Preset system
A provisioner preset is a named recipe — "install these stacks on every cluster" — that operators reference at edge create time. Two preset properties drive the cluster's production posture:
Profile
profile is edge or prod:
- edge — single-replica, lightweight storage, no PDBs. Fits 3-node clusters with constrained resources (8 vCPU / 16 GiB / 250 GB disks each).
- prod — multi-replica HA on stateless components, podAntiAffinity required, PDBs enabled, larger storage and retention budgets. Targets 3+ node clusters with HA-grade hardware (32 GiB+ RAM per node, 1 TB+ OSD disks).
Built-in presets:
| Preset | Profile |
|---|---|
| DT Edge Platform (private bootstrap) | prod |
| Standard Edge Instance | edge |
| Data Platform Edge | edge |
Operators with HA-grade hardware clone the public presets and
flip profile: prod.
Sensitive secrets
Each preset row carries an encrypted secret_vars column that
stores admin passwords for the services it installs:
- Grafana admin
- Harbor admin
- OpenSearch admin
- Prometheus / Alertmanager basic-auth (when ingress auth is on)
- fluent-bit local OpenSearch (always equals the OpenSearch admin password — coupled propagation keeps them in sync)
Passwords are auto-generated at preset create time (24-char
shell-safe random). They never live in the plaintext
stacks_config column. The reveal dialog
(How to → View preset admin passwords)
is the only path to plaintext access; the audit log captures
that someone revealed but masks the values themselves.
How vars reach a stack
When an edge is provisioned from a preset, the provisioner expands the preset into a per-stack vars map by layering:
- Stack defaults from the catalog
- Preset's
stacks_config[stack].vars(plaintext) - Preset's
secret_vars[stack](decrypted at resolve time) cluster_profile(injected on every stack)- Operator's
preset_var_overridesfrom the create request (highest priority)
Each stack template reads cluster_profile and adjusts
replicas, antiAffinity strictness, PDBs, storage defaults, and
retention budgets accordingly.
Why it's designed this way
- Discoverable defaults are dangerous. Earlier preset
versions hardcoded
Harbor12345/MyStrongP@ss1in the public column; every cluster spawned from the preset got the same password. Auto-generation per preset eliminates the shared-default vector. - Coupled secrets stay in lockstep. fluent-bit's local OpenSearch authentication needs the same password the OpenSearch admin user holds. Independent randoms break log shipping; coupling propagates the source value to the target before encryption.
- One-knob HA posture. Operators choosing a preset make
one decision (
edgeorprod); every stack falls in line behind it.