Skopeo # I have stumbled upon this tool: https://github.com/containers/skopeo - command line tools for manipulation with Docker images and Docker image registries.
It can work with OCI images as well as the original Docker v2 images.
Installation # brew install skopeo Usage # ➜ deploy-2018-10-24 skopeo --override-os=linux inspect docker://docker.io/fedora { "Name": "docker.io/library/fedora", "Digest": "sha256:b41cd083421dd7aa46d619e958b75a026a5d5733f08f14ba6d53943d6106ea6d", "RepoTags": [ "20", "21", "22", "23", "24", "25", "26-modular", "26", "27", "28", "29", "branched", "heisenbug", "latest", "modular", "rawhide" ], "Created": "2018-09-07T19:20:02.809176076Z", "DockerVersion": "17.06.2-ce", "Labels": null, "Architecture": "amd64", "Os": "linux", "Layers": [ "sha256:565884f490d9ec697e519c57d55d09e268542ef2c1340fd63262751fa308f047" ] } It works with protected repos as well - as long as creds are provided
Step 1 done.
https://www.certmetrics.com/amazon/public/badge.aspx?i=1&t=c&d=2018-06-06&ci=AWS00261816&fbclid=IwAR2K8B4FyKWVstBZXCXn5GhYX9iRyB4U2q8l2ROrM_16m-rlclioalnp0O4
And now dilemma: go deeper into AWS or look around what Google and Azure have to offer ?
So many clouds, so little time …
This describes creation of K8s cluster in AWS environment from scratch as done for microservices based eCommerce project.
Pre-requisites # AWS account access - IAM with Admin privileges AWS CLI installed - https://docs.aws.amazon.com/cli/latest/userguide/cli-install-macos.html CLI credentials (secret key + api Key) - https://docs.aws.amazon.com/cli/latest/reference/iam/index.html Kubectl and Kops local install ** see https://github.com/kubernetes/kops and https://kubernetes.io/docs/tasks/tools/install-kubectl/ Test of access # ➜ etc git:(feature/kubernetes) aws --version aws-cli/1.11.180 Python/3.6.4 Darwin/17.5.0 botocore/1.7.38 ➜ etc git:(feature/kubernetes) kubectl version Client Version: version.Info{Major:"1", Minor:"10", GitVersion:"v1.10.1", GitCommit:"d4ab47518836c750f9949b9e0d387f20fb92260b", GitTreeState:"clean", BuildDate:"2018-04-13T22:27:55Z", GoVersion:"go1.9.5", Compiler:"gc", Platform:"darwin/amd64"} Server Version: version.Info{Major:"1", Minor:"9", GitVersion:"v1.9.3", GitCommit:"d2835416544f298c919e2ead3be3d0864b52323b", GitTreeState:"clean", BuildDate:"2018-02-07T11:55:20Z", GoVersion:"go1.9.2", Compiler:"gc", Platform:"linux/amd64"} ➜ etc git:(feature/kubernetes) kops version Version 1.9.0 ➜ etc git:(feature/kubernetes) aws --profile twfulfill-miro iam list-users | jq '.Users[].UserName' .. DELETED ... "twfulfillment.prod.miro.adamy" .... Set the environment variables # These will be used by subsequent kops / aws commands
The idea / motivation # In order to run VisualVM from predefined configuration you need to point the app to the user directory. This directory takes about 20MB, but 90% of the the content is actually generated or repeated.
➜ 4devops-visualvm git:(master) du -sh tw-sl/* 244K tw-sl/config 7.3M tw-sl/modules 52K tw-sl/repository 4.0K tw-sl/update 104K tw-sl/update_tracking 11M tw-sl/var ➜ 4devops-visualvm git:(master) du -sh tw-wool/* 248K tw-wool/config 7.2M tw-wool/modules 60K tw-wool/repository 4.0K tw-wool/update 104K tw-wool/update_tracking 11M tw-wool/var ➜ 4devops-visualvm git:(master) du -sh tw-wool 19M tw-wool The only part that is specific and worthy of maintaining in the Git repo is repository
The purpose of this is to evaluate options and suggest possible approaches for handling the sensitive information in Git repositories such as database credentials, API credentials, passwords, keys, certificates etc. Joel asked this question a few weeks ago - this is part of Milos’s security awareness program.
The issue # Git repos store in cleartext all credentials, that may also be including PROD credentials.
This is based on J.’s’ question in Slack:
Do we have some customer where we are moving a git repo to svn in an automated fashion I just need to move the git repo into svn periodically nightly
The setup (as I understand it):
on client side we have a worktree that is Git repository the files needs to be copied to SVN regularly Options # Use git-svn bridge # Git client allows to “pretend” it is SVN and pull/push against remote SVN repo
Task # Transfer full Git history (all branches, tags, etc) to Bitbucket so that development can continue from there
User setup # List all keys in Gitolite must have access to Gitolite admin interface cd $ADMIN_HOME/pensieve/PRJ-admin/gitolite-admin ➜ gitolite-admin git:(master) ll keydir total 144K -rw-r--r-- 1 miro 401 Jun 29 2015 alter.pub -rw-r--r-- 1 miro 397 Jun 29 2015 codereview.pub -rw-r--r-- 1 miro 400 Apr 18 2016 hybris.pub -rw-r--r-- 1 miro 400 Apr 19 2016 hybris2.pub -rw-r----- 1 miro 398 Mar 30 2016 irae.pub ... DELETED ... -rw-r--r-- 1 miro 401 Jun 29 2015 miro.pub -rw-r--r-- 1 miro 411 Jun 29 2015 tkuser.jenkins0.pub -rw-r--r-- 1 miro 411 Jun 29 2015 tkuser.jenkins2.pub These will be split to 5 usergroups