Notes from 7/27 discussion about NDS-341 and NDS-377:
Beta Cluster
- DNS: beta.labs.nationaldataservice.org
- OpenStack:
- Deploy in NDSLabs project space
- Ask Chris to rebuild project (due to IP conflict problem)
- Jeff Tierstrip node
- Add CoreOS image to NDSLabs
- External monitoring
- Setup Naggio or similar
- Determine support coverage (M-F 8-5, who?)
- Backup etcd and GFS in the event of major failure
- Discuss moving ndslabs.org ownership?
- Get name on outbound for Docker registry
- Deploy beta cluster
- 3-4 compute nodes, expect to grow
- Implement reliable etcd support
- Account creation workflow
- Who gets approved for beta access and how do we track them
- How do we create accounts
- Communication plan
- How to notify users if system goes down (beta mailing list)
- How are we announcing the beta?
- Documentation
- EULA?
Integration Test Cluster
- DNS: test.labs.nationaldatabservice.org
- OpenStack
- Deploy in NDSLAbsDev project space
- Ask Chris to rebuild project (due to IP conflict problem)
- Deploy cluster with 3-4 compute nodes
TLS
- Discussed two options; Wildcard cert or using Letsencrypt (via Kubelego?)
- Setup test cluster with approved test wildcard certificate
- Schedule security review
- Prototype Kubelego or similar for per-service certs