DIGIT Urban
PlatformDomainsAcademyDesign SystemFeedback
v2.3
v2.3
  • DIGIT
  • Training Event
  • Architecture
  • Roadmap
  • Release Notes
    • MDMS Configuration & Service Build Updates
    • FSM Release Notes
    • HRMS Release Notes
    • EDCR Release Notes
    • Bill Amendment Release Notes
  • Products & Modules
    • mCollect (MCS)
      • mCollect Master Data Templates
        • Service Category
        • Service Sub Category
        • Service Sub Category GL Code Mapping
      • mCollect Roadmap
      • mCollect User Manual
        • MCS Citizen User Manual
        • MCS Employee User Manual
    • Trade License (TL)
      • TL Brochure
      • TL Roadmap
      • TL Module Functional Specifications
      • TL Workflows
      • TL Implementation Guide
      • TL Master Data Templates
        • Trade Type
        • Trade Sub Type
        • Trade Category
        • Trade License Fee
        • Structure Sub Type
        • Structure Type
        • Trade License Document Attachment
      • TL Service Configuration
      • TL User Manual
        • Citizen User Manual
        • Employee User Manual
      • TL Demo Script
    • Public Grievances & Redressal (PGR)
      • PGR Brochure
      • PGR Roadmap
      • PGR Module Functional Specifications
      • PGR Workflows
      • PGR Master Data Templates
        • Grievance Type
        • Grievance Sub Type
      • PGR Service Configuration
        • PGR Migration
      • PGR Implementation Guide
      • PGR User Manual
        • Complaint Types List
        • Employee User Manual
        • Citizen User Manual
      • PGR Demo Script
    • Property Tax
      • PT Brochure
      • PT Roadmap
      • PT Module Functional Specifications
      • PT Workflows
      • PT Implementation Guide
      • PT Master Data Templates
        • Mutation Fee
        • Rebate Rates
        • Penalty Rates
        • Interest Rates
        • Tax Rates
        • Unit Rates
        • Special Category Documents
        • Owner Special Category
        • Ownership Sub Category
        • Ownership Category
        • Usage Category Detail
        • Road Type
        • Construction Type
        • Property Type
        • Property Sub Type
        • Usage Category Major
        • Usage Category Minor
        • Usage Category Sub Minor
      • PT Data Migration
      • PT User Manual
        • Citizen User Manual
        • Employee User Manual
    • Water & Sewerage (W&S)
      • W&S Module Functional Specifications
      • Sewerage Charges Master Data Templates
        • Sewerage Rates
        • Sewerage Penalty Rates
        • Sewerage Interest Rates
      • Water Charges Master Data Templates
        • Water Rates (Metered)
        • Pipe Size Types
        • Water Source Types
        • Water Rates (Non-Metered)
        • Water Penalty Rates
        • Water Interest Rates
      • W&S User Manual
        • W&S Citizen User Manual
        • W&S Employee User Manual
    • Online Building Plan Approval System (OBPAS)
      • OBPAS Module Functional Specifications
      • OBPAS Master Data Templates
        • Fee Structure
        • NOC Departments
        • Stakeholders Type
        • List Of Services
        • Service-Wise Documents
        • Building Occupancy
        • Building Sub Occupancy
        • Building Usage
        • Inspection Checklist
        • Town Planning Schemes
      • OBPAS Brochure
      • OBPAS User Manual
        • OBPAS Citizen User Manual
        • OBPAS Employee User Manual
    • Faecal Sludge Management (FSM)
      • FSM Service Configuration
      • FSM Calculator v1.0
      • FSM Vendor Registry v1.0
      • FSM Vehicle Registry v1.0
      • FSM User Manual
        • Citizen User Manual
        • Employee User Manual
        • DSO User Manual
        • Septage Treatment Plant Operator User Manual
    • Finance
      • Finance Implementation Guide
      • Finance User Manual
        • Employee User Manual
        • Admin User Manual
        • Finance Reports Manual
      • Finance Module Functional Specifications
      • Finance Master Data Templates
        • Bank Account
        • Chart Of Accounts
        • Funds
        • Function
        • Contractors
        • Suppliers
        • Schemes
        • Sub Schemes
        • Banks
        • Bank Branch
        • Deduction
        • Opening Balances
        • Sub Ledger Category
        • Sub Ledger Master
    • Fire NOC
      • Fire NOC Master Data Templates
        • Building Usage Type
        • Building Sub Usage Type
        • Fire Station Master
        • Areas Served Master
        • Fire Station Mapping
        • Fire NOC Fee
      • Fire NOC User Manual
        • Fire NOC Citizen User Manual
        • Fire NOC Employee User Manual
    • DIGIT Service Configuration
      • Core Services
        • Workflow Services
        • Location Services
        • User Services
        • Access Control Services
        • PDF Generation Service
        • MDMS (Master Data Management Service)
        • Payment Gateway Service
        • User Session Management In DIGIT
        • Indexer Service
        • URL Shortening Service
      • Business Service
        • Bill Amendment
      • Municipal Service
        • PGR Services 2.0
          • PGR Migration
        • Trade-License Service
        • BPA Service
          • BPA Service Setup and Configuration
          • BPA Calculator Service
          • Land Services
          • Noc Services
      • Utilities
    • Product FAQs
  • Configuration Guide
    • Git Repos
    • Setting up DIGIT
      • Configuring InfraOps
      • Setting up DIGIT Environment
      • Email And SMS Setup
      • FileStore Setup
      • Setting Up SSL Certificate
      • Periodic Log Cleanup
    • Setting up Master Data
      • MDMS Overview
      • Configuring Tenants
      • Configuring Master Data
      • Adding New Master
      • State Level Vs City Level Master
    • Master Data Collection Templates
      • Environment Setup
        • State Level Setup
          • Tenants Information
          • SMS Account Configuration
          • Email Account Configuration
          • Google Play Store Account
          • Payment Gateway Configuration
          • POS Integration Configuration
          • Domain Name Configuration
          • SSL Configuration
          • ULB Departments
          • ULB Designations
          • Localization
          • Google Map Configuration
        • ULB Level Setup
          • Boundary Hierarchies
          • Boundary Data
          • Cross Hierarchy Mapping
          • ULB Bank Accounts
      • Module Setup
        • Web Portals Templates
          • State Portal
          • ULB Portal
        • HRMS Data Templates
          • User Roles
          • System Users
        • Billing And Payments Data Templates
          • Tax Heads
          • Receipt Format
          • Demand Bill Format
        • DSS Data Templates
          • KPI Acceptance
        • Workflow Data Templates
          • Workflow Actions
          • Workflow Levels
          • Workflow Process
          • Workflow Notifications
        • Common Configuration Details
          • Standard Document List
          • Service Document Mapping
          • Checklist
          • Configuring Data FAQs
    • Configuring Workflows
      • Setting Up Workflows
      • Configuring Workflows For An Entity
    • Configuring Services
      • API Dos and Don'ts
      • Setting Up Service Locally
      • Configuring New Reports
        • Types Of Reports Used In Report Service
        • Impact Of Heavy Reports On Platform
      • Customizing PDF Notices And Certificates
        • Integration Of PDF In UI For Download And Print PDF
        • Customizing PDF Receipts & Certificates
    • Persister Configuration
    • Indexer Configuration
    • Setting up a Language
      • Adding New Language
      • Setting Up Default Language For SMS & Emails
    • Configuring Localization
      • Setup Base Product Localization
      • Configure SMS and Email
    • Setting Up SMS Gateway
      • Using The Generic GET & POST SMS Gateway Interface
    • Configuration FAQs
    • Setting Up eDCR Service
    • Adding Roles To System
    • Mapping Roles With APIs
    • DSS Configuration And Setup
      • Building New Dashboards
    • Setting Up Finance Service
    • Adding New APIs For Access
    • Deployment Of App on Play Store
  • Customization Guide
    • Frontend/UI
    • DIGIT Customization
      • API Do's & Don'ts
      • Writing A New Customer
      • Enhancing Existing Service
  • Deployment Guide
    • Setup Requirements
      • Tech Enablement Training - Essential Skills and Pre-requisites
      • DIGIT Rollout Program Governance
      • DevOps Skills Requirements
      • Infra Requirements
      • Team Composition for DIGIT Implementation
      • Infra Best Practices
      • Operational Best practices
      • Why Kubernetes for DIGIT
    • Supported Clouds
      • Google Cloud
      • Azure
      • AWS
      • VSphere
      • SDC
      • NIC
    • Deployment - Key Concepts
      • Security Practices
      • CI/CD
      • Readiness & Liveness
      • Resource Requests & Limits
    • Understanding ERP Stack
      • ERP Monolithic Architecture
      • ERP Hybrid Architecture
      • ERP Coexistence Architecture
      • APMDP-HYBRID-INFRA-ARCHITECTURE
      • eGov SmartCity eGovernance Suite
      • ERP Deployment Process
      • ERP Release Process
      • ERP User Guide
    • Deploying DIGIT Services
      • Deployment Architecture
      • Routing Traffic
      • Backbone Deployment
    • Troubleshooting
      • Distributed Tracing
      • Logging
      • Monitoring & Alerts
  • Training Resources
    • Training Videos
  • Partner Support
    • eGov Enablement Support for DIGIT
    • Troubleshooting Guide
Powered by GitBook

​All content on this page by eGov Foundation is licensed under a Creative Commons Attribution 4.0 International License.

On this page
  • What to know when deploying Kubernetes on SDC
  • Automating the deployment process
  • Choosing a network solution
  • Choosing a storage solution
  • Handle security and authentication
  • Other Considerations

Was this helpful?

Edit on Git
Export as PDF
  1. Deployment Guide
  2. Supported Clouds

SDC

State Data Centres with On-Premise Kubernetes Clusters

PreviousVSphereNextNIC

Last updated 4 years ago

Was this helpful?

What to know when deploying Kubernetes on SDC

Running Kubernetes on-premise gives a cloud-native experience or SDC becomes cloud-agnostic when it comes to the experience of Deploying DIGIT.

Whether States have their own on-premise data centre, have decided to forego the various managed cloud solutions, there are few things one should know when getting started with on-premise K8s.

One should be familiar with Kubernetes and one should know that the consists of the Kube-apiserver, Kube-scheduler, Kube-controller-manager and an ETCD datastore. For managed cloud solutions like or it also includes the cloud-controller-manager. This is the component that connects the cluster to the external cloud services to provide networking, storage, authentication, and other feature support.

To successfully deploy a bespoke Kubernetes cluster and achieve a cloud-like experience on SDC, one need to replicate all the same features you get with a managed solution. At a high-level this means that we probably want to:

  • Automate the deployment process

  • Choose a networking solution

  • Choose a storage solution

  • Handle security and authentication

Let us look at each of these challenges individually, and we’ll try to provide enough of an overview to aid you in getting started.

Automating the deployment process

Using a tool like an ansible can make deploying Kubernetes clusters on-premise trivial.

When deciding to manage your own Kubernetes clusters, we need to set up a few proof-of-concept (PoC) clusters to learn how everything works, perform performance and conformance tests, and try out different configuration options.

After this phase, automating the deployment process is an important if not necessary step to ensure consistency across any clusters you build. For this, you have a few options, but the most popular are:

  • ****: a low-level tool that helps you bootstrap a minimum viable Kubernetes cluster that conforms to best practices

  • : an ansible playbook that helps deploy production- ready clusters

If you already using ansible, kubespray is a great option otherwise we recommend writing automation around kubeadm using your preferred playbook tool after using it a few times. This will also increase your confidence and knowledge in the tooling surrounding Kubernetes.

Choosing a network solution

When designing clusters, choosing the right container networking interface (CNI) plugin can be the hardest part. This is because choosing a CNI that will work well with an existing network topology can be tough. Do you need BGP peering capabilities? Do you want an overlay network using vxlan? How close to bare-metal performance are you trying to get?

Choosing a storage solution

For a cloud-like experience, you’ll need to add a plugin to dynamically create persistent volume objects that match the user’s persistent volume claims. You can use dynamic provisioning to reclaim these volume objects after a resource has been deleted.

Handle security and authentication

As anyone familiar with security knows, this is a rabbit-hole. You can always make your infrastructure more secure and should be investing in continual improvements.

Including different Kubernetes plugins can help build a secure, cloud-like experience for your users

When designing on-premise clusters you’ll have to decide where to draw the line. To really harden your cluster’s security you can add plugins like:

Other Considerations

Hope this has given you a good idea of deploying, networking, storage, and security for you to take the leap into deploying your own on-premise Kubernetes clusters. Like we mentioned above, the team will want to build proof-of-concept clusters, run conformance and performance tests, and really become experts on Kubernetes if you’re going to be using it to run DIGIT on production.

We’ll leave you with a few other things the team should be thinking of:

  • Externally backing up Kubernetes YAML, namespaces, and configuration files

  • Running applications across clusters in an active-active configuration to allow for zero-downtime updates

  • Running game days like deleting the CNI to measure and improve time-to-recovery

There are a lot of articles that compare the various CNI provider solutions (calico, weave, flannel, kube-router, etc.) that are must-reads like the article. We usually recommend Project Calico for its maturity, continued support, and large feature set or flannel for its simplicity.

For ingress traffic, you’ll need to pick a load-balancer solution. For a simple configuration, you can use MetalLB, but if you’re lucky enough to have F5 hardware load-balancers available we recommend checking out the . The controller supports connecting your network plugin to the F5 either through either vxlan or BGP peering. This gives the controller full visibility into pod health and provides the best performance.

Kubernetes provides a number of . If you’re going on-premise you’ll probably want to use network-attached storage (NAS) option to avoid forcing pods to be pinned to specific nodes.

Pure Storage has a great example helm chart, the , that provides smart provisioning although it only works for Pure Storage products.

: provides the underlying secure communication channel, and manages authentication, authorization, and encryption of service communication at scale

: is a user-space kernel, written in Go, that implements a substantial portion of the Linux system surface

: secure, store and tightly control access to tokens, passwords, certificates, encryption keys for protecting secrets and other sensitive data

For user authentication, we recommend checking out which will integrate with an existing authentication provider. If you’re already using Github teams to then this could be a no-brainer.

All content on this page by is licensed under a .

control plane
Google’s Kubernetes Engine (GKE)
Azure’s Kubernetes Service (AKS)
kubeadm
kubespray
benchmark results of Kubernetes network plugins
K8s F5 BIG-IP Controller
included storage volume plugins
Pure Service Orchestrator (PSO)
istio
gVisor
vault
guard
​
eGov Foundation
Creative Commons Attribution 4.0 International License
Creative Commons License