<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://wiki.bathcs.com/index.php?action=history&amp;feed=atom&amp;title=BOSS_kuberneter_cluster</id>
	<title>BOSS kuberneter cluster - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.bathcs.com/index.php?action=history&amp;feed=atom&amp;title=BOSS_kuberneter_cluster"/>
	<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;action=history"/>
	<updated>2026-08-26T12:02:53Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=227&amp;oldid=prev</id>
		<title>Pm2022: Pm2022 moved page BOSS/Hosting/Cluster to BOSS kuberneter cluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=227&amp;oldid=prev"/>
		<updated>2026-08-26T08:06:28Z</updated>

		<summary type="html">&lt;p&gt;Pm2022 moved page &lt;a href=&quot;/wiki/BOSS/Hosting/Cluster&quot; class=&quot;mw-redirect&quot; title=&quot;BOSS/Hosting/Cluster&quot;&gt;BOSS/Hosting/Cluster&lt;/a&gt; to &lt;a href=&quot;/wiki/BOSS_kuberneter_cluster&quot; title=&quot;BOSS kuberneter cluster&quot;&gt;BOSS kuberneter cluster&lt;/a&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;1&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:06, 26 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-notice&quot; lang=&quot;en-GB&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Pm2022</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=226&amp;oldid=prev</id>
		<title>Pm2022: reduce first person</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=226&amp;oldid=prev"/>
		<updated>2026-08-26T08:06:06Z</updated>

		<summary type="html">&lt;p&gt;reduce first person&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 08:06, 26 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l8&quot;&gt;Line 8:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 8:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Machine Structure ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Machine Structure ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{Note|text=The more technical detail about the cluster is stored within [https://gitlab.bath.ac.uk/cs/boss/int-wiki BOSS&amp;#039;s internal wiki in GitLab] and is only accessible by Committee and sysadmins. This page is here to provide some context and maybe provide some interesting information.}}&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;{{Note|text=The more technical detail about the cluster is stored within [https://gitlab.bath.ac.uk/cs/boss/int-wiki BOSS&amp;#039;s internal wiki in GitLab] and is only accessible by Committee and sysadmins. This page is here to provide some context and maybe provide some interesting information.}}&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Due to &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;me (&lt;/del&gt;hw2210&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;) &lt;/del&gt;bricking an SSD in 6 months on &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;my own &lt;/del&gt;5 node cluster due to disk intensive operations with [https://longhorn.io/ longhorn] (a storage manager that shares drives across nodes), it was decided that &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;we &lt;/del&gt;would only host a 1 node cluster with K3S&#039;s basic storage manager to extend the life of &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our &lt;/del&gt;finite disks as much as possible.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Due to &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[User:Hw2210|&lt;/ins&gt;hw2210&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;bricking an SSD in 6 months on &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;a &lt;/ins&gt;5 node cluster due to disk intensive operations with [https://longhorn.io/ longhorn] (a storage manager that shares drives across nodes), it was decided that &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;BOSS &lt;/ins&gt;would only host a 1 node cluster with K3S&#039;s basic storage manager to extend the life of &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;their &lt;/ins&gt;finite disks as much as possible.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;From experience, it was also decided &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;that we &lt;/del&gt;would host the clusters in VMs with immutable &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;distro&#039;s &lt;/del&gt;to allow more flexibility &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;with &lt;/del&gt;moving VMs between machines and stability (if it continuously crashes, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;we &lt;/del&gt;can get access to the console without plugging into host).&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;From experience, it was also decided &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;to &lt;/ins&gt;would host the clusters in VMs with immutable &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;distros &lt;/ins&gt;to allow more flexibility &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;when &lt;/ins&gt;moving VMs between machines&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;, &lt;/ins&gt;and stability (if it continuously crashes, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;you &lt;/ins&gt;can get access to the console without plugging into host).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Therefore our final structure &lt;/del&gt;was&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;:&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;ZFS &lt;/ins&gt;was &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;chosen due to extremely good data protection.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Production host machine running FreeBSD with ZFS &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;(for data protection as ZFS is king)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Therefore the final structure is:&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Production host machine running FreeBSD with ZFS&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;** Production VM with CoreOS running K3S&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;** Production VM with CoreOS running K3S&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Staging host machine running FreeBSD with ZFS&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Staging host machine running FreeBSD with ZFS&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;** Staging VM with CoreOS running K3S&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;** Staging VM with CoreOS running K3S&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;VM&#039;s &lt;/del&gt;themselves are then backed up to a backup server allowing for easy whole cluster &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;revertions &lt;/del&gt;and recovery without any painful redeployment.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;The &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;VMs &lt;/ins&gt;themselves are then backed up to a backup server allowing for easy whole cluster &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;reversions &lt;/ins&gt;and recovery without any painful redeployment.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== CoreOS ===&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;=== CoreOS ===&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;CoreOS was chosen as it is an immutable distro based off of Fedora with [[SELinux]] support and is extremely lightweight. When first &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;botting &lt;/del&gt;up, it uses an ignition file to configure itself (including network access), &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our &lt;/del&gt;ignition files can be found in [https://gitlab.bath.ac.uk/cs/int/ignition &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our &lt;/del&gt;ignition repo]. However, once the VM is running, it will not reapply ignition files, and so all changes must be performed by a wheel user.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;CoreOS was chosen as it is an immutable distro based off of Fedora with [[SELinux]] support and is extremely lightweight. When first &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;booting &lt;/ins&gt;up, it uses an ignition file to configure itself (including network access), &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the &lt;/ins&gt;ignition files can be found in [https://gitlab.bath.ac.uk/cs/int/ignition &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the &lt;/ins&gt;ignition repo]. However, once the VM is running, it will not reapply ignition files, and so all changes must be performed by a wheel user.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;By immutable, we mean &lt;/del&gt;that the root directory cannot be altered, only &amp;lt;code&amp;gt;/var&amp;lt;/code&amp;gt; can be altered during the running of the distro. &amp;lt;code&amp;gt;/etc&amp;lt;/code&amp;gt; can also be changed, but it can also be reverted during boot. This has a few quirks, for example, home directories are found in &amp;lt;code&amp;gt;/var/home/&amp;lt;username&amp;gt;&amp;lt;/code&amp;gt; and installing any package requires a reboot of the VM - but you shouldn&#039;t really need to install any packages. Additionally, the package manager is now &amp;lt;code&amp;gt;rpm-ostree install ...&amp;lt;/code&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Immutable means &lt;/ins&gt;that the root directory cannot be altered, only &amp;lt;code&amp;gt;/var&amp;lt;/code&amp;gt; can be altered during the running of the distro. &amp;lt;code&amp;gt;/etc&amp;lt;/code&amp;gt; can also be changed, but it can also be reverted during boot. This has a few quirks, for example, home directories are found in &amp;lt;code&amp;gt;/var/home/&amp;lt;username&amp;gt;&amp;lt;/code&amp;gt; and installing any package requires a reboot of the VM - but you shouldn&#039;t really need to install any packages. Additionally, the package manager is now &amp;lt;code&amp;gt;rpm-ostree install ...&amp;lt;/code&amp;gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Each alteration to the installed packages or &amp;lt;code&amp;gt;/etc&amp;lt;/code&amp;gt; creates a new version, by default, grub will choose the latest version to run, but during boot, there is the option to boot the previous version by using the down arrow.  If you are doing a dangerous update that might require you iterating through these versions, you can pin you current version before any updates, so you can go back to it if everything fails:&amp;lt;syntaxhighlight lang=&amp;quot;shell&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Each alteration to the installed packages or &amp;lt;code&amp;gt;/etc&amp;lt;/code&amp;gt; creates a new version, by default, grub will choose the latest version to run, but during boot, there is the option to boot the previous version by using the down arrow.  If you are doing a dangerous update that might require you iterating through these versions, you can pin you current version before any updates, so you can go back to it if everything fails:&amp;lt;syntaxhighlight lang=&amp;quot;shell&amp;quot;&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l35&quot;&gt;Line 35:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 37:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[wikipedia:FreeBSD|FreeBSD]] was specifically chosen as it offers two benefits:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[wikipedia:FreeBSD|FreeBSD]] was specifically chosen as it offers two benefits:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* The best support for [[wikipedia:ZFS|ZFS]] on root (Linux doesn&#039;t like &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;ZFSes &lt;/del&gt;license)&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* The best support for [[wikipedia:ZFS|ZFS]] on root (Linux doesn&#039;t like &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;ZFS&#039;s &lt;/ins&gt;license)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Additional layer of security as something other than Linux (for context the decision was made around the time when we had many Linux vulnerabilities released).&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* Additional layer of security as something other than Linux (for context the decision was made around the time when we had many Linux vulnerabilities released).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l43&quot;&gt;Line 43:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 45:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== K3S ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== K3S ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[https://k3s.io K3S] is used for the kubernetes implementation as it provides a really easy stable base. Our configuration follows the [https://docs.k3s.io/security/hardening-guide hardened configuration] on a IPv4 only cluster (Bath sadly does not provide &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;an &lt;/del&gt;IPv6 support) as well as running with &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/del&gt;SELinux&lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/del&gt;enabled. This means that network policies must be defined to permit communication between pods (e.g. the database and the backend) and allows us blocking all outgoing traffic from a specific pod and requiring all pods do not run as root (with a few permitted exceptions).&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[https://k3s.io K3S] is used for the kubernetes implementation as it provides a really easy stable base. Our configuration follows the [https://docs.k3s.io/security/hardening-guide hardened configuration] on a IPv4 only cluster (Bath sadly does not provide IPv6 support) as well as running with SELinux enabled. This means that network policies must be defined to permit communication between pods (e.g. the database and the backend) and allows us blocking all outgoing traffic from a specific pod and requiring all pods do not run as root (with a few permitted exceptions).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Helper services ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Helper services ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Kubernetes is hard, if you want more general knowledge about how to deploy and manage kubernetes cluster, please see the [[Kubernetes|Kubernetes page]]. To help with this, &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;we also deploy &lt;/del&gt;a range of &quot;helper&quot; applications which help with deployment and add cool features to your &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;own &lt;/del&gt;application:&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Kubernetes is hard, if you want more general knowledge about how to deploy and manage kubernetes cluster, please see the [[Kubernetes|Kubernetes page]]. To help with this, &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the cluster runs &lt;/ins&gt;a range of &quot;helper&quot; applications which help with deployment and add cool features to your application:&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://doc.traefik.io/traefik/ Traefik] - this is &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our &lt;/del&gt;http proxy software, managing routing traffic to the right application. This comes with the ability to [https://doc.traefik.io/traefik/expose/kubernetes/advanced/#create-middlewares create middlewares] to filter traffic based off a range of things, and combined with authelia, allows &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;us to add &lt;/del&gt;a login page for applications which don&#039;t have one.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://doc.traefik.io/traefik/ Traefik] - this is &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the &lt;/ins&gt;http proxy software, managing routing traffic to the right application. This comes with the ability to [https://doc.traefik.io/traefik/expose/kubernetes/advanced/#create-middlewares create middlewares] to filter traffic based off a range of things, and combined with authelia, allows &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;adding &lt;/ins&gt;a login page for applications which don&#039;t have one.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://cert-manager.io/ Cert manager] - this managers automatically generating and renewing all our certificates, either DNS based, HTTP based or even Cloudflare Origin certificates, allowing for easy proxying with Cloudflare.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://cert-manager.io/ Cert manager] - this managers automatically generating and renewing all our certificates, either DNS based, HTTP based or even Cloudflare Origin certificates, allowing for easy proxying with Cloudflare.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://www.authelia.com/ Authelia] - our authentication manager hooked up to Bath&amp;#039;s LDAP. This supports OpenConnect ID, allowing us to add authentication with bath credentials to more complex applications that require different groups. We have a range of unix groups which can be edited through [https://www.bath.ac.uk/services/group-manager/ Bath&amp;#039;s group manager].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://www.authelia.com/ Authelia] - our authentication manager hooked up to Bath&amp;#039;s LDAP. This supports OpenConnect ID, allowing us to add authentication with bath credentials to more complex applications that require different groups. We have a range of unix groups which can be edited through [https://www.bath.ac.uk/services/group-manager/ Bath&amp;#039;s group manager].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l56&quot;&gt;Line 56:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 58:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://grafana.com/ Grafana] - cool graphs right?&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://grafana.com/ Grafana] - cool graphs right?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://github.com/lldap/lldap LLDAP] - This is an LDAP server written in Rust and allows us to easily generate application specific credentials for our different services.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://github.com/lldap/lldap LLDAP] - This is an LDAP server written in Rust and allows us to easily generate application specific credentials for our different services.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://docs.k3s.io/upgrades/automated K3S upgrades] - keeps &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;our &lt;/del&gt;cluster up to date&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://docs.k3s.io/upgrades/automated K3S upgrades] - keeps &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;the &lt;/ins&gt;cluster up to date&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://k8up.io/ k8up] - Automatically backs up our critical &lt;del style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;PVs &lt;/del&gt;to a Scaleway S3 bucket.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://k8up.io/ k8up] - Automatically backs up our critical &lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;Persistent Volumes &lt;/ins&gt;to a Scaleway S3 bucket.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://github.com/kubernetes-sigs/security-profiles-operator Security Profile Operator] - Allows for managing SELinux policies within kubernetes resources. In most cases this should not need to be touched, and is quite brittle, but allows us to host applications which need access to the host machine itself (e.g. monitoring the node itself)&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://github.com/kubernetes-sigs/security-profiles-operator Security Profile Operator] - Allows for managing SELinux policies within kubernetes resources. In most cases this should not need to be touched, and is quite brittle, but allows us to host applications which need access to the host machine itself (e.g. monitoring the node itself)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:BOSS hosting methods]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:BOSS hosting methods]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Bath Open Source Society]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Bath Open Source Society]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pm2022</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=220&amp;oldid=prev</id>
		<title>Pm2022 at 07:54, 26 August 2026</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=220&amp;oldid=prev"/>
		<updated>2026-08-26T07:54:09Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw-interface=&quot;&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en-GB&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 07:54, 26 August 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l59&quot;&gt;Line 59:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 59:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://k8up.io/ k8up] - Automatically backs up our critical PVs to a Scaleway S3 bucket.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://k8up.io/ k8up] - Automatically backs up our critical PVs to a Scaleway S3 bucket.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://github.com/kubernetes-sigs/security-profiles-operator Security Profile Operator] - Allows for managing SELinux policies within kubernetes resources. In most cases this should not need to be touched, and is quite brittle, but allows us to host applications which need access to the host machine itself (e.g. monitoring the node itself)&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* [https://github.com/kubernetes-sigs/security-profiles-operator Security Profile Operator] - Allows for managing SELinux policies within kubernetes resources. In most cases this should not need to be touched, and is quite brittle, but allows us to host applications which need access to the host machine itself (e.g. monitoring the node itself)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:BOSS hosting methods]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Bath Open Source Society]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Pm2022</name></author>
	</entry>
	<entry>
		<id>https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=127&amp;oldid=prev</id>
		<title>Hw2210: Add information about BOSS&#039;s kubernetes cluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bathcs.com/index.php?title=BOSS_kuberneter_cluster&amp;diff=127&amp;oldid=prev"/>
		<updated>2026-06-04T10:20:55Z</updated>

		<summary type="html">&lt;p&gt;Add information about BOSS&amp;#039;s kubernetes cluster&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;To make hosting for free as easy as pie, [[Bath Open Source Society|BOSS]] has its own [[Kubernetes]] cluster. This is hosted on servers donated to us by the Department of Computer Science and is hosted within their server room in 1W. This allows us to host databases and any docker container for free, which all is configured within [https://gitlab.bath.ac.uk/cs/int/terraform our terraform repo].&lt;br /&gt;
&lt;br /&gt;
== Deployment ==&lt;br /&gt;
If you are wanting to use this cluster for hosting projects, please get in contact with committee. However, this should be part of the process with adding a project.&lt;br /&gt;
&lt;br /&gt;
When deploying, a module and related configuration will be added to [https://gitlab.bath.ac.uk/cs/int/terraform our terraform repo], which then is deployed by a sysadmin to the staging cluster. Once we have validated that it works on staging, it will finally be deployed to production.&lt;br /&gt;
&lt;br /&gt;
== Machine Structure ==&lt;br /&gt;
{{Note|text=The more technical detail about the cluster is stored within [https://gitlab.bath.ac.uk/cs/boss/int-wiki BOSS&amp;#039;s internal wiki in GitLab] and is only accessible by Committee and sysadmins. This page is here to provide some context and maybe provide some interesting information.}}&lt;br /&gt;
Due to me (hw2210) bricking an SSD in 6 months on my own 5 node cluster due to disk intensive operations with [https://longhorn.io/ longhorn] (a storage manager that shares drives across nodes), it was decided that we would only host a 1 node cluster with K3S&amp;#039;s basic storage manager to extend the life of our finite disks as much as possible.&lt;br /&gt;
&lt;br /&gt;
From experience, it was also decided that we would host the clusters in VMs with immutable distro&amp;#039;s to allow more flexibility with moving VMs between machines and stability (if it continuously crashes, we can get access to the console without plugging into host).&lt;br /&gt;
&lt;br /&gt;
Therefore our final structure was:&lt;br /&gt;
&lt;br /&gt;
* Production host machine running FreeBSD with ZFS (for data protection as ZFS is king)&lt;br /&gt;
** Production VM with CoreOS running K3S&lt;br /&gt;
* Staging host machine running FreeBSD with ZFS&lt;br /&gt;
** Staging VM with CoreOS running K3S&lt;br /&gt;
&lt;br /&gt;
The VM&amp;#039;s themselves are then backed up to a backup server allowing for easy whole cluster revertions and recovery without any painful redeployment.&lt;br /&gt;
&lt;br /&gt;
=== CoreOS ===&lt;br /&gt;
CoreOS was chosen as it is an immutable distro based off of Fedora with [[SELinux]] support and is extremely lightweight. When first botting up, it uses an ignition file to configure itself (including network access), our ignition files can be found in [https://gitlab.bath.ac.uk/cs/int/ignition our ignition repo]. However, once the VM is running, it will not reapply ignition files, and so all changes must be performed by a wheel user.&lt;br /&gt;
&lt;br /&gt;
By immutable, we mean that the root directory cannot be altered, only &amp;lt;code&amp;gt;/var&amp;lt;/code&amp;gt; can be altered during the running of the distro. &amp;lt;code&amp;gt;/etc&amp;lt;/code&amp;gt; can also be changed, but it can also be reverted during boot. This has a few quirks, for example, home directories are found in &amp;lt;code&amp;gt;/var/home/&amp;lt;username&amp;gt;&amp;lt;/code&amp;gt; and installing any package requires a reboot of the VM - but you shouldn&amp;#039;t really need to install any packages. Additionally, the package manager is now &amp;lt;code&amp;gt;rpm-ostree install ...&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Each alteration to the installed packages or &amp;lt;code&amp;gt;/etc&amp;lt;/code&amp;gt; creates a new version, by default, grub will choose the latest version to run, but during boot, there is the option to boot the previous version by using the down arrow.  If you are doing a dangerous update that might require you iterating through these versions, you can pin you current version before any updates, so you can go back to it if everything fails:&amp;lt;syntaxhighlight lang=&amp;quot;shell&amp;quot;&amp;gt;&lt;br /&gt;
sudo ostree admin pin 0&lt;br /&gt;
rpm-ostree status # See pinned versions&lt;br /&gt;
sudo ostree reset 2 # Reset back to the pinned version&lt;br /&gt;
&amp;lt;/syntaxhighlight&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== FreeBSD ===&lt;br /&gt;
[[wikipedia:FreeBSD|FreeBSD]] was specifically chosen as it offers two benefits:&lt;br /&gt;
&lt;br /&gt;
* The best support for [[wikipedia:ZFS|ZFS]] on root (Linux doesn&amp;#039;t like ZFSes license)&lt;br /&gt;
* Additional layer of security as something other than Linux (for context the decision was made around the time when we had many Linux vulnerabilities released).&lt;br /&gt;
&lt;br /&gt;
[[wikipedia:ZFS|ZFS]] was also chosen specifically because it has world-class data retention and backup tooling for RAID based systems, making it perfect for servers running with multiple large drives. We chose RAIDZ-1, which means one drive can fail and we can still recover all our data.&lt;br /&gt;
&lt;br /&gt;
FreeBSD is like Linux in many ways as it is Unix-like and subsequently many linux tools exist on FreeBSD and can be installed. However there are minor cultural differences, such as &amp;lt;code&amp;gt;sudo&amp;lt;/code&amp;gt; and &amp;lt;code&amp;gt;systemd&amp;lt;/code&amp;gt; are disliked. Instead &amp;lt;code&amp;gt;doas&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;mdo&amp;lt;/code&amp;gt; is recommended. Additionally VMs/containers are called jails and have many more useful features.&lt;br /&gt;
&lt;br /&gt;
== K3S ==&lt;br /&gt;
[https://k3s.io K3S] is used for the kubernetes implementation as it provides a really easy stable base. Our configuration follows the [https://docs.k3s.io/security/hardening-guide hardened configuration] on a IPv4 only cluster (Bath sadly does not provide an IPv6 support) as well as running with [[SELinux]] enabled. This means that network policies must be defined to permit communication between pods (e.g. the database and the backend) and allows us blocking all outgoing traffic from a specific pod and requiring all pods do not run as root (with a few permitted exceptions).&lt;br /&gt;
&lt;br /&gt;
== Helper services ==&lt;br /&gt;
Kubernetes is hard, if you want more general knowledge about how to deploy and manage kubernetes cluster, please see the [[Kubernetes|Kubernetes page]]. To help with this, we also deploy a range of &amp;quot;helper&amp;quot; applications which help with deployment and add cool features to your own application:&lt;br /&gt;
&lt;br /&gt;
* [https://doc.traefik.io/traefik/ Traefik] - this is our http proxy software, managing routing traffic to the right application. This comes with the ability to [https://doc.traefik.io/traefik/expose/kubernetes/advanced/#create-middlewares create middlewares] to filter traffic based off a range of things, and combined with authelia, allows us to add a login page for applications which don&amp;#039;t have one.&lt;br /&gt;
* [https://cert-manager.io/ Cert manager] - this managers automatically generating and renewing all our certificates, either DNS based, HTTP based or even Cloudflare Origin certificates, allowing for easy proxying with Cloudflare.&lt;br /&gt;
* [https://www.authelia.com/ Authelia] - our authentication manager hooked up to Bath&amp;#039;s LDAP. This supports OpenConnect ID, allowing us to add authentication with bath credentials to more complex applications that require different groups. We have a range of unix groups which can be edited through [https://www.bath.ac.uk/services/group-manager/ Bath&amp;#039;s group manager].&lt;br /&gt;
* [https://docker-mailserver.github.io/docker-mailserver/latest/ Docker mailserver] - This is configured with SPS, DKIM and DMARC to allow us to send emails under &amp;lt;code&amp;gt;bathcs.com&amp;lt;/code&amp;gt; for free and makes sure the emails are likely to actually reach the destination without going into spam.&lt;br /&gt;
* [https://cloudnative-pg.io/ Cloud native&amp;#039;s Postgres Operator] - This is just a tool to easily deploy postgres databases within the cluster and manage them.&lt;br /&gt;
* [https://prometheus-operator.dev/ Prometheus operator] - This allows easy monitoring of the whole cluster and emails us if anything is going wrong&lt;br /&gt;
* [https://grafana.com/ Grafana] - cool graphs right?&lt;br /&gt;
* [https://github.com/lldap/lldap LLDAP] - This is an LDAP server written in Rust and allows us to easily generate application specific credentials for our different services.&lt;br /&gt;
* [https://docs.k3s.io/upgrades/automated K3S upgrades] - keeps our cluster up to date&lt;br /&gt;
* [https://k8up.io/ k8up] - Automatically backs up our critical PVs to a Scaleway S3 bucket.&lt;br /&gt;
* [https://github.com/kubernetes-sigs/security-profiles-operator Security Profile Operator] - Allows for managing SELinux policies within kubernetes resources. In most cases this should not need to be touched, and is quite brittle, but allows us to host applications which need access to the host machine itself (e.g. monitoring the node itself)&lt;/div&gt;</summary>
		<author><name>Hw2210</name></author>
	</entry>
</feed>