Release of Cozystack 1.4, an open PaaS platform built on Kubernetes

The release of the free PaaS platform Cozystack 1.4, based on Kubernetes, is now available. The project aims to provide a ready-to-use platform for hosting providers and a framework for building private and public clouds. The platform installs directly on servers and covers all aspects of preparing the infrastructure for delivering managed services. Cozystack allows for launching and providing Kubernetes clusters, databases, and virtual machines. The platform's code is available on GitHub and is distributed under the Apache-2.0 license.

The platform includes a free implementation of the network infrastructure (fabric) based on Kube-OVN and utilizes Cilium for organizing the service network, with MetalLB for announcing services externally. Storage is implemented on LINSTOR, offering the use of ZFS as the base layer for storage and DRBD for replication. There is a pre-configured monitoring stack based on VictoriaMetrics and Grafana. To launch of virtual machines KubeVirt technology is used, which allows running traditional virtual machines directly in Kubernetes containers and already has all the necessary integrations with Cluster API for launching managed Kubernetes clusters within a 'bare metal' Kubernetes cluster. Within the platform, you can deploy Kafka, FerretDB, PostgreSQL, Cilium, Grafana, Victoria Metrics, and other services with a click.

Main innovations in Cozystack 1.4.0:

  • A new management interface has been introduced, based on the cozystack-ui project. The old openapi-ui and BFF stack has been replaced with a frontend using React 19 and TypeScript, which interacts directly with the Kubernetes API. Additionally, the interface now supports dynamic VNC WebSocket URLs for virtual machines, runtime branding through ConfigMap, reading ApplicationDefinition for the application catalog, and redirecting old addresses /openapi-ui/*.
  • Persistent storage has been implemented for worker nodes in tenant clusters. The virtual machines of worker nodes now use PVC disks through KubeVirt dataVolumeTemplates instead of emptyDisk. As a result, kubelet certificates, kubeconfig, and containerd state are preserved after the virtual machine restarts. The ephemeralStorage field has been renamed to diskSize, and a storageClass setting has been added at the NodeGroup level. During migration, old values are automatically converted.
  • A new resource presets scheme has been added, similar to virtual machine types offered by cloud providers. Presets are described in the format ., where series t1, c1, s1, u1, and m1 define different CPU and memory ratios, while sizes range from nano to 4xlarge. A total of 40 options are available. The old preset names are preserved as deprecated aliases and automatically migrate without altering the actual CPU and memory limits.
  • The declarative backup system for managed applications has been expanded. The backupstrategy controller now includes strategies for PostgreSQL, MariaDB, ClickHouse, and FoundationDB. BackupClass, Plan, BackupJob, and RestoreJob are supported, along with scheduled and on-demand backups, in-place recovery, and recovery to a copy. Data is exported to S3-compatible object storage, and credentials are passed via Kubernetes Secret.
  • An optional system package hami with HAMi 2.8.1 has been added for shared access to NVIDIA GPU in tenant clusters. User workloads can request resources from nvidia.com/gpu, nvidia.com/gpumem, and nvidia.com/gpucores, allowing vGPU to be distributed among multiple pods. Enabling it is done through the hami.enabled parameter and requires NVIDIA GPU Operator.
  • A unified setting publishing.proxyProtocol has been introduced to enable the PROXY protocol on hosts with ingress-nginx. When activated, Ouroboros is automatically deployed to resolve the hairpin-NAT issue for requests from the cluster to its public names. There is an addon for tenant clusters: addons.ouroboros.enabled.
  • The cozystack-operator now includes settings for HelmRelease generation: interval, retry interval, install timeout, upgrade timeout, and max history. The retry strategy has been changed to RetryOnFailure, and a timeout for specific applications can be specified through the annotation release.cozystack.io/helm-install-timeout. This resolves several issues during cold starts of tenant clusters.
  • For the worker nodes of the tenant Kubernetes, kubelet resource reservations for CPU and memory are automatically calculated. The cluster-autoscaler annotations now reflect the allocated resources rather than the total CPU and memory.
  • Core platform components have been updated: Talos 1.13.0, cert-manager 1.20.2, Cilium 1.19.3, NVIDIA GPU Operator 26.3.1, etcd-operator 0.4.3, KubeVirt 1.8.2, cozy-proxy 0.3.0, linstor-csi 1.10.6. New packages HAMi 2.8.1 and Ouroboros 0.7.2 have been added.
  • Diagnostics have been improved: cozyreport now collects information about Flux, cert-manager, the host environment, Application, ApplicationDefinition, and Tenant resources, while also creating a summary.txt with a brief overview of current issues. Grafana dashboards and data collection rules for GPU monitoring have been added.
  • Bug fixes have been made in MongoDB, Kafka, tenant Kubernetes bootstrap, etcd, Velero, Kamaji, LINSTOR, SeaweedFS, Harbor, objectstorage-controller, API, and other components. An IDOR vulnerability has been fixed in the handlers for TenantNamespace Get and Watch in the API.

When updating, note that worker nodes in tenant clusters will be sequentially replaced once due to the transition to persistent PVC disks. KubeVirt virtual machines running prior to the platform update will require a cold reboot after migrating to KubeVirt 1.8.2, as live migration of old virt-launcher processes may fail due to the QEMU version change. Additionally, PostgreSQL parameters are now typed and verified against a denylist, and cert-manager 1.20 runs containers with UID/GID 65532 by default.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster