WEBVTT 00:00:00.884 --> 00:00:03.163 And welcome to this presentation of Safespring's 00:00:03.163 --> 00:00:04.603 self-service portal. 00:00:04.603 --> 00:00:08.933 In this portal, you will be able to create and set up your own Kubernetes 00:00:08.933 --> 00:00:09.771 clusters. 00:00:09.771 --> 00:00:12.283 Let's get started. 00:00:12.283 --> 00:00:14.789 You go to the portal by going to portal. 00:00:14.789 --> 00:00:18.359 safespring. com, where you have a Sign in button. 00:00:18.359 --> 00:00:20.802 And as you can see now, when I press Sign in, I will be directed to this 00:00:20.802 --> 00:00:25.015 page, where I choose Continue with Safespring Provider. 00:00:25.015 --> 00:00:27.132 And right now my user session is cached, so 00:00:27.132 --> 00:00:32.014 this means that I will be logged in directly. 00:00:32.014 --> 00:00:34.647 But if this is the first time you do this, 00:00:34.647 --> 00:00:37.311 you might be directed to the IdP connected to the portal, where your 00:00:37.311 --> 00:00:42.672 account resides, and that is part of the onboarding process. 00:00:42.672 --> 00:00:45.399 Let's press Continue with Safespring Provider, and we will be presented 00:00:45.399 --> 00:00:50.634 with this view, where you have a number of environments. 00:00:50.674 --> 00:00:55.273 An environment is a way of grouping your resources together. 00:00:55.273 --> 00:00:59.566 Today, you can have several clusters in one environment, 00:00:59.566 --> 00:01:02.939 but in the future you will also be able to set up compute infrastructure 00:01:02.939 --> 00:01:07.845 projects and S3 storage accounts. 00:01:07.845 --> 00:01:09.125 Let's go down to this one. 00:01:09.125 --> 00:01:14.668 And you can see here that this environment is completely empty, 00:01:14.668 --> 00:01:17.274 and therefore I can add a cluster. 00:01:17.274 --> 00:01:19.788 And here you can also see the other buttons that will be 00:01:19.788 --> 00:01:20.544 available soon. 00:01:20.544 --> 00:01:25.356 So I just press Add Cluster, and I give my cluster a name. 00:01:25.356 --> 00:01:29.510 This is the first step in creating a new Kubernetes cluster. 00:01:29.510 --> 00:01:32.703 So I just call it safe-test-01. 00:01:32.703 --> 00:01:33.304 Then I press Next. 00:01:33.304 --> 00:01:34.806 And now I can choose which data center I would 00:01:34.806 --> 00:01:39.754 like to provision my resources in. 00:01:39.754 --> 00:01:42.143 I'm going to pick Stockholm 2 here, because GPU flavors are also available 00:01:42.143 --> 00:01:42.433 there. 00:01:42.433 --> 00:01:45.624 I will not use them right now, but that is one 00:01:45.624 --> 00:01:49.186 difference between the two. 00:01:49.186 --> 00:01:52.673 Otherwise, it could simply be geographical or sovereignty reasons why you choose 00:01:52.673 --> 00:01:54.197 either of the two. 00:01:54.197 --> 00:01:57.627 So I go with Stockholm 2 and press Next. 00:01:57.627 --> 00:02:00.340 And now it's time to configure how many control plane nodes I'm going to 00:02:00.340 --> 00:02:02.501 have and which type to use. 00:02:02.501 --> 00:02:06.826 More precisely, I choose three nodes, and I can choose their sizing. 00:02:06.826 --> 00:02:10.854 And you can see that there are different flavor variants here. 00:02:10.854 --> 00:02:13.897 You can have four vCPUs per control plane 00:02:13.897 --> 00:02:19.253 node, eight gigabytes of RAM, and 100 gigabytes of storage. 00:02:19.253 --> 00:02:21.468 But there are also other variants. 00:02:21.468 --> 00:02:24.594 I'm just going to go with the smallest one here. 00:02:24.594 --> 00:02:26.758 So: four vCPUs, eight gigabytes of RAM, and 100 GB of 00:02:26.758 --> 00:02:27.340 storage. 00:02:27.340 --> 00:02:31.994 Then it's time to provision my worker nodes. 00:02:31.994 --> 00:02:34.856 And you can see here that I can choose different numbers of them with this 00:02:34.856 --> 00:02:35.209 slider. 00:02:35.209 --> 00:02:38.383 I'm just going to choose three here, and I'm 00:02:38.383 --> 00:02:43.024 going to take the smallest one. 00:02:43.024 --> 00:02:46.794 You can also see that you have those GPU flavors here. 00:02:46.834 --> 00:02:49.424 And in the future there will also be something more like a shopping cart 00:02:49.424 --> 00:02:52.770 here, where you might have a use case in which you 00:02:52.770 --> 00:02:58.058 would like three worker nodes of this type and 00:02:58.058 --> 00:03:00.183 maybe just two GPU worker nodes. 00:03:00.183 --> 00:03:02.408 You might not want to have all your nodes running with GPU 00:03:02.408 --> 00:03:03.076 flavors. 00:03:03.076 --> 00:03:07.754 Those are only needed for certain applications. 00:03:07.914 --> 00:03:10.473 But right now I'm just going to pick the smallest one: eight vCPUs, 16 GB 00:03:10.473 --> 00:03:14.989 of RAM, and 100 GB of storage per node. 00:03:14.989 --> 00:03:15.719 And then I press Next. 00:03:15.719 --> 00:03:21.622 And now you can see a summary screen, where you can review what you're about to do. 00:03:21.622 --> 00:03:24.497 It says which environment I'm in and which data center I'm going to 00:03:24.497 --> 00:03:26.127 provision the resources in. 00:03:26.127 --> 00:03:29.794 And you can see the name of the cluster, 00:03:29.794 --> 00:03:34.335 safe-test-01; the control plane, which consists of three nodes of this flavor; 00:03:34.335 --> 00:03:40.322 and the worker nodes, which consist of three nodes of this flavor. 00:03:40.322 --> 00:03:42.641 It's also possible to download this configuration for later 00:03:42.641 --> 00:03:43.047 provisioning. 00:03:43.047 --> 00:03:47.241 So right now we're just going to select Create Cluster. 00:03:47.241 --> 00:03:49.914 And now it has started. 00:03:49.914 --> 00:03:54.287 It says that your request was submitted successfully, 00:03:54.287 --> 00:03:58.082 and you see the same review information again. 00:03:58.082 --> 00:04:01.218 So I can select Return to Environment. 00:04:01.218 --> 00:04:04.477 You can see here that I now have this cluster in the environment, with 00:04:04.477 --> 00:04:07.736 this ID. 00:04:07.736 --> 00:04:10.541 The ID is automatically generated, 00:04:10.541 --> 00:04:13.388 and you're going to see that it also appears elsewhere in 00:04:13.388 --> 00:04:14.143 the naming. 00:04:14.143 --> 00:04:17.164 When you set up this cluster, we also 00:04:17.164 --> 00:04:23.118 provision DNS automatically, with a DNS name. 00:04:23.118 --> 00:04:25.537 This is the name that you point your CNAMEs to 00:04:25.537 --> 00:04:29.369 in your DNS, so that you can publish your own applications 00:04:29.369 --> 00:04:33.611 running in the cluster. 00:04:33.611 --> 00:04:37.874 And you can see here that it is still being created. 00:04:37.874 --> 00:04:41.081 So it's working, and it takes maybe a minute or two because of what it is 00:04:41.081 --> 00:04:41.805 doing now. 00:04:41.805 --> 00:04:47.380 It is setting up the control plane, setting up and provisioning the worker 00:04:47.380 --> 00:04:52.610 nodes, and also doing the DNS provisioning that I 00:04:52.610 --> 00:04:53.151 talked about. 00:04:53.151 --> 00:04:58.107 There are several other things that we need to do in order to get the 00:04:58.107 --> 00:05:02.994 environment up and running. 00:05:03.034 --> 00:05:05.713 I can also tell you that it is based on Talos Linux from the 00:05:05.713 --> 00:05:11.485 ground up, which is an ephemeral OS, only API-based. 00:05:11.485 --> 00:05:14.955 There is no CLI connection to the Talos nodes, 00:05:14.955 --> 00:05:18.200 and this makes it rather easy to foresee the consequences when we perform 00:05:18.200 --> 00:05:22.953 upgrades and things like that. 00:05:22.953 --> 00:05:25.934 And that is, of course, part of the solution: we will manage the control 00:05:25.934 --> 00:05:26.318 plane. 00:05:26.318 --> 00:05:32.105 That means that when there is an upgrade to the Kubernetes version, or 00:05:32.105 --> 00:05:38.150 something similar, we will be able to perform those upgrades. 00:05:38.150 --> 00:05:41.365 Some upgrades can be a little larger and can affect the applications 00:05:41.365 --> 00:05:44.001 running in the cluster. 00:05:44.001 --> 00:05:45.978 In that case, 00:05:45.978 --> 00:05:48.809 the upgrade will be done in collaboration between the team at Safespring 00:05:48.809 --> 00:05:53.806 and your application team, so that they can coordinate and make sure that 00:05:53.806 --> 00:05:59.188 all your YAML files and similar resources 00:05:59.188 --> 00:06:02.473 work with the newer version of the environment. 00:06:02.553 --> 00:06:04.591 Now it is active, as you can see. 00:06:04.591 --> 00:06:07.987 So now we can click the name here and view our cluster. 00:06:07.987 --> 00:06:09.716 We have an overview here. 00:06:09.716 --> 00:06:11.444 We have the region—Stockholm 2, 00:06:11.444 --> 00:06:15.334 as we said before—which is the data center where it is running. 00:06:15.334 --> 00:06:18.144 You can see the Kubernetes version, the Talos version, and the underlying 00:06:18.144 --> 00:06:20.953 operating system. 00:06:20.993 --> 00:06:23.765 And you can also see the network. 00:06:23.765 --> 00:06:24.992 Here you have the API endpoint. 00:06:24.992 --> 00:06:29.857 This is the name that you can use to run your kubectl commands against the 00:06:29.857 --> 00:06:33.343 cluster. 00:06:33.343 --> 00:06:38.215 You can also see the IP address that has been provisioned. 00:06:38.215 --> 00:06:40.869 It also comes with an automatically configured ingress. 00:06:40.869 --> 00:06:45.987 I spoke about that before: we have this automatically generated DNS 00:06:45.987 --> 00:06:51.153 record, which looks pretty long. 00:06:51.153 --> 00:06:53.572 But you only need to copy this once and add it as a CNAME for your own 00:06:53.572 --> 00:06:53.882 domain. 00:06:53.882 --> 00:06:56.674 Then you can set up your own ingress resources 00:06:56.674 --> 00:07:01.449 in the cluster to match the name you have 00:07:01.449 --> 00:07:05.171 configured, with the CNAME pointing to this address. 00:07:05.171 --> 00:07:07.342 In that case, you will be able to serve applications from 00:07:07.342 --> 00:07:08.421 the cluster. 00:07:08.421 --> 00:07:11.656 And just one more thing here: 00:07:11.656 --> 00:07:14.085 you can see a little button for scaling the number of worker 00:07:14.085 --> 00:07:14.792 nodes. 00:07:14.792 --> 00:07:18.327 We can actually scale up. 00:07:18.327 --> 00:07:20.974 We had three from the beginning, so now we can perhaps have 00:07:20.974 --> 00:07:22.158 four instead. 00:07:22.158 --> 00:07:26.302 I can just select Scale Cluster here. 00:07:26.302 --> 00:07:28.768 And you can see that this sends an order to our provisioning 00:07:28.768 --> 00:07:29.182 system. 00:07:29.182 --> 00:07:33.270 Let's say that it will scale the cluster to four nodes. 00:07:33.270 --> 00:07:37.035 And if we go back to the environment, we can see that it is creating again. 00:07:37.035 --> 00:07:39.625 This operation takes far less time because it 00:07:39.625 --> 00:07:44.089 is just one worker node that needs to be 00:07:44.089 --> 00:07:47.472 provisioned, and everything else is already there. 00:07:47.472 --> 00:07:50.913 So we're just going to wait a little bit for it to finish. 00:07:50.913 --> 00:07:54.847 And you can see that it now has four nodes. 00:07:54.927 --> 00:07:55.504 Now it's finished. 00:07:55.504 --> 00:08:01.644 The cluster is active again, so we can go in and look at the overview page. 00:08:01.644 --> 00:08:04.664 And we can see that it now has four nodes here. 00:08:04.664 --> 00:08:06.523 So we managed to scale it up. 00:08:06.523 --> 00:08:08.648 But now, what do we do with this? 00:08:08.648 --> 00:08:11.347 Well, we want to connect to it, of course. 00:08:11.347 --> 00:08:13.789 And we have this button up here called Kubeconfig, which I'm going to 00:08:13.789 --> 00:08:14.342 press. 00:08:14.342 --> 00:08:19.425 And here you have the full configuration of the cluster. 00:08:19.425 --> 00:08:22.730 So I'm just going to copy this, and then I'm 00:08:22.730 --> 00:08:27.385 going to go to my terminal. 00:08:27.465 --> 00:08:29.510 Now I'm in the terminal. 00:08:29.510 --> 00:08:34.954 So I'm going to copy the contents from the portal into my kubeconfig file. 00:08:34.954 --> 00:08:37.206 So I'm just going to open the kubeconfig file and paste it 00:08:37.206 --> 00:08:37.829 here. 00:08:37.829 --> 00:08:41.569 I can go through this briefly. 00:08:41.569 --> 00:08:43.769 First, we have the certificate authority data and the 00:08:43.769 --> 00:08:46.144 keys that are needed in 00:08:46.144 --> 00:08:50.859 order to connect to the cluster correctly. 00:08:50.899 --> 00:08:54.673 You can also see the server for the cluster. 00:08:54.673 --> 00:08:59.476 This is the API endpoint that we also saw in the portal. 00:08:59.476 --> 00:09:03.421 But one interesting thing is down here: when we start running commands 00:09:03.421 --> 00:09:09.337 against this cluster, we will need to log in. 00:09:09.337 --> 00:09:12.293 And this is the IDM connected to Stockholm 2. 00:09:12.293 --> 00:09:13.179 You can see it here. 00:09:13.179 --> 00:09:16.654 That's where I will need an account in order to connect to the cluster. 00:09:16.654 --> 00:09:20.266 In this way, we have two levels of identity providers. 00:09:20.266 --> 00:09:22.519 We have the IdP for the portal, where you as 00:09:22.519 --> 00:09:27.460 an administrator can set up new clusters. 00:09:27.460 --> 00:09:30.776 But you also need another level: the IdPs for the actual data centers where 00:09:30.776 --> 00:09:32.049 those clusters are provisioned. 00:09:32.049 --> 00:09:37.669 In this way, you as an administrator can be in command of setting up and 00:09:37.669 --> 00:09:38.481 deleting clusters. 00:09:38.481 --> 00:09:44.167 But you can give permissions to certain users who only have an account in 00:09:44.167 --> 00:09:48.845 the IdP connected to the data center. 00:09:48.845 --> 00:09:51.344 So you have a layered access model. 00:09:51.344 --> 00:09:54.772 This makes it easy to separate responsibilities, 00:09:54.772 --> 00:09:58.022 so that technicians working with the clusters do not have the right to 00:09:58.022 --> 00:10:02.699 delete the clusters, for instance. 00:10:02.779 --> 00:10:05.439 So I'm just going to save this here. 00:10:05.219 --> 00:10:08.479 And then we can do the regular setup. 00:10:08.479 --> 00:10:12.267 I'm going to read this file and set my KUBECONFIG environment variable to 00:10:12.267 --> 00:10:13.360 point to it. 00:10:13.360 --> 00:10:16.639 So now I have added the information to the 00:10:16.639 --> 00:10:20.722 kubeconfig file, as you can see here. 00:10:20.722 --> 00:10:24.561 And now I'm going to set my KUBECONFIG environment variable to 00:10:24.561 --> 00:10:25.742 point to it. 00:10:25.742 --> 00:10:30.869 So now the KUBECONFIG environment variable points to my new kubeconfig 00:10:30.869 --> 00:10:34.557 file. 00:10:34.557 --> 00:10:39.021 Now I can run kubectl get nodes, for instance. 00:10:39.101 --> 00:10:41.821 And as you can see, I now need to log in to the IdP where my 00:10:41.821 --> 00:10:42.954 account is. 00:10:42.954 --> 00:10:46.353 So I'm going to do that. 00:10:46.353 --> 00:10:47.555 I enter my password here. 00:10:47.555 --> 00:10:48.998 Then I have two-factor authentication enabled, 00:10:48.998 --> 00:10:54.285 so I need to use my hardware key. 00:10:54.285 --> 00:10:57.533 And as you can see, I am now authenticated. 00:10:57.533 --> 00:11:00.517 If we go back here, we can see that I actually got a response from the 00:11:00.517 --> 00:11:03.501 command. 00:11:03.501 --> 00:11:07.565 So now I have an authentication token. 00:11:07.565 --> 00:11:11.256 Now I can run kubectl get pods --namespace kube-system, for 00:11:11.256 --> 00:11:14.946 instance. 00:11:14.946 --> 00:11:18.904 Here we can see all the components running in the cluster. 00:11:18.904 --> 00:11:22.326 You can see that we're running Cilium for 00:11:22.326 --> 00:11:25.856 networking and CoreDNS for DNS 00:11:25.856 --> 00:11:31.340 handling in the environment. 00:11:31.340 --> 00:11:34.450 We have Cinder CSI. 00:11:34.450 --> 00:11:39.374 This is because we're running our environment on OpenStack, 00:11:39.374 --> 00:11:42.294 where Cinder is the volume service. 00:11:42.294 --> 00:11:45.716 This is the plugin that handles the provisioning of PVCs—persistent volume 00:11:45.716 --> 00:11:49.137 claims. 00:11:49.137 --> 00:11:52.851 And then we have the other, more standard Kubernetes services that run in 00:11:52.851 --> 00:11:57.232 all Kubernetes clusters. 00:11:57.232 --> 00:11:58.901 So this was it. 00:11:58.941 --> 00:12:02.688 We have created a cluster and connected to it. 00:12:02.688 --> 00:12:05.376 And now, if I am finished with this cluster, I can also 00:12:05.376 --> 00:12:06.609 delete it. 00:12:06.609 --> 00:12:09.692 So I can go here. 00:12:09.692 --> 00:12:12.380 This is something I can do as an administrator of the 00:12:12.380 --> 00:12:12.795 environment. 00:12:12.795 --> 00:12:16.533 I need to enter the name, because otherwise it 00:12:16.533 --> 00:12:20.931 will not let me continue. 00:12:20.931 --> 00:12:23.823 So now I can delete the cluster, and it will be deprovisioned. 00:12:23.823 --> 00:12:29.404 I hope you liked this demonstration, and I hope to see you soon. 00:12:29.404 --> 00:12:29.934 Bye.