.
As a result to the developments of the Kerberos Agent, previously called Kerberos Open Source, the Kerberos Enterprise Suite is here to enable more flexibility through concepts such as Bring Your Own Cloud, Bring Your Own Storage and Bring Your Own Technology. [![An end-to-end scenario with Kerberos.io Enterprise Suite](youtube-end-to-end.png)](https://www.youtube.com/watch?v=OnmN99dq4tk "An end-to-end scenario with Kerberos.io Enterprise Suite")
As a result to the developments of the Kerberos Agent, previously called Kerberos Open Source, the Kerberos Enterprise Suite is here to enable more flexibility through concepts such as Bring Your Own Cloud, Bring Your Own Storage and Bring Your Own Technology.
Kerberos Enterprise Suite is taking the Kerberos Agent to another level, by building additional tools on top such as [Kerberos Vault](/vault/first-things-first) and [Kerberos Hub](/vault/first-things-first). It scales your Kerberos Agents through the concept of [Kerberos Factory](/factory/first-things-first) which helps to deploy your Kerberos Agents in bulk. Kerberos Enterprise Suite is taking the Kerberos Agent to another level, by building additional tools on top such as [Kerberos Vault](/vault/first-things-first) and [Kerberos Hub](/vault/first-things-first). It scales your Kerberos Agents through the concept of [Kerberos Factory](/factory/first-things-first) which helps to deploy your Kerberos Agents in bulk.
@@ -25,7 +27,7 @@ Kubernetes is a proven, and a widely spread technology which is gaining more mom
{{< figure src="kubernetes-enterprise.svg" alt="" caption="" class="stretch">}} {{< figure src="kubernetes-enterprise.svg" alt="" caption="" class="stretch">}}
Kubernetes sits at the center of the Kerberos Enterprise Suite. Every solution within the suite is build on top of Kubernetes, so it allows you to bring your own cloud, bring your own storage and bring your own technology. Kubernetes sits at the center of the Kerberos Enterprise Suite. Every solution within the suite is build on top of Kubernetes, so it allows you to bring your own cloud, bring your own storage and bring your own technology.
### Bring your own cloud ### Bring your own cloud
@@ -37,7 +39,7 @@ One thing you don't want, is to store your most precious data on someone else st
### Bring your own technology ### Bring your own technology
Kubernetes brings a lot of advantages in terms of deployment, scalability, resilience, and also high availability, but there is more. Due to the nature of Kubernetes, enterprises and administrators can bring any tool, service, solution or application inside their cluster. As the Kubernetes Enterprise Suite has specific dependencies, there is no need to install already existing tools, but you can reuse the ones you already have. Kubernetes brings a lot of advantages in terms of deployment, scalability, resilience, and also high availability, but there is more. Due to the nature of Kubernetes, enterprises and administrators can bring any tool, service, solution or application inside their cluster. As the Kubernetes Enterprise Suite has specific dependencies, there is no need to install already existing tools, but you can reuse the ones you already have.
Next to that, all solutions within the Kerberos Enterprise Suite ships Swagger APIs by default. This allows you to extend or integrate your own solutions or extend them with the technology you already master or prefer within your organisation. Next to that, all solutions within the Kerberos Enterprise Suite ships Swagger APIs by default. This allows you to extend or integrate your own solutions or extend them with the technology you already master or prefer within your organisation.
@@ -51,7 +53,7 @@ The Kerberos Enterprise Suite is a collection of modular solutions that can be d
### Kerberos Agents and Kerberos Factory ### Kerberos Agents and Kerberos Factory
An agent is deployed for each video stream. An agent is responsible for a specific video stream: recording, livestreaming and alerting. Kerberos Factory is used to scale and deploy the Kerberos Agents in your Kubernetes clusters by providing a UI. An agent is deployed for each video stream. An agent is responsible for a specific video stream: recording, livestreaming and alerting. Kerberos Factory is used to scale and deploy the Kerberos Agents in your Kubernetes clusters by providing a UI.
{{< figure src="kerberos-enterprise-suite.svg" alt="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." caption="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." class="stretch">}} {{< figure src="kerberos-enterprise-suite.svg" alt="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." caption="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." class="stretch">}}
@@ -67,7 +69,7 @@ Events and messages [are sent through integrations](/vault/integrations/) to ini
### Kerberos Hub ### Kerberos Hub
[Kerberos Hub](/vault/first-things-first) is a scale UI that consolidates the entire Kerberos ecosystem. It shows livestreams/alerts from your Kerberos Agents and recordings stored in Kerberos Vault through a single pane of glass. [Kerberos Hub](/vault/first-things-first) is a scale UI that consolidates the entire Kerberos ecosystem. It shows livestreams/alerts from your Kerberos Agents and recordings stored in Kerberos Vault through a single pane of glass.
[Kerberos Hub](/vault/first-things-first) is build out of modular and scalable microservices which you can install and scale independently, wherever you want. [Kerberos Hub](/vault/first-things-first) is build out of modular and scalable microservices which you can install and scale independently, wherever you want.

Binary file not shown.

After

Width:  |  Height:  |  Size: 539 KiB

View File

@@ -0,0 +1,64 @@
---
title: "Self-signed certificates"
description: "Using your own self-signed certifates."
lead: "Using your own self-signed certifates."
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
enterprise:
parent: "enterprise"
weight: 302
toc: true
---
When running an edge deployment for Kerberos Factory, Kerberos Vault, Kerberos Hub and/or your storage providers, you can enhance security by bringing your own self-signed certificates. Those certificates will be consumed to create a secure connection between the different applications, and for example encrypt your data while it's being send or retrieved from your storage provider (Minio, Ceph).
When using self-signed certificates, the different deployments needs to be aware of those certificates and more importantly trust them. To achieve this trust, traditionally you would benefit from services like Certmanager.io and LetsEncrypt which act as a trusted CA (Certification Authority). However when self-signing you will need to make your deployments aware as there is probably no public CA available.
## The issue
When using self-signed certificates you might experience the following errors.
"level":"info","msg":"Upload Failed: Post
\"https://vault.xxx.xxx/storage\": x509: certificate signed by unknown
authority","time":"2022-01-06T14:17:07Z"}
To overcome this you will need to inject a custom `ca-certificates.crt` holding your self-signed certificate in the `/etc/ssl/certs` directory. By injecting this in your Kerberos Factory, Kerberos Vault, Kerberos Hub deployments you will be able to create a secured and trusted connection over SSL with all relevant services.
## Injecting a ca-certificates.crt
Start by collecting all certificates you want to have trusted, and append them to an existing `ca-certificates.crt` file. Once done, create a `configmap` in your cluster, holding that information.
kubectl create configmap rootcerts -n kerberos-vault --from-file=./ca-certificates.crt
By creating the configmap, the file contents of your `ca-certificates.crt` will be loaded into a specific namespace in your cluster, and you will be able to attach it to a specific deployment.
## Kerberos Agent
To inject your certificates file into your Kerberos Agents, you'll need to make Kerberos Factory aware of the configmap `rootcerts` that holds the certificate file. Go to your relevant `deployment.yaml` file and specify the name of your configmap in `CERTIFICATES_CONFIGMAP` variable.
- name: CERTIFICATES_CONFIGMAP
value: "rootcerts"
This will include and override the existing `ca-certificates.crt` file and include your self-signed certificates in the Kerberos Agent deployments. Once done, your Kerberos Agents will benefit from a secure self-signed SSL connection.
## Kerberos Factory / Vault
As Kerberos Factory and Kerberos Vault are specified as a single deployment file, you can inject the configmap directly in the `deployment.yaml` file. Go and uncomment the `volumes` and `volumeMounts` sections. This will copy the configmap into your Kerberos Factory and/or Kerberos Vault deployments.
# Injecting the ca-certificates inside the container.
volumeMounts:
- name: rootcerts
mountPath: /etc/ssl/certs/ca-certificates.crt
subPath: ca-certificates.crt
Also uncomment the relevant volume definition.
volumes:
- name: rootcerts
configMap:
name: rootcerts

Binary file not shown.

After

Width:  |  Height:  |  Size: 402 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 485 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 116 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 480 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 509 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 491 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 144 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 517 KiB

View File

@@ -0,0 +1,224 @@
---
title: "Welcome"
description: "Configuring the Kerberos Enterprise Suite"
lead: "Configuring the Kerberos Enterprise Suite"
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
enterprise:
parent: "enterprise"
weight: 301
toc: true
---
Welcome to our family! This page will explain and showcase how to connect and configure the Kerberos Enterprise Suite. We will go through some configuration steps, so your data will flow from your Kerberos Factory and Kerberos Agents to Kerberos Vault to Kerberos Hub. What are we waiting for, let's go.
## Prerequisites
This section expects you have a working setup with all components installed; Kerberos Factory, Kerberos Vault and Kerberos Hub.
Typically you will host Kerberos Factory (including the Kerberos Agents) and Kerberos Vault on your side and leverage the Kerberos Hub SAAS environment. However nothing stops you in hosting all yourself, or only be in charge of the Kerberos Factory and let us handle Kerberos Vault and Kerberos Hub in a private installation.
## The Architecture
Everything starts at your Kerberos Agent. The agents are connected to camera streams (RTSP) and depending on the configuration they might record videos and store them locally on their local disk.
To get those recordings in a central storage like S3, Storj, Ceph, Minio or any other compatible S3 storage we will leverage the Kerberos Vault solution.
Once recordings are entering in the underlaying central storage an event is send to Kerberos Hub through a message broker like SQS or Kafka. The event is parsed and passed-through different microservices. Each microservice will perform a specific action on the recording varying from generating metadata to machine learning and computer vision.
Once done navigating through the different microservices the recording will become available in Kerberos Hub. Within Kerberos Hub you will able to view livestreams from your Kerberos Agents, create alerts and more.
![Kerberos Enterprise Suite](./kerberos-enterprise-architecture.svg)
## Kerberos Hub
Ok let's start! Before we can continue we will need to gather some information, which we will use in the next sections to configure and setup the different solutions and integrations properly.
Once you have your Kerberos Hub installed, or you have purchased a subscription on our Kerberos Hub SAAS, you will need following information:
- Username
- Public access key
- Private key (only with a subscription on Kerberos SAAS)
- Kerberos Hub API url (you retrieve this by opening the Swagger API docs in the left navigation)
You will find those details on the `Plans & Integrations` page of your Kerberos Hub installation. Use your username and password to sign into Kerberos Hub and navigate to the `Plans & Integrations` page.
![Public key](./publickey.png)
Next to the Kerberos Hub information we will also need details from other components that make up the Kerberos Enterprise Suite. We will need credentials from our MQTT broker, TURN server and Kafka broker. While moving forward we will configure Kerberos Vault and our Kerberos Factory and Kerberos Agents. We will come back at our Kerberos Hub application for a last minimal configuration step, but let's move forward for now.
![Kerberos Hub and components](./kerberos-hub-architecture-with-comp.svg)
### MQTT
To communicate with your Kerberos Agents across different networks, a MQTT broker is required. If you are using our Kerberos Hub SAAS edition you can leverage following MQTT broker:
- tcp: `tcp://mqtt.kerberos.io:1883`
When running a self-hosted Kerberos Hub, make sure you have properly installed the MQTT broker (Vernemq) [by following the Kerberos Hub installation (Helm chart)](https://github.com/kerberos-io/hub#vernemq). [The default credentials](https://github.com/kerberos-io/hub/blob/master/vernemq/values.yaml) will look like this:
- tcp: `tcp://mqtt.domain.com:1883`
- wss: `wss://mqtt.domain.com:8443`
- username: `yourusername`
- password: `yourpassword`
If you are running a private edition of Kerberos Hub managed by the Kerberos.io team you will receive above information as part of the license contract.
### Kafka (optional)
Within Kerberos Hub we are leveraging multiple microservices which are tied a scalable message broker Kafka. As part of your installation you will be required [to setup a Kafka broker in your Kubernetes cluster](https://github.com/kerberos-io/hub#kafka). As we will show later, Kafka will be added as an integration in Kerberos Vault to push an event into Kafka everytime a recording is stored in the underlaying storage system. [The default credentials](https://github.com/kerberos-io/hub/blob/master/kafka/values.yaml) will look like this:
- host: `kafka1.domain.com:9094,kafka2.domain.com:9094`
- group: `mygroup`
- username: `Yourusername`
- password: `Yourpassword`
- mechanism: `PLAIN`
- security: `SASL_PLAINTEXT`
- topic: `kcloud-event-queue`
If you are running a private edition of Kerberos Hub managed by the Kerberos.io team you will receive above information as part of the license contract. If you have purchased a Kerberos Hub SAAS subscription you can integrate with Kerberos Hub directly using your access keys, so no need to configure Kafka.
To debug your Kafka broker, and validate the connection is working we recommend to install [the Offset Explorer client](https://www.kafkatool.com/). This will give you more insights of what is happening inside Kafka. Next to that it is also possible to use Prometheus and Grafana to have a more consolidated and graphical view.
When setting up the Offset Explorer, you can use following configuration to setup your connection.
- Cluster name: a name of own choice
- Zookeeper Host: leave empty
- Zookeeper Port: leave empty
- Security: `SASL Plaintext`
- Advanced > Bootstrap servers: `kafka1.domain.com:9094,kafka2.domain.com:9094`
- SASL Mechanism: `PLAIN`
- JAAS Config: `org.apache.kafka.common.security.plain.PlainLoginModule required username="Yourusername" password="Yourpassword";`
### TURN server
A TURN server is required for high definition live streaming, by default only a low resolution is provided while using the MQTT broker. When using our Kerberos Hub SAAS edition you can use following information:
- stun: `stun:stun.l.google.com:19302`
- turn: `turn:turn.kerberos.io:8443`
- username: `username1`
- password: `password1`
When running a self-hosted installation you should make sure to have your TURN server configured on a stand-alone virtual machine. More information how to run our TURN server in a Docker container, [can be found here](https://github.com/kerberos-io/turn-and-stun).
If you are running a private edition of Kerberos Hub managed by the Kerberos.io team you will receive above information as part of the license contract.
## Kerberos Vault
Once we have above information we can start by setting up our Kerberos Vault, create storage provider and create an integration with our Kerberos Hub.
![Kerberos Vault and components](./kerberos-vault-architecture.svg)
### Storage Provider
Before starting you should have made a decision where you want to have your recordings stored. At the moment of writing we are supporting all S3 compliant providers such as: S3, Minio, Storj, Ceph, etc and Google Cloud Storage as well. To get a better understanding of how to setup and configure your storage provider [have a look at our providers page in the Kerberos Vault section](/vault/providers).
![Storage provider](./storage-provider.png)
### Integration
Once you have your storage provider setup, we can create our integration, using the credentials we gather in previous section. We have different integrations to hook up Kerberos Vault to Kerberos Hub. The first one is a direct integration with the Kafka broker and the second one is through the Kerberos Hub API. You will only need one integration so you can choose one of them.
![Integrate Kerberos Vault with Kerberos Hub](./integrations.png)
#### a. Kafka integration (self-hosted or private)
The most efficient is to integrate directly with Kafka, using the credentials we gather in previous section. On the integrations page of Kerberos Vault [you will find more information of how to configure](/vault/integrations/#kafka) and setup the Kafka integration. Make sure that you validate the connection.
Once testing the Kafka integration, you should see a message published in your Kafka broker. You can validate either by using Offset Explorer or Prometheus when having metrics enabled in the Helm chart.
#### b. Kerberos Hub integration
If you have purchase a Kerberos Hub SAAS subscription or you don't like to use the Kafka integration you can leverage the Kerberos Hub integration. Under the hood it will still use Kafka to distribute to the different microservices. The advantage of the Kerberos Hub integration is that it will hide the Kafka configuration for you, or in the case of the Hub SAAS subscription not available to you at all.
You will find more information about [the Kerberos Hub integration here](/vault/integrations/#kerberos-hub).
### Account creation
To finish the Kerberos Vault installation we will need to create a security account so that both our Kerberos Agents and Kerberos Hub can connect to Kerberos Vault, for publishing new recordings and retrieving them for displaying in the Kerberos Hub interface.
![Create an account and credentials](./accounts.png)
[Follow the accounts page in the Kerberos Vault section](vault/accounts/) to create a security account and retrieve some credentials. Important is to enable Cloud Analysis and leave Edge analysis disabled for a default installation. Once done we will collect following informations:
- Account name
- Access key
- Secret key
- Kerberos Vault API url (you retrieve this by opening the Swagger API docs in the left navigation)
We are done here, you know have setup your Kerberos Vault and linked it to Kerberos Hub. Next we will configure our Kerberos Agents and Kerberos Factory so that they will store recordings into your storage provider and trigger an event in Kerberos Hub so you will be able to see your recordings in a single pane of glass.
## Kerberos Factory
Yes, we are ready to hook up our Kerberos Factory and Kerberos Agents to Kerberos Vault and Kerberos Hub, so finally we are able to view some recordings. Let's get started.
![Kerberos Factory and components](./kerberos-factory-architecture.svg)
When running the stand-alone agent go to the settings page of your Kerberos Agent, when running Kerberos Factory go to your Kerberos Factory portal and navigate to the Global settings. We will focus on Kerberos Factory for now as Kerberos Agent is similar but easier.
![Global settings](./global-settings.png)
### MQTT
Search for the MQTT settings, and enter the MQTT settings you've collected in the first step.
![MQTT settings](./mqtt-settings.png)
### TURN
If you want to retrieve HD streams, configure the TURN settings in your Kerberos Factory or Kerberos Agent. You can use a google STUN server or also add your own.
![TURN settings](./turn-settings.png)
### Kerberos Hub
To connect your Kerberos Agent to your Kerberos Hub account, you'll need to provide the `API url` and `public key` that belongs to your Kerberos Hub account. Once provided your Kerberos Agents will start sending heartbeats to Kerberos Hub and your account, after a few seconds your agents should show up.
![Kerberos Hub settings](./hub-settings.png)
### Kerberos Vault
To have your recordings stored in Kerberos Vault, you'll need to setup the persistence settings. Select Kerberos Vault from the dropdown, and provide the credentials from your Kerberos Vault account.
![Kerberos Vault settings](./persistence-settings.png)
When everything works out you should see your Kerberos Agent popping up in the cameras section of your Kerberos Vault.
![Kerberos Agents connected to Kerberos Vault](./vault-cameras.png)
From now one all recordings made by your Kerberos Agents will also be send to Kerberos Vault and stored on the underlaying storage provider. On the media page you should see some recordings popping up.
![Kerberos Agents recordings send to Kerberos Vault](./vault-media.png)
## Kerberos Agents
When using a stand-alone Kerberos Agent, without Kerberos Factory, you want to follow the same configuration as described previous section; Kerberos Factory.
For Kerberos Factory, you have the option to override your global settings at Kerberos Agent level. You do this by opening the `Edit` option of your Kerberos Agent. Within this modal you are able to change and override specific settings.
![Override settings in Kerberos Agent](./factory-edit-agent.png)
## Wrapping up
Hurray, we're almost ready. You should now see recordings popping up in your storage provider and Kerberos Vault. Next to that you should already see some Kerberos Agents on the cameras page of Kerberos Hub, and also recordings coming into the media page.
![Kerberos Agents connected to Kerberos Hub](./hub-cameras.png)
Before closing, this a last configuration is required in Kerberos Hub. At this stage everything is connected integrated, expect Kerberos Hub and Kerberos Vault. We have added an integration from Kerberos Vault to Kerberos Hub, but not from Kerberos Hub to Kerberos Vault.
![Kerberos Enterprise Suite](./kerberos-enterprise-architecture.svg)
You might wonder why? Well, next to sending a message from Kerberos Vault to Kerberos Hub to announce a new recording was stored, Kerberos Hub also need to permissions to visualises recordings managed by Kerberos Vault. Without these credentials Kerberos Hub will not be able to show any recording, and any microservices included in Kerberos Hub will be able to access the recordings. The main reason for this is security.
To fix this go and sign into your Kerberos Hub account; make sure you have the `owner` role. Navigate to the `Plans & Integrations` page, and scroll down until you see the Kerberos Vault section.
![Connect Kerberos Hub to your Kerberos Vault](./hub-vault-settings.png)
Add the `api url` of your Kerberos Vault and `access key` and `secret key` of your Kerberos Vault account. Verify connection and update your settings. Once done successfully navigate to the media page, and you should see your recordings popping up.
![Kerberos Hub media page](./hub-media.png)
Congrats you made it!

Binary file not shown.

After

Width:  |  Height:  |  Size: 367 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 62 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 91 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 116 KiB

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 113 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 227 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 422 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 446 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 114 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 421 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 159 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 412 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 496 KiB

View File

@@ -13,13 +13,18 @@ weight: 300
toc: true toc: true
--- ---
[![Scale your video landscape with Kerberos Factory
](youtube-factory-kerberosio.png)](https://www.youtube.com/watch?v=uMv_6cubq6I "Scale your video landscape with Kerberos Factory")
<br/>
Kerberos Factory brings the Kerberos Agent to another level. The Kerberos Agent can be deployed anywhere you want, it can run as a binary, Docker container and inside a Kubernetes cluster. The latter is where Kerberos Factory shines, it is a UI that allows you to deploy and configure your Kerberos Agents into your Kubernetes cluster more easily. Kerberos Factory brings the Kerberos Agent to another level. The Kerberos Agent can be deployed anywhere you want, it can run as a binary, Docker container and inside a Kubernetes cluster. The latter is where Kerberos Factory shines, it is a UI that allows you to deploy and configure your Kerberos Agents into your Kubernetes cluster more easily.
{{< figure src="kerberos-enterprise-suite.svg" alt="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." caption="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." class="stretch">}} {{< figure src="introduction-enterprise.svg" alt="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." caption="Kerberos Enterprise Suite contains Kerberos Agent, Kerberos Factory, Kerberos Vault and Kerberos Hub." class="stretch">}}
## Kerberos Factory in a nutshell ## Kerberos Factory in a nutshell
Kerberos Factory is a front-end that consumes and interacts with the Kubernetes API. It schedules Kerberos Agents as Kubernetes resource, and more specific `deployments`. For every camera stream a Kerberos Agent is created as a Kubernetes deployment. Kerberos Factory is a front-end that consumes and interacts with the Kubernetes API. It schedules Kerberos Agents as Kubernetes resource, and more specific `deployments`. For every camera stream a Kerberos Agent is created as a Kubernetes deployment.
Through the front-end an administrator can configure or add more Kerberos Agents to the cluster. The administrator has the ability to interact with the Kerberos Agent through one or more configuration screens, to tune and optimize the Kerberos Agent. Through the front-end an administrator can configure or add more Kerberos Agents to the cluster. The administrator has the ability to interact with the Kerberos Agent through one or more configuration screens, to tune and optimize the Kerberos Agent.

File diff suppressed because one or more lines are too long

After

Width:  |  Height:  |  Size: 164 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.6 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 853 KiB

View File

@@ -1,7 +1,7 @@
--- ---
title: "Getting Started" title: "Getting Started"
description: "What to expect from the Kerberos Factory." description: "What to expect from Kerberos Factory"
lead: "What to expect from the Kerberos Factory." lead: "What to expect from Kerberos Factory"
date: 2020-10-06T08:49:31+00:00 date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00 lastmod: 2020-10-06T08:49:31+00:00
draft: false draft: false
@@ -13,7 +13,6 @@ weight: 301
toc: true toc: true
--- ---
Once you've installed Kerberos Factory, you will have the web application running inside your cluster. This web application allows you to administrate and automate the creation of your Kerberos Agents through the concept of [Kubernetes deployments](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) and pods. Once you've installed Kerberos Factory, you will have the web application running inside your cluster. This web application allows you to administrate and automate the creation of your Kerberos Agents through the concept of [Kubernetes deployments](https://kubernetes.io/docs/concepts/workloads/controllers/deployment/) and pods.
Important to note is that this web application is relying [on the official Golang Kubernetes API](https://github.com/kubernetes/client-go), so that means from an administration point of view, you could simply use the well known `kubectl` command instead. The web application adds some functionalities on top of the Kubernetes API, which are specific to a Kerberos Agent; for example region of interests, livestreaming settings, etc. Important to note is that this web application is relying [on the official Golang Kubernetes API](https://github.com/kubernetes/client-go), so that means from an administration point of view, you could simply use the well known `kubectl` command instead. The web application adds some functionalities on top of the Kubernetes API, which are specific to a Kerberos Agent; for example region of interests, livestreaming settings, etc.
@@ -35,7 +34,7 @@ The default username password, specified in the [`deployment.yaml`](https://gith
On the overview page you will find an intuitive overview of the different pages and functionalities. As Kerberos Factory is running on top of a Kubernetes cluster, Kerberos Agents are deployed as Kubernetes deployments. On the overview page you will find an intuitive overview of the different pages and functionalities. As Kerberos Factory is running on top of a Kubernetes cluster, Kerberos Agents are deployed as Kubernetes deployments.
Kerberos Factory allows you to inspect and configure your Kerberos Agents, but also provide an overview of the Kubernetes nodes and pods. Kerberos Factory allows you to inspect and configure your Kerberos Agents, but also provide an overview of the Kubernetes nodes and pods.
{{< figure src="overview.gif" alt="Review your Docker or Kubernetes agents." caption="Review your Docker or Kubernetes agents." class="stretch">}} {{< figure src="overview.gif" alt="Review your Docker or Kubernetes agents." caption="Review your Docker or Kubernetes agents." class="stretch">}}
@@ -60,10 +59,20 @@ The cameras section will list all the Kerberos Agents (running as deployments) t
### Adding a new deployment ### Adding a new deployment
By specifying a name for your Kerberos Agent, and it's corresponding RTSP url, a new Kubernetes deployment will be created for you, and a Kuebrnetes pod will be deployed to one of your installed nodes. By specifying a name for your Kerberos Agent, and it's corresponding RTSP url, a new Kubernetes deployment will be created for you, and a Kubernetes pod will be deployed to one of your installed nodes.
{{< figure src="add-kerberos-agent.gif" alt="Deploy a single Kerberos Agent or in bulk." caption="Deploy a single Kerberos Agent or in bulk." class="stretch">}} {{< figure src="add-kerberos-agent.gif" alt="Deploy a single Kerberos Agent or in bulk." caption="Deploy a single Kerberos Agent or in bulk." class="stretch">}}
#### Adding through ONVIF
Instead of creating a new Kerberos Agent through a RTSP stream, you can discover streams through ONVIF, and enable additional features through ONVIF such as PTZ. Enable the ONVIF toggle, and type in the IP address, ONVIF username and ONVIF password. Click the verify connection, and select an RTSP stream from the profile list.
{{< figure src="add-through-onvif.gif" alt="Deploy a Kerberos Agent with ONVIF capabilities." caption="Deploy a Kerberos Agent with ONVIF capabilities." class="stretch">}}
Once the Kerberos Agent is added, PTZ and other ONVIF capabilities will be enabled through Kerberos Hub.
{{< figure src="ptz-onvif.gif" alt="Moving a camera through ONVIF PTZ." caption="Moving a camera through ONVIF PTZ." class="stretch">}}
### Configuring a deployment ### Configuring a deployment
Once you have a running Kerberos Agent, you should see a green circle next to the deployment, indicating that it is successfully running. At any time you can configure your Kerberos Agent by clicking on the <SettingsIcon className="pointer"/> icon. This will open a popup, allowing you to change some settings. Once you have a running Kerberos Agent, you should see a green circle next to the deployment, indicating that it is successfully running. At any time you can configure your Kerberos Agent by clicking on the <SettingsIcon className="pointer"/> icon. This will open a popup, allowing you to change some settings.
@@ -90,7 +99,7 @@ By specifying configurations at a higher level, any Kerberos Agents will inherit
At Kerberos, we have agile development cycles, which means that new versions will be released every day, week or month. To make sure you can upgrade or downgrade these Kerberos Agent easily, an upgrade feature is built-in. When pressing the upgrade button, you will be able to select the version to which you would like to upgrade or downgrade. Once submitted, **a zero downtime upgrade will take place**. Kubernetes will download the new release, create a new pod, and destroy the old one. At Kerberos, we have agile development cycles, which means that new versions will be released every day, week or month. To make sure you can upgrade or downgrade these Kerberos Agent easily, an upgrade feature is built-in. When pressing the upgrade button, you will be able to select the version to which you would like to upgrade or downgrade. Once submitted, **a zero downtime upgrade will take place**. Kubernetes will download the new release, create a new pod, and destroy the old one.
At any moment you can reboot one of your Kerberos Agents. When pressing the reboot button, next to your deployment, Kubernetes will destroy the pod of your deployment, and schedule a new one. At any moment you can reboot one of your Kerberos Agents. When pressing the reboot button, next to your deployment, Kubernetes will destroy the pod of your deployment, and schedule a new one.
{{< figure src="upgrade-kerberos-agent.gif" alt="You can specify the configurations on a global level, so all agents will inherit from that." caption="You can specify the configurations on a global level, so all agents will inherit from that." class="stretch">}} {{< figure src="upgrade-kerberos-agent.gif" alt="You can specify the configurations on a global level, so all agents will inherit from that." caption="You can specify the configurations on a global level, so all agents will inherit from that." class="stretch">}}
@@ -117,7 +126,7 @@ On the other hand it's an open platform, as it allows you build extensions and i
To connect one or more Kerberos Agents to your Kerberos Vault instance, you should open the configuration option and navigate to the `cloud` tab. After selected you need to fill-in the credentials from your Kerberos Vault account. To connect one or more Kerberos Agents to your Kerberos Vault instance, you should open the configuration option and navigate to the `cloud` tab. After selected you need to fill-in the credentials from your Kerberos Vault account.
To connect one or more Kerberos Agents to your Kerberos Vault instance, you should open the configuration option and navigate to the `cloud` tab. After selected you need to fill-in the credentials from your Kerberos Vault account. To connect one or more Kerberos Agents to your Kerberos Vault instance, you should open the configuration option and navigate to the `cloud` tab. After selected you need to fill-in the credentials from your Kerberos Vault account.
- Kerberos Vault URI: this is the API endpoint of your Kerberos Vault instance. Usually this is in the following format: `http(s)://api.yourdomain.com`. Where `api.yourdomain.com` should match your Kerberos Vault API endpoint. If you are deploying Kerberos Vault at the edge, in the same cluster, you can use the internal DNS name, as following `http://kerberos-vault.kerberos-vault:8081`. - Kerberos Vault URI: this is the API endpoint of your Kerberos Vault instance. Usually this is in the following format: `http(s)://yourdomain.com/api`. Where `yourdomain.com` should match your Kerberos Vault endpoint. If you are deploying Kerberos Vault at the edge, in the same cluster, you can use the internal DNS name, as following `http://vault.kerberos-vault/api`. Where `vault` is the `service name` and `kerberos-vault` is the `namespace`.
- Provider: the name of the provider, which you created on the Kerberos Vault providers page, to which you want to send your recordings to. - Provider: the name of the provider, which you created on the Kerberos Vault providers page, to which you want to send your recordings to.
@@ -143,7 +152,7 @@ Select the Kerberos Hub option, and copy-paste the credentials from your Kerbero
- Region: this is the region where your recordings will be stored. Only `eu-west-1` for now (will change, on the roadmap). - Region: this is the region where your recordings will be stored. Only `eu-west-1` for now (will change, on the roadmap).
- Bucket: the name of the Kerberos Hub bucket. Only `kerberosaccept` for now (will change, on the roadmap). - Bucket: the name of the Kerberos Hub bucket. Only `kerberosaccept` for now (will change, on the roadmap).
- Directory: this is your personal directory, and matches your Kerberos Hub username. - Directory: this is your personal directory, and matches your Kerberos Hub username.

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.3 MiB

View File

@@ -4,7 +4,7 @@ description: ""
lead: "" lead: ""
date: 2020-10-06T08:49:31+00:00 date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00 lastmod: 2020-10-06T08:49:31+00:00
draft: false draft: true
images: [] images: []
menu: menu:
factory: factory:
@@ -103,12 +103,12 @@ The last step is to install the Kerberos Factory application. Kerberos Factory i
Kerberos Factory requires a MongoDB instance to be running, it uses it to store configuration files and other metrics. To specify those credentials a configmap is created and injected into the Kerberos Factory deployment. Kerberos Factory requires a MongoDB instance to be running, it uses it to store configuration files and other metrics. To specify those credentials a configmap is created and injected into the Kerberos Factory deployment.
Modify the MongoDB credentials, and make sure they match the credentials of your MongoDB instance. Modify the MongoDB credentials in the configmap `./factory/yaml/mongodb.config.yaml`, and make sure they match the credentials of your MongoDB instance.
- name: MONGODB_USERNAME - name: MONGODB_USERNAME
value: "root" value: "root"
- name: MONGODB_PASSWORD - name: MONGODB_PASSWORD
--> value: "xxxxxxxxxx" --> value: "yourmongodbpassword"
Create the config map. Create the config map.

View File

@@ -4,7 +4,7 @@ description: ""
lead: "" lead: ""
date: 2020-10-06T08:49:31+00:00 date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00 lastmod: 2020-10-06T08:49:31+00:00
draft: false draft: true
images: [] images: []
menu: menu:
factory: factory:
@@ -172,6 +172,7 @@ To access the Kerberos Factory application, we will create a service in the next
The idea is that Traefik, will have a dedicated IP address assigned from MetalLB, and will resolve the Ingress of our Kerberos Factory application. Let's go ahead with installing Traefik. The idea is that Traefik, will have a dedicated IP address assigned from MetalLB, and will resolve the Ingress of our Kerberos Factory application. Let's go ahead with installing Traefik.
helm repo add traefik https://helm.traefik.io/traefik helm repo add traefik https://helm.traefik.io/traefik
kubectl create namespace traefik
helm install traefik traefik/traefik -n traefik helm install traefik traefik/traefik -n traefik
### Ingress-Nginx (alternative for Traefik) ### Ingress-Nginx (alternative for Traefik)
@@ -228,12 +229,12 @@ The last step is to install the Kerberos Factory application. Kerberos Factory i
Kerberos Factory requires a MongoDB instance to be running, it uses it to store configuration files and other metrics. To specify those credentials a configmap is created and injected into the Kerberos Factory deployment. Kerberos Factory requires a MongoDB instance to be running, it uses it to store configuration files and other metrics. To specify those credentials a configmap is created and injected into the Kerberos Factory deployment.
Modify the MongoDB credentials, and make sure they match the credentials of your MongoDB instance. Modify the MongoDB credentials in the configmap `./factory/yaml/mongodb.config.yaml`, and make sure they match the credentials of your MongoDB instance.
- name: MONGODB_USERNAME - name: MONGODB_USERNAME
value: "root" value: "root"
- name: MONGODB_PASSWORD - name: MONGODB_PASSWORD
--> value: "xxxxxxxxxx" --> value: "yourmongodbpassword"
Create the config map. Create the config map.

File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 70 KiB

After

Width:  |  Height:  |  Size: 71 KiB

File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 111 KiB

After

Width:  |  Height:  |  Size: 134 KiB

File diff suppressed because one or more lines are too long

Before

Width:  |  Height:  |  Size: 90 KiB

After

Width:  |  Height:  |  Size: 106 KiB

View File

@@ -13,28 +13,28 @@ weight: 302
toc: true toc: true
--- ---
Kerberos Factory is shipped as a Docker container and is preferably installed inside a Kubernetes cluster. This means that it can run at the edge, or in the cloud. Kerberos Factory is shipped as a container image and is required to be installed inside a Kubernetes cluster. Kerberos Factory integrates with the Kubernetes API server to automatically provision Kerberos Agents on its behalf. This means that Kerberos Factory is out-of-scope if you are planning to use a `docker` or `docker compose` setup.
Although you might except that Kubernetes at the edge or Kubernetes in the cloud is the same installation, you will notice that there are a few differences. You can run Kerberos Factory wherever you can run a Kubernetes cluster, so it can run at the edge, or in the cloud. Although you might except that Kubernetes at the edge or Kubernetes in the cloud is the same installation, you will notice that there are a few differences.
When running a Kubernetes cluster on a Kubernetes service provider, such as [GKE](https://cloud.google.com/kubernetes-engine), [EKS](https://aws.amazon.com/eks/), you will have a couple of superpowers such as a `LoadBalancer` service, automatic `Volume` creation, etc. The latter is something what is missing in an Edge deployment, there you have to prepare the volumes yourself and install an edge load balancer like `MetalLB`. When running a managed Kubernetes cluster, such as [GKE](https://cloud.google.com/kubernetes-engine), [EKS](https://aws.amazon.com/eks/) or or [AKS](https://azure.microsoft.com/en-us/products/kubernetes-service/), you will have a wide range of superpowers such as a `LoadBalancer` service, automatic `Volume` creation, etc. The latter is something what is missing in an self-hosted deployment, where you will have to prepare the volumes yourself and install an edge load balancer like `MetalLB`.
{{< figure src="factory-edge-cloud.svg" alt="Kerberos Factory can be installed everywhere your Kubernetes cluster can be installed." caption="Kerberos Factory can be installed everywhere your Kubernetes cluster can be installed." class="stretch">}} {{< figure src="factory-edge-cloud.svg" alt="Kerberos Factory can be installed everywhere your Kubernetes cluster can be installed." caption="Kerberos Factory can be installed everywhere your Kubernetes cluster can be installed." class="stretch">}}
## Installation on a Kubernetes Service Provider ## Managed Kubernetes
Installing Kerberos Factory on a Kubernetes Service Provider (Azure, GCP, AWS) is straight forward, as you can create a Kubernetes cluster in a few clicks, get access to public load balancers, volumes and more. Running Kerberos Vault in such a cluster is just a matter of copy-pasting some configuration (yaml) files, and execution of `kubectl apply` commands. Installing Kerberos Factory in a managed Kubernetes cluster (Azure, GCP, AWS) is straight forward, as you create Kubernetes clusters in a few clicks, get access to public load balancers, volumes and more. Running Kerberos Factory in a managed Kubernetes cluster is just a matter of copy-pasting some configuration (yaml) files, and execution of `kubectl apply` commands.
Install Kerberos Vault on a Kubernetes Service Provider by [following this step-by-step installation guide](/factory/installation-cloud). > Install Kerberos Factory in a managed Kubernetes cluster by [following this step-by-step installation guide](https://github.com/kerberos-io/factory/tree/master/kubernetes#b-managed-kubernetes-1).
{{< figure src="factory-cloud.svg" alt="Process your video streams in the cloud." caption="Process your video streams in the cloud" class="stretch">}} {{< figure src="factory-cloud.svg" alt="Kerberos Factory managed cluster" caption="Kerberos Factory managed cluster" class="stretch">}}
## Installation in a private cloud or at the edge ## Self-hosted Kubernetes
No need to install Kerberos Factory on a Kubernetes Service Provider, it can be installed on your own Kubernetes cluster in your private cloud, or at the edge. The closer you bring Kerberos Vault to your video streams, and Kerberos Agents, the more benefits you will experience (low latency, low bandwidth, etc). No need to install Kerberos Factory on a Kubernetes Service Provider, it can be installed on your own Kubernetes cluster in your private cloud, or at the edge. The closer you bring Kerberos Vault to your video streams, and Kerberos Agents, the more benefits you will experience (low latency, low bandwidth, etc).
In contradiction to the Kubernetes Service Provider, there will be more work required. Setting up a Kubernetes Cluster, configure a load balancer, create persistent bolumes and claims. In contradiction to the Kubernetes Service Provider, there will be more work required. Setting up a Kubernetes Cluster, configure a load balancer, create persistent bolumes and claims.
Install Kerberos Factory on a private cloud or at the edge by [following this step-by-step installation guide](/factory/installation-edge). > Install Kerberos Factory on a private cloud or at the edge by [following this step-by-step installation guide](https://github.com/kerberos-io/factory/tree/master/kubernetes#a-self-hosted-kubernetes-1).
{{< figure src="factory-edge.svg" alt="Process your video streams at the edge. " caption="Process your video streams at the edge." class="stretch">}} {{< figure src="factory-edge.svg" alt="Kerberos Factory self-hosted cluster" caption="Kerberos Factory self-hosted cluster" class="stretch">}}

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.3 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.6 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.2 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 273 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.5 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 266 KiB

View File

@@ -0,0 +1,76 @@
---
title: "Analytics"
description: "Various types of video analytics are calculated."
lead: "Various types of video analytics are calculated."
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
hub:
parent: "hub"
weight: 305
toc: true
---
Kerberos Hub provides insights through video analytics. Recordings being uploaded to Kerberos Vault are triggering [the Kerberos Hub pipeline](/hub/pipeline/). Inside the pipeline, several computations are being done: sequencing, alerting and video analytics.
Having said that, please note that [you can build your own pipeline by](/vault/machine-learning/) integrating with Kerberos Vault. For example you could create your own cat/dog detector and inject your own machine learning algorithms, or interface with your favorite data science solution stack.
So what can you expect from the video analytics in Kerberos Hub? It provides two types of analytics: CPU and GPU enabled computations.
## CPU
These analytics are running on a CPU, and don't require a GPU installed in one of your nodes, as they are rather simple analytics. Following calculations or computer vision algorithms are executed in the pipeline. This list is still growing over time, as the Kerberos.io team is advancing the Kerberos Hub solution day by day.
### Thumbnail
Creating thumbnails might not bring any insightful analytics, but it helps to get already a sneak peek or context of the recording before it is downloaded from your Kerberos Vault. This also saves some bandwidth as videos do not need to be preloaded when searching for a particular event.
{{< figure src="thumbnail.png" alt="Thumbnail is the first image of the recording." class="stretch">}}
A simple scale down function is being used and converted to a `base64` encoded image. This `base64` object is stored in the Kerberos Hub database.
### Dominant color
A color histogram is created for every the first frame of the recordings. The dominant color can be used for looking for specific objects of interest.
{{< figure src="dominantcolor.png" alt="Thumbnail is the first image of the recording." class="stretch">}}
## GPU
More complex analytics are calculated using a GPU. Specific machine learning models are loaded inside the GPU memory and predict specific objects, patterns and more. Post-processes (heatmap, counting, etc) can leverage the results of the classifications, and do a more specific calculation.
### Object detection and tracking
The classification service executes a YOLOv3 algorithm on the recorded media. Moving or stationary objects are located in the recording, while the traject of moving objects are computed.
{{< figure src="classification.png" alt="A pedestrian detected and tracked." class="stretch">}}
The GPU workload is not available in the Kerberos Hub pipeline by default, and requires to be installed seperately. More information about the installation of the `hub-objecttracker` can be found on our [Github page](https://github.com/kerberos-io/hub-objecttracker).
![Analytics in Hub](analytics-media.png)
### Heatmap
The detected objects are displayed on a canvas when drilling down to the media page. On top of that a heatmap is shown which visualises the occurence of objects using a colormap.
![Counted some pedestrians](heatmap.png)
### Counting
The results of the object detection are passed to the counting service. Objects moving over a distance and crossing a line segment (defined in an alert) are counted.
![Counted some pedestrians](counting.png)
### Region detection
One or more regions can be specified. Objects of interest moving in a region will trigger
![Regions detected](region.png)
## Analytics overview page
All analytics are consolidated on the analytics overview page. On this page you'll find an overview for each day, site and camera. The total number of recordings, number of counts and number of region detections are shown on a hour graph. For each camera the full-day heatmap is shown, which illustrates the most active zones of that specific day.
![Analytics overview](analytics-page.gif)

Binary file not shown.

After

Width:  |  Height:  |  Size: 8.9 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 265 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 3.2 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 190 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 172 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 206 KiB

View File

@@ -0,0 +1,58 @@
---
title: "Archiving"
description: "Archiving media through the creation of a task."
lead: "Archiving media through the creation of a task."
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
hub:
parent: "hub"
weight: 305
toc: true
---
By default recordings are persisted for a short amount of time. Within Kerberos Hub you specify a retention period for each subscription, and assign the relevant subscription to a user. The retention period of a subscription can be set to 30, 60, 90 or any value you desire. The retention period decides how many days of footage will be shown to the end-user once he logged in, and also the removal of the relevant recordings in Kerberos Vault.
Many situation exists where you would like to archive recordings for future inspection, or just because you think the event is important. By archiving the relevant recording, the recording will be copied to another storage provider in Kerberos Vault which is not expiring or has a much higher rentention period; for example 3 years or longer.
The process of archiving through Kerberos Hub and Kerberos Vault is done through the creation of a task. Once a task is created in your Kerberos Hub account, the underlaying recording will be copied from the current storage provider to the archiving storage provider.
{{< figure src="create-task.png" alt="By creating a task, the recording is copied to the archive storage provider in Kerberos Vault." caption="By creating a task, the recording is copied to the archive storage provider in Kerberos Vault." class="stretch">}}
## Creating the archive storage provider and account
To benefit from tasks and the archiving process, an additional storage provider needs to be created in your Kerberos Vault.
{{< figure src="add-storage-provider.png" alt="Create a new storage provider for archiving in Kerberos Vault." caption="Create a new storage provider for archiving in Kerberos Vault." class="stretch">}}
To define the archiving retention period a new Kerberos Vault has to be created, as on account level we specify the retention period. By doing so, recordings copied to the archive storage provider will inherit the retention period from the newly created account.
{{< figure src="add-account.png" alt="Define a retention period in a new Kerberos Vault account." caption="Define a retention period in a new Kerberos Vault account." class="stretch">}}
## Define archive provider and account in Kerberos Hub
Now you have properly configured your Kerberos Vault instance for archiving, we need to make aware Kerberos Hub where to archive our recordings (in which provider and through which account). Open up the `values.yaml` and look for the `kerberosvault` section. Here you will find the `archive` property.
# We have a kerberos vault component installed which contains all the
# recordings. Kerberos vault is queried to retrieve the recordings
# from the appropriate provider.
kerberosvault:
uri: "https://api.storage.yourdomain.com"
accesskey: "xxx"
secretkey: "xxx"
provider: "a-provider"
# Archiving is used when creating a task. The underlying recording of the task will be copied from its
# existing provider to the below archived provider. Seperate credentials are used, as it makes possible to
# specify another retention period.
archive:
accesskey: "xxx"
secretkey: "xxx"
provider: "an-archive-provider"
Specify the `accesskey` and `secretkey` of your newly created Kerberos Vault account, and specify the name of your new archive `provider`. Update your helm chart.
{{< figure src="tasks.png" alt="Your tasks showing up on the tasks page are now showing recordings from your archived storage provider." caption="Your tasks showing up on the tasks page are now showing recordings from your archived storage provider." class="stretch">}}

Binary file not shown.

After

Width:  |  Height:  |  Size: 203 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.1 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.4 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.4 MiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.4 MiB

View File

@@ -79,13 +79,63 @@ Please note that when you are using the Kerberos Hub Saas offering you will need
## Integrations ## Integrations
You got your accounts setup, sites and groups created and last but not least some Kerberos Agents connected to your Kerberos Hub. You got your accounts setup, sites and groups created and last but not least, one or more Kerberos Agents connected to your Kerberos Hub.
Now it is time to configure some integrations using alerts and channels. The idea of integrations is that you can send messages to other third-party solutions on your own APIs, when an important/interesting event occurred.
Now it is time to configure some integrations using alerts and channels. The idea of integrations is that you can send messages to other 3rd-party services, or your own APIs, when an interesting event/alert occurred.
{{< figure src="hub-alerts.gif" alt="Get your credentials to link your Kerberos Agents." caption="Get your credentials to link your Kerberos Agents." class="stretch">}} {{< figure src="hub-alerts.gif" alt="Get your credentials to link your Kerberos Agents." caption="Get your credentials to link your Kerberos Agents." class="stretch">}}
### Alerts
Alerts can be configured to trigger one or more channels on a specific events. Generic or customer alerts can be configured to meet specific requirements and behaviours. A more indepth configuration of both generic and customer alerts are explained below.
![Configuring alerts](hub-customalerts.png)
#### Generic Alerts
Generic alerts (legacy) are the first alerts created in Kerberos Hub. Three different alerts can be configured:
![Configuring alerts](hub-alerts.gif)
- **Detections**: send a notification if a recording was received from a specific Kerberos agent, within a time range, with a specific classification, etc.
- **Devices**: when one of your Kerberos Agents stops working, a notification will be sent.
- **High upload**: when a lot of recordings are generated within a specific period of time, a notification can be send.
#### Custom Alerts
To be written
### Channels
Multiple channels can be configured and used as an event endpoint. Each channel has its own API and visualisation to the end user, therefore we will discuss them below.
#### Webhook
By configuring a webhook, you will be able to receive the event/notification through an HTTP (POST) call. The notification will contain basic information and the actual video recordings. An example of the event looks like this.
"body": {
"id": "c704244e6js97h3ob9k0",
"type": "detection",
"timestamp": 1639989520,
"title": "Hey martin something happend at your ingarage.",
"body": "A pedestrian was detected at 09:38.",
"unread": true,
"user": "martin",
"userid": "57e1011e3178aa6c5cc774d6",
"sequenceid": "61c040e27dc0c8cf9fb851a2",
"media": [
{
"timestamp": 1639989500,
"type": "video",
"url": "https://storage.googleapis.com/kstorage-europe-west1/martin/1639989500_6-967003_ingarage_200-200-400-400_24_769.mp4?Expires=1640162320&GoogleAccessId=xxx"
}
]
}
An easy way to verify if the POST request is happening, you can use a public webhook service like `https://pipedream.com/`. By creating an account, you will receive your own HTTP endpoint and all the required inspection tools.
{{< figure src="configure-webhook.gif" alt="Configure the webhook channel." caption="Configure the webhook channel." class="stretch">}}
## What's next ## What's next
Want to learn more how Kerberos Hub is working under the hood? Then [have a look at the Kerberos Hub pipeline page](/hub/pipeline) where we introduce the microservice architecture. Want to learn more how Kerberos Hub is working under the hood? Then [have a look at the Kerberos Hub pipeline page](/hub/pipeline) where we introduce the microservice architecture.

Binary file not shown.

After

Width:  |  Height:  |  Size: 485 KiB

View File

@@ -0,0 +1,51 @@
---
title: "Domains"
description: "Multi tenancy by using domains and user accounts."
lead: "Multi tenancy by using domains and user accounts."
date: 2020-10-06T08:49:31+00:00
lastmod: 2020-10-06T08:49:31+00:00
draft: false
images: []
menu:
hub:
parent: "hub"
weight: 305
toc: true
---
By default the Kerberos Hub project can be used in a multi tenancy mode. By creating multiple user and related (sub) accounts you can provide multiple users/customers/companies access to the (same) central platform. Each master user will have a set of sites, groups and cameras attached which can be further delegated to (sub) accounts. This means that sites in a geography can be managed by a specific user working in that specific timezone, etc.
By using domains you can bring the multi tenancy to another level. A domain adds another abstraction layer on top of the default user account. It creates a context in which usernames and users are unique, in others words the same username can be used in multiple domains.
## Introduction
The domain feature works through the concept of a subdomain. By prefixing the `BASE_DOMAIN` with a subdomain you indicate Kerberos Hub to which domain the user belongs. When opening the login page, the page will show the name of the domain you trying to sign in.
![Login page of a domain](login.png)
Once logged in, you will see the domain badge next to your username in the profile section (left top). This indicates to which domain the user currently signed in.
![Domain badge](domain-badge.png)
Any (sub) accounts you will create from the master account will automatically added to the same domain, and be linked to the master account.
## Configuration
To enable the domain feature, you will need to set two environment variables in the Kerberos Hub frontend container. By opening the `values.yaml` of your Helm chart, you can change following properties.
# By default the Kerberos Hub allows multi-tenancy through the concept
# of accounts and subaccounts. However through the concept of domains, you
# take it a step further. Within a domain, user accounts are unique, and are prefixed by a (domain\).
multiTenant: true
tenantBaseDomain: "yourdomain.com"
By setting `multiTenant` to true you indicate to Kerberos Hub you want to enable the domain feature. Once enabled you can provide the `tenantBaseDomain`, which you use as a basis for your domains as DNS sub domains.
When configured and deployed you can start using sub domains to different the domains in Kerberos Hub, for example `hub.kerberos.live` is used as the `tenantBaseDomain` and following subdomains will result in the equivalent Kerberos Hub domain.
- `customera.hub.kerberos.live` -> `customera` domain
- `customerb.hub.kerberos.live` -> `customerb` domain
- `xyz.hub.kerberos.live` -> `xyz` domain
- `develop.hub.kerberos.live` -> `develop` domain
Once hitting a specific domain, and for example creating a user. The user itself will be stored as a master user in the Kerberos Hub database, but will prefixed with a `domain@` in the username. When hitting the login page users will be able to sign in with their regular username, but internally the user will be authenticated with the `domain@` prefix.

Binary file not shown.

After

Width:  |  Height:  |  Size: 227 KiB

Some files were not shown because too many files have changed in this diff Show More