Azimuth is a self-service portal for managing cloud resources, aimed at high-performance computing (HPC) and artificial intelligence (AI) workloads.
It works with OpenStack clouds. Users can create workstations with web console and desktop access, Slurm clusters, and apps running on Kubernetes.
- Try Azimuth: deploy a demo on OpenStack or read the user guide.
- Contribute code or documentation: choose a component from the repository map and follow its development instructions. For the portal, start with CONTRIBUTING.md and the local development guide. The portal's API tests and UI builds can be run locally without a cloud account. To work against a running deployment, follow the OpenStack and Tilt development workflow.
- Find a component: use the repository map below.
- Operate Azimuth: follow the deployment and operations documentation.
The main deployment setup uses OpenStack. There is also a standalone mode for running apps on an existing Kubernetes cluster with OpenID Connect authentication. This is still experimental (alpha). CaaS and Cluster API are not available in standalone mode.
Azimuth is made up of several components. The portal repository contains the API, UI and their Helm chart.
| Component | Source | What it does |
|---|---|---|
| API, UI and portal chart | azimuth: api, ui, chart | Django REST API, React UI and Helm chart. |
| Kubernetes clusters | azimuth-capi-operator | Manages Kubernetes clusters through Cluster API. |
| Kubernetes cluster charts | capi-helm-charts | Helm charts for Kubernetes clusters and addons. |
| Cluster API addons | cluster-api-addon-provider | Manages addons for Cluster API clusters. |
| Cluster-as-a-Service | azimuth-caas-operator | Runs Ansible appliances to provision and configure platforms. |
| Kubernetes apps | azimuth-apps-operator | Manages apps using App and AppTemplate resources, including in standalone mode. |
| Platform access | zenith | Exposes platform services through authenticated tunnels. |
| Platform identity | azimuth-identity-operator | Manages platform identity integration. |
| Platform scheduling | azimuth-schedule-operator | Manages platform leases and expiry. |
| Deployment and development setup | azimuth-config | Deployment configuration, docs and Tilt setup. |
| Deployment playbooks | ansible-collection-azimuth-ops | Ansible roles and playbooks for deploying Azimuth and its dependencies. |
| User documentation | azimuth-user-docs | Guides for Azimuth users. |
- Supports multiple Keystone authentication methods simultaneously:
- Username and password, e.g. for LDAP integration.
- Keystone federation for integration with existing OpenID Connect or SAML 2.0 identity providers.
- Application credentials for distributing easily revocable credentials, e.g. for training, or for integrating with federated clouds where the required trust cannot be established.
- Monitoring of performance, utilization and cloud capacity.
- On-demand Platforms
- Site-specific application catalogs and resource limits, with optional maximum application runtime.
- Unified interface for managing Kubernetes and CaaS platforms.
- Kubernetes-as-a-Service and Kubernetes-based platforms
- Operators provide a curated set of templates defining available Kubernetes versions, networking configurations, custom addons etc.
- Uses Cluster API to provision Kubernetes clusters.
- Supports Kubernetes version upgrades with minimal downtime using rolling node replacement.
- Supports auto-healing clusters that automatically identify and replace unhealthy nodes.
- Supports multiple node groups, including auto-scaling node groups.
- Supports clusters that can utilise GPUs and accelerated networking (e.g. SR-IOV).
- Installs and configures addons for monitoring + logging, system dashboards and ingress.
- Kubernetes-based platforms as first-class citizens in the platform catalog.
- Cluster-as-a-Service (CaaS)
- Operators provide a curated catalog of appliances.
- The CaaS operator runs Ansible appliances using Ansible Runner.
- Appliances use OpenTofu to provision infrastructure and Ansible to configure it. Setup is covered in the CaaS documentation (the older AWX implementation is legacy).
- Application proxy using Zenith:
- Single sign-on access to desktops and applications.
- Securely share applications with external users.
- Zenith uses SSH tunnels to expose services running behind NAT or a firewall to the internet using operator-controlled, random domains.
- Exposed services do not need to be directly accessible to the internet.
- Exposed services do not consume a floating IP.
- Zenith supports an auth callout for proxied services, which Azimuth uses to secure proxied services.
- Used by Azimuth to provide access to platforms, e.g.:
- Web-based console / desktop access using Apache Guacamole
- Monitoring and system dashboards
- Platform-specific interfaces such as Jupyter Notebooks and Open OnDemand
- (Deprecated) Simplified interface for managing basic OpenStack resources:
- Automatic detection of networking, with auto-provisioning of networks and routers if required.
- Create, update and delete machines with automatic network detection.
- Create, delete and attach volumes.
- Allocate, attach and detach floating IPs.
- Configure instance-specific security group rules.
To try Azimuth, follow the demo deployment guide. You'll need OpenStack credentials, enough project capacity and a machine that can run the deployment tools. The demo is for short-lived use. For use in production, see the production checklist.
The React UI calls the Django REST API in the portal repository. In an OpenStack deployment, the API manages cloud resources on behalf of the logged-in user. The main platform components are:
- The CAPI operator manages Kubernetes clusters through Cluster API and its infrastructure providers.
- The CaaS operator reconciles appliance resources and runs Ansible jobs.
- Kubernetes apps use either the Cluster API addon provider's HelmRelease resources or the Apps operator's App resources, depending on the configured apps provider. With Cluster API enabled, the default is HelmRelease.
- Zenith exposes platform services through tunnels, with authentication integrated into Azimuth. Service registrations are stored as Kubernetes resources.
See the component repositories and the configuration guides for Kubernetes clusters, Kubernetes apps and CaaS for details.
Azimuth runs on Kubernetes, with components installed using Helm. The deployment setup uses configuration from azimuth-config and Ansible playbooks from azimuth-ops to install Azimuth and its dependencies, including operators and Zenith. The components installed depend on which features you enable.
Follow the deployment documentation for cloud prerequisites, Kubernetes, storage, ingress and configuration. The portal chart is one part of that deployment.
Azimuth started as a simpler alternative to the OpenStack Horizon dashboard for the JASMIN Cloud. It now also provides a platform catalog for deploying workstations, Slurm clusters and Kubernetes apps, with a focus on scientific computing.
The Zenith application proxy exposes services to users without consuming floating IPs or requiring SSH keys.
Stig Telfer and Matt Pryor from StackHPC gave this introduction to Azimuth at the OpenInfra Summit in Berlin in 2022:
Major milestones in the development of Azimuth and its components:
- Autumn 2015: Development begins on the JASMIN Cloud Portal, targeting JASMIN's VMware cloud.
- Spring 2016: JASMIN Cloud Portal goes into production.
- Early 2017: JASMIN Cloud plans to move to OpenStack, and development begins on Cloud Portal v2.
- Summer 2017: JASMIN's OpenStack cloud goes into production, with the JASMIN Cloud Portal v2.
- Spring 2019: Work begins on JASMIN Cluster-as-a-Service (CaaS) with StackHPC.
- Initial work presented at UKRI Cloud Workshop.
- Summer 2019: JASMIN CaaS beta rollout.
- Spring 2020: JASMIN CaaS in use by customers, e.g. the ESA Climate Change Initiative Knowledge Exchange project.
- Production system presented at UKRI Cloud Workshop.
- Summer 2020: Production rollout of JASMIN CaaS.
- Spring 2021: StackHPC fork JASMIN Cloud Portal to develop it for IRIS.
- Summer 2021: Zenith application proxy developed and used to provide web consoles in Azimuth.
- November 2021: StackHPC fork detached and rebranded to Azimuth.
- December 2021: StackHPC Slurm appliance integrated into CaaS.
- January 2022: Native Kubernetes support added using Cluster API (previously supported by JASMIN as a CaaS appliance).
- February 2022: Support for exposing services in Kubernetes using Zenith.
- March 2022: Support for exposing services in CaaS appliances using Zenith.
- June 2022: Unified platforms interface for Kubernetes and CaaS.
- October 2022: Support for Kubernetes platforms in the unified platforms interface.
- January 2023: Work begins on the CaaS operator to replace AWX.
- March 2023: Identity operator and Keycloak integration added for platform access through Zenith.
- June 2023: CaaS deployments move from AWX to the CaaS operator.
- March 2024: Schedule operator added to the deployment.
- April 2024: Zenith service registrations move from Consul to Kubernetes custom resources.
- May 2024: Exploration of standalone Kubernetes clusters using FluxCD and capi-helm-charts.
- May 2024: First upstream release of OpenStack Magnum driver that uses capi-helm-charts.
- July 2024: CaaS state moves to Kubernetes Secrets, removing the remaining Consul dependency.
- August 2024: Support for scheduled leases added to CaaS and Kubernetes platforms.
- February 2025: Apps operator introduced to deploy Kubernetes apps using Flux.
- June 2025: OpenID Connect authentication and tenancy membership added to the portal, along with Apps operator integration.
- September 2025: Experimental standalone mode added for running Azimuth on an existing Kubernetes cluster without OpenStack.
- July 2026: AMD GPU Operator addon added for Kubernetes clusters.
- September 2026: Headlamp dashboard added for viewing and managing Kubernetes cluster resources.
- September 2026: Maximum platform lifetimes can be configured for individual CaaS appliances and Kubernetes cluster templates.
