Node Management
Create Node for Parallel Development
Prerequisits
Install the cluster-wide Amazon Load Balancer controller.
Create node
First create a node config file in the project root folder <node-id>.node.yaml:
id: <node-id>
version: 1.0.0
channel: dev
kind: prod
databases:
paraflow: sqlite
versions:
platform: 0.35.0-rc
paranet: 2.16.0-colab
paraflow: 3.8.0-colab
Create a load-balancer service file public-nlb.yaml:
apiVersion: v1
kind: Service
metadata:
name: public-nlb
annotations:
service.beta.kubernetes.io/aws-load-balancer-type: external
service.beta.kubernetes.io/aws-load-balancer-nlb-target-type: ip
service.beta.kubernetes.io/aws-load-balancer-scheme: internet-facing
spec:
type: LoadBalancer
ports:
- name: broker
port: 3131
protocol: TCP
targetPort: 3131
- name: service
port: 3132
protocol: TCP
targetPort: 3132
- name: sys
port: 3133
protocol: TCP
targetPort: 3133
- name: logstream
port: 3134
protocol: TCP
targetPort: 3134
selector:
app: paranode
- Create a k8s new namespace
- Setup node:
para kube setup - Deploy node:
para kube deploy node - Create service for developer access:
kubectl -n <namespace> create -f public-nlb.yaml
Wait for the load balancer to be ready. Check with kubectl -n <namespace> get svc public-nlb. It
will display the DNS hostname.
Create a nodelist.yaml file in the project root folder:
nodes:
- id: <node-id>
url: https://<public-alb-hostname>:3131
The nodelist.yaml file should be checked in to the project repository so developers can access.
Follow the section below to create users with developer access.
Create Users
Developers
Developers typically are created with two roles:
sys::adminrequired to upload codeagent::deployrequired to deploy already uploaded code
For nodes using Otonoma Cognito login, developers can be configured to allow auto-login using their DevKit credentials. Create a development user using Otonoma Cognito login as follows:
$ para create cognito-user --login root --insecure --role sys::admin --role agent::deploy <node-url> <devkit-username>
Project Development
Each project should contain a nodelist.yaml file in the root folder that defines the nodes where the project is deployed. Each entry includes the node's ID, the connection URL, an optional alias, and optional deployment package file.
Example file:
nodes:
- id: acme-corporate-prod
alias: prod
url: https://hq.pro-service.com
package: core.package.yaml
- id: sandbox
url: https://inernal.pro-service.com
package: core.package.yaml
If an alias is present then it can be used for node id arguments in para commands.
Package deployment
If you've configured the node with a package in nodelist.yaml, then deploy it with:
$ para deploy --devkit --insecure <node-id>
Skill requests
Skills requests can be make from the command-line. In the project root folder, use:
$ para deploy --devkit --insecure <node-id>
Secrets
Secrets are used to pass sensitive data such as passwords or API keys to an actor via environment variables. Any actor can create a secret. Only system admins and the creator can modify the secret. Only system admins, the creator, and an explicit list of readers can read a secret.
To create a secret, create a file containing the variable names and values to include in the secret. For example,
DB_USERNAME=root
DB_PASSWORD=dlemnvppqm331s
Create the secret on the node and give access to an actor:
$ para secret write --devkit --insecure <node-id> <secret-id> --reader <actor-id>
The secret now exists, and is readable by the given actor, but to include it in the actor's environment, you must add it to the package file. For example,
id: demo
version: 1.0.0
actors:
- name: demo
paraflow: demo.paraflow
secrets: ["db-login"]