3 ms·
I think you're looking for Chef or Puppet recipes, real configuration management tools which can flexibly deploy a complete stack, not some Bitnami toy which do
by cat-dev-null 11y ago
I think you're looking for Chef or Puppet recipes, real configuration management tools which can flexibly deploy a complete stack, not some Bitnami toy which doesn't solve anything.
The limitations with most all container platforms is what they don't do major things which need to be addressed somehow in production systems:
- data backups / restores
- security practices / policies (good luck running SELinux)
- migrations to new versions
- security updates
- firewall rules
- monitoring & performance agents
- hard resource isolation (cpu, ram, network, IOPS)
- [something else obviously important here]
Containers are great for limited testing and local development, but for production they are like anti-type 1 hypervisors... more trouble that they're worth (docker instances still get stuck all the time as zombie processes, requiring a hard host reboot).
Worse, most of these containers are built by unknown persons, are unsigned and hosted publicly, so it's effectively running untrustworthy code however they decided to package and deliver it.
Finally, to add insult to injury, there's no reliable way to rebuild an image from scratch without some sources, whereas configuration management tools are intended to describe how to deploy apps and put systems into a desired configuration.
- cpitman 11y agoI actually am very experienced with Puppet, and I agree configuration management tools still have a (now narrower) space. But most of your concerns are actually handled by what we are doing at Red Hat. OpenShift v3: * applies SELinux policies to each running container * can handle multiple styles of container upgrades (rolling, green/blue, canary, etc) * includes an automated build process for automatically patching all of your containers when there is an update to their base image (including supported releases of RHEL containers that are kept up to date with errata) * automatically reconfigures iptables as containers go up/dowm/migrate * collects metrics on all running containers * health checks for running containers to ensure they are not zombies Since it is built on top of Kubernetes, the only configuration that you need to apply/maintain is the pod description, a short json document that describes what to run, what ports to expose, etc.