Skip to content
Browse Gluu Flex 6.0.0

Amazon EKS


tags:

  • administration
  • installation
  • helm
  • EKS
  • Amazon Web Services
  • AWS

#System Requirements

The resources may be set minimally to the below:

  • 8-13 GB RAM based on the services deployed
  • 8-11 CPU cores based on the services deployed
  • 50GB hard-disk

Use the listing below for a detailed estimation of the minimum required resources. The table contains the default resources recommendation per service. Depending on the use of each service the resources need may be increase or decrease.

ServiceCPU UnitRAMDisk SpaceProcessor TypeRequired
Auth server2.52.5GBN/A64 BitYes
config - job0.30.3GBN/A64 BitYes on fresh installs
persistence - job0.30.3GBN/A64 BitYes on fresh installs
auth-key-rotation0.30.3GBN/A64 BitNo [Strongly recommended]
cleanup - job0.30.3GBN/A64 BitNo [Strongly recommended]
fido20.50.5GBN/A64 BitNo
scim11GBN/A64 BitNo
nginx11GBN/A64 BitNo
config-api11GBN/A64 BitNo
casa0.50.5GBN/A64 BitNo
admin-ui22GBN/A64 BitNo
link0.51GBN/A64 BitNo
saml0.51GBN/A64 BitNo
kc-scheduler - job0.30.3GBN/A64 BitNo

Releases of images are in style 0.0.0-nightly or x.y-z-1

#Initial Setup

  1. Before initiating the setup, please obtain an SSA for Flex trial, after which you will issued a JWT.

  2. Install aws cli

  3. Configure your AWS user account using aws configure command. This makes you able to authenticate before creating the cluster. Note that this user account must have permissions to work with Amazon EKS IAM roles and service linked roles, AWS CloudFormation, and a VPC and related resources

  4. Install kubectl

  5. Install eksctl

  6. Create cluster using eksctl such as the following example:

    eksctl create cluster --name gluu-cluster --nodegroup-name gluu-nodes --node-type NODE_TYPE --nodes 2  --managed --region REGION_CODE

    You can adjust node-type and nodes number as per your desired cluster size

  7. To be able to attach volumes to your pod, you need to install the Amazon EBS CSI driver

  8. Install Helm3

  9. Create gluu namespace where our resources will reside

    kubectl create namespace gluu

#Gluu Flex Installation using Helm

  1. Install Nginx-Ingress, if you are not using Istio ingress

    helm repo add ingress-nginx https://kubernetes.github.io/ingress-nginx
    helm repo add stable https://charts.helm.sh/stable
    helm repo update
    helm install nginx ingress-nginx/ingress-nginx
  2. Create a file named override.yaml and add changes as per your desired configuration:

    • FQDN/domain is not registered:

      Get the Loadbalancer address:

      kubectl get svc nginx-ingress-nginx-controller --output jsonpath='{.status.loadBalancer.ingress[0].hostname}'

      Add the following yaml snippet to your override.yaml file:

      config:
          configmap:
              lbAddr: http:// #Add LB address from previous command
    • FQDN/domain is registered:

      Add the following yaml snippet to your override.yaml file:

      global:
          fqdn: demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
      config:
          configmap:
              lbAddr: http:// #Add LB address from previous command
      nginx:
        ingress:
            enabled: true
            path: /
            hosts:
            - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
            tls:
            - secretName: tls-certificate
              hosts:
              - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
    • PostgreSQL for persistence storage

      In a production environment, a production grade PostgreSQL server should be used such as Amazon RDS

      For testing purposes, you can deploy it on the EKS cluster using the following commands:

      wget https://raw.githubusercontent.com/GluuFederation/flex/v6.0.0/automation/pgsql.yaml
      kubectl apply -f pgsql.yaml

      Add the following yaml snippet to your override.yaml file:

      config:
        configmap:
          cnSqlDbName: gluu
          cnSqlDbPort: 5432
          cnSqlDbDialect: pgsql
          cnSqlDbHost: postgresql.gluu.svc
          cnSqlDbUser: postgres
          cnSqlDbTimezone: UTC
          cnSqldbUserPassword: Test1234#
    • MySQL for persistence storage

      In a production environment, a production grade MySQL server should be used such as Amazon RDS

      For testing purposes, you can deploy it on the EKS cluster using the following commands:

      wget https://raw.githubusercontent.com/GluuFederation/flex/v6.0.0/automation/mysql.yaml
      kubectl apply -f mysql.yaml

      Add the following yaml snippet to your override.yaml file:

      config:
        configmap:
          cnSqlDbName: gluu
          cnSqlDbPort: 3306
          cnSqlDbDialect: mysql
          cnSqlDbHost: mysql.gluu.svc
          cnSqlDbUser: root
          cnSqlDbTimezone: UTC
          cnSqldbUserPassword: Test1234#

      So if your desired configuration has FQDN and MySQL, the final override.yaml file will look something like that:

      global:
        fqdn: demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
      nginx-ingress:
        ingress:
            path: /
            hosts:
            - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu
            tls:
            - secretName: tls-certificate
              hosts:
              - demoexample.gluu.org #CHANGE-THIS to the FQDN used for Gluu  
      config:
        configmap:
          lbAddr: http:// #Add LB address from previous command
          cnSqlDbName: gluu
          cnSqlDbPort: 3306
          cnSqlDbDialect: mysql
          cnSqlDbHost: mysql.gluu.svc
          cnSqlDbUser: root
          cnSqlDbTimezone: UTC
          cnSqldbUserPassword: Test1234#
  3. Install Gluu Flex

    After finishing all the tweaks to the override.yaml file, we can use it to install gluu flex.

    helm repo add gluu-flex https://docs.gluu.org/charts
    helm repo update
    helm install gluu gluu-flex/gluu -n gluu -f override.yaml

#Configure Gluu Flex

You can use the Janssen TUI to configure Flex components. The TUI calls the Config API to perform ad hoc configuration.

We use analytics cookies to measure which pages are useful, so we can improve them. They are only set if you accept. Essential cookies needed for the site to work are always on. See our privacy policy.