<div dir="ltr"><div style="font-family:courier new,monospace;display:inline" class="gmail_default">Kevin, just one comment inline below.<br></div><div class="gmail_extra"><div class="gmail_quote">On Thu, Jun 22, 2017 at 3:33 PM, Fox, Kevin M <span dir="ltr"><<a href="mailto:Kevin.Fox@pnnl.gov" target="_blank">Kevin.Fox@pnnl.gov</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">No, I'm not necessarily advocating a monolithic approach.<br>
<br>
I'm saying that they have decided to start with functionality and accept whats needed to get the task done. Theres not really such strong walls between the various functionality, rbac/secrets/kublet/etc. They don't spawn off a whole new project just to add functionality. they do so only when needed. They also don't balk at one feature depending on another.<br>
<br>
rbac's important, so they implemented it. ssl cert management was important. so they added that. adding a feature that restricts secret downloads only to the physical nodes need them, could then reuse the rbac system and ssl cert management.<br>
<br>
Their sigs are more oriented to features/functionality (or catagories there of), not as much specific components. We need to do X. X may involve changes to components A and B.<br>
<br>
OpenStack now tends to start with A and B and we try and work backwards towards implementing X, which is hard due to the strong walls and unclear ownership of the feature. And the general solution has been to try and make C but not commit to C being in the core so users cant depend on it which hasn't proven to be a very successful pattern.<br>
<br>
Your right, they are breaking up their code base as needed, like nova did. I'm coming around to that being a pretty good approach to some things. starting things is simpler, and if it ends up not needing its own whole project, then it doesn't get one. if it needs one, then it gets one. Its not by default, start whole new project with db user, db schema, api, scheduler, etc. And the project might not end up with daemons split up in exactly the way you would expect if you prepoptomized breaking off a project not knowing exactly how it might integrate with everything else.<br>
<br>
Maybe the porcelain api that's been discussed for a while is part of the solution. initial stuff can prototyped/start there and break off as needed to separate projects and moved around without the user needing to know where it ends up.<br>
<br>
Your right that OpenStack's scope is much grater. and think that the commons are even more important in that case. If it doesn't have a solid base, every project has to re-implement its own base. That takes a huge amount of manpower all around. Its not sustainable.<br>
<br>
I guess we've gotten pretty far away from discussing Trove at this point.<br></blockquote><div><br><div style="font-family:courier new,monospace;display:inline" class="gmail_default">Please keep the conversation going.<br></div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
Thanks,<br>
Kevin<br>
______________________________<wbr>__________<br>
From: Jay Pipes [<a href="mailto:jaypipes@gmail.com">jaypipes@gmail.com</a>]<br>
Sent: Thursday, June 22, 2017 10:05 AM<br>
To: <a href="mailto:openstack-dev@lists.openstack.org">openstack-dev@lists.openstack.<wbr>org</a><br>
Subject: Re: [openstack-dev] [trove][all][tc] A proposal to rearchitect Trove<br>
<br>
On 06/22/2017 11:59 AM, Fox, Kevin M wrote:<br>
> My $0.02.<br>
><br>
> That view of dependencies is why Kubernetes development is outpacing OpenStacks and some users are leaving IMO. Not trying to be mean here but trying to shine some light on this issue.<br>
><br>
> Kubernetes at its core has essentially something kind of equivalent to keystone (k8s rbac), nova (container mgmt), cinder (pv/pvc/storageclasses), heat with convergence (deployments/daemonsets/etc), barbican (secrets), designate (kube-dns), and octavia (kube-proxy,svc,ingress) in one unit. Ops dont have to work hard to get all of it, users can assume its all there, and devs don't have many silo's to cross to implement features that touch multiple pieces.<br>
<br>
I think it's kind of hysterical that you're advocating a monolithic<br>
approach when the thing you're advocating (k8s) is all about enabling<br>
non-monolithic microservices architectures.<br>
<br>
Look, the fact of the matter is that OpenStack's mission is larger than<br>
that of Kubernetes. And to say that "Ops don't have to work hard" to get<br>
and maintain a Kubernetes deployment (which, frankly, tends to be dozens<br>
of Kubernetes deployments, one for each tenant/project/namespace) is<br>
completely glossing over the fact that by abstracting away the<br>
infrastructure (k8s' "cloud provider" concept), Kubernetes developers<br>
simply get to ignore some of the hardest and trickiest parts of operations.<br>
<br>
So, let's try to compare apples to apples, shall we?<br>
<br>
It sounds like the end goal that you're advocating -- more than anything<br>
else -- is an easy-to-install package of OpenStack services that<br>
provides a Kubernetes-like experience for application developers.<br>
<br>
I 100% agree with that goal. 100%.<br>
<br>
But pulling Neutron, Cinder, Keystone, Designate, Barbican, and Octavia<br>
back into Nova is not the way to do that. You're trying to solve a<br>
packaging and installation problem with a code structure solution.<br>
<br>
In fact, if you look at the Kubernetes development community, you see<br>
the *opposite* direction being taken: they have broken out and are<br>
actively breaking out large pieces of the Kubernetes repository/codebase<br>
into separate repositories and addons/plugins. And this is being done to<br>
*accelerate* development of Kubernetes in very much the same way that<br>
splitting services out of Nova was done to accelerate the development of<br>
those various pieces of infrastructure code.<br>
<br>
> This core functionality being combined has allowed them to land features that are really important to users but has proven difficult for OpenStack to do because of the silo's. OpenStack's general pattern has been, stand up a new service for new feature, then no one wants to depend on it so its ignored and each silo reimplements a lesser version of it themselves.<br>
<br>
I disagree. I believe the reason Kubernetes is able to land features<br>
that are "really important to users" is primarily due to the following<br>
reasons:<br>
<br>
1) The Kubernetes technical leadership strongly resists pressure from<br>
vendors to add yet-another-specialized-<wbr>feature to the codebase. This<br>
ability to say "No" pays off in spades with regards to stability and focus.<br>
<br>
2) The mission of Kubernetes is much smaller than OpenStack. If the<br>
OpenStack community were able to say "OpenStack is a container<br>
orchestration system", and not "OpenStack is a ubiquitous open source<br>
cloud operating system", we'd probably be able to deliver features in a<br>
more focused fashion.<br>
<br>
> The OpenStack commons then continues to suffer.<br>
><br>
> We need to stop this destructive cycle.<br>
><br>
> OpenStack needs to figure out how to increase its commons. Both internally and externally. etcd as a common service was a step in the right direction.<br>
><br>
> I think k8s needs to be another common service all the others can rely on. That could greatly simplify the rest of the OpenStack projects as a lot of its functionality no longer has to be implemented in each project.<br>
<br>
I don't disagree with the goal of being able to rely on Kubernetes for<br>
many things. But relying on Kubernetes doesn't solve the "I want some<br>
easy-to-install infrastructure" problem. Nor does it solve the types of<br>
advanced networking scenarios that the NFV community requires.<br>
<br>
> We also need a way to break down the silo walls and allow more cross project collaboration for features. I fear the new push for letting projects run standalone will make this worse, not better, further fracturing OpenStack.<br>
<br>
Perhaps you are referring to me with the above? As I said on Twitter,<br>
"Make your #OpenStack project usable by and useful for things outside of<br>
the OpenStack ecosystem. Fewer deps. Do one thing well. Solid APIs."<br>
<br>
I don't think that the above leads to "further fracturing OpenStack". I<br>
think it leads to solid, reusable components.<br>
<br>
Best,<br>
-jay<br>
<br>
> Thanks,<br>
> Kevin<br>
> ______________________________<wbr>__________<br>
> From: Thierry Carrez [<a href="mailto:thierry@openstack.org">thierry@openstack.org</a>]<br>
> Sent: Thursday, June 22, 2017 12:58 AM<br>
> To: <a href="mailto:openstack-dev@lists.openstack.org">openstack-dev@lists.openstack.<wbr>org</a><br>
> Subject: Re: [openstack-dev] [trove][all][tc] A proposal to rearchitect Trove<br>
><br>
> Fox, Kevin M wrote:<br>
>> [...]<br>
>> If you build a Tessmaster clone just to do mariadb, then you share nothing with the other communities and have to reinvent the wheel, yet again. Operators load increases because the tool doesn't function like other tools.<br>
>><br>
>> If you rely on a container orchestration engine that's already cross cloud that can be easily deployed by user or cloud operator, and fill in the gaps with what Trove wants to support, easy management of db's, you get to reuse a lot of the commons and the users slight increase in investment in dealing with the bit of extra plumbing in there allows other things to also be easily added to their cluster. Its very rare that a user would need to deploy/manage only a database. The net load on the operator decreases, not increases.<br>
><br>
> I think the user-side tool could totally deploy on Kubernetes clusters<br>
> -- if that was the only possible target that would make it a Kubernetes<br>
> tool more than an open infrastructure tool, but that's definitely a<br>
> possibility. I'm not sure work is needed there though, there are already<br>
> tools (or charts) doing that ?<br>
><br>
> For a server-side approach where you want to provide a DB-provisioning<br>
> API, I fear that making the functionality depend on K8s would make<br>
> TroveV2/Hoard would not only depend on Heat and Nova, but also depend on<br>
> something that would deploy a Kubernetes cluster (Magnum?), which would<br>
> likely hurt its adoption (and reusability in simpler setups). Since<br>
> databases would just work perfectly well in VMs, it feels like a<br>
> gratuitous dependency addition ?<br>
><br>
> We generally need to be very careful about creating dependencies between<br>
> OpenStack projects. On one side there are base services (like Keystone)<br>
> that we said it was alright to depend on, but depending on anything else<br>
> is likely to reduce adoption. Magnum adoption suffers from its<br>
> dependency on Heat. If Heat starts depending on Zaqar, we make the<br>
> problem worse. I understand it's a hard trade-off: you want to reuse<br>
> functionality rather than reinvent it in every project... we just need<br>
> to recognize the cost of doing that.<br>
><br>
> --<br>
> Thierry Carrez (ttx)<br>
><br>
> ______________________________<wbr>______________________________<wbr>______________<br>
> OpenStack Development Mailing List (not for usage questions)<br>
> Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" rel="noreferrer" target="_blank">OpenStack-dev-request@lists.<wbr>openstack.org?subject:<wbr>unsubscribe</a><br>
> <a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" rel="noreferrer" target="_blank">http://lists.openstack.org/<wbr>cgi-bin/mailman/listinfo/<wbr>openstack-dev</a><br>
><br>
> ______________________________<wbr>______________________________<wbr>______________<br>
> OpenStack Development Mailing List (not for usage questions)<br>
> Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" rel="noreferrer" target="_blank">OpenStack-dev-request@lists.<wbr>openstack.org?subject:<wbr>unsubscribe</a><br>
> <a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" rel="noreferrer" target="_blank">http://lists.openstack.org/<wbr>cgi-bin/mailman/listinfo/<wbr>openstack-dev</a><br>
><br>
<br>
______________________________<wbr>______________________________<wbr>______________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" rel="noreferrer" target="_blank">OpenStack-dev-request@lists.<wbr>openstack.org?subject:<wbr>unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" rel="noreferrer" target="_blank">http://lists.openstack.org/<wbr>cgi-bin/mailman/listinfo/<wbr>openstack-dev</a><br>
<br>
______________________________<wbr>______________________________<wbr>______________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" rel="noreferrer" target="_blank">OpenStack-dev-request@lists.<wbr>openstack.org?subject:<wbr>unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" rel="noreferrer" target="_blank">http://lists.openstack.org/<wbr>cgi-bin/mailman/listinfo/<wbr>openstack-dev</a><br>
</blockquote></div><br></div></div>