SlideShare une entreprise Scribd logo
1  sur  20
Télécharger pour lire hors ligne
Containerization*
Primary Goals Dreams
● Improvements in reliability among different compute environment. Prod ==
QA ==Dev
● Better CI /CD
○ Deployment process aligned with our branching policy
○ A common pipeline to catch mistakes
○ Flexibility to bring new environments
○ RBAC
○ Deploy anything, anytime
● Improvements in AWS resource usage
● Scalability - Faster boot times
New Changes
● Config file Management - Encrypt all sensitive datas and No AWS keys
● Dependency Management - Composer, Maven and go modules
● Prometheus operators / Push-gateways
● Kubernetes native Jenkins containers
● Certificate management
● Granular IAM Roles for security
● Port Management
● Egress controls for security
New Changes
● Canary deployments
● Easier A/B Testing using Service mesh
● Smart routing using ingress controllers
● Continuous Integration using Jenkins
● Continuous Delivery
● Get rid of Rsyslog
● 90 % workloads is on Spot instances
● Better RBAC on exotel infra
New Changes
● Automatic Network retries
● Rate limiting
● Production traffic mirroring
● Zipkin request tracing
● Controlled CPU and RAM for all services
This is what I can remember as of now :)
We did a Mistake
● We named the project wrongly
● This is not just about containers and it’s orchestration
● This is a complete exotel platform revamp
Gitops - our philosophy
● A Git repo is the single source of truth for the desired state of whole
system
● All changes to the desired state are git commits
● In case of divergence, Kubernetes will try to sync according to git repo
● Rollback is “Convergence to an earlier desired state”
● There can’t be one more cron machine or Erix server or exoconsole
Containerization
Repository Structure Changes
● Each service will have it’s own repository
● All service config files will be present in a separate repository called
“Exotel_Configs”
● All Kubernetes deployment files will be present in one more repository
called “Exotel_Deployments”
Service Repo + Exotel_configs => Exotel_Deployments => Git-Ops => Exotel
Exotel Configs
● Single repository to host all config files. It’s a monorepo
● Only sensitive information in the configs are encrypted using PGP or AWS
KMS
● Only certain members in the team will have KMS access to encrypt/decrypt
passwords
● This will be the home for Kubernetes helm configs as well
● Configs are encrypted during runtime when the pod is created
Exotel Deployments
● Single repository that contains all the deployment files (For every
environment) of Kubernetes.
● Kubernetes controllers like argo watches this repo and any new change
can be synced to the cluster
● Wanna Rollback to previous versions ? Just do a git revert of the
deployment file.
SOPS - Envelope Encryption
● Mozilla/sops is used to manage the encryption and decryption.
Envelope Decryption
Steps to containerize
● Add Dockerfile & docker-compose file in the service repo
● Add Jenkinsfile in the service repo
● Push all your logs to stdout / stderr
● Use versions for all your dependencies
● Move config files to config repo
● Add Helm files in config repo
● Commit to PU branch
CI Pipeline - Jenkins
● Works based on PU and Next branches
● A commit pushed to PU/Next branch triggers an CI Jenkins job and an
image is built and pushed to ECR
● Helm deployment files are created and pushed to “exotel_deployments”
repository
CD Pipeline - Argo
● We don’t do continuous deployment
● There is just 1 Jenkins for all environment but different argocd tool for
each environment
Logging Pipeline
● Fluentd daemonset runs on all machines that collects all logs that are
pushed to stdout/stderr of the containers
● All logs are shipped to doglump
● Doglump will die in near future.
● We are ready for the futrure - Fluentd already enriches the logs so that it
can be consumed by an Elastic cluster
Collecting Metrics
● We got rid of Rsyslog
● Jellibabix was using 500Mb of RAM but rsyslog required 2.5 Gb of RAM to
ship metrics
● Fluentd-metrics daemonset runs in every machine to collect the metrics
from containers and forwards it to kafka
● Services can no longer just push to localhost / 127.0.0.1
Kubernetes Monitoring
● Prometheus operators are used
● Any divergence in the declarative config is raised as an alert
● Grafana is present to visualise server / container metrics
● Kubelet daemon running on every machine sends container metrics to
prometheus
● You can just expose an metrics endpoint on your service and configure
prometheus-operator to scrape data
Feedback /
Questions ?

Contenu connexe

Dernier

08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?Antenna Manufacturer Coco
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slidespraypatel2
 

Dernier (20)

08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Slack Application Development 101 Slides
Slack Application Development 101 SlidesSlack Application Development 101 Slides
Slack Application Development 101 Slides
 

En vedette

How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at WorkGetSmarter
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...DevGAMM Conference
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationErica Santiago
 
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellGood Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellSaba Software
 
Introduction to C Programming Language
Introduction to C Programming LanguageIntroduction to C Programming Language
Introduction to C Programming LanguageSimplilearn
 

En vedette (20)

How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellGood Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
 
Introduction to C Programming Language
Introduction to C Programming LanguageIntroduction to C Programming Language
Introduction to C Programming Language
 

Containerization

  • 2. Primary Goals Dreams ● Improvements in reliability among different compute environment. Prod == QA ==Dev ● Better CI /CD ○ Deployment process aligned with our branching policy ○ A common pipeline to catch mistakes ○ Flexibility to bring new environments ○ RBAC ○ Deploy anything, anytime ● Improvements in AWS resource usage ● Scalability - Faster boot times
  • 3. New Changes ● Config file Management - Encrypt all sensitive datas and No AWS keys ● Dependency Management - Composer, Maven and go modules ● Prometheus operators / Push-gateways ● Kubernetes native Jenkins containers ● Certificate management ● Granular IAM Roles for security ● Port Management ● Egress controls for security
  • 4. New Changes ● Canary deployments ● Easier A/B Testing using Service mesh ● Smart routing using ingress controllers ● Continuous Integration using Jenkins ● Continuous Delivery ● Get rid of Rsyslog ● 90 % workloads is on Spot instances ● Better RBAC on exotel infra
  • 5. New Changes ● Automatic Network retries ● Rate limiting ● Production traffic mirroring ● Zipkin request tracing ● Controlled CPU and RAM for all services This is what I can remember as of now :)
  • 6. We did a Mistake ● We named the project wrongly ● This is not just about containers and it’s orchestration ● This is a complete exotel platform revamp
  • 7. Gitops - our philosophy ● A Git repo is the single source of truth for the desired state of whole system ● All changes to the desired state are git commits ● In case of divergence, Kubernetes will try to sync according to git repo ● Rollback is “Convergence to an earlier desired state” ● There can’t be one more cron machine or Erix server or exoconsole
  • 9. Repository Structure Changes ● Each service will have it’s own repository ● All service config files will be present in a separate repository called “Exotel_Configs” ● All Kubernetes deployment files will be present in one more repository called “Exotel_Deployments” Service Repo + Exotel_configs => Exotel_Deployments => Git-Ops => Exotel
  • 10. Exotel Configs ● Single repository to host all config files. It’s a monorepo ● Only sensitive information in the configs are encrypted using PGP or AWS KMS ● Only certain members in the team will have KMS access to encrypt/decrypt passwords ● This will be the home for Kubernetes helm configs as well ● Configs are encrypted during runtime when the pod is created
  • 11. Exotel Deployments ● Single repository that contains all the deployment files (For every environment) of Kubernetes. ● Kubernetes controllers like argo watches this repo and any new change can be synced to the cluster ● Wanna Rollback to previous versions ? Just do a git revert of the deployment file.
  • 12. SOPS - Envelope Encryption ● Mozilla/sops is used to manage the encryption and decryption.
  • 14. Steps to containerize ● Add Dockerfile & docker-compose file in the service repo ● Add Jenkinsfile in the service repo ● Push all your logs to stdout / stderr ● Use versions for all your dependencies ● Move config files to config repo ● Add Helm files in config repo ● Commit to PU branch
  • 15. CI Pipeline - Jenkins ● Works based on PU and Next branches ● A commit pushed to PU/Next branch triggers an CI Jenkins job and an image is built and pushed to ECR ● Helm deployment files are created and pushed to “exotel_deployments” repository
  • 16. CD Pipeline - Argo ● We don’t do continuous deployment ● There is just 1 Jenkins for all environment but different argocd tool for each environment
  • 17. Logging Pipeline ● Fluentd daemonset runs on all machines that collects all logs that are pushed to stdout/stderr of the containers ● All logs are shipped to doglump ● Doglump will die in near future. ● We are ready for the futrure - Fluentd already enriches the logs so that it can be consumed by an Elastic cluster
  • 18. Collecting Metrics ● We got rid of Rsyslog ● Jellibabix was using 500Mb of RAM but rsyslog required 2.5 Gb of RAM to ship metrics ● Fluentd-metrics daemonset runs in every machine to collect the metrics from containers and forwards it to kafka ● Services can no longer just push to localhost / 127.0.0.1
  • 19. Kubernetes Monitoring ● Prometheus operators are used ● Any divergence in the declarative config is raised as an alert ● Grafana is present to visualise server / container metrics ● Kubelet daemon running on every machine sends container metrics to prometheus ● You can just expose an metrics endpoint on your service and configure prometheus-operator to scrape data