Skip to content
@azimuth-cloud

azimuth-cloud

Azimuth Cloud

Azimuth is a self-service portal for managing cloud resources, aimed at high-performance computing (HPC) and artificial intelligence (AI) workloads.

It works with OpenStack clouds. Users can create workstations with web console and desktop access, Slurm clusters, and apps running on Kubernetes.

Get started

The main deployment setup uses OpenStack. There is also a standalone mode for running apps on an existing Kubernetes cluster with OpenID Connect authentication. This is still experimental (alpha). CaaS and Cluster API are not available in standalone mode.

Repositories

Azimuth is made up of several components. The portal repository contains the API, UI and their Helm chart.

Component Source What it does
API, UI and portal chart azimuth: api, ui, chart Django REST API, React UI and Helm chart.
Kubernetes clusters azimuth-capi-operator Manages Kubernetes clusters through Cluster API.
Kubernetes cluster charts capi-helm-charts Helm charts for Kubernetes clusters and addons.
Cluster API addons cluster-api-addon-provider Manages addons for Cluster API clusters.
Cluster-as-a-Service azimuth-caas-operator Runs Ansible appliances to provision and configure platforms.
Kubernetes apps azimuth-apps-operator Manages apps using App and AppTemplate resources, including in standalone mode.
Platform access zenith Exposes platform services through authenticated tunnels.
Platform identity azimuth-identity-operator Manages platform identity integration.
Platform scheduling azimuth-schedule-operator Manages platform leases and expiry.
Deployment and development setup azimuth-config Deployment configuration, docs and Tilt setup.
Deployment playbooks ansible-collection-azimuth-ops Ansible roles and playbooks for deploying Azimuth and its dependencies.
User documentation azimuth-user-docs Guides for Azimuth users.

Contents

Features

  • Supports multiple Keystone authentication methods simultaneously:
    • Username and password, e.g. for LDAP integration.
    • Keystone federation for integration with existing OpenID Connect or SAML 2.0 identity providers.
    • Application credentials for distributing easily revocable credentials, e.g. for training, or for integrating with federated clouds where the required trust cannot be established.
  • Monitoring of performance, utilization and cloud capacity.
  • On-demand Platforms
    • Site-specific application catalogs and resource limits, with optional maximum application runtime.
    • Unified interface for managing Kubernetes and CaaS platforms.
    • Kubernetes-as-a-Service and Kubernetes-based platforms
      • Operators provide a curated set of templates defining available Kubernetes versions, networking configurations, custom addons etc.
      • Uses Cluster API to provision Kubernetes clusters.
      • Supports Kubernetes version upgrades with minimal downtime using rolling node replacement.
      • Supports auto-healing clusters that automatically identify and replace unhealthy nodes.
      • Supports multiple node groups, including auto-scaling node groups.
      • Supports clusters that can utilise GPUs and accelerated networking (e.g. SR-IOV).
      • Installs and configures addons for monitoring + logging, system dashboards and ingress.
      • Kubernetes-based platforms as first-class citizens in the platform catalog.
    • Cluster-as-a-Service (CaaS)
      • Operators provide a curated catalog of appliances.
      • The CaaS operator runs Ansible appliances using Ansible Runner.
      • Appliances use OpenTofu to provision infrastructure and Ansible to configure it. Setup is covered in the CaaS documentation (the older AWX implementation is legacy).
  • Application proxy using Zenith:
    • Single sign-on access to desktops and applications.
    • Securely share applications with external users.
    • Zenith uses SSH tunnels to expose services running behind NAT or a firewall to the internet using operator-controlled, random domains.
      • Exposed services do not need to be directly accessible to the internet.
      • Exposed services do not consume a floating IP.
    • Zenith supports an auth callout for proxied services, which Azimuth uses to secure proxied services.
    • Used by Azimuth to provide access to platforms, e.g.:
  • (Deprecated) Simplified interface for managing basic OpenStack resources:
    • Automatic detection of networking, with auto-provisioning of networks and routers if required.
    • Create, update and delete machines with automatic network detection.
    • Create, delete and attach volumes.
    • Allocate, attach and detach floating IPs.
    • Configure instance-specific security group rules.

Try Azimuth

To try Azimuth, follow the demo deployment guide. You'll need OpenStack credentials, enough project capacity and a machine that can run the deployment tools. The demo is for short-lived use. For use in production, see the production checklist.

Architecture

The React UI calls the Django REST API in the portal repository. In an OpenStack deployment, the API manages cloud resources on behalf of the logged-in user. The main platform components are:

  • The CAPI operator manages Kubernetes clusters through Cluster API and its infrastructure providers.
  • The CaaS operator reconciles appliance resources and runs Ansible jobs.
  • Kubernetes apps use either the Cluster API addon provider's HelmRelease resources or the Apps operator's App resources, depending on the configured apps provider. With Cluster API enabled, the default is HelmRelease.
  • Zenith exposes platform services through tunnels, with authentication integrated into Azimuth. Service registrations are stored as Kubernetes resources.

See the component repositories and the configuration guides for Kubernetes clusters, Kubernetes apps and CaaS for details.

Deploying Azimuth

Azimuth runs on Kubernetes, with components installed using Helm. The deployment setup uses configuration from azimuth-config and Ansible playbooks from azimuth-ops to install Azimuth and its dependencies, including operators and Zenith. The components installed depend on which features you enable.

Follow the deployment documentation for cloud prerequisites, Kubernetes, storage, ingress and configuration. The portal chart is one part of that deployment.

Azimuth History

Azimuth started as a simpler alternative to the OpenStack Horizon dashboard for the JASMIN Cloud. It now also provides a platform catalog for deploying workstations, Slurm clusters and Kubernetes apps, with a focus on scientific computing.

The Zenith application proxy exposes services to users without consuming floating IPs or requiring SSH keys.

Stig Telfer and Matt Pryor from StackHPC gave this introduction to Azimuth at the OpenInfra Summit in Berlin in 2022:

Azimuth - self service cloud platforms for reducing time to science

Timeline

Major milestones in the development of Azimuth and its components:

Pinned Loading

  1. azimuth azimuth Public

    Python 55 11

  2. zenith zenith Public

    Python 14 2

  3. azimuth-config azimuth-config Public

    Example configuration repository for Azimuth deployments.

    Python 5 16

Repositories

Showing 10 of 38 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Most used topics

Loading…