Skip to main content

Preset system

A provisioner preset is a named recipe — "install these stacks on every cluster" — that operators reference at edge create time. Two preset properties drive the cluster's production posture:

Profile​

profile is edge or prod:

  • edge — single-replica, lightweight storage, no PDBs. Fits 3-node clusters with constrained resources (8 vCPU / 16 GiB / 250 GB disks each).
  • prod — multi-replica HA on stateless components, podAntiAffinity required, PDBs enabled, larger storage and retention budgets. Targets 3+ node clusters with HA-grade hardware (32 GiB+ RAM per node, 1 TB+ OSD disks).

Built-in presets:

PresetProfile
DT Edge Platform (private bootstrap)prod
Standard Edge Instanceedge
Data Platform Edgeedge

Operators with HA-grade hardware clone the public presets and flip profile: prod.

Sensitive secrets​

Each preset row carries an encrypted secret_vars column that stores admin passwords for the services it installs:

  • Grafana admin
  • Harbor admin
  • OpenSearch admin
  • Prometheus / Alertmanager basic-auth (when ingress auth is on)
  • fluent-bit local OpenSearch (always equals the OpenSearch admin password — coupled propagation keeps them in sync)

Passwords are auto-generated at preset create time (24-char shell-safe random). They never live in the plaintext stacks_config column. The reveal dialog (How to → View preset admin passwords) is the only path to plaintext access; the audit log captures that someone revealed but masks the values themselves.

How vars reach a stack​

When an edge is provisioned from a preset, the provisioner expands the preset into a per-stack vars map by layering:

  1. Stack defaults from the catalog
  2. Preset's stacks_config[stack].vars (plaintext)
  3. Preset's secret_vars[stack] (decrypted at resolve time)
  4. cluster_profile (injected on every stack)
  5. Operator's preset_var_overrides from the create request (highest priority)

Each stack template reads cluster_profile and adjusts replicas, antiAffinity strictness, PDBs, storage defaults, and retention budgets accordingly.

Why it's designed this way​

  • Discoverable defaults are dangerous. Earlier preset versions hardcoded Harbor12345 / MyStrongP@ss1 in the public column; every cluster spawned from the preset got the same password. Auto-generation per preset eliminates the shared-default vector.
  • Coupled secrets stay in lockstep. fluent-bit's local OpenSearch authentication needs the same password the OpenSearch admin user holds. Independent randoms break log shipping; coupling propagates the source value to the target before encryption.
  • One-knob HA posture. Operators choosing a preset make one decision (edge or prod); every stack falls in line behind it.

See also​