Go to file
Felipe Monteiro 0ca7d64824 trivial: Remove unused method from secrets_manager module
This removes an unusued method _get_encrypted_secret which is
really a duplicate of get_encrypted_data, which is used.

Change-Id: Ic7db09037a7da7ac9ca313365fd51281fbf5884a
2018-06-16 06:31:11 +00:00
2018-06-09 00:25:15 +00:00
2017-08-15 16:11:35 -04:00
2018-03-28 13:06:46 -04:00
2018-05-10 22:25:14 +01:00
2018-06-08 09:17:21 -05:00
2018-04-24 22:34:49 +01:00
2017-06-26 16:57:50 -07:00
2018-06-07 09:35:10 -04:00
2018-06-10 12:19:46 +00:00

Deckhand

Doc Status

Deckhand is a storage service for YAML-based configuration documents, which are managed through version control and automatically validated. Deckhand provides users with a variety of different document types that describe complex configurations using the features listed below.

Find more documentation for Deckhand on Read the Docs.

Core Responsibilities

  • layering - helps reduce duplication in configuration by applying the notion of inheritance to documents
  • substitution - provides separation between secret data and other configuration data for security purposes and reduces data duplication by allowing common data to be defined once and substituted elsewhere dynamically
  • revision history - maintains well-defined collections of documents within immutable revisions that are meant to operate together, while providing the ability to rollback to previous revisions
  • validation - allows services to implement and register different kinds of validations and report errors
  • secret management - leverages existing OpenStack APIs -- namely Barbican -- to reliably and securely store sensitive data

Getting Started

For more detailed installation and setup information, please refer to the Getting Started guide.

Testing

Automated Testing

To run unit tests using sqlite, execute:

$ tox -epy27
$ tox -epy35

against a py27- or py35-backed environment, respectively. To run individual unit tests, run:

$ tox -e py27 -- deckhand.tests.unit.db.test_revisions

for example.

To run functional tests:

$ tox -e functional

You can also run a subset of tests via a regex:

$ tox -e functional -- gabbi.suitemaker.test_gabbi_document-crud-success-multi-bucket

Integration Points

Deckhand has the following integration points:

Note

Currently, other database back-ends are not supported.

Though, being a low-level service, has many other UCP services that integrate with it, including:

  • Drydock is orchestrated by Shipyard to perform bare metal node provisioning.
  • Promenade is indirectly orchestrated by Shipyard to configure and join Kubernetes nodes.
  • Armada is orchestrated by Shipyard to deploy and test Kubernetes workloads.

Further Reading

Undercloud Platform (UCP).

Description
A configuration management service with support for secrets.
Readme 8.9 MiB
Languages
Python 97.5%
Shell 1.9%
Makefile 0.5%