Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

1,905 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Y-stack

Y-stack is a micro-PaaS(?) with the following goals:

  • Allow every developer to experiment with architecture on a cluster level
  • Make moitoring and alerts a first class tool in coding
  • Make Kubernetes patterns like sidecars and operators an intergral part of design
  • Support event-driven microservices patterns

Installation

Use git clone https://github.com/Yolean/ystack

Add the following to env:

export YSTACK_HOME=/Users/me/Yolean/ystack
export PATH=$PATH:$YSTACK_HOME/bin

Note that ystack should be after system path entries because it contains fallback impls for MacOS such as basepath and sha256sum.

However you're recommended to override default binaries for some commands. Run:

y-yarn help
y-npx help
hash -r
y-bin-default ensure

Why

Y-stack is higly opinionated: It says "registry" to refer to a Docker registry with a particular setup, while "knative" refers to an installer that combines Knative modules. The point with being opinionated is that registry and knative work well together.

The stack supports local development ("inner development loop") using Skaffold with local and remote clusters alike. Image builds during development are in-cluster: Many dev setups transfer container images but we transfer the build context. We see builds as temporary and per-cluster, though they upon different kinds of verification can be pushed to a productiono registry. Build contexts are small and there's no need to git push to trigger a build.

Y-stack should be independent of cluster vendor, but we provide some utilities like microk8s-multipass.sh to automate cluster creation. Note that these scripts don't actually apply anything. Actually installing y-stack is done through kubectl apply -k [path(s) in this repo].

TLS certificate for https

A crucial part of modern development is to access your stack using https://. For that you need a valid SSL certificate. If your cluster has a public IP we assume that you can get real valid certificats, through for example LetsEncrypt.

If your cluster has a local IP you'll probably want something like mkcert. It needs to run locally, so y-stack can't automate much, but some assistance is provided in the form of:

  • A Kustomize base for ingress at ingress-tls-local which as base for actual ingress resources helps with the transfer of a local cert to in-cluster Ingress.
  • A utility tls-local.sh to (re)generate certs for all host: entries in any ingress resource.

Unless you have a local DNS that gets updated with your ingress entries, you'll probably also want to update your /etc/hosts file. For that we use https://github.com/solsson/k8s-ingress-hosts/releases

Installation

Clone this repo to your Yolean workspace.

Add YSTACK_HOME env pointing to the root of y-stack, and $YSTACK_HOME/bin to path.

Dependencies

Y-stack doesn't have a CLI, but depends on assorted tooling from the Kubernetes community. To ease the burden of maintaining a dev stack, there's tooling to keep these binaries updated. If a requred binary exists in path, a version check is performed. If not it is downloaded and placed in $YSTACK_HOME/bin.

Namespace

Why do we name the stack namespace with a stage, for example ystack-dev? Still doesn't guard against mistakes, because kubectl -n ystack-dev delete pod

Cluster setup

  1. Provision
    • Look for bins named y-cluster-provision-*
    • ... but note that all of them are hacks that you'll probably need to understand
    • Provision rougly means setting up a new cluster for:
      • Kubectl access with current (or default) KUBECONFIG
      • Current user can configure rbac
      • A default namespace selected (not used yet)
      • Creates namespace ystack
      • Set up container runtime to support insecure pull from builds-registry.ystack.svc.cluster.local
    • After provision the cluster should be ready to run Y-stack coponents. Unlike scripts, paths that support apply -k should be declarative resource config that you can re-apply and extend.
  2. Converge kubectl apply -k converge-generic/
    • The converge-generic kustomization sets namespace: ystack, but individual features only set namespace if thery have configuration that depend on a fixed namespace
  3. Forward
    • port-forward the dev stack for local development
    • y-kubefwd svc -n ystack
  4. Test "inner development loop"
    • Check that CLIs are ok using y-buildctl and y-skaffold
    • In ./examples/basic-dev-inner-loop/ run skaffold dev

Tooling

Y-stack is opinionated on Kubernetes devops tooling as well. We therefore download some CLIs to the aforementioned PATH entry.

CI test suite

docker volume rm ystack_admin 2> /dev/null || true
./test.sh

Multi-arch runner build (beta)

YSTACK_GIT_COMMIT=$(git rev-parse --verify HEAD 2>/dev/null || echo '')
if [[ ! -z "$YSTACK_GIT_COMMIT" ]]; then
GIT_STATUS=$(git status --untracked-files=no --porcelain=v2)
if [[ ! -z "$GIT_STATUS" ]]; then
YSTACK_GIT_COMMIT="$YSTACK_GIT_COMMIT-dirty"
fi
fi
SOURCE_DATE_EPOCH=0 docker buildx build --progress=plain --platform=linux/amd64,linux/arm64/v8 --output type=image,name=yolean/ystack-runner:$YSTACK_GIT_COMMIT,oci-mediatypes=true,push=true --sbom=false --provenance=false -f runner.Dockerfile .

Dogfooding build

PLATFORMS=linux/amd64,linux/arm64/v8 y-build . --opt filename=runner.Dockerfile

Development

For port-forward uou need cat /etc/hosts | grep 127.0.0 | grep cluster.local to have something like:

127.0.0.1	builds-registry.ystack.svc.cluster.local
127.0.0.1	buildkitd.ystack.svc.cluster.local
127.0.0.1	monitoring.ystack.svc.cluster.local

OR use kubefwd which manages the hosts file automatically

y-kubefwd --context=local svc -n ystack -m 443:59443

Test that kubefwd (or docker stack port forwarding) works using:

curl http://builds-registry.ystack.svc.cluster.local/v2/

About

Kubernetes platform-as-a-platform

Resources

Stars

7 stars

Watchers

2 watching

Forks

Releases

Packages

Used by

Contributors

Languages