# Documentation

Welcome to the public documentation of cegedim.cloud, a trusted partner for private cloud hosting!

## Getting started with cegedim.cloud

Learn the fundamentals and start building with cegedim.cloud. Find the product that fits your needs to help you launch your next application and master our Cloud Management Platform called ITCare.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Products</strong></td><td>Find the complete list of Products available in our catalog with features, user guides, tutorials and more.</td><td></td><td><a href="/files/kLsRAZR9rjKMd8QjazqY">/files/kLsRAZR9rjKMd8QjazqY</a></td><td><a href="/pages/710jb1XOy7sHn9CIjvWf">/pages/710jb1XOy7sHn9CIjvWf</a></td></tr><tr><td><strong>Cloud Management Platform</strong></td><td>Discover our <a data-footnote-ref href="#user-content-fn-1">CMP</a> that empowers our customers with managed Products and actions available in self-service.</td><td></td><td><a href="/files/Xi8CEk8Z0k5WwAwG3l29">/files/Xi8CEk8Z0k5WwAwG3l29</a></td><td><a href="/pages/tfN5RTSFhi110VeNdnhc">/pages/tfN5RTSFhi110VeNdnhc</a></td></tr><tr><td><strong>Release Notes</strong></td><td>Find the release notes of our catalog with new Products, features, improvements and bug fixes.</td><td></td><td><a href="/files/Gg2qCit6vlawPvmfstA6">/files/Gg2qCit6vlawPvmfstA6</a></td><td><a href="/pages/ehgzo3dvsczRff40vcir">/pages/ehgzo3dvsczRff40vcir</a></td></tr></tbody></table>

[^1]: Cloud Management Platform - ITCare


# What is ITCare ?

## What is ITCare? <a href="#centredaideitcare-whatisitcare" id="centredaideitcare-whatisitcare"></a>

ITCare is cegedim.cloud cloud management platform.

It incorporates a web administration interface and an API that provide a 360° view of your Cloud resources hosted and managed by cegedim.cloud.

Designed as a unified web service, it governs the following key points:

* **Cloud resource management**: deploy and administer your resources.
* **Supervision**: monitor the health and performance of your applications, be notified in case of incidents.
* **Support**: contact our support teams for any queries or incidents.
* **Governance**: view security and obsolescence reports, manage maintenance slots.
* **Integration**: integrate your business processes with your cloud via the ITCare API.

You can access ITCare from any page of this website using the ITCare link in the header.

## How can I access ITCare? <a href="#centredaideitcare-howcanifindoutmoreaboutmyaccountanditcareaccess" id="centredaideitcare-howcanifindoutmoreaboutmyaccountanditcareaccess"></a>

The [Get started with ITCare](/itcare/what-is-itcare/get-started-with-itcare) page explains in detail how to access ITCare with information about authentication and permissions.

## Does ITCare have an API? <a href="#centredaideitcare-wherecanifindtheitcareapireferencedocumentation" id="centredaideitcare-wherecanifindtheitcareapireferencedocumentation"></a>

The page [Authentication](/itcare-api/itcare-api-authentication) gathers all the information necessary for the discovery and the good use of the ITCare API.

## How can I reach cegedim.cloud support by phone? <a href="#support-howcanireachcegedim.cloudsupportbyphone" id="support-howcanireachcegedim.cloudsupportbyphone"></a>

If you are a customer, you can reach our Service Desk through this direct phone line for any support request: +33 (0)1 49 09 22 22

## How can I reach cegedim.cloud by e-mail? <a href="#support-howdoicontactcegedim.cloudbye-mail" id="support-howdoicontactcegedim.cloudbye-mail"></a>

For any information request or contact, please use the contact form of our public website:

{% embed url="<https://cegedim.cloud/en/contact/>" %}


# Get started with ITCare

## How do I connect to ITCare? <a href="#gestiondecompte-howdoiconnecttoitcare" id="gestiondecompte-howdoiconnecttoitcare"></a>

It is not possible to create your own ITCare account to access the platform.

To receive an ITCare account, your organization's security representative must submit an account creation request.

## How do I request an ITCare account? <a href="#gestiondecompte-howdoirequestanitcareaccount" id="gestiondecompte-howdoirequestanitcareaccount"></a>

Please contact your Service Delivery Management or the commercial team at cegedim.cloud.

## How is ITCare authentication handled? <a href="#gestiondecompte-howisitcareauthenticationhandled" id="gestiondecompte-howisitcareauthenticationhandled"></a>

ITCare authentication is based on an e-mail address and a password that comply with the standards of the cegedim security policy.

API accounts use the OpenID protocol. More information about the ITCare API can be found at [Authentication](/itcare-api/itcare-api-authentication).

## Is multi-factor authentication available? <a href="#gestiondecompte-ismulti-factorauthenticationavailable" id="gestiondecompte-ismulti-factorauthenticationavailable"></a>

Multi-factor authentication is available and mandatory for certain high privilege actions.

During the on-boarding process, you will be provided with all the information necessary to properly configure the MFA.

## What are the possible privileges in ITCare? <a href="#gestiondecompte-whatarethepossibleprivilegesinitcare" id="gestiondecompte-whatarethepossibleprivilegesinitcare"></a>

ITCare privileges are broken down into roles assigned to profiles.

Profiles are assigned to users.

### The roles <a href="#gestiondecompte-theroles" id="gestiondecompte-theroles"></a>

<table><thead><tr><th width="247">Roles</th><th>Description</th></tr></thead><tbody><tr><td>See resources</td><td>See all the resources and their informations. Read only</td></tr><tr><td>Manage maintenances</td><td>Ability to manage maintenances</td></tr><tr><td>Modify resources</td><td>Ability to modify resources except creation and deletion</td></tr><tr><td>Manage resources</td><td>Complete resource management</td></tr></tbody></table>

{% hint style="warning" %}
MFA must be configured and is mandatory for the following roles:

* Manage maintenances
* Modify resources
* Manage resources
  {% endhint %}

### The profiles <a href="#gestiondecompte-theprofiles" id="gestiondecompte-theprofiles"></a>

<table data-full-width="true"><thead><tr><th>Profiles</th><th data-type="checkbox">See resources</th><th data-type="checkbox">Manage maintenances</th><th data-type="checkbox">Modify resources</th><th data-type="checkbox">Manage resources</th></tr></thead><tbody><tr><td>Standard (STD)</td><td>true</td><td>false</td><td>false</td><td>false</td></tr><tr><td>Maintenance (DTM)</td><td>true</td><td>true</td><td>false</td><td>false</td></tr><tr><td>Operator (OPE)</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Power (POW)</td><td>true</td><td>true</td><td>true</td><td>true</td></tr></tbody></table>

### Privilege Matrix <a href="#gestiondecompte-privilegematrix" id="gestiondecompte-privilegematrix"></a>

This non-exhaustive table describes the basic actions allowed by profile:

<table data-full-width="true"><thead><tr><th>Features</th><th>Label</th><th>Available for</th></tr></thead><tbody><tr><td>Bodies</td><td>create-instance</td><td>POW</td></tr><tr><td>start-instance</td><td>OPE</td><td></td></tr><tr><td>stop-instance</td><td>OPE</td><td></td></tr><tr><td>reset-instance</td><td>OPE</td><td></td></tr><tr><td>resize-compute-instance</td><td>OPE</td><td></td></tr><tr><td>delete-instance</td><td>POW</td><td></td></tr><tr><td>Instance monitoring</td><td>enable-monitoring-instance</td><td>OPE</td></tr><tr><td>disable-monitoring-instance</td><td>OPE</td><td></td></tr><tr><td>Snapshot of instances</td><td>create-snapshot</td><td>MNT</td></tr><tr><td>recover-snapshot</td><td>MNT</td><td></td></tr><tr><td>delete-snapshot</td><td>MNT</td><td></td></tr><tr><td>DNS aliases of instances</td><td>create-dns</td><td>OPE</td></tr><tr><td>delete-dns</td><td>OPE</td><td></td></tr><tr><td>LoadBalancers</td><td>create-lb</td><td>POW</td></tr><tr><td>start-lb</td><td>OPE</td><td></td></tr><tr><td>stop-lb</td><td>OPE</td><td></td></tr><tr><td>delete-lb</td><td>POW</td><td></td></tr><tr><td>Monitoring of LoadBalancers</td><td>enable-monitoring-lb</td><td>OPE</td></tr><tr><td>disable-monitoring-lb</td><td>OPE</td><td></td></tr><tr><td>Manage LoadBalancers</td><td>add-member-lb</td><td>OPE</td></tr><tr><td>delete-member-lb</td><td>OPE</td><td></td></tr><tr><td>update-member-state</td><td>OPE</td><td></td></tr><tr><td>DNS alias of LoadBalancers</td><td>create-dns-lb</td><td>OPE</td></tr><tr><td>delete-dns-lb</td><td>OPE</td><td></td></tr><tr><td>Manage maintenance</td><td>create-maintenance</td><td>MNT</td></tr><tr><td>delete-maintenance</td><td>MNT</td><td></td></tr><tr><td>Indicators</td><td>create-indicator</td><td>POW</td></tr><tr><td>update-indicator</td><td>POW</td><td></td></tr><tr><td>delete-indicator</td><td>POW</td><td></td></tr><tr><td>SMS</td><td>subscribe-vortext</td><td>POW</td></tr><tr><td>Storage Object</td><td>create-object-stores</td><td>POW</td></tr><tr><td>update-object-stores</td><td>OPE</td><td></td></tr><tr><td>delete-object-stores</td><td>POW</td><td></td></tr><tr><td>Storage Object - Users</td><td>create-user-objectstores</td><td>POW</td></tr><tr><td>update-user-objectstores</td><td>POW</td><td></td></tr><tr><td>delete-user-objectstores</td><td>POW</td><td></td></tr><tr><td>K8S Clusters</td><td>create-cluster</td><td>POW</td></tr><tr><td>create-cluster-namespace</td><td>OPE</td><td></td></tr><tr><td>delete-cluster-namespace</td><td>OPE</td><td></td></tr><tr><td>create-cluster-nodes</td><td>POW</td><td></td></tr><tr><td>delete-cluster-nodes</td><td>POW</td><td></td></tr></tbody></table>

## What are the Regions and Availability Zones in ITCare? <a href="#presentationitcare-whataretheregionsandavailabilityzonesinitcare" id="presentationitcare-whataretheregionsandavailabilityzonesinitcare"></a>

The topology of the cegedim.cloud hosting platform is divided into:

* **Regions**: a group of low latency data centers ( < 1 ms)
* **Availability zones**: a set of dedicated infrastructure components in a data center

```mermaid
graph LR
    subgraph region["🚩 Region"]
        direction LR
        subgraph dc1["Datacenter"]
            subgraph az1["Availability zone"]
                i1["📦 Instances"]
            end
        end
        subgraph dc2["Datacenter"]
            subgraph az2["Availability zone"]
                i2["📦 Instances"]
            end
        end
        subgraph dc3["Datacenter"]
            subgraph az3["Availability zone"]
                i3["📦 Instances"]
            end
        end
    end

    i1 ~~~ i2 ~~~ i3

    style region fill:#cfe2ff,stroke:#0066cc,stroke-width:2px,color:#000
    style dc1 fill:#3a3a3a,stroke:#000,stroke-width:2px,color:#fff
    style dc2 fill:#3a3a3a,stroke:#000,stroke-width:2px,color:#fff
    style dc3 fill:#3a3a3a,stroke:#000,stroke-width:2px,color:#fff
    style az1 fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style az2 fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style az3 fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style i1 fill:#dde8f5,stroke:#000,stroke-width:2px,color:#000
    style i2 fill:#dde8f5,stroke:#000,stroke-width:2px,color:#000
    style i3 fill:#dde8f5,stroke:#000,stroke-width:2px,color:#000
```

### What regions are available? <a href="#presentationitcare-whatregionsareavailable" id="presentationitcare-whatregionsareavailable"></a>

Here is the list of regions available to our customers:

<table><thead><tr><th width="134.33333333333331">Region</th><th width="173">Description</th><th>Datacenters</th></tr></thead><tbody><tr><td>EB</td><td>Paris area</td><td><p>EB3 : Boulogne-Billancourt</p><p>EB4 : Boulogne-Billancourt</p><p>EB5 : Magny-les-Hameaux</p></td></tr><tr><td>ET</td><td>Toulouse area</td><td><p>ET1 : Labège</p><p>ET2 : Balma</p></td></tr></tbody></table>

### What Availability Zones are available? <a href="#presentationitcare-whataretheavailableareas" id="presentationitcare-whataretheavailableareas"></a>

#### EB Region <a href="#presentationitcare-ebregion" id="presentationitcare-ebregion"></a>

<table><thead><tr><th width="180.33333333333331">Availability Zone</th><th width="342">Description</th><th>Datacenter</th></tr></thead><tbody><tr><td>EB-HDS-A</td><td>Client zone</td><td>EB4</td></tr><tr><td>EB-HDS-B</td><td>Client zone</td><td>EB3</td></tr><tr><td>EB-HDS-C</td><td>Client zone</td><td>EB5</td></tr><tr><td>EB-A</td><td>Area reserved for the cegedim group</td><td>EB4</td></tr><tr><td>EB-B</td><td>Area reserved for the cegedim group</td><td>EB3</td></tr><tr><td>EB-C</td><td>Area reserved for the cegedim group</td><td>EB5</td></tr></tbody></table>

#### ET Region <a href="#presentationitcare-regionand" id="presentationitcare-regionand"></a>

<table><thead><tr><th width="186.33333333333331">Availability Zone</th><th width="360">Description</th><th>Datacenter</th></tr></thead><tbody><tr><td>ET-HDS-A</td><td>Client zone</td><td>ET1</td></tr><tr><td>ET-HDS-B</td><td>Client zone</td><td>ET1</td></tr><tr><td>ET-HDS-C</td><td>Client zone</td><td>ET2</td></tr><tr><td>ET-A</td><td>Area reserved for the cegedim group</td><td>ET1</td></tr><tr><td>ET-B</td><td>Area reserved for the cegedim group</td><td>ET1</td></tr><tr><td>ET-C</td><td>Area reserved for the cegedim group</td><td>ET2</td></tr></tbody></table>

## What is an ITCare resource? <a href="#presentationitcare-whatisanitcareresource" id="presentationitcare-whatisanitcareresource"></a>

A resource is an infrastructure or middleware component deployed in the **cegedim.cloud** Information System.

It can only belong to one Service (see [#presentationitcare-howaremyitcareresourcesorganized](#presentationitcare-howaremyitcareresourcesorganized "mention") for the definition of a Service)

A resource is systematically defined by the following properties:

* an **id**: unique identifier of the resource.
* a **type**: the type of the resource e.g. virtual instance, Kubernetes cluster, etc.
* a **name**: more convenient to handle than an id.
* a **status**: defines the state of the resource (active, inactive).
* an **environment**: defines the type of environment of the resource (production, qa, dev, test, etc.).
* **tags**: allows you to tag your resources with customizable keys/values that are queryable.

## What are the possible statuses for resources? <a href="#presentationitcare-whatarethepossiblestatusesforresources" id="presentationitcare-whatarethepossiblestatusesforresources"></a>

Here are the possible statuses of a resource that are visible by the web UI or returned by the API:

<table><thead><tr><th width="144.33333333333331">Status</th><th width="453">Description</th><th>API code</th></tr></thead><tbody><tr><td>Active</td><td>The resource is active and the service is available.</td><td>ACTIVE</td></tr><tr><td>Preparation</td><td>The resource is being installed or configured.<br>The service is not yet available.</td><td>PREPARATION</td></tr><tr><td>Inactive</td><td>The resource is inactive and the service is unavailable.</td><td>INACTIVE</td></tr></tbody></table>

## How are my ITCare resources organized? <a href="#presentationitcare-howaremyitcareresourcesorganized" id="presentationitcare-howaremyitcareresourcesorganized"></a>

Each cegedim.cloud customer has an **Organization** that materializes its existence within our IS.

Multiple **Clouds** can be created within an organization. These allow partitioning of resources and user rights.

{% hint style="info" %}
By default, only one Cloud is defined for a new Organization.\
Additional Clouds can be created upon request.
{% endhint %}

You can therefore define, at the level of a Cloud, who has access to what and what actions can be performed.

It is therefore possible, for example, to have a Cloud that gives full power to your development teams so as not to disrupt production. Within a Cloud, resources are then grouped into **Services**.

The Services allow you to group your resources in a logical way according to several free criteria:

* The scope of an application
* By environment
* Any other free criteria: by customer for example

{% hint style="warning" %}
The Services do not allow the application of user rights restrictions.
{% endhint %}

In ITCare, the Services have dedicated pages that allow you to easily consult all the resources attached to them.

```mermaid
graph TD
    subgraph org["🏢 Organization"]
        subgraph cloud["☁️ Cloud"]
            subgraph service["🌐 Service"]
                r1["📦 Resources"]
            end
        end
    end

    style org fill:#faf6e9,stroke:#000,stroke-width:2px,color:#000
    style cloud fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style service fill:#cfe2ff,stroke:#0066cc,stroke-width:2px,color:#000
    style r1 fill:#dde8f5,stroke:#000,stroke-width:2px,color:#000
```


# Demos

To help you understand and master every aspect of the ITCare platform, we offer a set of interactive demos specific to the features available in our Cloud Management Platform.

## Resources

### Manage your ressources

Various actions are possible to manage resources on our ITCare platform. We present them to you below!

{% @supademo/embed url="<https://app.supademo.com/demo/cm1qf7jtk009fspgcjhrq5mpg>" demoId="cm1qf7jtk009fspgcjhrq5mpg" %}

### Dynamic filters

Based on the selected resources in the filter window, dynamic filters will now be available to more efficiently display what you care about.

{% embed url="<https://app.supademo.com/demo/cm0zdai6x0exoy2bfebcjoxv3>" %}

## Notifications

Your notifications are configurable and customizable through subscriptions. We show you how below!

### Create a subscription

The first essential step: create a subscription according to your personalized criteria.

{% embed url="<https://app.supademo.com/demo/cluwn2hzq0am7q2s9onppfri1>" %}

### Manage your subscriptions

Now that you know how to create a subscription, let's see how to manage it.

{% embed url="<https://app.supademo.com/demo/clvghigbn0f1d769dc28chdg4>" %}

### Manage delivery groups

Subscriptions take advantage of delivery groups. We will show you how to manage them.

{% embed url="<https://app.supademo.com/demo/clvmco9if160u769db7vcb2yj>" %}

### Monitor the notifications

When your notifications are configured, it's essential to know how to monitor them.

{% embed url="<https://app.supademo.com/demo/clxbwri0v0ylbt2oe2c9538vs>" %}


# Enercare

## Overview

cegedim.cloud provides a dedicated section in ITCare for its carbon footprint.

This section allows users to identify the environmental impact of applications in detail, displaying both the CO2 emissions of Global Services and those of associated instances.

The carbon footprint calculation is an integral part of the Enercare project, based on the energy consumption distribution of services. It takes into account IT equipment (servers, storage bays, networks, etc.) as well as all components necessary for their proper operation (air conditioning, generators, uninterruptible power supplies, etc.). These components are associated with the data center energy performance indicator calculated using Power Usage Effectiveness (PUE).

The scope includes both Cegedim’s proprietary data centers and those in colocation.

## Principle

cegedim.cloud has developed internal tools and a methodology to allocate service consumption for shared instances. As part of a continuous improvement approach, this methodology will evolve with the reliability and accuracy of data collected.

The calculation of the carbon footprint for our cloud services adheres to the rules of the [GHG Protocol](https://ghgprotocol.org/). We include the following elements in the Enercare functionality:

* Direct emissions under Scope 1 from data centers: fossil fuel combustion from generators, and fugitive emissions from refrigerants in cooling systems.
* Indirect emissions under Scope 2: electricity consumption of equipment, including the PUE.
* Indirect emissions under Scope 3: upstream emissions linked to fuels and electricity production, goods and services purchased for service operations (considering their production to end-of-life cycle), and employee travel.

The data presented in Enercare corresponds to cegedim.cloud’s activities, independent of those of other subsidiaries or the Cegedim group. As the carbon footprint is conducted and audited annually, we cannot correlate calculation coefficients to real-time service usage.

The **Calculation Rules** section below explains the collection of energy consumption data from physical equipment and the method used to calculate the carbon footprint for services and instances.

To learn more about cegedim.cloud’s initiatives to reduce its environmental impact, you can visit the [CSR page](https://cegedim.cloud/a-propos/responsabilite-societale-et-environnementale/) on our website.


# Carbon footprint

## Equipment Categories and CO2 Emission Calculation

### Equipment Categories

A Data Center uses three main categories of equipment:

* **Compute equipment** (e.g., ESX servers based on X86 processors, IBM servers based on Power processors, etc.), which host the various instances.
* **Storage equipment** (e.g., data storage arrays, object storage arrays, backup and archiving storage arrays).
* **Network equipment** (e.g., network switches, firewalls, BigIP, etc.), which enable internal and external flow exchanges between services and instances.
* **Note**: These three categories themselves consist of subcategories that allow for a more detailed calculation of CO2 emissions per user instance. For simplicity, these subcategories will not be included in the calculation method outlined below.

### Energy Consumption Collection

The energy consumption of each piece of equipment is collected every minute (instantaneous power in watts) and stored in a database (MIMIR key-value database).

Additionally, we collect the following elements to calculate the associated CO2 emission:

* The **PUE** (Power Usage Effectiveness), calculated daily for the data centers we operate and monthly for colocation data centers.
* The **CO2 emission factors** (in kgCO2e/kWh), which are updated annually based on data from ADEME and suppliers.

### CO2 Emission Calculation for Equipment

The CO2 emission of a piece of equipment is calculated on a daily basis:

* Convert the instantaneous consumption into kWh/day from the data collected in the key-value database.
* Apply the PUE of the data center:
  * If a piece of equipment consumes 1000 kWh/day and the PUE of the data center is 1.3, the actual consumption of the equipment will be 1300 kWh.
* Convert the kWh/day into CO2 (kg) using the CO2 emission factor from the supplier:
  * If 80% of the energy used by the data center comes from a supplier who emits 0.008 kg of CO2 per kWh, and the remaining 20% comes from a second supplier who emits 0.01 kg of CO2 per kWh, the equipment’s emission will be: 1300 \* 0.008 \* (80 / 100) + 1300 \* 0.01 \* (20 / 100), which equals 10.92 kg of CO2 per day.

## CO2 Emission Calculation for a Global Service

### Reminder

A **Global Service** is the logical grouping of resources (primarily Instances) that use resources from different categories of physical equipment (Compute, Storage, and Network). The carbon footprint of a Global Service will therefore be the sum of the CO2 emissions of its resources.


# Release notes

Discover the latest updates of cegedim.cloud! Continuous improvements, new products, new features and evolutions are referenced here.

## February 2026

### :rocket: New design ITCare

The ITCare interface gets a fresh look with a modernized and harmonized design for an enhanced user experience. These improvements include:

* Modernized visual interface with updated design elements
* Harmonized and consistent UI components across the entire portal
* Better readability and information clarity
* Enhanced responsiveness for smoother navigation

This new design provides you with a more pleasant and intuitive working environment, while retaining all the features you're familiar with. Navigation between different portal sections is now smoother and more consistent.

### :rocket: Kubernetes 1.33

The new Kubernetes 1.33 release is now available, bringing significant improvements in performance, security, and workload management. This version includes:

* Topology Aware Routing
* Take taints/tolerations into consideration when calculating PodTopologySpread skew
* Introduce MatchLabelKeys to Pod Affinity and Pod Anti Affinity
* Sidecar Containers
* node: cpumanager: add options to reject non SMT-aligned workload

### :tools: Satisfaction survey IT support

Share your feedback in just a few clicks! When closing a ticket, ITCare now offers you the opportunity to respond to a short satisfaction survey, directly within the tool. Simple, fast, and useful for continuously improving your IT support experience.

## January 2026

### :rocket: Valkey 8.1

Valkey 8.1 is now part of our product catalog and available for provisioning in ITCare! This Redis fork, supported by the Linux Foundation, offers the same core features and incorporates significant technical improvements: performance optimizations for replication operations, enhanced memory management, and extended security protocol support.

Migration from Redis to Valkey 8.1 is fully automated and managed by cegedim.cloud. Simply submit a ticket from ITCare, specifying your availability window.

### :rocket: MariaDB 11.4

MariaDB's last LTS version 11.4 is now available and includes several updates such as :

* InnoDB engine optimizations for better read/write performance
* Enhanced support for distributed transactions
* New security features with strengthened authentication
* Improvements to replication and high availability with Galera Cluster

### :rocket: RabbitMQ 4.2

The new RabbitMQ 4.2 release is now available, bringing significant improvements in performance and reliability:

* Routing engine optimizations for improved message throughput
* Enhanced memory management and concurrent connection handling
* Extended support for security protocols and TLS 1.3 encryption
* High availability improvements with quorum queues

## December 2025

### :rocket: RKE2 for new Kubernetes clusters

Starting with this release, all new Kubernetes clusters are deployed with RKE2, Rancher's next-generation Kubernetes distribution. As RKE (Rancher Kubernetes Engine) reached end-of-life in June 2025, this upgrade ensures the sustainability and security of your infrastructure. Existing RKE clusters will continue to operate normally and can be migrated later according to your schedule.

For more information, please read the dedicated page: [Migration RKE to RKE2](/compute/containers-k8s/k8s-get-started/k8s-migration-rke-to-rke2)

## November 2025

### :tools: ITCare UI

Multiple updates have been released in ITCare:

* Display AIX information for Dedicated CPU, Semi-Dedicated CPU or Standard CPU
* Consult urls blocked by botdefense
* Remove Support level actions at Load balancer level

### :tools: Matomo

Temporary deactivation of the XL sizing of Matomo in self service. An issue has been found and will be fixed. Until then, this sizing is not available at creation or resize.

## October 2025

### :rocket: RHEL 9

RHEL 9 is now available for provisioning in ITCare. On the security side, OpenSSL 3.0.1 and SELinux strengthen protection, and root password authentication is now disabled by default.

### :rocket: Apache Kafka 4

The new Apache Kafka 4 release is here, and includes several updates such as:

* Consumer rebalances are faster and smoother thanks to a new broker-side protocol.
* Apache Kafka also introduces an experimental queue mode, improves transactional robustness, and strengthens leader election security.
* On the performance side, requests are now more responsive, with enhanced built-in observability.

### :tools: Availability indicator

An availability indicator for each resource is now visible next to your resource in the list of resources for your services. This indicator shows you whether the resource or hosted service is available and functional. As examples, a bare VM must at least respond to ping, and a Postgresql PaaS must allow connections on its listening port. This information is also visible at the resource level in the overview.

### :tools: Monitoring console

* Visible support level for each alarm: you can now see the support level associated with each of your alarms directly.
* Improved filter management: filters and quick filters are now compatible with the results count, for a more accurate display.
* Search by check: searching by check name is now functional with all check names. In addition, additional information about checks can be viewed in a popover.

## August 2025

### :rocket: Windows Server 2025

The latest version of Windows Server 2025 is now available in self service in ITCare and includes a number of improvements, including:

* Enhanced security: New anti-cyberattack mechanisms, Credential Guard enabled by default.
* Increased performance: NVMe storage, advanced virtualization, and hotpatching without restart.
* Modernized experience: Improved interface, real-time diagnostics, and centralized management.

### :rocket: Kubernetes 1.32

The latest version of Kubernetes 1.32 is now available and brings significant improvements focused on stability, management simplicity, and better observability. The upgrade can be done in self service via ITCare, please refer to the upgrade guide in the K8S section.

## July 2025

### :tools: SQL Server - Cumulative Updates

You can now request for an upgrade of your SQL Server instances via ticket in ITCare. A new sub-panel showcasing the version details of your SQL Server is now displayed in the Configuration panel of your ressource in the Overview tab.

### :tools: ITCare Support - Improvements

UX and UI have been completly redesigned to facilitate the use of the support section when raising an incident or a request.

### :tools: Apache Kafka - Add Broker Node disk size

When adding a broker node in an Apache Kafka cluster, the disk size is now automatically configured to align with the size of the existing nodes. You can still choose to change this size if needed.

### :tools: Object Storage - Improvements

The number of buckets owned by each user is now displayed for each user in an object store in ITCare. User deletion is disabled when the user owns at least one bucket.

### :tools: Monitoring - UI Improvements

* Removed acknowledgment picto and filters
* Disabled auto refresh by default
* Removed count by status

### :tools: ITCare - Improvements

Multiple improvements have been made to enhance the user experience, the performance and the interface of ITCare.

## June 2025

### :tools: Matomo Monitoring Management

Support level can now be modified in self service using ITCare once a Matomo instance has been deployed.

### :tools: Kubernetes - Add Ingress Node

Ingress nodes can now be added in a Kubernetes cluster through self-service in ITCare.

## April 2025

### :rocket: OpenSearch 2.19

OpenSearch 2.19 is now available for provisioning in ITCare! It includes a number of updates that help you build machine learning (ML)-powered applications, increase performance and stability.

### :tools: OpenSearch - Delete nodes

You can now delete data nodes in an existing OpenSearch cluster in self-service. Nodes must be deleted in pairs to keep data distribution balanced throughout the cluster.

### :rocket: Kubernetes 1.31

Kubernetes 1.31 is now available for provisioning in ITCare! It includes a number of updates such as the ability to specify an AppArmor profile for a container or pod in the API, improved connectivity reliability for KubeProxy Ingress and initial design to support pod-level resource limits.

{% hint style="info" %}

## Note regarding the upgrade process

The upgrade process requires restarting nodes (10% of worker nodes at a time) due to a configuration change between Kubelet versions. Depending on the level of resilience in your stack, we recommend scheduling this update during a period of low usage to minimize disruption.
{% endhint %}

As done previously, the upgrade can be triggered in self service using ITCare.

{% hint style="warning" %}
Remember to **check compatibility before** launching an upgrade! More information here: [K8s - Get started](/compute/containers-k8s/k8s-get-started#kuberneteshowtos-compatibilitycheckbeforeupgradingkubernetesversion)
{% endhint %}

### :rocket: Apache Kafka 3.9

Apache Kafka 3.9 is now available for provisioning in ITCare! Kafka 3.9 includes a number of bug fixes and updates as tiered storage, dynamic Kraft quorums and OAuth authentication with an OIDC provider.

### :tools: Apache Kafka - Add node

You can now add a broker node to an existing Apache Kafka cluster. The sizing will be identical to the one defined initially when creating your cluster. The storage can be changed, but it is recommended to allocate the same amount as configured on the other broker nodes in the cluster. Finally, the choice of availability zone is possible before submission.

### :rocket: Ubuntu 24.04

Ubuntu 24.04 is now available for provisioning in ITCare! The hardening of the operating system deployed in previous versions is still present in this version.

### :tools: Backup Policies

You can now select a backup policy for all our Paas during the creation step. The following products are now eligible: PostgreSQL, MariaDB, SQL Server, Oracle.

### :tools: Object Storage improvements

Features and improvements have been added to the Object Stores Page. You can now sort through all categories in the COS list page, a 'Filter' button has also been added. From the COS page you can now access the Grafana dashboard with the Advanced metrology button.

## March 2025

### :rocket: ITCare support level improvements

Support level management has been greatly improved on our products. You can now chose to enable and deploy the monitoring without enabling alerting immediately. This lets our users test the monitoring checks without triggering tickets or on-call support.

### :tools: PostgreSQL - Upgrade in place

A new self service action is available on all PostgreSQL PaaS: upgrade in place. This lets you upgrade your deployment from any version to the last version in autonomy and without having to redeploy another PaaS. This operation is described in the Upgrade page of this Academy for PostgreSQL. All safety measures have been implemented and in case any error would appear, a rollback is included in the upgrade process.

### :tools: ITCare UI / UX / Performance

Multiple improvements have been made to enhance the user experience, the performance and the interface of ITCare.

## February 2025

### :tools: ITCare - New security dashboard

A new security dashboard provides real-time visibility into vulnerabilities, Bot Defense protection, Vault instances, and resource obsolescence. It enables precise tracking of resolved vulnerabilities and blocked attacks. The "Vulnerabilities" and "Bot Defense" pages have been enhanced for optimized management.

### :tools: ITCare - Improved availability rate calculation

We have enhanced the accuracy of calculations by considering only the support periods defined in the indicator. Visibility has been improved with the display of availability and unavailability periods by month or day. The reasons for interruptions are now accessible, and maintenance periods are no longer counted as unavailability, ensuring more reliable indicators.

## January 2025

### :tools: PostgreSQL TLS

TLS encryption activation is now possible on request after the provisioning of the PostgreSQL PaaS. Please file a request ticket in ITCare for this feature.

### :tools: Backup Policies for PaaS

We improved the backup policy selection and we are now allowing the selection of a "replicated" policy even in "non-production" service. Meaning if you have sensible ressources of non-production type, you can select a policy that handle off-site backup replication.

### :tools: Backup information

The backup panel has been improved in ITCare for all our PaaS products. It should be displayed on all products and more information have been displayed like the backup policies, the last backup timestamp and the storage footprint of the system (and database where applicable) in GB.

### :rocket: Object Stores in top search bar

Object Stores are now indexed in the top search bar and can be found for easier nagivation to the detailled information page.

## December 2024

### :rocket: SQL Server Always On

Always On is now available in ITCare in self service for SQL Server 2022 Enterprise edition. For more information, please head over to the [SQL Server - Features](/databases/sql-server/sql-server-features) product information.

### :rocket: Backup Policies for PaaS

In september, we released the backup policy selection for Linux and Windows when provisioning. You can now select the policy for several PaaS when provisioning: OpenSearch, Redis, Apache Kafka, RabbitMQ, GlusterFS, Tomcat, Wildfly.

Also, we've improved the UI overview for those products to let you see the backup footprint and the associated policies configured.

The next and last delivery will be for the remaining products: PostgreSQL, MariaDB, SQL Server.

### :tools: Apache Kafka - Add nodes

The addition of extra nodes for the Apache Kafka product is now possible on request via a ticket from ITCare. As a reminder, an Apache Kafka cluster consists of a minimum of 3 nodes for production use.

## October 2024

### :rocket: Kubernetes 1.28

Kubernetes 1.28 is now available for provisioning in ITCare!

Also, you can upgrade your existing cluster to version 1.28 in self service. Remember to [K8s - Get started](/compute/containers-k8s/k8s-get-started#kuberneteshowtos-compatibilitycheckbeforeupgradingkubernetesversion) before launching an upgrade!

## September 2024

### :tools: ITCare - Dynamic Filtering

A new filtering option is now available in the resource section! The filters adapt dynamically based on the type of resource selected, offering a more personalized experience and optimized display of relevant data.

An interactive demo is available in the demo section: [Demos](/itcare/what-is-itcare/demos#dynamic-filters)

### :rocket: Redis 7.2.5

We are excited to announce that Redis 7.2.5 is now available on our ITCare platform. You can also request an upgrade to version 7.2.5 for an existing Redis PaaS by submitting a ticket.

### :tools: Backup Policies (Beta)

You can now independently select your backup policy for Linux and Windows virtual instances when creating your resources in ITCare!

This feature is currently in Beta and accessible to everyone.

## July-August 2024

### :rocket: Oracle Linux 9

Oracle Linux distribution is now available in self service using ITCare, our Cloud management platform. This distribution is available as part of our virtual instances product with the same options and properties.

{% embed url="<https://www.oracle.com/linux/>" %}

### :tools: Bot Defense - Transparent mode

Bot Defense has been updated to introduce the **transparent mode**, allowing you to view requests deemed illegitimate without impacting traffic. This mode makes it easier to analyze logs and identify false positives, so you can fine-tune by adding legitimate IPs to the whitelist before switching to blocking mode.

For more information, please read the [Bot Defense](/security/bot-defense) documentation.

### :rocket: OverDrive - XS

OverDrive, based on Nextcloud technology, offers a file storage and sync platform with powerful collaboration capabilities with desktop, mobile and web interfaces. This new product is available in self-service through ITCare in sizing XS and is hosted on-premise with high security standards.

For more information, please read the [OverDrive](/storage/overdrive) documentation.

### :tools: Kubernetes - Create load balancer

To simplify the load balancer creation, it is now possible to create a load balancer on your Kubernetes cluster directly from the **Manage** dropdown.

### :tools: Kubernetes - Healthcheck for API

A new healthcheck has been added to all Kubernetes clusters where monitoring is enabled to monitor the Kubernetes API.

### :tools: OS upgrades on all PaaS

On all PaaS, the base operating system has been upgraded to the last version of the distribution when possible. This ensures that all new deployments will be up to date and benefit from security patches.

## June 2024

### :tools: OpenSearch - Migrate to dedicated masters

A new feature is available for OpenSearch clusters to migrate from a **basic** topology to a **dedicated master** topology. This migration will add 3 nodes dedicated to the Master role (not hosting datas).

An interactive demo is available here: [OpenSearch - Get started](/databases/opensearch/opensearch-get-started#migration-demo)

### :tools: OpenSearch - Ingest nodes

Specialized nodes dedicated to Ingest role can now be added to your OpenSearch cluster. This new feature is available under the **Manage** dropdown and will add 2 new nodes dedicated to Ingest role.

An interactive demo is available here: [OpenSearch - Get started](/databases/opensearch/opensearch-get-started#ingestion-nodes-demo)

## May 2024

### :rocket: RabbitMQ 3.13

Versions 3.12 and 3.13 are now supported by RabbitMQ PaaS!\
For more information, please read the [RabbitMQ](/messaging/rabbitmq) documentation and the official release notes.

{% embed url="<https://github.com/rabbitmq/rabbitmq-server/releases/tag/v3.13.0>" %}

## April 2024

### :rocket: PostgreSQL 16

Version 16 is now supported in the PostgreSQL PaaS!\
For more information, please read the [PostgreSQL](/databases/postgresql) documentation and the official release notes.

{% embed url="<https://www.postgresql.org/about/press/presskit16/en/>" %}

### :rocket: PostgreSQL - Extensions management

You can now install PostgreSQL extensions on your PaaS in self-service via ITCare. The list of supported extensions is available in the documentation [PostgreSQL - Features](/databases/postgresql/postgresql-features).

This feature is only available for PostgreSQL 15 and above.

### :rocket: OpenSearch 2.11.1

The OpenSearch PaaS has been updated to support and allow the provisioning of version 2.11.1.

{% embed url="<https://github.com/opensearch-project/opensearch-build/blob/main/release-notes/opensearch-release-notes-2.11.1.md>" %}

### :tools: ITCare - UI improvements

The main menu of ITCare has been improved to provide a better navigation by reducing the page cascading.

### :tools: ITCare - New notification engine

The old notification has been scraped and replaced with a better one capable of handled very precise notifications rules. This lets you customize exactly which notifications you want to receive using subscriptions and to which recipients using email broadcast groups.

Your previous notification subscriptions have been retained.

### :tools: Kubernetes - Ingress provider customization

It is now possible to select the Ingress provider you want for Kubernetes in the creation wizard.\
Ingress providers available are : NGINX, Istio and Traefik.

## March 2024

### :rocket: SQL Server 2022

[SQL Server](/databases/sql-server) 2022 is now available in self service in ITCare. Both Standard and Enterprise editions can be selected for provisioning as in previous versions.

## February 2024

### :tools: Kubernetes - display improvements

In ITCare, the Kubernetes display has been improved to display the Ingress role on your nodes as well as the version of the Operating System deployed on each nodes.

### :tools: Load balancers - Custom HTTP URL check

After improving the way URL are handled in ITCare, it is now possible to create your own HTTP URL checks directly from ITCare on your load balancer using the URL tab.

## January 2024

### :rocket: Debian 12

Version 12 of the Linux Debian distribution is available for deployment in ITCare.\
Automation has been improved and provisioning is now quicker.

Security enforcement previously available in Debian 11 is still applied but it is now optional and can be disabled in the wizard.

### :rocket: MariaDB 10.11

New LTS version of [MariaDB](/databases/mariadb) is available for deployment in ITCare.\
Check the official MariaDB release notes for more information.

### :tools: Patch Party - improvement

Resources can now be included or excluded in batch mode from your Service page. Also, we've improved the Patch status information with a dedicated panel in your resource overview to quickly see if your resource is patched and when will the next Patch Party happen.

### :rocket: Custom descriptions for resources and Services

Custom descriptions can be added to your resources and Services in ITCare to quickly identify your applications.

### :rocket: Favorite resources

To help you navigate to your preferred resources, you can now add resources to your personal favorite list that you can can summon from the ITCare header.

### :rocket: New Networks tab in Compute section

A new tab in available in the Compute section to browse the Networks available for your cloud with their properties.

### :tools: Maintenance calendar - improvement

The maintenance calendar has been improved to display custom events specific to each customer. Private RFCs and events will now appear in the ITCare calendar for your cloud.

### :tools: Security section - improvement

The Security section has been improved with a new entry point for Bot Defense & DoS Protection with its details regarding blocked requests and attacks.

## October 2023

### :rocket: Apache Kafka 3.6.0

Version 3.6.0 of [Apache Kafka](/messaging/apache-kafka), the open-source platform for distributed event streaming, is now available for deployment via ITCare. This new version uses the Raft consensus algorithm and does away with Zookeeper.

### :rocket: PostgreSQL 15

Version 15 of [PostgreSQL](/databases/postgresql) is available for deployment via ITCare. It is compatible with all the features previously offered.

### :rocket: PostgreSQL - Self-service restoration

The [PostgreSQL](/databases/postgresql) self-service restore feature, which lets you restore a backup from one source to another destination, is now available in ITCare.

### :hammer\_pick: Load balancer - Bot defense

A new "Strict" mode has been added to the [Bot Defense](/security/bot-defense) feature.

This more restrictive profile can be rapidly deployed in the event of an attack on your load balancers. Its fine-tuning is designed to block a greater number of requests.

## September 2023

### :rocket: Create multiple resources at once

You can create up to 5 additional resources with the same configuration. The additional resources will be located in the same area but the availability zones can be different.

### :rocket: New "duplicate" template action

When displaying a virtual instance, you can now use this existing resource as a template to create a new resource with the same properties: CPU, RAM, network, storage, management options.

{% hint style="warning" %}
Please verify the **amount of storage** of the disk in the new template. Based on the source template, you might have the wrong amount of storage configured. This is a known bug!
{% endhint %}

The feature can save time to create a new virtual instance but will not **CLONE** anything.

### :hammer\_pick: **Wizard - Network selection** <a href="#releasesitcare-trueblueimprovementnetworkconfiguration" id="releasesitcare-trueblueimprovementnetworkconfiguration"></a>

When creating a resource, the network selection is now aware of the Service environment.\
If the Service has:

* a **Production** environment, production networks are displayed by default.
* a **Non-Production** environment, non-production networks are displayed by default.

In both cases, production and non-production networks remain available for selection.

### :hammer\_pick: Global Service - **Maintenance management** <a href="#releasesitcare-trueblueimprovementmaintenanceatservicelevel" id="releasesitcare-trueblueimprovementmaintenanceatservicelevel"></a>

Maintenances can now be scheduled on multiple or all resources at the service level.

### :rocket: PostgreSQL - **Enable High Availability** <a href="#releasesitcare-farm" id="releasesitcare-farm"></a>

Single [PostgreSQL](/databases/postgresql) instance can now be converted to a highly available PostgreSQL cluster with two nodes. This operation is **not reversible**.

### :hammer\_pick: New **management options on clusters** <a href="#releasesitcare-trueblueimprovementmanagementoptionsatfarmlevel" id="releasesitcare-trueblueimprovementmanagementoptionsatfarmlevel"></a>

New management actions are now available on clusters:

* **Resize**: it can also be done at node level depending on the configuration of the product
* **Patch party**: statuses for each resource are now visible in the service extended view

### :rocket: Kubernetes - U**pgrade in self-service** <a href="#releasesitcare-truegreennewupgrade" id="releasesitcare-truegreennewupgrade"></a>

It is now possible to upgrade your [Containers (K8s)](/compute/containers-k8s) cluster to the last supported version from the manage menu of the cluster:

* Upgrade to the next highest version is possible - jumping versions is not allowed
* Downgrade is not possible

### :rocket: Load balancers - **URL management** <a href="#releasesitcare-loadbalancers.1" id="releasesitcare-loadbalancers.1"></a>

URLs related to a Load balancer can now be managed individually:

* A dedicated URL tab is available in the Load balancer page
* Following actions can be performed per URL or on a group of URL: Schedule Maintenance, Enable / Disable Monitoring
* URL creation is available in the management actions of the Load balancer


# Overview

## Getting started with the ITCare API <a href="#apiitcare-gettingstartedwiththeitcare-api" id="apiitcare-gettingstartedwiththeitcare-api"></a>

The ITCare REST API complies with the OpenAPI standard specifications.\
The online documentation is available at this address: [https://api.cegedim.cloud/](https://api.cegedim.cloud/itcare-console/swagger-ui/index.html)

Example:

<pre class="language-bash" data-title="Get ITCare status"><code class="lang-bash"><strong>curl -X GET "https://api.cegedim.cloud/itcare/health"
</strong></code></pre>

## ITCare API structure <a href="#apiitcare-philosiphy" id="apiitcare-philosiphy"></a>

Each resource belongs to one of these 3 levels of hierarchy : Category, Type, Family. An overview of the categorization is described as follows :

| Category           | Type          | family |
| ------------------ | ------------- | ------ |
| Application server | Tomcat        |        |
|                    | Wildfly       |        |
| Container          | Kubernetes    |        |
| Instance           | Linux         | CentOS |
|                    |               | Debian |
|                    |               | Oracle |
|                    |               | RHEL   |
|                    |               | Ubuntu |
|                    | Windows       |        |
|                    | Unix          |        |
| Load balancer      | Load Balancer |        |
| Managed database   | MariaDB       |        |
|                    | OpenSearch    |        |
|                    | PostgreSQL    |        |
|                    | Redis         |        |
|                    | SQL Server    |        |
| Message broker     | Apache Kafka  |        |
|                    | RabbitMQ      |        |
| Storage            | GlusterFS     |        |

When getting a resource an attribut named `path` is available in the output to inform about which category-type-family to navigate in order to get details about the resource.

The API is resource centric : the main entry point of the API could be `/compute/resources`. It can be used to explore basic informations and navigate to the proper category and get the details.

## What date/time format is used by the API? <a href="#apiitcare-whatdate-timeformatisusedbytheapi" id="apiitcare-whatdate-timeformatisusedbytheapi"></a>

JSON does not natively support the Date/Time format.\
All parameters tagged as Date by the API are therefore strings in ISO8601 format.

```
YYYY-MM-DDTHH:MM:SS.sssZ
```

Z corresponds to the time zone: +0200 for example.

```
2016-06-01T12:27:19.000+0200
```

For GET requests, do not forget to URL-Encode these parameters.

## Can I run blank actions via the API? <a href="#apiitcare-canirunblankactionsviatheapi" id="apiitcare-canirunblankactionsviatheapi"></a>

Some methods allow testing of API calls without actually triggering the action in ITCare. However, the validation is still done. To activate the Dry Run mode, simply add a custom header to your HTTP requests:

```
ITCare-DryRun: true
```

Once the server processes your request, the same custom header will be included in the response.

## How do asynchronous actions work? <a href="#apiitcare-howdoasynchronousactionswork" id="apiitcare-howdoasynchronousactionswork"></a>

Some methods are asynchronous and require a delay after their invocation.\
This applies to time-consuming transactions such as resource administration or reporting.\
Methods that operate asynchronously will respond:

* an HTTP return code 202
* a body containing a tracking ID for the current asynchronous operation

Here is an example of code in Python that explains the asynchronous operation:

{% code overflow="wrap" %}

```python
"""
Launch action and get its descriptor
"""
action = itcare.post('/api/resource', payload=my_payload)
  
"""
Loop on getting its status
"""
while action['status']=='IN_PROGRESS':
    time.sleep(1)
    action = itcare.get('/api/actions/{}'.format(action['id']))
  
"""
Print its status
"""
print action['status']
```

{% endcode %}

The status of the actions can be :

* IN\_PROGRESS
* SUCCESS
* ERROR


# Authentication

## How do I authenticate to the ITCare API ? <a href="#apiitcare-howdoiauthenticatetotheitcareapi" id="apiitcare-howdoiauthenticatetotheitcareapi"></a>

The ITCare API uses the OAuth 2.0 protocol for authentication and authorization. It supports the usual OAuth 2.0 scenarios such as those used for web servers and client applications.

This means that each API request must contain an "Authorization" header embedding an access token previously obtained through credentials.

{% code overflow="wrap" fullWidth="false" %}

```bash
curl -X GET "https://itcare.cegedim.cloud/itcare/{api-definition}/{api-endpoint}" -H "Authorization: Bearer {token}"
```

{% endcode %}

## How do I get an API account? <a href="#apiitcare-howdoigetanapiaccount" id="apiitcare-howdoigetanapiaccount"></a>

To query the ITCare API, an API account is required in order to obtain the mandatory access token.\
To obtain this API account, a request must be submitted to the **cegedim.cloud** support teams by providing the following information:

* The target organization
* A simple description of the target usage of the API

## How do I get an access token? <a href="#apiitcare-howdoigetanaccesstoken" id="apiitcare-howdoigetanaccesstoken"></a>

To obtain an access token, the client must submit a request to the endpoint [/token](https://accounts.cegedim.cloud/auth/realms/cloud/protocol/openid-connect/token).\
The authorization server requires client authentication to issue an access\_token.\
Here is an example of an access\_token request:

{% code overflow="wrap" %}

```bash

curl -X POST "https://accounts.cegedim.cloud/auth/realms/cloud/protocol/openid-connect/token" \
-H "Authorization: Basic $(echo -n 'CLIENT_ID:CLIENT_SECRET' | base64)" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials"


```

{% endcode %}

In general, we can use the base64 command to encode a string.\
Using command-line tools in Linux for exemple :

{% code overflow="wrap" %}

```bash
$echo -n 'CLIENT_ID:CLIENT_SECRET' | base64
(gives the base64 of your CLIENT_ID:CLIENT_SECRET)
```

{% endcode %}

If the access\_token request is allowed and valid, here is a sample response:

{% code overflow="wrap" %}

```json
{
   "access_token":"...",
   "expires_in":1200,
   "refresh_expires_in":7200,
   "refresh_token":"...",
   "token_type":"bearer"
}
```

{% endcode %}

When the token expires, it is possible to :

* Request a new access\_token
* Refresh the token by querying the endpoint /token

{% code overflow="wrap" %}

```bash
curl -X POST "https://accounts.cegedim.cloud/auth/realms/cloud/protocol/openid-connect/token" \
-H "Authorization: Basic $(echo -n 'CLIENT_ID:CLIENT_SECRET' | base64)" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=client_credentials&refresh_token=****************"
```

{% endcode %}


# Errors

ITCare API uses conventional HTTP response codes to indicate the success or failure of an API request.

As a general rule:

* Codes in the **`2xx`** range indicate success.
* Codes in the **`4xx`** range indicate incorrect or incomplete parameters (e.g. a required parameter was omitted, or an operation failed with a 3rd party, etc.).
* Codes in the **`5xx`** range indicate an error with ITCare's servers.

This table shows more exemples about HTTP response codes

<table><thead><tr><th width="133.33333333333331">Code</th><th>Description</th><th>Reponse body</th></tr></thead><tbody><tr><td><code>200</code></td><td>Request successfully processed</td><td>Varies depending on what was</td></tr><tr><td><code>201</code></td><td>Successfully created object</td><td>Object created</td></tr><tr><td><code>202</code></td><td>Order of creation of the object successfully processed, the request will be processed asynchronously</td><td>Empty or tracking object describing the processing of the asynchronous request</td></tr><tr><td><code>400</code></td><td>Bad query - Syntax or consistency error in the query. Must be corrected by the issuer</td><td>Blank or indication of the error to be corrected on the client side</td></tr><tr><td><code>401</code></td><td>Unauthenticated access to the resource</td><td>Empty</td></tr><tr><td><code>403</code></td><td>Unauthorized access</td><td>Empty</td></tr><tr><td><code>404</code></td><td>Non-existent resource</td><td>Empty</td></tr><tr><td><code>409</code></td><td>Conflict</td><td>Empty</td></tr><tr><td><code>422</code></td><td>Inconsistent data</td><td>Empty</td></tr><tr><td><code>500</code></td><td>Fatal API error</td><td>Empty</td></tr><tr><td><code>503</code></td><td>Service temporarily unavailable</td><td>Empty</td></tr></tbody></table>

ITCare also outputs an error message and an error code formatted in JSON:

```json

{
    "status": "BAD_REQUEST",
    "errorCode": "INVALID_FIELD_VALUE",
    "errorDesc": "name",
    "errorMessage": "Error on field 'name'
}


```


# Pagination

Some methods return paginated results. The formatting of a paginated result is always:

```json
{
    "content": [
        ...
    ],
    "totalElements": ...,
    "last": false,
    "totalPages": ...,
    "sort": {
        "empty": true,
        "sorted": false,
        "unsorted": true
    },
    "first": true,
    "size": ...,
    "number": ...,
    "numberOfElements": ...,
    "empty": false
}
```

The `page` and `size` values can be added to the query parameters of the original query in order to get the next or previous page.

## Example

You make a GET request to a paginated endpoint and to get the first page and 50 items `https://api.cegedim.cloud/foo/bar?page=1&size=50`


# API Reference

You can explore the categorized API specification and use the **Test it** feature in order to execute and test the endpoints.


# Quick start

You can explore the categorized API specifications and use the **Test it** feature in order to execute and test the endpoints.

Two kinds of authentifications are available : *Bearer* or *Oauth*.

When using the **Test it** option with *Oauth2* , please :

* Select the scopes : `openid` and `email`
* Enter the cliendId to be : `cgdm-itcare-api-academy`

To use Bearer checkout the [Authentication](/itcare-api/itcare-api-authentication) section.

**Notes :**

* The parameters *Cookies*, *Headers* are optional.
* The display of the popup after clicking to **Test it** may take several seconds.


# Analytics


# Matomo

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/analytics/matomo" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/analytics/matomo" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/analytics/matomo/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/analytics/matomo/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/analytics/matomo/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Changes


# Changes

{% openapi src="/files/zANOakynyNg4s1uqBPfC" path="/changes" method="get" %}
[changes.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-bcff6b510ca7c26fc8ed039d5b34194c834bfba3%2Fchanges.json?alt=media\&token=96bbb20d-5015-4dc3-b26b-ae53af68a098)
{% endopenapi %}


# Compute


# Application Servers

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/application-servers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Backup Policies

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/backup-policies" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/backup-policies/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Containers

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/ingress-providers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}/loadbalancers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}/loadbalancers" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}/metrics" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/containers/kubernetes/{id}/nodes/{nodeId}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Environments

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/environments" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Instances

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}/snapshots" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}/snapshots" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}/snapshots" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}/snapshots/{snapshotId}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/instances/{id}/storage" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Platform

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/platform/products" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/platform/products/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/platform/products/{id}/regions" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/platform/resources-obsolescence" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/platform/stats/global" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/platform/support-policy" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Resource Filters

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resource-filters" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Resource Types

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resource-types" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resource-types/{type}/technologies" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Resources

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/metrics" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/parents" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/backup-policies" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/comments" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/dns-aliases" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/dns-aliases" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/dns-aliases/{fqdn}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/farm-networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/history" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/loadbalancers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/parent" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/patch-policy" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/tags" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/tags" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/tags" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/tags" method="put" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{id}/urls" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/resources/{name}" method="head" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Services

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/actions-in-progress" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/application-servers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/brokers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/hardwares" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/instances" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/kubernetes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/loadbalancers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/managed-databases" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/network-clusters" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/patch-policies" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/patch-policies" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/relations" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/relations/stats" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/resources" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/stats" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{id}/storage" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/services/{serviceId}/history" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Statuses

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/statuses" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Tag Keys

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/tag-keys" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Tag Values

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/tag-values" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Types

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/compute/types" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Databases


# Databases

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# MariaDB

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/mariadb" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/mariadb/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/mariadb/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/mariadb/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/mariadb/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/mariadb/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# OpenSearch

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/opensearch" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/opensearch/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/opensearch/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/opensearch/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/opensearch/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/opensearch/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# PostgreSQL

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}/databases" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}/extensions" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/postgresql/{id}/versions" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Redis

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/redis" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/redis/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/redis/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/redis/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/redis/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/redis/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# SQL Server

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/databases/sqlserver/{name}" method="head" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Hardwares


# Hardwares

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/hardwares/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Messaging


# Apache Kafka

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/apache-kafka" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/apache-kafka/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/apache-kafka/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/apache-kafka/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/apache-kafka/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/apache-kafka/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Message Brokers

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# RabbitMQ

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/rabbitmq" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/rabbitmq/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/rabbitmq/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/rabbitmq/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/rabbitmq/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/message-brokers/rabbitmq/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Networking


# Domains

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/domains" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/domains/{domainId}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Load Balancers

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/internal-whitelist" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/protocols" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/events" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/members" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/members" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/members/{memberId}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/members/{memberId}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/ssl-profiles" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/stats" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/urls" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/urls" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/loadbalancers/{id}/urls/{urlId}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Network Clusters

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/network-clusters/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/network-clusters/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/network-clusters/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Networks

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/networking/networks/{id}/loadbalancers-networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Operations


# Actions

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/actions" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/actions/{actionId}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Operations

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/operations" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Storage


# Glusterfs

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs/{id}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs/{id}/nodes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/glusterfs/{id}/volumes" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Overdrive

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/overdrive" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/overdrive" method="post" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/overdrive/{id}" method="delete" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/overdrive/{id}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/storage/overdrive/{id}" method="patch" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Topology


# Topology

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{regionId}/areas/{areaId}/certificates" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{regionId}/areas/{areaId}/ssl-profiles" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}/areas" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}/areas/{area}/availability-zones/{az}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}/areas/{area}/availability-zones/{az}/networks/{network}/authentication-domains" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}/areas/{area}/healthchecks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}/areas/{area}/loadbalancers-networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}

{% openapi src="/files/ndTxZvrQZ62XTQm5rjob" path="/topology/regions/{region}/areas/{area}/networks" method="get" %}
[compute.json](https://835168969-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2FXoHyOBZPpJv3UALn4V%2Fuploads%2Fgit-blob-79ec766c6c3781ef30e74d5f30d16cbb7c5b2f82%2Fcompute.json?alt=media\&token=8e8e1d4e-fa97-41af-8b4f-0cee24fb02e8)
{% endopenapi %}


# Products

Several Cloud Native products are available in the cegedim.cloud catalog.

They are listed by category in the sections below, for a quick overview and the ability to navigate directly to the associated public documentation.

The vast majority of these products are available in self-service via ITCare, our cloud platform management tool.

For more information on our commercial offers, please visit our official website.

{% embed url="<https://cegedim.cloud/en/products/>" %}

## Compute

{% tabs %}
{% tab title="Virtual instances" %}

<figure><img src="/files/At1Ze1M8FdNm84ul0wJG" alt=""><figcaption></figcaption></figure>

With the exception of AIX, all managed [Virtual instances](/compute/virtual-instances) are available for self-service consumption using our cloud management platform, ITCare.

They are highly customizable and resizable. They offer the greatest flexibility when a product is not available in platform-as-a-service (PaaS) mode.

The following operating systems and distributions are supported by cegedim.cloud :

* Linux
  * Debian
  * Ubuntu
  * Centos
  * Red Hat Linux Enterprise (RHEL)
  * Oracle Linux
* Windows Server
* AIX
  {% endtab %}

{% tab title="Containers (K8s)" %}

<figure><img src="/files/eRPZ4hiyxM80dmnN5vEK" alt=""><figcaption></figcaption></figure>

[Containers (K8s)](/compute/containers-k8s) are dedicated Kubernetes clusters available for self-service consumption in our ITCare cloud management platform.

Kubernetes is an open-source container orchestration platform that automates the deployment, scaling, and management of containerized applications. It is provided as a managed service by cegedim.cloud and benefits from the infrastructure, operations, and support we provide.

This includes features like scaling, monitoring, security patching, and simplified deployment, making it easier for developers and teams to focus on application development and avoid the complexities of managing the underlying infrastructure.
{% endtab %}
{% endtabs %}

## Analytics

{% tabs %}
{% tab title="Matomo" %}

<figure><img src="/files/YkWVpbpsDDOGWUCgQi8y" alt=""><figcaption></figcaption></figure>

[Matomo](/analytics/matomo) is a PaaS[^1] available for self-service consumption via our ITCare cloud management platform.

Depending on the number of pages tracked per month, several components will be deployed and managed by cegedim.cloud, allowing you to focus on using and configuring Matomo.
{% endtab %}
{% endtabs %}

## Databases

{% tabs %}
{% tab title="MariaDB" %}

<figure><img src="/files/iHobCHq1G3EFXiUBXOv1" alt="" width="50"><figcaption></figcaption></figure>

[MariaDB](/databases/mariadb) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table><thead><tr><th width="273"></th><th width="212.33333333333331">Standalone</th><th>Galera Cluster</th></tr></thead><tbody><tr><td>Instances</td><td>1</td><td>3</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Storage (per instance)</td><td>10 - 2048 GB</td><td>10 - 2048 GB</td></tr><tr><td>Supported Version(s)</td><td><ul><li>11.4</li><li>10.11</li><li>10.6</li></ul></td><td><ul><li>11.4</li><li>10.11</li><li>10.6</li></ul></td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://mariadb.org/>" %}
{% endtab %}

{% tab title="OpenSearch" %}

<figure><img src="/files/W4YydZ17l4des9uX2ihm" alt="" width="54"><figcaption></figcaption></figure>

[OpenSearch](/databases/opensearch) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table data-full-width="false"><thead><tr><th width="286"></th><th width="412.3333333333333">Cluster</th></tr></thead><tbody><tr><td>Instances</td><td>3 - 5+</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td></tr><tr><td>Stockage (per instance)</td><td>100 - 8000 GB</td></tr><tr><td>Supported Version(s)</td><td>2.*</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://opensearch.org/>" %}
{% endtab %}

{% tab title="PostgreSQL" %}

<figure><img src="/files/qDGf1sjU2JIi6QMRkNRT" alt="" width="52"><figcaption></figcaption></figure>

[PostgreSQL](/databases/postgresql) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table data-full-width="true"><thead><tr><th width="267"></th><th width="222">Standalone</th><th>High availability</th></tr></thead><tbody><tr><td>Instance</td><td>1</td><td>2</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Stockage (per instance)</td><td>10 - 2048 GB</td><td>10 - 2048 GB</td></tr><tr><td>Supported versions</td><td>10 to 16</td><td>12 to 16</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://www.postgresql.org/>" %}
{% endtab %}

{% tab title="Redis" %}

<figure><img src="/files/s98LFcReNIEfEcZ22KED" alt="" width="50"><figcaption></figcaption></figure>

[Redis](/databases/redis) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table data-full-width="false"><thead><tr><th width="267"></th><th width="237">Standalone</th><th>Cluster</th></tr></thead><tbody><tr><td>Instance(s)</td><td>1</td><td>3</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Stockage (per instance)</td><td>10 - 2048 GB</td><td>10 - 2048 GB</td></tr><tr><td>Supported version(s)</td><td><ul><li>7.2</li><li>6.2</li></ul></td><td><ul><li>7.2</li><li>6.2</li></ul></td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>TLS/SSL</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://redis.io/>" %}
{% endtab %}

{% tab title="SQL Server" %}

<figure><img src="/files/vYhrvqqTiNR92BjkKHyb" alt="" width="37"><figcaption></figcaption></figure>

[SQL Server](/databases/sql-server) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table data-full-width="false"><thead><tr><th width="267"></th><th width="237">Standalone</th><th>Always On</th></tr></thead><tbody><tr><td>Instance(s)</td><td>1</td><td>3</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Storage (per instance)</td><td>10 - 4096 GB</td><td>10 - 4096 GB</td></tr><tr><td>Supported version(s)</td><td><ul><li>2022</li><li>2019</li><li>2017</li><li>2016</li></ul></td><td><ul><li>2022</li><li>2019</li><li>2017</li><li>2016</li></ul></td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>
{% endtab %}
{% endtabs %}

## Messaging

{% tabs %}
{% tab title="Apache Kafka" %}

<figure><img src="/files/FR2LJ8yKFpDaOwTsDj5B" alt="" width="30"><figcaption></figcaption></figure>

[Apache Kafka](/messaging/apache-kafka) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table data-full-width="false"><thead><tr><th width="267"></th><th>Cluster</th></tr></thead><tbody><tr><td>Brokers</td><td>3+</td></tr><tr><td>Controllers</td><td>3</td></tr><tr><td>CPU (per broker)</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per broker)</td><td>4 - 384 GB</td></tr><tr><td>Stockage</td><td>40 - 1024 GB</td></tr><tr><td>Supported version(s)</td><td>3.6.0</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://kafka.apache.org/>" %}
{% endtab %}

{% tab title="RabbitMQ" %}

<figure><img src="/files/xqozWEcJNErQmjC6XtqF" alt=""><figcaption></figcaption></figure>

[RabbitMQ](/messaging/rabbitmq) is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table><thead><tr><th width="273"></th><th width="212.33333333333331">Standalone</th><th>Cluster</th></tr></thead><tbody><tr><td>Instances</td><td>1</td><td>3</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Stockage (per instance)</td><td>10 - 2048 GB</td><td>10 - 2048 GB</td></tr><tr><td>Supported version(s)</td><td>3.13</td><td>3.13</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://www.rabbitmq.com/>" %}
{% endtab %}
{% endtabs %}

## Security

{% tabs %}
{% tab title="AVA" %}

<figure><img src="/files/0Dzz6smxImVyCTkGpFnL" alt=""><figcaption></figcaption></figure>

The [Advanced Vulnerability Assessment](/security/advanced-vulnerability-assessment) solution is a vulnerability analysis and detection service for your resources exposed to the Internet.

This service is not available on a self-service basis and requires contact with the cegedim.cloud sales team.
{% endtab %}

{% tab title="Bot Defense" %}

<figure><img src="/files/Ebqj9zDP4za6aYPdDWNS" alt=""><figcaption></figcaption></figure>

[Bot Defense](/security/bot-defense) is a protection feature against malicious bots and distributed denial-of-service attacks.

It can be individually activated on your load balancers directly from our cloud management platform, ITCare.
{% endtab %}

{% tab title="Phishing" %}

<figure><img src="/files/gUkKdMzkbCYjVvcKtcSk" alt=""><figcaption></figcaption></figure>

The [Phishing Campaign](/security/phishing-campaign) service is tailored to assess the effectiveness of e-mail security awareness.

This service is not available on a self-service basis and requires contact with the cegedim.cloud sales team.
{% endtab %}
{% endtabs %}

## Monitoring

{% tabs %}
{% tab title="Extrahop" %}

<figure><img src="/files/Jdj9mtwUcfHnQ0k86djD" alt=""><figcaption></figcaption></figure>

The [ExtraHop](/monitoring/extrahop) based advanced monitoring solution gives you access to detailed dashboards on your resources.

This service can be activated on a self-service basis via our ITCare cloud management platform.
{% endtab %}
{% endtabs %}

## Storage

{% tabs %}
{% tab title="GlusterFS" %}

<figure><img src="/files/6rLUnMDveYADaBT42Uos" alt=""><figcaption></figcaption></figure>

[GlusterFS](/storage/glusterfs) is an open-source distributed file system that allows for scalable and high-performance storage across multiple servers. It aggregates storage resources from multiple machines into a single storage pool, offering a single namespace for easy management and access.

With its ability to scale and handle large amounts of data, GlusterFS provides benefits such as improved storage capacity, fault tolerance, and high availability for various applications and workloads.

GlusterFS is a self-service PaaS[^1] available for consumption via our ITCare cloud management platform.

<table data-full-width="false"><thead><tr><th></th><th>Cluster</th></tr></thead><tbody><tr><td>Instance(s)</td><td>2</td></tr><tr><td>CPU (per instance)</td><td>2 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 GB</td></tr><tr><td>Supported version(s)</td><td>10.2</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

{% embed url="<https://www.gluster.org/>" %}
{% endtab %}

{% tab title="Object Storage" %}

<figure><img src="/files/LlBUDfqVNwiDHsDW1DRG" alt=""><figcaption></figcaption></figure>

cegedim.cloud's S3-compatible (Simple Storage Service) [Object Storage](/storage/object-storage) solution is a cloud-based storage service. It provides scalable, secure, and durable storage for various types of data, including files, images, videos, and backups.

The benefits of an S3 object storage solution include high availability, low-cost storage, flexible access controls, automatic data redundancy, and the flexibility to choose different providers and avoid vendor lock-in.

<table data-full-width="false"><thead><tr><th width="331">Features</th><th>Availability</th></tr></thead><tbody><tr><td>S3 compatibility</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr><tr><td>Geo-replication</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Quota</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Object Lock</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>File lifecycle</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Presigned URLs</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr></tbody></table>
{% endtab %}
{% endtabs %}

[^1]: Platform as a Service


# Support policy

How does cegedim.cloud support its managed products?

## Product support policy

cegedim.cloud's managed services include support.\
This support is divided into 4 phases:

* **Standard phase**: cegedim.cloud offers full product support.
* **End-of-sale phase**: secondary phase indicating that a new version has been elected in the Standard support phase. We strongly advise you to migrate to a more recent version.
* **Extended support phase:** third phase, starting at the end-of-life (EOL) date announced by the publisher for the product. This means that many services are no longer guaranteed, and switched to best efforts.
* **End of Support phase**: terminal phase activated when cegedim.cloud is no longer able to provide support. Charges may apply if the system is considered a security risk (breach, data compromise, need for isolation).

Here is a detailed listing of features by support phase:

<table data-full-width="true"><thead><tr><th width="419">Description</th><th data-type="checkbox">Standard</th><th data-type="checkbox">End of sale</th><th data-type="checkbox">Extended</th><th data-type="checkbox">End of support</th></tr></thead><tbody><tr><td>Technical incident supervision &#x26; support</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Standard requests</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Guaranteed restoration time</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>24x7 Support</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Data backup, restoration and Geo-replication</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Disaster recovery</td><td>true</td><td>true</td><td>true</td><td>false</td></tr><tr><td>Managed cybersecurity</td><td>true</td><td>true</td><td>false</td><td>false</td></tr><tr><td>Quarterly security patches and minor updates</td><td>true</td><td>true</td><td>false</td><td>false</td></tr><tr><td>Critical security patches and updates</td><td>true</td><td>true</td><td>false</td><td>false</td></tr><tr><td>Deployment via ITCare</td><td>true</td><td>true</td><td>false</td><td>false</td></tr></tbody></table>

## How to request support ? <a href="#postgresqlhowtos-howtorequestsupport" id="postgresqlhowtos-howtorequestsupport"></a>

From our could platform manager ITCare, you can create a support request ticket.\
Either directly from the homepage or from the **Support** section in the left-hand side menu.\
Click on the button **Make a request.**

First, search for the form corresponding to the product you need assistance with by typing the product name in the search bar. Select the form and provide the required information.

A support ticket will be created upon submission.

{% hint style="info" %}
Please allow up to 7 working days for your request to be processed.
{% endhint %}

## How to report an incident ?

Managed resources are monitored by cegedim.cloud if the Monitoring has been enabled.\
However, an incident form is available in our cloud platform manager ITCare if you need let us know about an issue that we would have missed.

From the homepage or the **Support** section of the left-hand side menu, click on the **Report an incident** button.

To better process your incident, a severity level is required:

* No impact
* Degradation
* Service disruption

Look for the proper form by searching the product name you have an issue with then provide the required information.

An incident ticket will be created, and our support team will contact you as soon as possible.


# Patch policy

How does cegedim.cloud handle patching servers ?

## What's a Patch Party?

cegedim.cloud ensures all servers are patched during events called **Patch Parties**.

These events happen **every quarter on Sundays**, so 4 times per year.

During a Patch Party, patchs are installed on all servers not excluded from the events then followed by a reboot.

{% hint style="warning" %}
Services will be interrupted during a Patch Party!
{% endhint %}

## What's the schedule?

Patch Parties happen every quarter. Two Patch Parties are scheduled every quarter:

* **QA Patch Party**: happens first during business hours on **Thursdays** and is only applicable to non-production environments.
* **Production Patch Party**: happens 3 weeks after the QA Patch Party on **Sundays** and is only applicable to production environments.

{% hint style="info" %}
Patch Party events are available in the calendar of our cloud platform management tool ITCare.
{% endhint %}

## What can I do?

### Review patch information

On every resource details page, a panel named **Patch status** lets you review:

* The last time the resource was patched successfully
  * Timestamp of the upgrade
  * Patch tag of the upgrade with this format: **YYYY-QQ** (e.g. 2022-Q4)
* The next Patch Party scheduled if the resource is not excluded
* The person who excluded the resource and when if the resource is excluded

### Include or exclude

On every resource details page, a **Patch Party** button lets you include or exclude the resource from all future Patch Parties.

Excluding a resource requires a reason explaining why. Including lets you select the **Patch Group** which will affect when your resource is effectively patched during the patching day.

### Change the Patch Group

In the same **Patch Party** button as described above, you can change the desired **Patch Group** at any moment.

3 Patch Groups are available to split your resources. Each group be will handled at different times.

This is useful if you don't want multiple resources to be patched (and interrupted) at the same time, thus, improving your application's resiliency.

{% hint style="info" %}
PaaS products in cluster topologies will already have optimized Patch groups assigned to ensure the availability of the cluster during Patch parties.
{% endhint %}


# RACI

Sharing responsibilities

## Objective and Definitions <a href="#matomoraci-objectiveanddefinitions" id="matomoraci-objectiveanddefinitions"></a>

To have a common understanding about the responsibilities and duties between cegedim.cloud and the customer, we use a RACI matrix.

{% embed url="<https://en.wikipedia.org/wiki/Responsibility_assignment_matrix>" %}

<table data-header-hidden><thead><tr><th width="87"></th><th width="149"></th><th></th></tr></thead><tbody><tr><td><strong>R</strong></td><td>Responsible</td><td>Assigned to complete the task or deliverable</td></tr><tr><td><strong>A</strong></td><td>Accountable</td><td>Has final decision-making authority and accountability for completion (only 1 per task)</td></tr><tr><td><strong>C</strong></td><td>Consulted</td><td>An adviser, stakeholder, or subject matter expert who is consulted before a decision or action</td></tr><tr><td><strong>I</strong></td><td>Informed</td><td>Must be informed after a decision or action</td></tr></tbody></table>

## Generic RACI Matrix <a href="#matomoraci-racimatrix" id="matomoraci-racimatrix"></a>

Below is the RACI matrix describing actions related to managed products from cegedim.cloud's catalog.

There are slight differences according to the plan subscribed by the customer :

<table><thead><tr><th width="161">Plan</th><th>Description</th></tr></thead><tbody><tr><td>Self Service</td><td>The customer can create resources directly through ITCare, using self-service and pay-per-usage.</td></tr><tr><td>On Request</td><td>Resources are provisioned and delivered by cegedim.cloud on request by the customer.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="247">Actions</th><th width="174.2">Plan</th><th width="154">cegedim.cloud</th><th width="124">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Create, Stop, Start, Delete or Resize an instance or a cluster</td><td>Self Service</td><td>I</td><td>A / R</td><td><p>The decision of provisioning / stopping / starting / deleting a deployment and associated parameters is done by the customer.</p><p>The actions are performed :</p><ul><li>by customers through ITCare if they have subscribed to the "On Demand" service</li><li>for others customers, by cegedim.cloud's Professional Services team</li></ul></td></tr><tr><td>Use an instance or a cluster</td><td>*</td><td>I</td><td>A / R</td><td>Customer is responsible of the healthy usage of the product.</td></tr><tr><td>Modify configurations</td><td>On request</td><td>A / R</td><td>I</td><td>Certain configuration parameters can be modified at the customer's request.</td></tr><tr><td>Standard Monitoring</td><td>*</td><td>A / R</td><td>I</td><td>Monitoring is mandatory, and accessible to customer through ITCare.</td></tr><tr><td>Performance metrics</td><td>*</td><td>R</td><td>I</td><td>Performance metrics are provided by default and reachable through ITCare.</td></tr><tr><td>Backup and Restoration</td><td>*</td><td>R</td><td>A / I</td><td><p>Backup policy is defined by customer and applied by cegedim.cloud, which is responsible of ensuring that backups are done, and restoration of data when requested.</p><p>Customer has information about the backup in ITCare.</p></td></tr><tr><td>Disaster Recovery Protection</td><td>*</td><td>R</td><td>A / I</td><td><p>Disaster Recovery is activated by customer and applied by cegedim.cloud, which is responsible of ensuring that associated RTO and RPO are reached.</p><p>Customer has information about the Disaster Recovery Protection in ITCare.</p></td></tr><tr><td>Security Patches</td><td>*</td><td>R</td><td>A / I</td><td>Cegedim.cloud passes security patches in the execution environment, quarterly, during "Patch parties", by default.</td></tr><tr><td>Version Upgrades</td><td>On Request<br>or<br>Self Service</td><td>R</td><td>A / I / R</td><td>Upgrade can be done by the customer from the ITCare in autonomy when possible OR a request can be issued by the customer, and if the transition is possible, cegedim.cloud will upgrade or update the product version.</td></tr></tbody></table>

## Specific RACI Matrix

Some of our products have specific actions that can be carried out autonomously and in self-service from our ITCare cloud management tool. The matrices below are therefore complementary to the generic RACI matrix.

### Kubernetes

<table data-full-width="true"><thead><tr><th width="192">Actions</th><th width="153">Plan</th><th width="163">cegedim.cloud</th><th width="107">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Add a Kubernetes node</td><td>Self-service</td><td>I</td><td>A / R</td><td>Customer can add Kubernetes nodes in self-service using ITCare.</td></tr><tr><td>Resize Kubernetes nodes</td><td>Self-service</td><td>I</td><td>A / R</td><td>Customer can resize Kubernetes nodes in self-service using ITCare.</td></tr><tr><td>Remove a Kubernetes node</td><td>Self-service</td><td>I</td><td>A / R</td><td>Customer can remove a Kubernetes node in self-service using ITCare.</td></tr><tr><td>Enable HA mode</td><td>Self-service</td><td>I</td><td>A / R</td><td>Customer can enable High Availability on a Kubernetes cluster in self-service using ITCare.</td></tr></tbody></table>

### MariaDB

<table data-full-width="true"><thead><tr><th width="186">Actions</th><th width="148">Plan</th><th width="166">cegedim.cloud</th><th width="107">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Add a MariaDB read-only Replica</td><td>On Request</td><td>A / R</td><td>I</td><td>On request, a read only MariaDB replica can be configured for a standalone MariaDB node.</td></tr></tbody></table>

### OpenSearch

<table data-full-width="true"><thead><tr><th width="174">Actions</th><th width="135">Plan</th><th width="166">cegedim.cloud</th><th width="102">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Index management</td><td>*</td><td>I</td><td>A / R</td><td>Customer is responsible of the creating and managing his indices. cegedim.cloud do not have access to them except for the security_audit index.</td></tr></tbody></table>

### PostgreSQL

<table data-full-width="true"><thead><tr><th width="174">Actions</th><th width="128">Plan</th><th width="161">cegedim.cloud</th><th width="102">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Restore source PostgreSQL on a destination (seed)</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>The decision to restore a PostgreSQL farm to another PostgreSQL farm is made by the client. The actions are carried out:</p><ul><li>through ITCare if they have subscribed to the "On Demand" service.</li><li>by the Professionnals Services team at cegedim.cloud</li></ul></td></tr><tr><td>Convert to High availability</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>The decision to restore a PostgreSQL farm to another PostgreSQL farm is made by the client. The actions are carried out:</p><ul><li>through ITCare if they have subscribed to the "On Demand" service.</li><li>by the Professionnals Services team at cegedim.cloud</li></ul></td></tr></tbody></table>

### Apache Kafka

<table data-full-width="true"><thead><tr><th width="200">Actions</th><th width="148">Plan</th><th width="163">cegedim.cloud</th><th width="114">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Manage Apache Kafka objects</td><td>*</td><td>I</td><td>A / R</td><td>Customer is responsible of the Apache Kafka objects management (topics, partitions, etc..) and its healthy usage.</td></tr><tr><td>Add a broker node to an Apache Kafka cluster</td><td>*</td><td>I</td><td>A / R</td><td>Customer is responsible of the Apache Kafka cluster's nodes (topics, partitions, etc.) and its healthy usage.</td></tr></tbody></table>

### RabbitMQ

<table data-full-width="true"><thead><tr><th width="195">Actions</th><th width="148">Plan</th><th width="161">cegedim.cloud</th><th width="113">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Manage RabbitMQ objects</td><td>*</td><td>I</td><td>A / R</td><td>Customer is responsible of the RabbitMQ objects management (exchanges, queues, etc..) and its healthy usage.</td></tr></tbody></table>

### Bot Defense

<table data-full-width="true"><thead><tr><th width="224">Actions</th><th width="148">Plan</th><th width="158">cegedim.cloud</th><th width="110">customer</th><th>Commentaires</th></tr></thead><tbody><tr><td>Enable / Disable Bot Defense option on a Load Balancer</td><td>Self-service</td><td>I</td><td>A / R</td><td>The decision of enabling / disabling the Bot Defense option is done by the customer.</td></tr><tr><td>Add or delete Whitelisted IP</td><td>Self-service</td><td>I</td><td>A / R</td><td>Customer can add or delete whitelisted IP.</td></tr><tr><td>Access to DDOS and blocked requests from Bot Defense and Dos Protection</td><td>Self-service</td><td>I</td><td>A / R</td><td>Report in real time blocked request (Including blocked ip, blocking reason and the support ID).</td></tr><tr><td>Request details on blocked request</td><td>On Request</td><td>A / R</td><td>I</td><td>Upon request by the customer, more information can be provided for a blocked request by providing the support ID</td></tr></tbody></table>

### GlusterFS

<table data-full-width="true"><thead><tr><th width="195">Actions</th><th width="148">Plan</th><th width="163">cegedim.cloud</th><th width="113">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Manage storage volumes</td><td>Self-service</td><td>I</td><td>A / R</td><td>Customer is responsible of the management (creation, deletion, resize) of the storage volumes for his cluster.</td></tr></tbody></table>

### Object Storage

<table data-full-width="true"><thead><tr><th width="214">Actions</th><th width="135.2">Plan</th><th width="166">cegedim.cloud</th><th width="85">customer</th><th>Comments</th></tr></thead><tbody><tr><td>Create an <strong>Object Store</strong></td><td>Self-service</td><td>I</td><td>A / R</td><td><p>The decision of provisioning / Deleting / modify an <strong>Object Store</strong> and associated parameters is done by the customer.</p><p>The actions are performed :</p><ul><li>by customers through ITCare if they have subscribed to the "On Demand" service</li><li>for others customers, by <strong>cegedim.cloud</strong>'s Professional Services team</li></ul></td></tr><tr><td>Manage Object Store Quota</td><td>Self-service</td><td>I</td><td>A / R</td><td></td></tr><tr><td>Delete a Object Store</td><td>Self-service</td><td>I</td><td>A / R</td><td></td></tr><tr><td>Create an Object User</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>The decision of creating an <strong>Object User</strong> and associated parameters is done by the customer.</p><p>The actions are performed :</p><ul><li>by customers through ITCare if they have subscribed to the "On Demand" service</li><li>for others customers, by cegedim.cloud's Professional Services team</li></ul></td></tr><tr><td>Manage Object Users</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>The decision of modify an <strong>Object User</strong> and associated parameters is done by the customer.</p><p>These actions include the <strong>Secret Key renewal</strong> or <strong>Object User</strong> locking.</p><p>The actions are performed :</p><ul><li>by customers through ITCare if they have subscribed to the "On Demand" service</li><li>for others customers, by <strong>cegedim.cloud</strong>'s Professional Services team</li></ul></td></tr><tr><td>Delete Object Users</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>The decision of Delete an <strong>Object User</strong> and associated parameters is done by the customer.</p><p>The actions are performed :</p><ul><li>by customers through ITCare if they have subscribed to the "On Demand" service</li><li>for others customers, by <strong>cegedim.cloud</strong>'s Professional Services team</li></ul></td></tr><tr><td>Create Bucket</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>Bucket creation and associated parameters is done by the customer.</p><p>The actions are performed using the <strong>S3 API.</strong></p></td></tr><tr><td>Delete Bucket</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>Bucket deletion and associated parameters is done by the customer.</p><p>The actions are performed using the <strong>S3 API.</strong></p></td></tr><tr><td>Manage Bucket Policy</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>Bucket Policy management is done by the customer.</p><p>The actions are performed using the <strong>S3 API.</strong></p></td></tr><tr><td>Manage Lifecycle Configuration</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>Lifecycle Configuration management is done by the customer.</p><p>The actions are performed using the <strong>S3 API.</strong></p></td></tr><tr><td>Manage Object Configuration</td><td>Self-service</td><td>I</td><td>A / R</td><td><p>Object Lock configuration on Bucket or object is done by the customer.</p><p>The actions are performed using the <strong>S3 API.</strong></p></td></tr><tr><td>Availability and Monitoring</td><td>*</td><td>R / A</td><td>I</td><td><strong>cegedim.cloud</strong> will ensure the Object Storage Service is globally available and healthy at all times.</td></tr><tr><td>Multi Region Replication</td><td>*</td><td>R / A</td><td>I</td><td><p>Data replication between region is done by <strong>cegedim.cloud</strong>, which is responsible of ensuring that associated RTO and RPO are reached.</p><p>Customer has information about the Disaster Recovery Protection in ITCare.</p></td></tr><tr><td>Security Patches</td><td>*</td><td>R / A</td><td>I</td><td><strong>cegedim.cloud</strong> apply security patches. it is transparent for customers and this does not lead to an interruption of service.</td></tr><tr><td>Version Upgrades</td><td>*</td><td>R / A</td><td>I</td><td><p><strong>cegedim.cloud</strong> apply upgrade patches. it is transparent for customers and this does not lead to an interruption of service.</p><p><strong>S3 API</strong> may change.</p></td></tr></tbody></table>


# Matomo

## Description

**Matomo** (formerly called *Piwik)* is an open source measurement software that provides statistics of data on the use of a web page, such as visits, page views, origin of visits and much more.

Matomo offers the possibility of having a **complete analysis** on certain aspects of your websites with information regarding : your visitors, their behavior, patterns and more.

{% embed url="<https://matomo.org/>" %}

## Why Matomo ?

Matomo is an excellent replacement for Google Analytics for the following reasons :

* 100% Data Ownership
* Privacy Protection
* No Data Sampling
* GDPR Compliance (Recommended by the CNIL)
* Flexibility (data portability, raw access, open source, etc..)

## Platform as a Service

Matomo is deployed on-premise in **cegedim.cloud** 's data centers and is provided as a service.

**cegedim.cloud** guarantees the following level of managed service : deployment of instances, maintenance in operational condition, flexibility, security and monitoring are thus ensured by our experts.

|                        | Instance                                                      |
| ---------------------- | ------------------------------------------------------------- |
| Sizings                | <ul><li>XS</li><li>S</li><li>M</li><li>L</li><li>XL</li></ul> |
| Monitoring             | :white\_check\_mark: Option                                   |
| 24x7 Monitoring        | :white\_check\_mark: Option                                   |
| Backup                 | :white\_check\_mark: Option                                   |
| Data replication (DRP) | :white\_check\_mark: Option                                   |
| Availability           | 99.8%                                                         |
| Region selection       | :white\_check\_mark:                                          |
| Self-service           | :white\_check\_mark:                                          |

For more information, please visit [Matomo - Features](/analytics/matomo/matomo-features).

## Billing

Billing occurs monthly and varies based on the sizing selected.

Please contact your Service Delivery Manager for more information regarding pricing.


# Matomo - Features

## Description

Matomo is available in self-service in ITCare for all authorized users.

Based on the sizing selected (see Sizings below), multiple components will be deployed with a bare minimum of :

* 1 front-end web server
* 1 back-end database server
* 1 load balancer with a public facing IP (certificate included)

Higher sizings (to track more pages viewed per month) can include more web servers for load balancing. For sizing higher than XL a request ticket will be required.

Once provisioned, your Matomo instance is publicly accessible through the URL provided in ITCare.

Plugins installation and Matomo upgrades can be done by the customer in autonomy.

## Architecture

### Regions

Matomo is available in the following regions:

* EMEA - France - Boulogne-Billancourt
* EMEA - France - Toulouse

### Sizings

The following sizings are available:

<table><thead><tr><th width="103">Sizing</th><th>Estimated capacity</th></tr></thead><tbody><tr><td>XS</td><td>Tracks 100,000 page views per month or less</td></tr><tr><td>S</td><td>Tracks 1 Millions page views per month or less</td></tr><tr><td>M</td><td>Tracks 10 Millions page views per month or less</td></tr><tr><td>L</td><td>Tracks 100 Millions page views per month or less</td></tr><tr><td>XL</td><td>Tracks more than 100 Millions page views per month</td></tr></tbody></table>

#### Resize your Matomo instance

Resize is available in ITCare self-service but only allows resizing UP.

{% hint style="warning" %}
Scaling down is not currently possible.
{% endhint %}

## Supported versions

The version of the Matomo deployed depends on the last patch party.

The last version will often be available but you could have some cases where the version is lagging a bit.

In this case, the update can be either triggered by the customer in autonomy directly from the web UI interface or on request by creating a request ticket in ITCare.

## Features <a href="#matomoarchitecture-features" id="matomoarchitecture-features"></a>

This section is to list which feature / capabilities are available to customer, and how to request / perform them:

<table data-header-hidden><thead><tr><th width="161"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done by cegedim.cloud support team.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="270">Features</th><th width="130.5" data-type="checkbox">Self-service</th><th width="121" data-type="checkbox">On request</th><th>Comments</th></tr></thead><tbody><tr><td>Update Matomo</td><td>true</td><td>true</td><td>Update can be done by the super user.</td></tr><tr><td>Install and activate plugin(s)</td><td>true</td><td>false</td><td>Plugins can be installed by the super user from the web UI.</td></tr><tr><td>Manage user privileges</td><td>true</td><td>false</td><td>Super user can grant privileges to any users.</td></tr><tr><td>SSH access</td><td>false</td><td>false</td><td>SSH access is disabled and reserved to cegedim.cloud administrators.</td></tr><tr><td>Change configuration file</td><td>false</td><td>true</td><td>On request via ticket.</td></tr></tbody></table>

## Security <a href="#matomoarchitecture-security" id="matomoarchitecture-security"></a>

### Authentication & Authorizations <a href="#matomoarchitecture-authentication-and-authorizations" id="matomoarchitecture-authentication-and-authorizations"></a>

Customer is provided with a super user local account.

OpenOIDC is configured to easily add and grant other users access to Matomo.

### Secured Transport <a href="#matomoarchitecture-securedtransport" id="matomoarchitecture-securedtransport"></a>

Access to your Matomo instance is done securely through HTTPS.

### Data location <a href="#matomoarchitecture-datalocation" id="matomoarchitecture-datalocation"></a>

All datas are stored in cegedim.cloud data centers on encrypted storage arrays.

### Passwords <a href="#matomoarchitecture-passwords" id="matomoarchitecture-passwords"></a>

The password of the super user account provided to the customer is not stored nor saved by cegedim.cloud.

## Monitoring <a href="#matomoarchitecture-monitoring" id="matomoarchitecture-monitoring"></a>

Matomo and associated components are monitored by our support team.

A global health status is displayed in ITCare for your convenience.


# Matomo - Get started

## Create a Matomo instance

Connect to ITCare platform, click on the Analytics button in the main menu on the left

Click on "**Create a Matomo Instance**" and follow the instructions.

Provide the global service in which you want to create a Matomo instance into.

Give the name of the instance you want to create.

A default website name and URL can be configured during provisioning. It's optional. If left empty, dummy values will be used. Click **Next**.

Pick the sizing of the Matomo Analytics instance matching your needs and click **Next**:

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-12-59.png?version=1&#x26;modificationDate=1656940379523&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Provide the password of the super user named "administrator" that will be given to you.

{% hint style="warning" %}
The super user's password is not saved by cegedim.cloud.

Make sure to save your password!
{% endhint %}

At the next step, you can configure management options :

* Monitoring (highly recommended)
* 24/7 monitoring
* Backup (highly recommended)
* Storage replication

Click **Next**.

Select the **region** in which you want to create your Matomo instance. Click **Next**.

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-20-24.png?version=1&#x26;modificationDate=1656940824103&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Verify your inputs in the synthesis page. You can :

* Check the instance that will be created
* See the target global service
* Save your administrator password.
* Verify the management options.

Click **Submit** when ready to submit.

Once the instance is ready, you will be notified by email with the information required to connect to it. Instance creation can take up to 2 hours based on the current load on automation.

The instance will then be displayed in the management page in the Analytics section.

## Start a Matomo instance

Go to the "**Analytics**" menu from the left main menu and click on the manage link. Once presented with all the Matomo instances, click on the **Start** button of the instance of your choice.

{% hint style="warning" %}
Starting a Matomo instance will start all components.
{% endhint %}

An email notification will be sent when the service will be activated.

## Stop a Matomo instance

Go to the "Analytics" menu from the left main menu and click on the manage link. Once presented with all the Matomo instances, click on the stop button of the instance of your choice.

Input an RFC number for tracking (optional) then submit by clicking on Stop.

{% hint style="warning" %}
Stopping a Matomo instance will stop all associated components and monitoring will be disabled.
{% endhint %}

An email notification will be sent when the instance is stopped.

## Delete a Matomo instance

Go to the "Analytics" menu from the left main menu and click on the manage link. Once presented with all the Matomo instances, click on the delete button of the instance of your choice.

{% hint style="info" %}
You can only delete a previously stopped instance !
{% endhint %}

This action will **delete** all components used by that Matomo instance.

{% hint style="danger" %}
Please note that this action is not recoverable.
{% endhint %}

Input an RFC number for tracking (optional) and the instance name (mandatory) to confirm your choice then click **Delete**.

An email notification will be sent when the instance is removed.

## Resize a Matomo instance

Go to the "Analytics" menu from the left main menu and click on the manage link. Once presented with all the Matomo instances, click on the resize button of the instance of your choice.

{% hint style="info" %}
Only an instance already started can be resized.
{% endhint %}

Select the new size that can only be higher than current one and click on **Resize**.

{% hint style="danger" %}
Service will be interrupted.
{% endhint %}

An email notification will be sent when the instance is resized.

## Install Matomo plugins

Connect to your Matomo Analytics instance with the "administrator" user you provided during provisioning.

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-32-1.png?version=1&#x26;modificationDate=1656941521232&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Click on the Administration icon :\\

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-35-33.png?version=1&#x26;modificationDate=1656941733911&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Select Extensions menu

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-41-18.png?version=1&#x26;modificationDate=1656942078772&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Go at the end of the page and click on the "Install new components" button:

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-43-14.png?version=1&#x26;modificationDate=1656942194441&#x26;api=v2" alt=""><figcaption></figcaption></figure>

Look for, install and activate modules at your own discretion:\\

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-5_10-20-16.png?version=1&#x26;modificationDate=1657009217053&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

## Update Matomo software version

Connect to your Matomo Analytics instance with the "administrator" user.

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-32-1.png?version=1&#x26;modificationDate=1656941521232&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Click on the adminitration icon

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-4_15-35-33.png?version=1&#x26;modificationDate=1656941733911&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Click at the top of the page on the message indicating a new version

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-5_10-46-50.png?version=1&#x26;modificationDate=1657010810468&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Confirm the automatic upgrade\\

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-5_9-14-30.png?version=1&#x26;modificationDate=1657005270333&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>

Wait until the end of the upgrade with success message\\

<figure><img src="https://docs.cegedim.cloud/download/attachments/36689477/image2022-7-5_10-49-17.png?version=1&#x26;modificationDate=1657010957491&#x26;api=v2&#x26;effects=drop-shadow" alt=""><figcaption></figcaption></figure>


# Virtual instances

## Description

Virtual Instance is a fully managed product offered by cegedim.cloud, designed to simplify and enhance your hosting experience. With Virtual Instances, you no longer need to worry about the complexities of managing your hosting infrastructure – our expert team takes care of it all.

Our product supports a variety of operating systems such as Linux, Windows, and AIX, giving you the freedom to choose the environment that best suits your needs. It can be effortlessly deployed through our user-friendly cloud platform management tool called ITCare.

This empowers you with the flexibility to spin up your desired instance, select your preferred operating system and customize resources to meet your specific needs with a few clicks, ensuring that your instances are tailored to match your business requirements precisely.

We understand the importance of performance and reliability, which is why Virtual Instances come equipped with tailored monitoring systems, backup services and data replication. This ensures real-time visibility into the health of your instances and added security.

In summary, whether you need a Linux, Windows, or AIX operating system, and regardless of your resource requirements, Virtual Instances provide the flexibility and scalability you need.

## Virtual instances as a Service

Resource configuration can vary based on the target operating system.

|                                     | Instance                                            |
| ----------------------------------- | --------------------------------------------------- |
| Supported operating systems         | <ul><li>Linux</li><li>Windows</li><li>AIX</li></ul> |
| CPU (per instance)                  | 2 - 16                                              |
| RAM (per instance)                  | 4 - 384 GB                                          |
| Storage (per instance)              | 35 - 4096 GB                                        |
| Backup                              | :white\_check\_mark: Option                         |
| Monitoring                          | :white\_check\_mark: Option                         |
| 24x7 monitoring                     | :white\_check\_mark: Option                         |
| Data replication (DRP)              | :white\_check\_mark: Option                         |
| Availability                        | 99.8%                                               |
| Custom region and availability zone | :white\_check\_mark:                                |
| Self-service                        | :white\_check\_mark:                                |

## Billing

Billing is processed monthly and based on the number of instances and additional costs for storage, backup, 24x7 monitoring.

Cost estimation for a Virtual Instance is available via your Service Delivery Manager.


# Virtual instances - Features

## Supported operating systems

### Linux

The following Linux distributions are available when selecting Linux as an operating system for your Virtual Instance:

* Centos
* Debian
* Ubuntu
* Red Hat Linux Enterprise (RHEL)
* Oracle Linux

{% hint style="info" %}
Oracle Linux 9 offers two kernels: one fully compatible with RedHat 9 and another one labelled "unbreakable", optimized for Oracle applications.
{% endhint %}

#### Hardening on Linux

Hardening is applied on some recent Linux distributions such as Debian 11, Debian 12, Ubuntu 22, Ubuntu 24, Oracle Linux 9 and RHEL 9. Here are the different parts of the system concerned by the hardening:

* Enforcement of network security parameters
* Protection of sensible file systems
* Limitations of connection to methods using solid protocols and enforced crypting schemes within ssh
* Disabling of dynamic kernel module loading

### Windows

Windows Server is available as an operating system for your Virtual Instance. cegedim.cloud supports multiple versions from Windows Server 2016 to Windows Server 2025.

#### Hardening on Windows Server

Since Windows Server 2022 version, Hardening is applied on virtual instances, based on official Microsoft Security Baseline and CIS (Center for Internet Security) Benchmark for aligning with the latest standards and best practices to ensure Windows operating System health

### AIX

cegedim.cloud support IBM AIX operating system on IBM Power Systems. Currently supported version is major version 7 and associated Technological level versions.

## Regions <a href="#mariadbarchitecture-regions" id="mariadbarchitecture-regions"></a>

Virtual Instances are available in the following **cegedim.cloud** data centers:

* **EB3** - Boulogne-Billancourt, France
* **EB4** - Boulogne-Billancourt, France
* **EB5** - Magny-les-Hameaux, France
* **ET1** - Labège, France
* **ET2** - Balma, France

## Resources <a href="#mariadbarchitecture-ressources" id="mariadbarchitecture-ressources"></a>

A Virtual Instance can be configured and customized to your needs regarding:

* **Compute**: number of vCPUs
* **RAM**: quantity of memory allocated (will vary based on the number of vCPUs)
* **Storage**: additional disks and storage in GB to allocate to the virtual instance

### AIX Instances

Cegedim offers three levels of CPU resource guarantees available continuously (24/7):

* **Standard** : guarantees a portion of CPU resources
* **Semi-dedicated** : guarantees half of the CPU resources
* **Dedicated** : guarantees nearly all CPU resources

## Features

This section is to list which feature / capabilities are available to customer, and how to request / perform them :

<table data-header-hidden><thead><tr><th width="167"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done to cegedim.cloud support team.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="259">Feature</th><th width="125" data-type="checkbox">Self service</th><th width="118" data-type="checkbox">On request</th><th>Comments</th></tr></thead><tbody><tr><td>SSH or RDP access</td><td>true</td><td>false</td><td>SSH or RDP access is allowed and automatically provided to the requester of the virtual instance.</td></tr><tr><td>Start, stop, restart, delete and resize a Virtual Instance</td><td>true</td><td>false</td><td>Actions available in self-service in our cloud platform management tool ITCare.</td></tr><tr><td>Create, delete, restore a snapshot</td><td>true</td><td>false</td><td>Actions available in self-service in our cloud platform management tool ITCare.</td></tr><tr><td>Enable or disable Monitoring, 24x7, Backup and Data replication</td><td>true</td><td>false</td><td>Actions available in self-service in our cloud platform management tool ITCare.</td></tr><tr><td>Add or remove Monitoring downtime</td><td>true</td><td>false</td><td>Actions available in self-service in our cloud platform management tool ITCare.</td></tr><tr><td>Modify storage allocation</td><td>false</td><td>true</td><td>A request ticket is required to modify the storage allocation of a Virtual Instance.</td></tr><tr><td>Change configuration file</td><td>false</td><td>true</td><td>Some configuration files (such as repositories) will be enforced by cegedim.cloud. A request ticket is required to modify some components.</td></tr></tbody></table>

## Security <a href="#mariadbarchitecture-security" id="mariadbarchitecture-security"></a>

### Authentication <a href="#mariadbarchitecture-authentication" id="mariadbarchitecture-authentication"></a>

Authentication to the virtual instance is Active Directory based for Linux and Windows (not AIX).\
The requesting user will automatically be added as an administrator of the Virtual Instance.\
This user is then free to configure and add more users with the desired privileges.

## Backup <a href="#mariadbarchitecture-backup" id="mariadbarchitecture-backup"></a>

Backup is an option that can be enabled for your Virtual Instance. In a production environment, the backup option will always be toggled on, by default, in ITCare.

{% hint style="warning" %}
You can disable the backup option at your own risks.
{% endhint %}

Backup are taken every day and saved in the local data center then replicated to a second data center in the campus. Backup retention for virtual instances is 28 days by default but can be customized with your Service Delivery Manager to suit your needs.

The date of the last backup and the backup storage footprint can be seen directly in ITCare in the resource details page of your Virtual Instance.

## Monitoring <a href="#mariadbarchitecture-monitoring" id="mariadbarchitecture-monitoring"></a>

As featured, virtual instances are managed and thus monitoring is provided if the option has been toggled. In a production environment, the monitoring toggle is always activated by default.

{% hint style="warning" %}
You can disable the monitoring option at your own risks.
{% endhint %}

By activating the monitoring, multiple health-checks will be deployed to ensure your virtual instance is running and stays healthy. If any of those checks are triggered, our support team is notified with a ticket to solve the issue in the allowed service agreement level.

These monitoring alerts can be consulted directly in ITCare and metrics of performance are also provided for key indicators like CPU, memory, disk and network consumption.

### 24x7 monitoring

When the monitoring is enabled, it is only effective during Business Hours. To extend the monitoring outside Business Hours, the 24x7 option can be enabled and additional fees will apply.

This ensure that your Virtual Instance is monitoring at all times by our Support team and actions will be taken to escalate and solve any issue.

{% hint style="info" %}
24x7 monitoring is not mandatory and it can only be activated when the monitoring option is enabled.
{% endhint %}

## Data replication

Data replication is a feature which enables the Disaster Recovery protection. When the feature is enabled, the datas of your Virtual Instance will be replicated from the local storage array to an offsite storage array.

This means that in the event of losing the local data center, your datas are still safe in another data center and the procedure to restore and revive your Virtual Instance can be activated.

{% hint style="warning" %}
You can disable the replication option at your own risks.
{% endhint %}


# Linux - Hardening

The following Linux distributions will be hardened during provisioning and upgrade in place:

* Debian starting version 11, 12 and 13
* Ubuntu starting version 22.04 and 24.04
* Oracle Linux starting version 9
* Red Hat Enterprise Linux 9

Recommendations from the [CIS Benchmark documents](https://www.cisecurity.org/benchmark) have been followed in order to enforce, harden and secure our Linux operating systems.

## Filesystems

* Some weak filesystems are disabled in the kernel
* Separate mount points for very active filesystems: /var/log, /var/log/audit, /var/tmp
* Protection of /var/log, /tmp and /var/tmp
* Disabling removable storage

### Default Partitioning Scheme

During provisioning, instances are deployed with a standardized LVM partitioning layout. The following logical volumes are created by default:

| Mount Point    | Size   | Purpose                      |
| -------------- | ------ | ---------------------------- |
| /              | 10 GB  | Root filesystem              |
| /boot          | \~1 GB | Boot partition               |
| /boot/efi      | \~1 GB | EFI system partition         |
| /home          | 2 GB   | User home directories        |
| /opt           | 4 GB   | Optional applications        |
| /var           | 2 GB   | Variable data                |
| /var/log       | 4 GB   | System logs                  |
| /var/log/audit | 1 GB   | Audit logs                   |
| /var/tmp       | 1 GB   | Temporary files (persistent) |
| /tmp           | 2 GB   | Temporary files              |
| swap           | 2 GB   | Swap space                   |

**Total allocated space: \~28 GB**

> **Note:** The default partitioning scheme may vary depending on the operating system type (RHEL, Debian, Ubuntu) and version. The sizes indicated above are provided for reference purposes.

### Storage Allocation Behaviour

When provisioning an instance via ITcare, you can choose:

* The size of the system disk
* Additional storage volumes if needed

The provisioning process deploys the instance with the default partitioning scheme described above, but **does not automatically extend the logical volumes** to use all available disk space. The remaining space stays available in the LVM volume group for you to allocate according to your specific needs.

#### Example 1: Single System Disk (60 GB)

| Component                    | Size        |
| ---------------------------- | ----------- |
| System disk                  | 60 GB       |
| Volume group total           | \~58 GB     |
| Allocated (default LVs)      | 28 GB       |
| **Available for allocation** | **\~30 GB** |

#### Example 2: System Disk (70 GB) + Additional Volume (80 GB)

| Component                             | Size                |
| ------------------------------------- | ------------------- |
| System disk                           | 70 GB               |
| Additional volume                     | 80 GB (unformatted) |
| Volume group total (system disk only) | \~68 GB             |
| Allocated (default LVs)               | 28 GB               |
| **Available in VG for allocation**    | **\~40 GB**         |
| **Additional volume available**       | **80 GB**           |

### Extending Storage After Provisioning

Once your instance is provisioned, you can allocate the available space according to your requirements:

* **Extend existing logical volumes** to increase space for specific mount points (e.g., /var/log, /opt, /home)
* **Create new logical volumes** for application data or databases
* **Format and mount additional volumes** for dedicated storage needs

This approach provides flexibility to adapt the storage layout to your specific application and data requirements.

## Secure boot

* Ensure root password is required to boot in rescue mode

## Sudo usage

* Tracing of every usage of sudo command

## Process hardening

* Several parameters are activated in kernel to protect running processes

## Network

* Unnecessary or weak network services are disabled (enforced by configuration manager)
* Ensure time service is configured and active
* IPv6 is disabled
* Several kernel parameters are set to protect network
* Disable uncommon network protocols

### RHEL 9 Specifics — Firewall (firewalld)

On **Red Hat Enterprise Linux 9** instances, the `firewalld` service is **enabled and started by default** from provisioning.

The default zone applied is `public`, which enforces a **deny-by-default** policy on incoming traffic: all inbound traffic is blocked unless explicitly allowed. By default, only the following services are permitted inbound:

| Service       | Port(s) |
| ------------- | ------- |
| SSH           | TCP 22  |
| DHCPv6-client | UDP 546 |

> **Note:** Outbound traffic is allowed by default. If your application requires additional open ports, you will need to add explicit firewalld rules using `firewall-cmd` or through your configuration management tool (e.g., Puppet).

## Logging

* Centralization of system logs
* Ensure that every event is logged

## Access and Authentication

* Ensure cron service is active and configured
* Ensure cron directories are protected
* Ensure SSH is active and configured
* Force SSH secure protocols and parameters
* Ensure idle sessions deactivation
* Ensure strong password rules are applied
* Ensure sensitive authentication files are protected


# Windows - Hardening

The Windows operating system are hardened during provisioning since 2022 Version.

Recommandations from the [Microsoft Security Compliance Toolkit](https://www.microsoft.com/en-us/download/details.aspx?id=55319) and [CIS Benchmark documents](https://www.cisecurity.org/benchmark) are applied in order to enforce, harden and secure the Windows operating systems. Several hundred parameters are checked and configured to ensure Windows Health The following topics are covered :

## Account Policies

* Define different account option for user authentication on microsoft network

## User Rights Assignment

* Specify what a user or system account is authorized to do on a Windows Server

## Administrative templates

Define specifics and secures configurations on the following windows component

* Control Panel
* Network
* Printers
* Start Menu and Taskbar
* System

## System Services

* Configure Windows Services, disabling unnecessary and unsecure services

## Security Options

* Define a set of operating system configurations that govern how users can interact with devices and corporate resources

## Windows Firewall

## Advanced Audit Policy Configuration

* Allows to specify which security events are audited on Windows and how logs are saved

## PowerShell

* PowerShell's execution policy is a safety feature that controls the conditions under which PowerShell loads configuration files and runs scripts


# Virtual instances - Get started

## How do I deploy a virtual instance?

To create a new virtual instance, head over to ITCare and search for your target global service where you'll create your new instance.

Search for your Global Service in the top search bar and click on it to display its information page.

Once in your Global Service, click on the **Create Resource** button, select either **Linux, Windows** or **AIX** and the desired version and/or distribution.

Fill in the fields:

* Name of the virtual machine
* CPU/RAM sizing
* Disks and storage capacity for each disk
* Target location
* Target network
* Management options (backup, monitoring, 24/7, data replication)

Click Next once all fields have been filled in.

In the customization step, you can:

* Ask for a specific request (note that this will delay the automated task as it requires human intervention)
* Create multiple instances with the same configuration (names and location to be provided)

Then click on Next.

Review the summary before submitting the form.

{% hint style="info" %}
Provisioning can take up to 2 hours, depending on the current automation load.
{% endhint %}

Once the deployment is ready, you'll be notified by e-mail.

## How do I connect to my virtual instance?

Whatever the instance or operating system you need to connect to, the use of a Bastion is mandatory. You first need to connect to the Bastion assigned to your tenant from which you can then initiate an SSH or RDP connection to your instances.

### Linux

SSH connection using Putty or mRemoteNG installed on your Bastion. Credentials to use are your own adm.corp user credentials.

Direct root login is disabled on all Linux virtual instances. You have to login with a non root user, then use **sudoers** permissions to perform high privilege action.

#### How to authenticate ?

Two authentication methods are allowed:

* LDAP
* Public and Private Key

To login over SSH using **LDAP** authentication method, you must have a valid account in the same LDAP domain where your virtual instance is enrolled.

It is not necessary to specify the LDAP domain name in your login.

```shell-session
$ ssh johndoe@myinstance
 johndoe@myinstance's password: xxxxxx 
 Creating directory '/home/johndoe'. 
 johndoe@myinstance:~$
```

On first logon, your home directory will be automatically created : /home/\<yourlogin>/

To get the list of your allowed commands, enter the following command: **sudo -l**

```shell-session
johndoe@myinstance:~$ sudo -l
Matching Defaults entries for johndoe on myinstance:
    env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
 
User johndoe may run the following commands on myinstance:
    (ALL) NOPASSWD: ALL
    (ALL) NOPASSWD: ALL
```

To login to a virtual linux instance with your SSH public key, your key must be added in the **/home/\<user>/.ssh/authorized\_keys** file.

Where **\<user>** is the name of the local account on the target server and login specifying the name of the local user : ssh user\@host

To remove access to an user with SSH key, delete its public key from authorized\_keys file on the target local account.

### Window

RDP connection using Remote Desktop from mRemoteNG or builtin Windows mstsc on your Bastion. Credentials to use are your own adm.corp user credentials.

### AIX

SSH connection using Putty or mRemoteNG installed on your Bastion. Local user account with sudo or root access will be provided when the instance is delivered.

## How do I grant access to a Linux virtual instance ?

### LDAP login authorization

To list LDAP users and groups allowed to login, use the following command:

<pre class="language-shell-session"><code class="lang-shell-session"><strong>$ grep allow /etc/sssd/sssd.conf
</strong>simple_allow_groups = LDAP_GROUP_ADMIN
simple_allow_users = bernard
</code></pre>

* **simple\_allow\_groups** : LDAP groups
* **simple\_allow\_users** : LDAP users

{% hint style="info" %}
You can only add group or user that are enrolled into the same LDAP Domain where your **virtual instance** is enrolled.
{% endhint %}

#### Add users

To allow login to an LDAP user, use the following command:

```shell-session
// add one user
$ realm permit --realm <domain> <user>

// add multiple users
$ realm permit --realm <domain> user1 user2 userX
```

#### Add groups

To allow login to an LDAP groups, use the following command:

```shell-session
// add one group
$ realm permit --realm <domain> --groups <group>

// add multiple groups
$ realm permit --realm <domain> --groups group1 group2 groupX
```

#### Remove access

To remove access to an LDAP user or group, use the following command:

```shell-session
// remove user
$ realm permit --withdraw <user>

// remove group
$ realm permit --withdraw --groups <group>
```

## How do I manage Linux permissions ?

To grant **sudo** statements to an LDAP users or groups (and also for local user or groups), create a new file in **/etc/sudoers.d**

{% hint style="warning" %}
It is not recommended to add some **sudoers** statement in **/etc/sudoers** file.\
Reserved to the system.
{% endhint %}

<pre class="language-shell-session"><code class="lang-shell-session"><strong>$ touch /etc/sudoers.d/devops
</strong></code></pre>

Use **visudo** command to edit your sudoers file:

```shell-session
$ visudo -f /etc/sudoers.d/devops
# devops
%G_GROUP_DEVOPS    ALL=(ALL)  NOPASSWD:ALL
bernard            ALL=(ALL)  NOPASSWD:ALL
```

{% hint style="info" %}
As UNIX groups, LDAP groups in **sudoers** file, must be prefixed by a **'%**'.
{% endhint %}


# Containers (K8s)

## Description

**cegedim.cloud** provides enterprise-grade **managed Kubernetes** clusters with the highest level of security and resilience built-in. All clusters are powered by **RKE2** (Rancher Kubernetes Engine 2), a security-focused Kubernetes distribution designed to meet stringent compliance requirements.

By leveraging these managed clusters, you can deploy your standard Kubernetes workloads across **cegedim.cloud** Availability Zones and data centers to maximize your applications' availability and ensure business continuity.

**cegedim.cloud** also provides a comprehensive management console powered by **Rancher**, enabling you to:

* Manage your workloads through an intuitive interface
* Configure **built-in Observability capabilities** (Logging and Monitoring)
* Integrate with your existing platforms (Grafana, ElasticSearch, Prometheus, etc.)
* Monitor cluster health and performance in real-time

{% hint style="info" %}
For customers with existing RKE-based clusters, please refer to our [Migration Guide](/compute/containers-k8s/k8s-get-started/k8s-migration-rke-to-rke2) for information about transitioning to RKE2.
{% endhint %}

## Cegedim Container Services (CCS)

**cegedim.cloud** Cegedim Container Services (CCS) delivers production-ready Kubernetes infrastructure with the following key capabilities:

* **Latest Kubernetes Versions**: Access to the most recent, stable Kubernetes releases on demand
* **Persistent Storage (Optional)**: Ceph CSI available for persistent volumes with Auto-Provisioning and High Availability
* **Enterprise-Grade Security**: Hardened cluster configurations adhering to CIS Kubernetes Benchmark standards
* **Network Compliance**: Adherence to enterprise network, storage, and security standards
* **Built-in Observability**: Integrated monitoring and metrics systems available on-demand for each application
* **Flexible Networking**: Support for dynamic network policies and security rules

|                           | Cluster                                |
| ------------------------- | -------------------------------------- |
| Nodes                     | 2 - 2000 (depending on CNI provider)   |
| CPU (per node)            | 2 - 16                                 |
| RAM (per node)            | 6 - 256 GB                             |
| Kubernetes Distribution   | RKE2                                   |
| Management Platform       | Rancher                                |
| Monitoring                | :white\_check\_mark:                   |
| 24x7 Monitoring           | :white\_check\_mark: Option            |
| Backup worker node        | :x:                                    |
| Backup ETCD               | Every 2 hours with 7 days of retention |
| Backup Persistent Volumes | :white\_check\_mark:                   |
| Data replication (DRP)    | :white\_check\_mark: Option            |
| High availability         | :white\_check\_mark: Option            |
| Availability              | 99.9%                                  |
| Region selection          | :white\_check\_mark:                   |
| Self-service              | :white\_check\_mark:                   |

For more information, please visit [K8s - Features](/compute/containers-k8s/k8s-features).

## Ordering a Kubernetes Cluster

To provision a new Kubernetes cluster through ITCare:

1. **Access ITCare Portal**: Log in to [ITCare](https://itcare.cegedim.cloud)
2. **Navigate to Kubernetes**: Go to Compute > Services, select your Service, then "Create a resource" > Kubernetes under Containers section
3. **Specify Your Requirements**:
   * Cluster size and topology (Standard or High Availability)
   * CNI provider preference (Canal, Calico, or Cilium)
   * Ingress provider preference (Nginx, Traefik, or Istio)
   * Node specifications (CPU, RAM per node)
   * Number of nodes required
   * Region selection (EB or ET)
   * VLAN selection for network connectivity
4. **Submit Your Order**: Review and confirm your cluster configuration
5. **Provisioning Time**: Cluster deployment typically takes 2-4 hours

Once your cluster is provisioned, you will receive a notification email. You can then log in to the Rancher URL with your Cegedim credentials to access and manage your cluster.

## Billing

Kubernetes cluster billing is processed **monthly** and includes the following cost factors:

### Base Costs

* **Node count and specifications**: Number of nodes and their CPU/RAM configuration
* **Storage**: Persistent volumes and backup services (if applicable)

### Monitoring Options (Additional Cost)

* **Standard Monitoring**: Alerts with no support
* **Office Hours Support**: Support during business hours
* **24x7 On-Call Support**: Round-the-clock support availability

### No Impact on Cost

* **CNI provider selection**: Canal, Calico, or Cilium have the same pricing
* **Ingress provider selection**: Nginx, Traefik, or Istio have the same pricing

For a detailed cost estimation tailored to your specific Kubernetes cluster requirements, please contact your **Service Delivery Manager**.


# K8s - Features

There are 2 possible topologies of K8s cluster provided by **cegedim.cloud**:

* **Standard**: workloads are deployed in a single data center, but protected against data center disaster using a secondary data center as failover.
* **High Availability**: workloads are deployed amongst two datacenters. If multi-replica is used and workload is well distributed, no service interruption occurs when a datacenter is down.

## Topologies <a href="#kubernetesarchitecture-topologies" id="kubernetesarchitecture-topologies"></a>

### Compute topology <a href="#kubernetesarchitecture-computetopology" id="kubernetesarchitecture-computetopology"></a>

**cegedim.cloud** provides a compute topology based on :

* Region : a pair of data centers
* Area : infrastructure network isolation between tenants
* Availability Zones : inside an area, isolated infrastructure for Compute and Storage

```mermaid
graph LR
    subgraph region["Region"]
        direction LR
        subgraph dc1["Datacenter"]
            azA["Availability<br/>Zone A"]
            azB["Availability<br/>Zone B"]
        end
        subgraph dc2["Datacenter"]
            azC["Availability<br/>Zone C"]
        end
    end
    azB -. "Area — network isolation between tenants" .- azC

    classDef az fill:#e3f2fd,stroke:#1565c0,stroke-width:2px,color:#000
    classDef dc fill:#bbdefb,stroke:#1565c0,stroke-width:1px,color:#000
    class azA,azB,azC az
```

### Kubernetes clusters topologies <a href="#kubernetesarchitecture-kubernetesclusterstopologies" id="kubernetesarchitecture-kubernetesclusterstopologies"></a>

Kubernetes clusters can be deployed using 2 topologies :

<table data-full-width="true"><thead><tr><th>Topology</th><th>Datacenters of Masters</th><th>Datacenters of workers</th><th>Worker Availability Zones</th><th>Cluster Availability Zones</th><th data-type="checkbox">Disaster Recovery Protection</th><th>Recovery Time Objective (RTO)</th></tr></thead><tbody><tr><td>Standard</td><td>1</td><td>1</td><td>2</td><td>2</td><td>true</td><td>4h</td></tr><tr><td>High Availability</td><td>3</td><td>2</td><td>3</td><td>4</td><td>true</td><td>0 - 15 min</td></tr></tbody></table>

Based on your requirements in terms of RTO and costs, you can choose the best topology for your needs.

### Availability of topologies

<table data-full-width="true"><thead><tr><th>Topology</th><th data-type="checkbox">EB-EMEA</th><th data-type="checkbox">EB-HDS</th><th data-type="checkbox">ET-EMEA</th><th data-type="checkbox">ET-HDS</th></tr></thead><tbody><tr><td>Standard</td><td>true</td><td>true</td><td>true</td><td>true</td></tr><tr><td>High Availability</td><td>true</td><td>false</td><td>true</td><td>false</td></tr></tbody></table>

For more details about the High Availability topology, please follow this page [High Availability](/compute/containers-k8s/k8s-get-started/high-availability#title-text).

### Topology Keys <a href="#kubernetesarchitecture-topologykeys" id="kubernetesarchitecture-topologykeys"></a>

**cegedim.cloud** uses standard topology keys :

<table><thead><tr><th width="454">Key</th><th>Component</th></tr></thead><tbody><tr><td>topology.kubernetes.io/region</td><td>Region</td></tr><tr><td>topology.kubernetes.io/zone</td><td>Availability Zone</td></tr><tr><td>kubernetes.io/hostname</td><td>FQDN of node</td></tr></tbody></table>

## Components and Versions <a href="#kubernetesarchitecture-componentsandversions" id="kubernetesarchitecture-componentsandversions"></a>

**cegedim.cloud** uses **RKE2** (Rancher Kubernetes Engine 2) as the Kubernetes distribution. RKE2 is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector.

Here is the list of the components and tools that are deployed in a standard delivered cluster:

| Features                | Versions                                          |
| ----------------------- | ------------------------------------------------- |
| Kubernetes Distribution | RKE2                                              |
| Rancher                 | 2.12                                              |
| Kubernetes              | 1.33                                              |
| Ingress controllers     | ingress-nginx 1.12.1, traefik 3.3.4, istio 1.24.1 |
| Prometheus              | 2.53.1                                            |
| Grafana                 | 11.1.0                                            |
| Helm                    | 3.17.0                                            |
| CSI Ceph                | 3.14.0                                            |
| Node OS                 | Ubuntu 24.04                                      |

## Network Architecture <a href="#kubernetesarchitecture-networkarchitecture" id="kubernetesarchitecture-networkarchitecture"></a>

{% hint style="info" %}
The following network architecture is described using **Nginx ingress controller**. The configuration is slightly different with Traefik or Istio, but the overall architecture and concepts remain the same.
{% endhint %}

Here is a figure with all network components explained:

### Outbound flow <a href="#kubernetesarchitecture-outboundflow" id="kubernetesarchitecture-outboundflow"></a>

<figure><img src="/files/fvelPWRzWxSpw4i0Hjk9" alt=""><figcaption></figcaption></figure>

* Two pods of 2 namespaces that belong to the same Rancher Project can fully communicate between them.
* Two pods of 2 namespaces that belong to two different Rancher Project cannot communicate unless user defines a Network Policy dedicated for this need.
* Pods from Rancher Project named System can communicate to pods from other Rancher Projects.
* Pods can only send requests to servers of the same VLAN, unless a specific network opening rule is configured between the two VLANs.
* Pods cannot send requests to Internet unless, a proxy is setup inside the pod or specific network opening rule is configured for the related VLAN.

### Inbound flow <a href="#kubernetesarchitecture-inboundflow" id="kubernetesarchitecture-inboundflow"></a>

<figure><img src="/files/xxGwNAWYh8gACD8CqakG" alt=""><figcaption></figcaption></figure>

* Requests toward kube api-server can be reverse-proxied by Rancher URL.
* Workload hosted by pods cannot be directly accessible from outside of K8S cluster, but via ingress layer for HTTP protocol or via a NodePort service for TCP protocol with a respective Load Balancer.

### Ingress Controller : nginx <a href="#kubernetesarchitecture-ingresscontroller-nginx" id="kubernetesarchitecture-ingresscontroller-nginx"></a>

nginx is the ingress controller deployed to expose your workloads. You can find relevant documentation on official Github.

{% embed url="<https://github.com/nginxinc/kubernetes-ingress>" %}

Two ingress controllers are deployed:

* One exposing to internal Cegedim Network
  * Workload name: nginx-int-ingress-nginx-controller
  * Listen on every ingress node at the port :80
  * Ingress class: "nginx" (default, so no ingress class needs to be specified)
* One exposing to internet
  * Workload name: nginx-ext-ingress-nginx-controller
  * Listen to every ingress node at the port :8081
  * Ingress class: nginx-ext
    * using the annotation: kubernetes.io/ingress.class: "nginx-ext"

### Load Balancing, DNS and Certificates <a href="#kubernetesarchitecture-loadbalancing-dnsandcertificates" id="kubernetesarchitecture-loadbalancing-dnsandcertificates"></a>

A K8s cluster comes with :

* An Elastic Secured Endpoint, managed by F5 appliances, exposing the K8s workload to the cegedim internal network (once you're connected to Cegedim LAN, either physically or through VPN)
* A \*.\<yourclustername>.ccs.cegedim.cloud DNS resolution to this endpoint
* A \*.\<yourclustername>.ccs.cegedim.cloud SSL certificate configured

### Requesting specific configuration <a href="#kubernetesarchitecture-requestingspecificconfiguration" id="kubernetesarchitecture-requestingspecificconfiguration"></a>

You can use ITCare in case of a need of a specific configuration :

* Exposing your workloads to the Internet or private link
* Using a specific FQDN to deploy your workload
* Using a specific certificate to deploy your workload
* Using Traefik as Ingress Provider instead of nginx
* Adding other Ingress Providers
* Accessing resources outside of cluster

## Cluster Customization Options <a href="#kubernetesarchitecture-clustercustomizationoptions" id="kubernetesarchitecture-clustercustomizationoptions"></a>

When creating a new Kubernetes cluster, **cegedim.cloud** provides you with the flexibility to customize key networking components according to your specific requirements and workload characteristics.

### CNI Provider Selection <a href="#kubernetesarchitecture-cniproviderselection" id="kubernetesarchitecture-cniproviderselection"></a>

You can select from the following Container Network Interface (CNI) providers when provisioning your cluster:

| CNI Provider | Description                                                                               | Maximum Nodes |
| ------------ | ----------------------------------------------------------------------------------------- | ------------- |
| **Canal**    | Combination of Calico and Flannel, providing policy enforcement and simplified networking | 200 nodes     |
| **Calico**   | Advanced networking and network policy solution with high scalability                     | 2,000 nodes   |
| **Cilium**   | eBPF-based networking, observability, and security with high performance                  | 2,000 nodes   |

{% hint style="info" %}
The CNI provider selection should be based on your cluster size requirements and specific networking needs. For clusters requiring more than 200 nodes, Calico or Cilium is recommended.
{% endhint %}

{% hint style="warning" %}
When using **Cilium** as the CNI provider, **kube-proxy** is not deployed. Cilium replaces kube-proxy functionality with its eBPF-based implementation, providing enhanced performance and efficiency.
{% endhint %}

#### When to Choose Each CNI Provider

**Canal (Calico + Flannel)**

* Standard deployments requiring up to 200 nodes
* Proven stability with simplified networking
* FIPS 140-2 compliance requirements
* Default choice for most use cases

**Calico**

* Large-scale deployments (200-2,000 nodes)
* Advanced network policy requirements
* High scalability requirements

**Cilium**

* High-performance workloads requiring maximum throughput
* Advanced observability and monitoring needs
* eBPF-based networking and security features
* Large-scale deployments (200-2,000 nodes) with enhanced performance
* Clusters where eliminating kube-proxy overhead is beneficial

### Ingress Provider Selection <a href="#kubernetesarchitecture-ingressproviderselection" id="kubernetesarchitecture-ingressproviderselection"></a>

You can choose your preferred Ingress controller to manage external access to services within your cluster:

| Ingress Provider | Description                                                                                           |
| ---------------- | ----------------------------------------------------------------------------------------------------- |
| **Nginx**        | Industry-standard ingress controller with robust features and wide community support (default option) |
| **Traefik**      | Modern cloud-native ingress controller with automatic service discovery                               |
| **Istio**        | Service mesh providing advanced traffic management, security, and observability capabilities          |

{% hint style="info" %}
To request a specific CNI or Ingress provider during cluster creation, please specify your requirements through ITCare when ordering your Kubernetes cluster.
{% endhint %}

## Cluster Hardening <a href="#kubernetesarchitecture-clusterhardening" id="kubernetesarchitecture-clusterhardening"></a>

For more information regarding the hardening of Kubernetes, please follow this page [Hardening](/compute/containers-k8s/k8s-features/hardening).

## Persistent Storage <a href="#kubernetesarchitecture-persistantstorage" id="kubernetesarchitecture-persistantstorage"></a>

For more information regarding the persistant solution available for **cegedim.cloud**'s Kubernetes clusters, please follow this page [Persistent Storage](/compute/containers-k8s/k8s-features/persistent-storage).


# Hardening

## Context and motivation <a href="#kubernetesclusterhardening-contextandmotivation" id="kubernetesclusterhardening-contextandmotivation"></a>

**cegedim.cloud** provides CNCF certified Kubernetes clusters, ensuring compliance with industry standards and best practices.

Kubernetes has built-in features & mecanisms to keep healthy kubernetes nodes and workoads:

* kube-scheduler decides on which nodes to place pods in function of pod requested resources and node unreserved resources.
* kubelet Out-Of-Memory kills pods that consumes more resources than limited values defined in the spec (OOM killed).
* For any reason, if the node is run out of resources, kubelet evicts pods to relieve the pressure on the nodes (pod eviction). Pod eviction decision is based on QoS of pods.

Keep in mind that **cegedim.cloud** provides standard Kubernetes clusters with these features and qualified the official Kubernetes documentations below:

{% embed url="<https://kubernetes.io/docs/tasks/configure-pod-container/assign-cpu-resource/>" fullWidth="false" %}

{% embed url="<https://kubernetes.io/docs/tasks/configure-pod-container/assign-memory-resource/>" %}

The problem is in real life application:

* not all technologies are natively container friendly
* resource usage metrics collected by kubelet (or node exporter, etc.) is not real time
* resource usage metrics are not taken into account by kube scheduler
* kubelet as a Linux process is not always the most prioritized process, especially when nodes run out of CPU.

Failing to handle resources stresses on nodes by kubelet leads to node failures and the redeployment of all workloads related. In worse case, a domino effect on node faillure can happen.

## cegedim.cloud's solution <a href="#kubernetesclusterhardening-cegedim.cloudssolution" id="kubernetesclusterhardening-cegedim.cloudssolution"></a>

**cegedim.cloud** provides a hardening solution called cgdm-hardening:

* One pod hardening-slave per worker nodes: writes CPU & RAM consumption to centralized database
* One pod hardening-master deployed on master nodes: reads metrics from database and takes action in case of crisis
* Hardening stack has a very low resource footprint
* cgdm-hardening is also capable of detecting network issues present on nodes and labels them with **cegedim.io/network=broken** for operational visibility

Hardening-master pod can take action in two modes:

* Preventive mode (as a kube scheduler assistant, default mode): puts the taint **cegedim.io/overload=true:NoSchedule** to avoid placing more pods on under-pressure nodes (85% RAM or 90% CPU). When CPU is below 85% and RAM is below 80% taint will be removed.
* Protective mode (as a kube controler assistant): when RAM consumption reach 95%, kills newest pods, ones after anothers, to relieve the pressure. It is not activated by default

{% hint style="warning" %}
You should never use wildcard toleration on applications, otherwise preventive effect of this solution will be invalid.
{% endhint %}

<pre class="language-yaml" data-title="Toleration to avoid in apps" data-overflow="wrap" data-line-numbers><code class="lang-yaml"><strong>tolerations:
</strong>  - effect: NoSchedule
    operator: Exists
</code></pre>

{% hint style="warning" %}
**Limitation:** Node faillure due to extremly high peak of CPU during very short period of time can not be mitigated with this solution.
{% endhint %}

## How to disable / enable the hardening <a href="#kubernetesclusterhardening-howtodisable-enablethehardening" id="kubernetesclusterhardening-howtodisable-enablethehardening"></a>

New Kubernetes clusters wil be provisioned with the preventive hardening activated.

If workloads deployed by customers create a lot of node failure (TLS\_K8S\_NODES), the protective mode will be activated.

Customer can disable this hardening by creating an ITCare request ticket.\
This means customer will have to reboot the nodes themself in case of crisis.

Customer can re-enable this hardening by creating an ITCare request ticket any time.


# Persistent Storage

## Introduction <a href="#kubernetespersistentstorage-introduction" id="kubernetespersistentstorage-introduction"></a>

**cegedim.cloud** now provides a multi-tenants Ceph Storage Platform as a CSI provider with the following specifications:

* Data is replicated 4 times and is evenly distributed (using Ceph Crush Map) across 2 Datacenters to ensure that under disaster scenarios, 2 replicas of data are always available.
* Each Kubernetes cluster, as a Ceph client, has its own pool of data on Ceph server and consumes services with its own pool scoped credential.
* Only CSI Ceph RBD is provided for the moment.

Further information on Ceph CSI can be found here:

{% embed url="<https://docs.ceph.com/>" %}

### Versions <a href="#kubernetespersistentstorage-versions" id="kubernetespersistentstorage-versions"></a>

<table><thead><tr><th width="177">Component</th><th>Version</th></tr></thead><tbody><tr><td>Ceph Cluster</td><td>19.2.2</td></tr><tr><td>CSI Ceph</td><td>3.14</td></tr></tbody></table>

{% hint style="info" %}
**cegedim.cloud** annually performs RFC (Request for Change) to keep both Ceph server and client (CSI) up-to-date with the latest stable releases.
{% endhint %}

### Storage Class <a href="#kubernetespersistentstorage-storageclass" id="kubernetespersistentstorage-storageclass"></a>

<table><thead><tr><th width="176">Name</th><th>Description</th></tr></thead><tbody><tr><td>cgdm-rwo</td><td>use <strong>CSI Ceph rbd</strong> to provision <code>ReadWriteOnce</code> persistent volumes</td></tr></tbody></table>

### High Availability <a href="#kubernetespersistentstorage-highavailability" id="kubernetespersistentstorage-highavailability"></a>

<table><thead><tr><th width="280"></th><th>EB</th><th>ET</th></tr></thead><tbody><tr><td>Replication</td><td>x4</td><td>x4</td></tr><tr><td>Fault Tolerance: 1 AZ is DOWN</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr><tr><td>Fault Tolerance: 1 DC is DOWN</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

### CSI features <a href="#kubernetespersistentstorage-csifeatures" id="kubernetespersistentstorage-csifeatures"></a>

|                                      | CSI ceph-rbd         |
| ------------------------------------ | -------------------- |
| Provisioning new PV                  | :white\_check\_mark: |
| Remount existing PV                  | :white\_check\_mark: |
| Compatible with all K8S applications | :white\_check\_mark: |
| Multi-mount (RWX)                    | :x:                  |
| Resizable                            | :white\_check\_mark: |
| Snapshot                             | :white\_check\_mark: |
| Fault Tolerance: loss of 1 AZ        | :white\_check\_mark: |
| Fault Tolerance: loss of 1 DC        | :white\_check\_mark: |
| Compatible with K8S 1.22+            | :white\_check\_mark: |
| Compatible with K8S 1.22-            | :white\_check\_mark: |

## Enabling Ceph Storage <a href="#kubernetespersistentstorage-enablingcephstorage" id="kubernetespersistentstorage-enablingcephstorage"></a>

{% hint style="warning" %}
CSI Ceph persistent storage is **not enabled by default** on Kubernetes clusters. To enable this feature, please submit an ITCare request ticket specifying the cluster name and your storage requirements.
{% endhint %}

## Usage Recommendations <a href="#kubernetespersistentstorage-usagerecommendations" id="kubernetespersistentstorage-usagerecommendations"></a>

{% hint style="info" %}
**cegedim.cloud** recommends careful consideration when planning to use CSI Ceph for your storage needs:

* **Database Workloads**: For production database requirements, we recommend using **cegedim.cloud**'s official managed database PaaS offerings (PostgreSQL, MariaDB, Redis, etc.) instead of CSI Ceph. These managed services are specifically optimized, monitored, and supported for database workloads.
* **Critical Applications**: For critical application data, thorough testing in pre-production environments is essential before deploying to production with CSI Ceph storage.
* **Best Use Cases**: CSI Ceph is well-suited for:
  * Application state storage
  * Configuration and cache data
  * File storage for non-critical workloads
  * Development and testing environments

Testing your specific workload with CSI Ceph in a non-production environment will help ensure it meets your performance and reliability requirements before production deployment.
{% endhint %}

## Snapshot and Restore PVC in Kubernetes <a href="#kubernetespersistentstorage-snapshotandrestorepvcinkubernetes" id="kubernetespersistentstorage-snapshotandrestorepvcinkubernetes"></a>

**cegedim.cloud** uses External Snapshotter to snapshot & restore PVC of your Kubernetes clusters.

All information about this application can be found here:

{% embed url="<https://github.com/kubernetes-csi/external-snapshotter>" %}

### How to know if I have active snapshotclass on my cluster <a href="#kubernetespersistentstorage-howtoknowifihaveactivesnapshotclassonmycluster" id="kubernetespersistentstorage-howtoknowifihaveactivesnapshotclassonmycluster"></a>

We recommend to name the snapshotclass after the storageclass as a best practice. Simply execute the below command to check:

{% code lineNumbers="true" fullWidth="true" %}

```bash
$ kubectl get sc
NAME                 PROVISIONER           RECLAIMPOLICY   VOLUMEBINDINGMODE   ALLOWVOLUMEEXPANSION   AGE
cgdm-rwo (default)   rbd.csi.ceph.com      Delete          Immediate           true                   57d

$ kubectl get  volumesnapshotclass
NAME       DRIVER                DELETIONPOLICY   AGE
cgdm-rwo   rbd.csi.ceph.com      Delete           36d
```

{% endcode %}

## How to list available CSI in my cluster <a href="#kubernetespersistentstorage-howtolistavailablecsiinmycluster" id="kubernetespersistentstorage-howtolistavailablecsiinmycluster"></a>

To list all CSI available in a Kubernetes cluster, perform the following:

{% code lineNumbers="true" fullWidth="true" %}

```
$ kubectl get sc
NAME                  PROVISIONER              RECLAIMPOLICY   VOLUMEBINDINGMODE      ALLOWVOLUMEEXPANSION   AGE
cgdm-rwo (default)    rbd.csi.ceph.com         Delete          Immediate              true                   42d
```

{% endcode %}

Here is a mapping between Storage Class and CSI:

<table><thead><tr><th width="234">Storage Classes</th><th>CSI</th></tr></thead><tbody><tr><td>cgdm-rwo</td><td>Ceph RBD</td></tr></tbody></table>


# K8s - Get started

## Getting started

### Connect to Rancher UI

**cegedim.cloud** uses [Rancher](https://rancher.com/docs/rancher/v2.x/en/) as the [Kubernetes ](https://kubernetes.io/fr/docs/home/)platform management.

Rancher handle ITCare SSO authentication : the login / password is the same as ITCare.

#### Rancher Instances <a href="#kuberneteshowtos-rancherinstances" id="kuberneteshowtos-rancherinstances"></a>

Rancher is reachable through different URLs depending on your cluster's region and environment:

| Region / Environment                           | Rancher URL                               | Access Requirements                             |
| ---------------------------------------------- | ----------------------------------------- | ----------------------------------------------- |
| **ET (Toulouse-Labège) - Production**          | <https://rancher-et.cegedim.cloud>        | Server network access only (e.g., from bastion) |
| **ET (Toulouse-Labège) - Non-Production**      | <https://rancher-et-qa.cegedim.cloud>     | Standard network access                         |
| **EB (Boulogne-Billancourt) - Production**     | <https://rancher-eb.cegedim.cloud>        | Server network access only (e.g., from bastion) |
| **EB (Boulogne-Billancourt) - Non-Production** | <https://rancher-eb-qa.cegedim.cloud>     | Standard network access                         |
| **EM (Monaco Cloud)**                          | Managed by the same Ranchers as EB region | Same access as EB                               |

{% hint style="warning" %}
**rancher-et.cegedim.cloud** and **rancher-eb.cegedim.cloud** are only accessible from the server network. You must connect through a bastion host to access these Rancher instances.
{% endhint %}

\
In ITCare, you can find your cluster URL in the cluster detail page :

<figure><img src="/files/lW0d8sQygHrRFJJm7KqG" alt=""><figcaption></figcaption></figure>

#### Connect to Rancher <a href="#kuberneteshowtos-connecttorancher" id="kuberneteshowtos-connecttorancher"></a>

Rancher will ask for an authentication at first login : simply click on "Login with OIDC"

<figure><img src="/files/UnnGQiamjMjdnRvGGEpm" alt=""><figcaption></figcaption></figure>

Then you will be redirected to the standard login process :

<figure><img src="/files/1SeJtLPb66mZgEpc3J8B" alt=""><figcaption></figcaption></figure>

Once logged in, you should have a screen listing all the clusters you have accesses to :

<figure><img src="/files/kdySWO8IXeGRN58bqI7V" alt=""><figcaption></figcaption></figure>

If the UI gets stuck on "Loading" after logging in, please try:

* Opening the Rancher URL in an incognito/private browser window
* Or connecting directly to:
  * <https://rancher-et.cegedim.cloud/dashboard/home>
  * <https://rancher-et-qa.cegedim.cloud/dashboard/home>
  * <https://rancher-eb.cegedim.cloud/dashboard/home>
  * <https://rancher-eb-qa.cegedim.cloud/dashboard/home>

If on first login you don't see your cluster in the cluster list you might want to logout and login again.

<figure><img src="/files/ckHRAWWYA1QFJgSDaZJR" alt=""><figcaption></figcaption></figure>

#### Manage your preferences <a href="#kuberneteshowtos-manageyourpreferences" id="kuberneteshowtos-manageyourpreferences"></a>

You can manage your UI preferences (dark theme, number of rows per table...) by setting up your user preferences. Please refer here to a full documentation:

{% embed url="<https://rancher.com/docs/rancher/v2.x/en/user-settings/preferences/>" %}

### Configure kubectl

In order to connect to the cluster using CLI, you have two options :

* by regular remote kubectl
* using rancher online kubectl

Both are available by getting to the "cluster" page in Rancher.\
There are two ways of doing that :

<figure><img src="/files/ZhWKbm3FhLk5JD9dtxln" alt=""><figcaption><p>Click on the cluster name in the cluster list</p></figcaption></figure>

<figure><img src="/files/mzEdwLgtSf8cPlLJosPu" alt=""><figcaption><p>Click on the cluster name in the top left menu</p></figcaption></figure>

#### Using the kubectl configuration file <a href="#kuberneteshowtos-usingthekubectlconfigurationfile" id="kuberneteshowtos-usingthekubectlconfigurationfile"></a>

Once on the cluster homepage you can download the "Kubeconfig File":

<figure><img src="/files/tkq7PkLA1cKlsXGHZ0bw" alt=""><figcaption></figcaption></figure>

Or just copy the content of "Kubeconfig File":

<figure><img src="/files/FijODHywbBzuEVdjgTTg" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
if you dont have `kubectl` we highly suggest you to install `kubectl` on your administration workstation, following [this document](https://kubernetes.io/docs/tasks/tools/install-kubectl/).
{% endhint %}

This configuration can be mixed with other kubectl configuration.

The authentication can be shared with any cluster managed by the same rancher instance.

#### Using the web cli <a href="#kuberneteshowtos-usingthewebcli" id="kuberneteshowtos-usingthewebcli"></a>

Once on the cluster home page you can use the web cli by clicking on the below icon :

<figure><img src="/files/tHhXCVpIm5gVgVFuTXQd" alt=""><figcaption></figcaption></figure>

This should launch a web shell like this one :

<figure><img src="/files/etBiZDmFrAGDYQlfZNTP" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
This shell is temporary, any changes made inside will be discarded once the window closed. This session might get disconnected if no input/output is observed.
{% endhint %}

### Get API an Token

Token management UI is accessible right beneath the user avatar :

<figure><img src="/files/rjoW2tdLqVNTh84wWwMk" alt=""><figcaption></figcaption></figure>

#### Token scopes <a href="#kuberneteshowtos-tokenscopes" id="kuberneteshowtos-tokenscopes"></a>

There are two scopes :

* no-scope : global scope : used to interact with global rancher API
* cluster-scoped : token dedicated to access specific cluster

{% hint style="info" %}
A cluster-scoped token is recommended for configuring CI/CD pipelines.\
This means that you need a token per cluster in your CI/CD pipelines.
{% endhint %}

#### Token lifecycle <a href="#kuberneteshowtos-tokenlifecycle" id="kuberneteshowtos-tokenlifecycle"></a>

Token can have different lifecycles :

* a token can have a unlimited lifespan, it will follow the lifecycle of the account attached to it
* a specific lifetime

## Nodes management

### Scale cluster

You can use ITCare to add or remove nodes to your cluster.

## Manage Namespaces

### Understanding Project - A Rancher concept <a href="#publicdocumentationreview-understandingproject-arancherconcept" id="publicdocumentationreview-understandingproject-arancherconcept"></a>

Rancher manages namespaces via project, which is a concept specifically existing only in Kubernetes clusters managed by Rancher.

Project is not a Kubernetes native resource.

By default, a Kubernetes cluster is provisioned with 2 projects:

* System: containing core-component's namespaces like: kube-system, etc.
* Default: containng the "default" namespace

Users are free to create more Projects if needed.

Basing on Project level, Rancher offers built-in automation like: access rights granting, network isolation, etc.

Users are very encouraged to classify namespace into a Project.

### How to properly create a namespace <a href="#publicdocumentationreview-howtocreateproperlyanamespace" id="publicdocumentationreview-howtocreateproperlyanamespace"></a>

* Switch to project view

<figure><img src="/files/K6SWhrHKsbYwgzvDaaKK" alt=""><figcaption></figcaption></figure>

* Create a new namespace from project view

<figure><img src="/files/YUFqANRj3agkL2fOXuSx" alt=""><figcaption></figcaption></figure>

* Insert a unique name, and fill other fields if needed, and click on "Create"

{% hint style="info" %}
If you create a namespace with kubernetes CLI, e.g. kubectl, the created namespace will be moved into the the project parent of the namespace "default" (which is, by default, the project named Default)
{% endhint %}

## Rights Management <a href="#kuberneteshowtos-rightsmanagement" id="kuberneteshowtos-rightsmanagement"></a>

**cegedim.cloud** recommends and officially supports access rights managing via AD groups.

Only AD groups starting with G\_EMEA\_\* and G\_K8\_\* are known by Rancher.

By default, when a cluster is created:

* Standard user role is given to the group **G\_K8\_**\<CLUSTER\_NAME>**\_USERS** which contains the power users of the related Cloud
* Admin role is given to the group **G\_K8\_**\<CLUSTER\_NAME>**\_ADMINS** which is empty by default and can be populated with competent & certified users via ITCare ticket toward AD support team.

For instance, user **<user1@cegedim.com>** needs to have standard user access to cluster **test-preprod**, he needs to ask to add <user1@cegedim.com> to the AD group named **G\_K8\_TEST\_PREPROD\_USERS**.

When users create a new Project, as default owner, they are free to bind any role on any AD group in the scope of this project.

{% embed url="<https://ranchermanager.docs.rancher.com/how-to-guides/new-user-guides/authentication-permissions-and-global-configuration/manage-role-based-access-control-rbac/cluster-and-project-roles>" %}

If the Rancher predefined roles cannot fullfill your needs, please contact admins of your cluster to configure a custom rolebinding or clusterrolebinding.

{% embed url="<https://kubernetes.io/docs/reference/access-authn-authz/rbac/>" %}

### Manage Rights

**Project Level Rights Management**

{% hint style="warning" %}
**cegedim.cloud** only supports rights binding on **groups**, not individual users. This ensures consistent access management and simplifies administration.
{% endhint %}

In order to manage rights on a project, there are two ways: The UI or the API.

The highest role you can assign is **"Cegedim.Cloud Project Admin"**, which is a predefined Rancher Project Owner role with extended rights on CRD (Custom Resource Definition) resources.

#### Using UI

Edit the project that you are owner or are given to sufficient rights from the project creator.

<figure><img src="/files/oDkM294tW9B0KZkyjtbd" alt=""><figcaption></figcaption></figure>

Select the group and the role in the form.

{% hint style="info" %}
Please note that only groups starting with G\_EMEA\_\* and G\_K8\_\* are known by Rancher.
{% endhint %}

<figure><img src="/files/8WdlveRDiTU6bs8pQrlv" alt=""><figcaption></figcaption></figure>

#### Using API

Using the API is straightforward. You will first need some parameters:

* **Getting Project ID**

To get the project ID, you can use the API explorer or simply use the "View in API" button.

{% code overflow="wrap" %}

```bash
curl --request GET \
 --url https://rancher-eb.cegedim.cloud/v3/projects \
 --header 'authorization: Bearer token-tttt:token-of-doom'
```

{% endcode %}

* **Give access**

Using your API token, you can make a single POST request to create the role binding:

{% code overflow="wrap" %}

```bash
curl --request POST \
--url https://rancher-eb.cegedim.cloud/v3/projectRoleTemplateBindings \
--header 'authorization: Bearer token-tttt:token-of-doom' \
--header 'content-type: application/json' \
--data '{
"projectId": "c-6t7f4:p-d43l6",
"namespaceId":"",
"groupPrincipalId":"keycloakoidc_group_group://G_EMEA_DUPER_GROUP",
"roleTemplateId": "cgdm-project-admin"
}'
```

{% endcode %}


# High Availability

This guide will go through all the configuration items needed to improve the availability and service continuity of your applications deployed in a **cegedim.cloud** managed Kubernetes clusters.

This is a "must-read" guide in order that your Disaster Recovery Strategy meets **cegedim.cloud** compute topology.

## How to configure deployments to leverage HA capabilities <a href="#title-text" id="title-text"></a>

Once your Kubernetes cluster configured to run using the High Availability (HA) topology, some configuration best practices are required to allow your applications :

* to run simutenaously on all datacenters of the region
* to have sufficient capacity in all datacenters in case of Disaster on one of them

### Deployment Configuration <a href="#howtoconfiguredeploymentstoleveragehacapabilities-deploymentconfiguration" id="howtoconfiguredeploymentstoleveragehacapabilities-deploymentconfiguration"></a>

As a reminder, the nodes of the Kubernetes clusters are distributed into 3 availability zones (AZ) and 2 datacenters :

* AZ "A" and "B" are running on the primary datacenter
* AZ "C" is running on the secondary datacenter

#### Replica Count <a href="#howtoconfiguredeploymentstoleveragehacapabilities-replicacount" id="howtoconfiguredeploymentstoleveragehacapabilities-replicacount"></a>

For stateless services that support scaling, best practice is to have at least 3 pods running :

{% code lineNumbers="true" %}

```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: myapp
  labels:
    name: myapp
spec:
  replicas: 3
```

{% endcode %}

#### Anti-Affinity <a href="#howtoconfiguredeploymentstoleveragehacapabilities-anti-affinity" id="howtoconfiguredeploymentstoleveragehacapabilities-anti-affinity"></a>

Those at-least 3 pods needs to be properly configured to have at least one pod running on each Availability Zone:\\

{% code lineNumbers="true" %}

```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: dep-nginx
spec:
  selector:
    matchLabels:
      app: nginx
  replicas: 3
  template:
    metadata:
      labels:
        app: nginx
    spec:
      affinity:
        podAntiAffinity:
          preferredDuringSchedulingIgnoredDuringExecution:
          - weight: 100
            podAffinityTerm:
              labelSelector:
                matchExpressions:
                - key: app
                  operator: In
                  values:
                  - nginx
              topologyKey: "topology.kubernetes.io/zone"
      containers:
      - name: web-app
        image: nginx
```

{% endcode %}

We are using `preferedDuringSchedulingIgnoredDuringExecution` and not `requiredDuringSchedulingIgnoredDuringExecution` because we want this requirement to be "soft" : Kubernetes will then allow to schedule multiple pods on same AZ if you are running more replicas than AZs, or in case of failure of a zone.

### Spread Constraints for Pods <a href="#howtoconfiguredeploymentstoleveragehacapabilities-spreadconstraintsforpods" id="howtoconfiguredeploymentstoleveragehacapabilities-spreadconstraintsforpods"></a>

{% embed url="<https://kubernetes.io/docs/concepts/workloads/pods/pod-topology-spread-constraints/>" %}

{% embed url="<https://github.com/kubernetes/enhancements/tree/master/keps/sig-scheduling/895-pod-topology-spread#motivation>" %}

## How to size your HA Cluster <a href="#title-text" id="title-text"></a>

If you are using the High Availability cluster topology, your objective is to deploy resilient applications in case of a datacenter failure.

This page describe some best practices to determine sizing of worker nodes for each Availability Zone where your workloads are running.

### Thinking about the "Worst Case Scenario" <a href="#howtosizeyourhacluster-thinkingaboutthe-worstcasescenario" id="howtosizeyourhacluster-thinkingaboutthe-worstcasescenario"></a>

As a reminder, Kubernetes Cluster is deployed in 3 availability zones, and 2 datacenters. In the worst case scenario, only 1 AZ will run if the primary datacenter has a major disaster.

That's the hypothesis to take into account to determine the "nominal" sizing, that we can call *"***If the primary datacenter fails, how much CPU / RAM capacity do I need to keep my application working ?***"*

<figure><img src="/files/Cvrx1TbUthuN0NGoIzKa" alt=""><figcaption></figcaption></figure>

### Defining Nominal Capacity <a href="#howtosizeyourhacluster-definingnominalcapacity" id="howtosizeyourhacluster-definingnominalcapacity"></a>

#### Understanding your requirements <a href="#howtosizeyourhacluster-understandingyourrequirements" id="howtosizeyourhacluster-understandingyourrequirements"></a>

To determine this capacity, and then the worker nodes deployed in "C" Availability Zone (how many, and with which resources), you will need 3 parameters :

:

<table data-full-width="true"><thead><tr><th width="336">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>Minimum Business Continuity Objective (MBCO)</td><td><p>As RTO / RPO, MBCO is a major parameter to size your DRP.</p><p>To sum up, it is the percentage of capacity of your deployed application that is required to have your business up and running.</p><p>Depending on how did you size your workloads when running in 3 AZs, performance you determine as sufficient, it can be 30%, 50% or 100%.</p><p>For example, if you have an application with 3 replicas of 4GB RAM on each AZ, you can determine the MBCO really differently :</p><ul><li><p>33%</p><ul><li>having only one running during outage is sufficient, because performance will be OK</li><li>you can take the risk to not have redundancy during outage period</li></ul></li><li><p>66%</p><ul><li>either, 2 pods minimum is required to have a performance OK</li><li>and/or you don't want take the risk to fail if the only pod left fails</li></ul></li><li><p>100%</p><ul><li>you need absolutely 3 pods minimum to run the service with nominal performance</li></ul></li></ul><p>Choice is yours !</p></td></tr><tr><td>Pods Resources Requests</td><td><p>Pods are deployed using Kubernetes <a href="https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/">resources requests and limits</a>.</p><p>As Kubernetes will try to reschedule your pods in case of an outage, the requests is an absolutely major parameter to manage.</p><p>If the AZ-C has not enough resources to satisfy all requirements of desired pods deployments, Kubernetes will not deploy them, and maybe your applications won't be available !</p><p>To know about your requests, you can run this command :<br></p><p><code>kubectl get pods --all-namespaces -o=jsonpath='{range .items[*]}{.metadata.namespace}{"/"}{.metadata.name}{"-"}{range .spec.containers[*]}{"/"}{.name}{";"}{.resources.requests.cpu}{";"}{.resources.limits.cpu}{";"}{.resources.requests.memory}{";"}{.resources.limits.memory}{"\n"}{end}{"\n"}{end}'</code> <code>| grep</code> <code>-v</code> <code>-e '^$'</code></p></td></tr><tr><td>Resources Usage</td><td><p>Determining requests is OK to be sure that Kubernetes will deploy as many pods as you want to, but what about <strong>real</strong> capacity your pods are using ? This is also to take in account to have the picture on how "raw" resources your applications require.</p><p>To determine that, you can run this command to know about your pod's current usage :<br><br><code>kubectl top pod</code></p></td></tr></tbody></table>

### Calculate Sizing <a href="#howtosizeyourhacluster-calculatesizing" id="howtosizeyourhacluster-calculatesizing"></a>

Then you have two choices to calculate sizing :

* **At the "Cluster Level" granularity**: if you are just beginning the process and do not have such complexity or variability in your workloads, use this :
  * Determine a global MBCO cross-deployments
  * Summing all pods resources requests to get an unique number
  * Summing all pods resources usages to get an unique number
* **At the "Pod Level" granularity**: If you want the sizing to be fitted perfectly and you have time to, take the time to determine those parameters for each deployment in your Kubernetes Cluster, because MBCO may vary ! For example :
  * A web application will require a MBCO with 100%
  * A cache will require a MBCO of 50%
  * A "nice-to-have" feature, or an internal tool can be 0%

{% hint style="warning" %}
The "Cluster Level" calculation is not accurate enough to be absolutely certain that cluster will be appropriately sized. Just know about it, and evaluate if it's worth taking the risk.

In any case, this sizing have to be reassessed regularly, depending on new deployments or rescaling you are running on your daily operations
{% endhint %}

#### Using "Cluster Level" Granularity <a href="#howtosizeyourhacluster-using-clusterlevel-granularity" id="howtosizeyourhacluster-using-clusterlevel-granularity"></a>

If you have summed all requests and usage, and you've determined the MBCO on the "cluster" level, you can use this simple formula to calculate required sizing for AZ "C" in secondary datacenter :

```
required_capacity = MBCO * max(requests, usage)
```

#### Using "Pod" Granularity <a href="#howtosizeyourhacluster-using-pod-granularity" id="howtosizeyourhacluster-using-pod-granularity"></a>

If you've determined a per-deployment MBCO, you will have to calculate your sizing with a more complex formula :

```
required_capacity = sum(pod.MBCO * max(pod.requests, pod.usage))
```

## Adjust your deployment descriptors <a href="#howtosizeyourhacluster-adjustyourdeploymentdescriptors" id="howtosizeyourhacluster-adjustyourdeploymentdescriptors"></a>

Once you've calculated your MBCO, it is important to leverage Kubernetes capabilities (QoS, especially `PodDisruptionBudget`) to make your deployment follow your decision.

## Adjust your cluster sizing <a href="#howtosizeyourhacluster-adjustyourclustersizing" id="howtosizeyourhacluster-adjustyourclustersizing"></a>

Use ITCare or request help from our support to size your cluster.

## How to use Kubernetes QoS and Guaranteed Availability <a href="#title-text" id="title-text"></a>

During this phase, you'll need to prioritize your assets and define the components that are essential to the availability of your services.

To know your resource utilization, once deployed, it's a good idea to observe the resource consumption of your workload.

you can access your metrics via the rancher user interface or via a client like Lens.

### Quality of service

In Kubernetes there are 3 classes of QOS:

* Guaranteed
* Burstable
* BestEffort

For critical workloads, you can use "guaranteed" QOS, which simply sets resource limits equal to resource demands:

{% code overflow="wrap" %}

```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: myapp
spec:
  replicas: 3
  template:
    spec:
      resources:
        limits:
          memory: "200Mi"
          cpu: "700m"
        requests:
          memory: "200Mi"
          cpu: "700m"
```

{% endcode %}

For less critical workloads, you can use the "Burstable" QOS, which will define resource limits and demands.

{% code lineNumbers="true" %}

```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: myapp
spec:
  replicas: 2
  template:
    spec:
      resources:
        requests:
          memory: "200Mi"
          cpu: "700m"
```

{% endcode %}

{% embed url="<https://kubernetes.io/docs/tasks/configure-pod-container/quality-service-pod/>" %}

### Pod disruption budget

The pod disruption budget lets you configure your fault tolerance and the number of failures your application can withstand before becoming unavailable.

#### Stateless

With a stateless workload, the aim is to have a minimum number of pods available at all times. To achieve this, you can define a simple pod disruption budget:

{% code lineNumbers="true" %}

```yaml
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
  name: myapp-pdb
spec:
  minAvailable: 2
  selector:
    matchLabels:
      app: myapp
```

{% endcode %}

#### Stateful <a href="#howtousekubernetesqosandguaranteedavailability-stateful" id="howtousekubernetesqosandguaranteedavailability-stateful"></a>

Avec une charge de travail à état, le but est d'avoir un nombre maximum de pods indisponibles à tout moment, afin de maintenir le quorum par exemple :

{% code lineNumbers="true" %}

```yaml
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
  name: myapp-pdb
spec:
  maxUnavailable: 1
  selector:
    matchLabels:
      app: myapp
```

{% endcode %}

{% embed url="<https://kubernetes.io/docs/tasks/run-application/configure-pdb/>" %}

#### Horizontal Pod Autoscaler <a href="#howtousekubernetesqosandguaranteedavailability-horizontalpodautoscaler" id="howtousekubernetesqosandguaranteedavailability-horizontalpodautoscaler"></a>

High traffic scenarios:

{% embed url="<https://kubernetes.io/docs/tasks/run-application/horizontal-pod-autoscale/>" %}


# Migration RKE to RKE2

## Overview <a href="#k8smigration-overview" id="k8smigration-overview"></a>

As **cegedim.cloud** transitions to **RKE2** (Rancher Kubernetes Engine 2) as the standard Kubernetes distribution for all clusters running version 1.31 and above, customers with existing RKE-based clusters may need to migrate their workloads to benefit from enhanced security, compliance features, and long-term support.

This guide outlines the available migration strategies to help you transition from RKE to RKE2 with minimal disruption.

{% hint style="info" %}
RKE2 is a fully conformant Kubernetes distribution that focuses on security and compliance, particularly designed to meet U.S. Federal Government requirements. It provides improved security hardening and simplified operations compared to RKE.
{% endhint %}

## Why Migrate to RKE2? <a href="#k8smigration-whymigrate" id="k8smigration-whymigrate"></a>

Migrating from RKE to RKE2 offers several benefits:

* **Enhanced Security**: RKE2 is built with security as a primary focus, incorporating CIS Kubernetes Benchmark standards by default
* **Improved Compliance**: Meets stringent compliance requirements (FIPS 140-2 available with Canal CNI)
* **Active Development**: RKE2 receives ongoing updates and new features, while RKE is in maintenance mode
* **Better Performance**: Optimized architecture for improved cluster performance and stability
* **Access to Latest Kubernetes Versions**: Support for Kubernetes 1.31 and beyond
* **Advanced CNI Options**: Support for high-performance CNI providers like Cilium with eBPF capabilities

### RKE vs RKE2 Comparison

| Feature                        | RKE                           | RKE2 (cegedim.cloud)                         |
| ------------------------------ | ----------------------------- | -------------------------------------------- |
| **Kubernetes Version Support** | Up to 1.32                    | 1.31 and above                               |
| **Security Hardening**         | Manual configuration required | CIS Kubernetes Benchmark by default          |
| **Development Status**         | Maintenance mode              | Active development                           |
| **CNI Options**                | Canal only                    | Canal, Calico, Cilium                        |
| **FIPS 140-2 Compliance**      | Not available                 | Available with Canal CNI                     |
| **eBPF Networking**            | Not available                 | Available with Cilium CNI                    |
| **kube-proxy Deployment**      | Always deployed               | Not deployed when using Cilium (eBPF native) |
| **Maximum Cluster Size**       | Up to 200 nodes               | Up to 2,000 nodes (with Calico or Cilium)    |

## Migration Strategies <a href="#k8smigration-strategies" id="k8smigration-strategies"></a>

**cegedim.cloud** offers two migration approaches to accommodate different customer requirements, technical capabilities, and operational constraints:

### Strategy 1: Autonomous Workload Migration <a href="#k8smigration-autonomousmigration" id="k8smigration-autonomousmigration"></a>

This strategy is recommended for customers with:

* Strong Kubernetes expertise
* Well-documented infrastructure-as-code practices
* Flexibility to manage their own migration timeline
* Desire for complete control over the migration process

#### Process Overview

1. **Preparation**
   * Provision a new RKE2 cluster through ITCare
   * Configure the new cluster with desired CNI and Ingress providers
   * Set up network connectivity between old and new clusters if needed
2. **Application Migration**
   * Export application manifests, configurations, and secrets from the RKE cluster
   * Review and update any deprecated Kubernetes API versions (use `kubent` tool)
   * Deploy applications to the new RKE2 cluster
   * Validate application functionality in the new environment
3. **Data Migration**
   * Back up persistent volumes from the RKE cluster
   * Restore data to persistent volumes in the RKE2 cluster
   * Verify data integrity after migration
4. **Traffic Cutover**
   * Update DNS records to point to the new RKE2 cluster
   * Monitor application performance and logs
   * Perform rollback procedures if issues are detected
5. **Decommissioning**
   * Once the migration is validated, decommission the old RKE cluster through ITCare

#### Advantages

* Full control over migration timing and approach
* Ability to perform gradual, phased migrations
* Opportunity to optimize configurations during migration
* No dependency on support team availability

#### Considerations

* Requires in-depth Kubernetes knowledge
* Customer is responsible for all migration activities
* May require more time for planning and execution

### Strategy 2: Semi-Automated Migration with IT Support <a href="#k8smigration-semiautomatedmigration" id="k8smigration-semiautomatedmigration"></a>

This strategy is ideal for customers who:

* Prefer assistance from **cegedim.cloud** IT support team
* Have complex workloads requiring expert guidance
* Want to leverage automation tools for faster migration
* Need support for critical production environments

#### Process Overview

1. **Migration Request**
   * Submit a support ticket through ITCare requesting RKE to RKE2 migration assistance
   * Provide details about your workloads, dependencies, and migration timeline preferences
   * Schedule a planning session with the support team
2. **Automated Migration Execution**
   * **cegedim.cloud** IT team uses **Velero** (Kubernetes backup and restore tool) and **Ansible** automation to:
     * Create comprehensive backups of your RKE cluster (including workloads, configurations, and persistent volumes)
     * Provision a new RKE2 cluster with equivalent specifications
     * Restore workloads to the new RKE2 cluster
     * Migrate persistent volume data
3. **Customer Reconfiguration Tasks**

   After the automated migration, customers are responsible for:

   * **CI/CD Pipeline Updates**: Update your CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, etc.) to point to the new RKE2 cluster's kubeconfig and API endpoints
   * **External PaaS Connections**: Reconfigure connections to other **cegedim.cloud** PaaS services:
     * **Vault**: Update Kubernetes auth method configurations
     * **Databases**: Verify connection strings and network policies
     * **Object Storage**: Update S3 credentials and endpoints if needed
     * **Monitoring Tools**: Reconfigure Prometheus, Grafana, or other monitoring integrations
   * **External Integrations**: Update any third-party services or external systems that connect to your cluster
   * **DNS and Load Balancers**: Coordinate traffic cutover with the IT team
   * **Testing and Validation**: Perform comprehensive testing to ensure all applications function correctly
4. **Post-Migration Support**
   * The IT team remains available to troubleshoot any issues during the stabilization period
   * Assistance with performance tuning and optimization if needed

#### Advantages

* Faster migration with automation tools
* Expert guidance from **cegedim.cloud** IT team
* Reduced risk of data loss with Velero backup/restore
* Support for complex scenarios and troubleshooting

#### Considerations

* Requires coordination with IT support team schedule
* Customer must still handle application-specific reconfigurations
* May involve support costs (consult your Service Delivery Manager)

## Migration Planning Checklist <a href="#k8smigration-checklist" id="k8smigration-checklist"></a>

Regardless of the migration strategy you choose, use this checklist to ensure a smooth transition:

* [ ] **Inventory Assessment**: Document all applications, services, and dependencies running in your RKE cluster
* [ ] **API Version Check**: Use `kubent` to identify deprecated Kubernetes API versions
* [ ] **Backup Verification**: Ensure all critical data has valid backups
* [ ] **Network Requirements**: Identify network policies, firewall rules, and connectivity requirements
* [ ] **Integration Mapping**: List all external systems, PaaS services, and CI/CD pipelines that connect to your cluster
* [ ] **Testing Plan**: Define test cases and validation criteria for the new RKE2 cluster
* [ ] **Rollback Plan**: Document rollback procedures in case of migration issues
* [ ] **Communication Plan**: Notify stakeholders and users of the migration schedule
* [ ] **Post-Migration Tasks**: Create a checklist of all reconfiguration tasks required after migration

## Best Practices <a href="#k8smigration-bestpractices" id="k8smigration-bestpractices"></a>

### Before Migration

* **Test in Non-Production First**: Always migrate development or staging environments before production
* **Document Current State**: Take detailed notes about your current RKE cluster configuration
* **Validate Backups**: Test backup restoration procedures before starting migration
* **Review Resource Quotas**: Ensure the new RKE2 cluster has adequate resources

### During Migration

* **Minimize Changes**: Avoid making configuration changes to the RKE cluster during migration
* **Monitor Both Clusters**: Keep close watch on both old and new clusters during cutover
* **Maintain Communication**: Keep stakeholders informed of migration progress
* **Document Issues**: Record any problems encountered for future reference

### After Migration

* **Performance Monitoring**: Monitor application performance for at least 48 hours after migration
* **Log Analysis**: Review logs for any errors or warnings
* **Cleanup**: Decommission the old RKE cluster only after confirming the new cluster is stable
* **Documentation Update**: Update all documentation to reflect the new RKE2 cluster details

## Getting Help <a href="#k8smigration-gettinghelp" id="k8smigration-gettinghelp"></a>

If you need assistance with your RKE to RKE2 migration:

* **For Migration Planning**: Contact your Service Delivery Manager to discuss the best approach for your use case
* **For Technical Support**: Submit a ticket through [ITCare](https://itcare.cegedim.cloud) with the subject "RKE to RKE2 Migration Request"
* **For Emergency Issues**: Submit an ITCare ticket if you encounter critical problems during migration

## Additional Resources <a href="#k8smigration-resources" id="k8smigration-resources"></a>

* [Velero Documentation](https://velero.io/docs/) - Backup and restore tool used in semi-automated migrations
* [Kubernetes API Deprecation Guide](https://kubernetes.io/docs/reference/using-api/deprecation-guide/) - Information about API version changes
* [RKE2 Documentation](https://docs.rke2.io/) - Official RKE2 documentation
* [Kubernetes Migration Best Practices](https://kubernetes.io/docs/tasks/administer-cluster/migrating-from-dockershim/) - General migration guidance

{% hint style="success" %}
Successful migrations require careful planning and execution. Don't hesitate to reach out to the **cegedim.cloud** support team for guidance at any stage of your migration journey.
{% endhint %}


# Troubleshooting

This guide helps you diagnose and resolve common issues encountered when working with **cegedim.cloud** Kubernetes clusters.

## Rancher UI Issues <a href="#k8stroubleshooting-rancheruiissues" id="k8stroubleshooting-rancheruiissues"></a>

### Rancher UI Stuck on "Loading"

**Symptoms**: After logging in, the Rancher UI displays "Loading" indefinitely.

**Solution**:

1. Try accessing the direct dashboard URL:
   * For ET region: <https://rancher-et.cegedim.cloud/dashboard/home>
   * For EB production: <https://rancher-eb.cegedim.cloud/dashboard/home>
   * For EB non-production: <https://rancher-eb-qa.cegedim.cloud/dashboard/home>
2. If the issue persists, log out and log back in
3. Try using a different browser or **incognito/private mode**
4. Clear your browser cache and cookies for the Rancher domain

### Cluster Not Visible After First Login

**Symptoms**: After your first login to Rancher, your cluster doesn't appear in the cluster list.

**Solution**:

1. Log out of Rancher completely
2. Log back in
3. Your cluster should now appear in the list
4. If the cluster still doesn't appear, verify your access rights through ITCare or contact your administrator

### Cannot Access Rancher (Connection Refused or Timeout)

**Symptoms**: Unable to reach rancher-et.cegedim.cloud or rancher-eb.cegedim.cloud.

**Solution**:

1. **Check network access**: Some Rancher instances are only accessible from the server network
   * **rancher-et.cegedim.cloud** - Requires server network access (connect through bastion)
   * **rancher-eb.cegedim.cloud** (production) - Requires server network access (connect through bastion)
   * **rancher-eb-qa.cegedim.cloud** (non-production) - Accessible from standard network
2. **Verify Rancher status**: Check if a Rancher upgrade is in progress (typically 15-30 minutes)

## kubectl Access Issues <a href="#k8stroubleshooting-kubectlaccessissues" id="k8stroubleshooting-kubectlaccessissues"></a>

### kubectl Commands Fail with "Connection Refused"

**Symptoms**: kubectl commands return connection errors or timeouts.

**Possible Causes and Solutions**:

**1. Rancher Proxy Issue**

* If your kubeconfig uses Rancher URL, Rancher might be down or upgrading
* Wait for Rancher to become available again
* Consider using direct cluster access if available

**2. Invalid or Expired Credentials**

* Download a fresh kubeconfig from Rancher UI
* Verify your token hasn't expired (check token lifecycle in Rancher)

**3. Network Connectivity**

* Test connectivity: `curl -v https://<rancher-url>`
* Verify you're on the correct network (bastion for ET/EB production)
* Check firewall rules and proxy settings

### kubectl Context Not Switching

**Symptoms**: kubectl commands affect the wrong cluster.

**Solution**:

```bash
# List all available contexts
kubectl config get-contexts

# Switch to the correct context
kubectl config use-context <context-name>

# Verify current context
kubectl config current-context
```

## Cluster Access and Authentication <a href="#k8stroubleshooting-clusteraccessandauthentication" id="k8stroubleshooting-clusteraccessandauthentication"></a>

### "Forbidden" Errors When Running kubectl Commands

**Symptoms**: Commands return "Error from server (Forbidden): is forbidden".

**Solution**:

1. **Verify your access rights in Rancher**: Check the "Manage Rights" page for your Project/Cluster permissions
2. **Use SelfSubjectAccessReview**: Run the following command to check your permissions for specific resources:

```bash
kubectl create -f - -o yaml << EOF
apiVersion: authorization.k8s.io/v1
kind: SelfSubjectAccessReview
spec:
  resourceAttributes:
    group: ""
    resource: "*"
    verb: "*"
EOF
```

3. **Check Project/Namespace permissions**: Ensure you have the correct role in the Project
4. **Verify AD group membership**: Confirm you're in the correct G\_K8\_\* groups
5. **Check token scope**: Ensure you're using a cluster-scoped token for kubectl operations

### Cannot Create Resources in Namespace

**Symptoms**: Permission denied when creating pods, deployments, etc.

**Solution**:

1. Verify the namespace belongs to a Project you have access to
2. If the namespace was created via kubectl (not Rancher UI), it may be in the "Default" project with restricted access
3. Contact your Project admin to move the namespace to the correct Project or grant permissions

## Workload Issues <a href="#k8stroubleshooting-workloadissues" id="k8stroubleshooting-workloadissues"></a>

### Pods Stuck in "Pending" State

**Symptoms**: Pods remain in "Pending" status and don't start.

**Diagnosis**:

```bash
# Check pod details
kubectl describe pod <pod-name> -n <namespace>

# Look for events at the bottom of the output
```

**Common Causes and Solutions**:

**1. Insufficient Resources**

* Message: "Insufficient cpu" or "Insufficient memory"
* Solution: Request more nodes through ITCare or reduce resource requests

**2. Persistent Volume Issues**

* Message: "persistentvolumeclaim not found" or "no persistent volumes available"
* Solution: Verify PVC exists and storage class is correct

**3. Node Selector/Affinity Mismatch**

* Message: "No nodes are available that match all of the following predicates"
* Solution: Review nodeSelector and affinity rules

**4. Image Pull Errors**

* Message: "Failed to pull image" or "ImagePullBackOff"
* Solution: See "Image Pull Issues" section below

### Image Pull Issues (ImagePullBackOff)

**Symptoms**: Pods fail with "ImagePullBackOff" or "ErrImagePull" status.

**Diagnosis**:

```bash
kubectl describe pod <pod-name> -n <namespace>
# Look for "Failed to pull image" messages
```

**Common Causes and Solutions**:

**1. Private Registry Authentication**

* Create or verify image pull secret exists
* Ensure secret is referenced in pod spec or service account

**2. Image Name Typo**

* Verify image name and tag are correct
* Check registry URL is properly formatted

**3. Network Connectivity to Registry**

* Verify cluster can reach external registry
* Check if network policies block registry access
* Request network opening through ITCare if needed

### Ingress Not Routing Traffic

**Symptoms**: Cannot access application through ingress URL.

**Diagnosis**:

```bash
# Check ingress configuration
kubectl get ingress -n <namespace>
kubectl describe ingress <ingress-name> -n <namespace>

# Verify service and endpoints
kubectl get svc -n <namespace>
kubectl get endpoints <service-name> -n <namespace>
```

**Common Causes and Solutions**:

**1. Incorrect Ingress Class**

* For Nginx (default): No class annotation needed or use `kubernetes.io/ingress.class: "nginx"`
* For Nginx external: Use `kubernetes.io/ingress.class: "nginx-ext"`
* For Traefik: Use appropriate Traefik ingress class
* For Istio: Use Istio Gateway configuration

**2. Service Not Found or Misconfigured**

* Verify service name and port match ingress backend
* Check that service has endpoints (pods selected)

**3. Certificate Issues**

* Default: `*.yourclustername.ccs.cegedim.cloud` certificate is pre-configured
* Custom domains: Request certificate configuration through ITCare

## Persistent Storage Issues <a href="#k8stroubleshooting-persistentstorageissues" id="k8stroubleshooting-persistentstorageissues"></a>

### PVC Stuck in "Pending" State

**Symptoms**: PersistentVolumeClaim remains "Pending" and pods cannot start.

**Diagnosis**:

```bash
kubectl describe pvc <pvc-name> -n <namespace>
# Look for error messages in Events
```

**Common Causes and Solutions**:

**1. Storage Class Not Found**

* Verify storage class name in PVC
* List available storage classes: `kubectl get storageclass`
* Use Ceph-based storage classes provided by cegedim.cloud

**2. Storage Quota Exceeded**

* Check if storage quota is available
* Request additional storage through ITCare

**3. Ceph CSI Not Available**

* Verify Ceph CSI is enabled for your cluster
* Contact support if Ceph CSI is not provisioned

## Network Policy Issues <a href="#k8stroubleshooting-networkpolicyissues" id="k8stroubleshooting-networkpolicyissues"></a>

### Pods Cannot Communicate Between Namespaces

**Symptoms**: Pods in different namespaces cannot reach each other.

**Understanding Rancher Project Network Isolation**:

* Pods in namespaces within the **same Rancher Project** can communicate by default
* Pods in namespaces in **different Rancher Projects** cannot communicate unless explicitly allowed

**Solution**:

1. **Option 1**: Move namespaces to the same Rancher Project (if appropriate)
2. **Option 2**: Create a NetworkPolicy to explicitly allow cross-project communication
3. **Note**: Pods in the "System" project can communicate with all other projects

### Pods Cannot Access External Services

**Symptoms**: Pods cannot reach internet or external services.

**Understanding Network Restrictions**:

* By default, pods can only reach services within the same VLAN
* Internet access requires proxy configuration or network opening

**Solution**:

1. **For internet access**: Configure HTTP proxy in your pods or request network opening through ITCare
2. **For specific external services**: Request network opening between VLANs through ITCare
3. **For external databases/APIs**: Verify network policies and firewall rules

## Logging and Monitoring Issues <a href="#k8stroubleshooting-loggingandmonitoringissues" id="k8stroubleshooting-loggingandmonitoringissues"></a>

### Logs Not Appearing in OpenSearch/ELK

**Symptoms**: Application logs are not visible in your log aggregation platform.

**Diagnosis**:

```bash
# Check if logging pods are running
kubectl get pods -n cattle-logging-system

# Check buffer size (should not grow continuously)
kubectl -n cattle-logging-system get po -l app.kubernetes.io/name=fluentd -o name | \
  xargs -I {} sh -c "kubectl -n cattle-logging-system exec {} -c fluentd -- du -hs /buffers"
```

**Common Causes and Solutions**:

**1. Flow/Output Not Configured**

* Verify Flow and Output/ClusterOutput resources exist for your namespace
* Check configuration matches your OpenSearch cluster

**2. Conflicting Log Fields**

* OpenSearch/ELK rejects logs with field type conflicts
* Check fluentd logs for "Rejected" messages
* See detailed logging configuration in the "Get Started" guide

**3. Application Producing Malformed JSON**

* Application logs must be properly formatted
* Consider excluding problematic pods from logging Flow

## Migration Issues <a href="#k8stroubleshooting-migrationissues" id="k8stroubleshooting-migrationissues"></a>

### Application Fails After Migration to RKE2

**Symptoms**: Application worked on RKE but fails on RKE2.

**Common Causes and Solutions**:

**1. Deprecated API Versions**

* Run `kubent` tool before migration to detect deprecated APIs
* Update manifests to use current API versions
* See [Kubernetes API Deprecation Guide](https://kubernetes.io/docs/reference/using-api/deprecation-guide/)

**2. CNI Differences**

* If migrating to Cilium from Canal, network policies might behave differently
* Review and test network policies after migration

**3. Missing ConfigMaps or Secrets**

* Verify all ConfigMaps and Secrets were migrated
* Check namespaces and names match exactly

**4. External Integration Issues**

* Update CI/CD pipelines with new cluster kubeconfig
* Reconfigure connections to Vault, databases, and other PaaS services
* Update monitoring and alerting integrations

## Getting Help <a href="#k8stroubleshooting-gettinghelp" id="k8stroubleshooting-gettinghelp"></a>

If you cannot resolve the issue using this guide:

### Self-Service Resources

* Check the [Kubernetes official documentation](https://kubernetes.io/docs/home/)
* Review [Rancher documentation](https://ranchermanager.docs.rancher.com/)
* Consult other sections of this documentation (Features, Get Started, etc.)

### Contact Support

* **For non-urgent issues**: Submit a ticket through [ITCare](https://itcare.cegedim.cloud)
* **For production incidents**: Contact 24x7 support team (if you have 24x7 monitoring option)
* **For migration assistance**: Submit a ticket with subject "RKE to RKE2 Migration Request"

### Information to Provide When Requesting Support

To help support diagnose your issue quickly, please provide:

1. **Cluster Information**:
   * Cluster name
   * Region (ET, EB)
   * Kubernetes version
2. **Problem Description**:
   * What you were trying to do
   * What happened vs. what you expected
   * When the issue started
   * Any recent changes (deployments, upgrades, configuration changes)
3. **Relevant Details**:
   * Namespace and resource names affected
   * Error messages from kubectl or Rancher UI
   * Output of relevant kubectl describe commands
   * Screenshots of Rancher UI errors (if applicable)
4. **Troubleshooting Already Performed**:
   * Steps you've already tried
   * Results of those attempts

{% hint style="success" %}
Most issues can be resolved quickly with proper diagnostics. Don't hesitate to gather relevant information before submitting a support ticket - it helps the support team assist you faster!
{% endhint %}


# Upgrade

This page covers the upgrade procedures for both **Kubernetes clusters** and the **Rancher management platform**.

## **Rancher Upgrade Schedule** <a href="#k8supgrade-rancherupgradeschedule" id="k8supgrade-rancherupgradeschedule"></a>

To ensure that the **cegedim.cloud** infrastructure remains up-to-date with the latest features, security patches, and Kubernetes version support, **Rancher** is upgraded on a quarterly basis.

### Scheduled Upgrade Windows

Rancher upgrades are performed on the **Thursday closest to** the following dates:

* **January 15th** (Q1)
* **April 15th** (Q2)
* **July 15th** (Q3)
* **October 15th** (Q4)

### What to Expect

During Rancher upgrades:

* **Cluster Management**: Your Kubernetes clusters continue to run without interruption. Workloads are not affected by Rancher upgrades.
* **Rancher UI Access**: The Rancher management interface may be temporarily unavailable during the upgrade window (typically 15-30 minutes).
* **kubectl Access**: If your kubectl is configured to access the Kubernetes API through Rancher URL, you may experience temporary connectivity issues during the upgrade window, as the API is proxied through Rancher. Direct cluster access remains functional.
* **New Kubernetes Versions**: Rancher upgrades provide access to more recent Kubernetes versions, enabling you to upgrade your clusters to benefit from the latest features and improvements.
* **Enhanced Features**: You gain access to new Rancher capabilities and improvements in cluster management tools.

{% hint style="info" %}
Customers will be notified in advance of scheduled Rancher upgrades. No action is required on your part for Rancher platform upgrades.
{% endhint %}

{% hint style="success" %}
After each Rancher upgrade, newer Kubernetes versions may become available after validation by the provider. Check the ITCare UI to see which Kubernetes versions are available for your clusters.
{% endhint %}

### Supported Version Matrix <a href="#k8supgrade-supportedversionmatrix" id="k8supgrade-supportedversionmatrix"></a>

The following table shows the Kubernetes versions supported by the current Rancher platform:

| Rancher Version | Supported Kubernetes Versions (RKE2) |
| --------------- | ------------------------------------ |
| 2.11            | 1.30, 1.31, 1.32                     |
| 2.12            | 1.31, 1.32, 1.33                     |

{% hint style="info" %}
While Rancher upgrades enable support for newer Kubernetes versions, their availability for your clusters is validated and controlled by **cegedim.cloud** through the ITCare UI. Check ITCare regularly to see which Kubernetes versions are available for upgrade.
{% endhint %}

### Kubernetes Version Lifecycle Policy <a href="#k8supgrade-versionlifecyclepolicy" id="k8supgrade-versionlifecyclepolicy"></a>

**cegedim.cloud** maintains Kubernetes version support in alignment with Rancher's quarterly upgrade schedule:

* **Active Support**: Kubernetes versions are fully supported and receive security patches as validated and released through ITCare
* **Version Availability**: New Kubernetes versions become available after Rancher upgrades and provider validation
* **Customer Responsibility**: Customers are responsible for maintaining their clusters on supported Kubernetes versions

{% hint style="info" %}
Before releasing any new Kubernetes version to ITCare self-service, point-in-time backup/restore of ETCD is carefully tested by IT to ensure data integrity and cluster recoverability.
{% endhint %}

{% hint style="warning" %}
It is important to keep your clusters updated with supported Kubernetes versions. Customers should plan regular upgrades following the quarterly Rancher upgrade cycle to ensure continued access to security patches and new features.
{% endhint %}

#### Non-Compliant Cluster Handling Policy

**Important:** Clusters that cannot be upgraded to be compatible with incoming Rancher versions will be subject to the following policy:

* **Identification**: Clusters incompatible with the upcoming Rancher version will be identified by IT, and customers will be informed.
* **Month 1**: If no action is taken within 1 month, the cluster will be temporarily detached from Rancher management. Customers will be provided with minimum access for cluster usage.
* **Month 2-3**: If no action is taken within the next 2 months, the cluster will be permanently detached to allow Rancher upgrade. If the customer makes changes to achieve cluster compliance, the cluster will be re-attached.
* **Month 3+**: If the customer makes the cluster compliant within 3 months, IT will attempt to re-attach the cluster, but this is best effort without any guarantee. This policy ensures platform stability while allowing time for customers to address compatibility issues.

## PaaS upgrade workflow <a href="#k8supgradeinplace-k8spaasupgrade" id="k8supgradeinplace-k8spaasupgrade"></a>

### Request <a href="#k8supgradeinplace-request" id="k8supgradeinplace-request"></a>

The update of a Kubernetes PaaS can be done in self-service on the Kubernetes cluster's resource page in [ITCare](https://itcare.cegedim.cloud)

It is recommended that you upgrade your non-production environments first in order to estimate the downtime generated by the operation and to test your applications using the new engine version.

### Process <a href="#k8supgradeinplace-process" id="k8supgradeinplace-process"></a>

The Kubernetes cluster upgrade follows these steps through a **Rolling Update** process :

1. Pods reboot one node after another : 10% of the nodes at a time
2. Post-upgrade validation (health checks, monitoring).

```mermaid
graph TD
    start["Kubernetes 1.28"] --> upgrade["Upgrade cluster's node<br/>(not more than 10% of the cluster's node)"]
    upgrade --> validation["Post upgrade validation"]
    validation --> done["Kubernetes 1.32"]

    upgrade -.->|Handled by cegedim.cloud| validation

    style start fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style upgrade fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style validation fill:#ffe0b2,stroke:#e8820c,stroke-width:2px,color:#000
    style done fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
```

### Impacts

Some API versions can be obsolete or even deleted during a Kubernetes upgrade. There is a risk of breakage if you have resources with an API version that has been removed in the new version of Kubernetes.

To avoid this issue, you can check compatibility with the tool "kubent".

{% embed url="<https://github.com/doitintl/kube-no-trouble>" %}

Kubent checks obsolete objects on the Kubernetes cluster. You need to migrate/change the identified resources before upgrading Kubernetes.

**Check compatibility before a Kubernetes upgrade**

To install kubent :

```bash
sh -c "$(curl -sSL 'https://git.io/install-kubent')"
```

To identify obsolete objects that will be deleted in the next Kubernetes version :

```
kubent [--context my-cluster]
```

An output exemple :

```
...
__________________________________________________________________________________________
>>> Deprecated APIs removed in 1.22 <<<
------------------------------------------------------------------------------------------
KIND                       NAMESPACE      NAME                                   API_VERSION                         REPLACE_WITH (SINCE)
Ingress                    <undefined>     toto                                 networking.k8s.io/v1beta1           networking.k8s.io/v1 (1.19.0)
...
```

In this tutorial, if your cluster has an upgrade planned to the Kubernetes version 1.22, you need to migrate the ingress resource named "toto" of the API version `networking.k8s.io/v1beta1` to `networking.k8s.io/v1` before the upgrade.

This migration can imply a change of more fields in the resource. Please check the official documentation :

{% embed url="<https://kubernetes.io/docs/home/>" %}

{% hint style="danger" %}
Kubent could fail to report some information, for instance the ingress namespace, you can report this issue to the publisher : <https://github.com/doitintl/kube-no-trouble/issues>
{% endhint %}

**Upgrade the Kubernetes cluster**

On the top of your cluster's page, click on the **Manage** button, then **Update**. An information popup will be displayed, click on **Sumit**

{% hint style="warning" %}
The upgrade can take several minutes depending of the size of the cluster.
{% endhint %}

{% @supademo/embed url="<https://app.supademo.com/demo/cmam706440bci2gbp5sts8p52>" demoId="cm0xxrbp40091132huaivveld" %}

### Time references <a href="#k8supgradeinplace-timereferences" id="k8supgradeinplace-timereferences"></a>

A Kubernetes cluster upgrade typically takes around 15 minutes on average. Nodes will be upgraded one after another with no more than 10% of the cluster's node at the same time

Note that these times are estimates and can vary depending on the cluster configuration

## **OS / Kubernetes support matrix** <a href="#k8supgradeinplace-os-k8ssupportmatrixmatrice" id="k8supgradeinplace-os-k8ssupportmatrixmatrice"></a>

Linux distributions supported by **cegedim.cloud** depending on the Kubernetes version:

| Kubernetes Version | Supported Linux Distributions |
| ------------------ | ----------------------------- |
| Kubernetes 1.31    | Ubuntu 22.04, 24.04           |
| Kubernetes 1.32    | Ubuntu 22.04, 24.04           |

## Supported Kubernetes upgrade paths <a href="#k8supgradeinplace-supportedk8supgradepaths" id="k8supgradeinplace-supportedk8supgradepaths"></a>

### Upgrade Policy

{% hint style="info" %}
**cegedim.cloud** does not release every Kubernetes minor version. For example, the platform may support versions 1.28, 1.30, 1.31, and 1.32, skipping version 1.29.**Important:** When upgrading your cluster, you **must** go through **all minor versions** that are released by **cegedim.cloud**. You cannot skip any version that is available on the platform.
{% endhint %}

### Currently Supported Versions

The following Kubernetes versions are currently supported on **cegedim.cloud**:

| Available Version | Status                   |
| ----------------- | ------------------------ |
| Kubernetes 1.31   | Supported                |
| Kubernetes 1.32   | Latest supported version |

{% hint style="warning" %}
**Note:** Kubernetes versions 1.28 and 1.30 are no longer supported. If your cluster is running these versions, please upgrade to a supported version as soon as possible.
{% endhint %}

### Upgrade Path Diagram

The diagram below illustrates the required upgrade paths between versions. Each arrow represents a mandatory upgrade step:

```mermaid
graph LR
    v128["Kubernetes 1.28<br/>deprecated"] --> v130["Kubernetes 1.30<br/>deprecated"]
    v130 --> v131["Kubernetes 1.31<br/>✓ supported"]
    v131 --> v132["Kubernetes 1.32<br/>✓ latest"]

    style v128 fill:#ffcccb,stroke:#cc0000,stroke-width:2px,color:#000
    style v130 fill:#ffcccb,stroke:#cc0000,stroke-width:2px,color:#000
    style v131 fill:#90EE90,stroke:#006400,stroke-width:2px,color:#000
    style v132 fill:#87CEEB,stroke:#0066cc,stroke-width:2px,color:#000
```

{% hint style="info" %}
The diagram shows the historical upgrade path. Versions 1.28 and 1.30 are no longer supported but are shown to illustrate the required upgrade sequence for clusters that may still be running these versions.
{% endhint %}

### Upgrade Examples

**Example 1:** Upgrading from 1.31 to 1.32 (currently supported versions)

* Path: `1.31 → 1.32`
* Direct upgrade is possible as these are consecutive supported versions

**Example 2:** Upgrading from 1.28 or 1.30 (deprecated versions)

* If your cluster is on 1.28: `1.28 → 1.30 → 1.31 → 1.32`
* If your cluster is on 1.30: `1.30 → 1.31 → 1.32`
* You must upgrade through all intermediate versions that were released by cegedim.cloud

{% hint style="warning" %}
**Remember:** The upgrade path depends on which versions are available on **cegedim.cloud** at any given time. Always check ITCare UI to see the current list of available versions before planning your upgrade.
{% endhint %}


# MariaDB

Managed MariaDB

## Description

MariaDB is an open-source database management system created by the original developers of MySQL. MariaDB uses tables to store data in an organized way, and it is possible to interact with the database using SQL queries.

It supports concepts such as primary keys, indexes and relationships between tables. MariaDB is widely used for data storage and management in a variety of applications, from websites to enterprise systems. It is a popular choice due to its reliability, performance and open-source nature.

{% embed url="<https://mariadb.org/>" %}

## Platform as a Service

MariaDB is deployed on-premise in **cegedim.cloud'**&#x73; data centers. The long term support (LTS) can be deployed in self-service using ITCare

The same level of service as the Compute offer is guaranteed : deployment of instances, maintenance in operational condition, flexibility, security and monitoring are thus ensured by our experts.

Two topologies are available in self-service :

* Standalone (replica can be added on request)
* Galera cluster (3 nodes)

Galera cluster is production ready with at least 3 nodes spread over all Availability Zones of a target Area.

Sizing can be configured according to your needs.

<table><thead><tr><th width="295"></th><th>Standalone</th><th>Galera</th></tr></thead><tbody><tr><td>Instances</td><td>1</td><td>3</td></tr><tr><td>CPU (per node)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per node)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Supported version(s)</td><td>10.6, 10.11, 11.4</td><td>10.6, 10.11, 11.4</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr><tr><td>Self-service</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

For more information, please visit [MariaDB - Features](/databases/mariadb/mariadb-features).

## Billing

Billing is processed monthly and based on the number of instances plus supplementary costs for storage, backup, 24x7 monitoring.

Cost estimation for a MariaDB instance is available via your Service Delivery Manager.


# MariaDB - Features

## Description <a href="#mariadbarchitecture-description" id="mariadbarchitecture-description"></a>

MariaDB Community Edition is available in two self-service topologies:

* A standalone instance (with a [GTID](https://mariadb.com/kb/en/gtid/) replica on request)
* A Galera cluster based on 3 active/active instances

For more information on MariaDB architecture :

{% embed url="<https://mariadb.com/kb/en/understanding-mariadb-architecture/>" %}

MariaDB instances are accessible on port 3306 by default.

## Regions <a href="#mariadbarchitecture-regions" id="mariadbarchitecture-regions"></a>

MariaDB is available in the following **cegedim.cloud** data centers:

* EB4 (Boulogne-Billancourt, France)
* EB3 (Boulogne-Billancourt, France)
* ET1 (Labège, France)
* ET2 (Balma, France)

In some cases, when a third node is deployed (Galera cluster), nearby secondary data centers may also be used to ensure maximum resilience:

* EB5 (Magny-les-Hameaux, France)
* ET2 (Balma, France)

## Resources <a href="#mariadbarchitecture-ressources" id="mariadbarchitecture-ressources"></a>

The MariaDB Platform as a Service is hosted on the Linux Debian 10 distribution.

Minimum system requirements are 2 CPUs and 4GB RAM.

Storage can be configured during provisioning and subsequently increased on request.

## Topologies <a href="#mariadbarchitecture-topologies" id="mariadbarchitecture-topologies"></a>

### Standalone instance

This is a single instance deployed in a single data center.

### **Active/passive replication**

Two MariaDB instances are deployed in the same data center: the main node with a read-only replica.

{% hint style="warning" %}
Only deployed on request!
{% endhint %}

{% embed url="<https://mariadb.com/kb/en/gtid/>" %}

```mermaid
graph LR
    subgraph dc["Datacenter"]
        primary["🦭 MariaDB<br/>Primary"] --> replica["🦭 MariaDB<br/>Replica (read only)"]
    end
    style primary fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style replica fill:#ffe0b2,stroke:#e8820c,stroke-width:2px,color:#000
```

### Galera cluster

A MariaDB Galera cluster is a virtually synchronous multi-primary cluster for MariaDB.\
A cluster based on 3 active/active instances can be deployed in any cegedim.cloud data center.

{% hint style="warning" %}
MyISAM tables are not compatible with MariaDB Galera clusters because this storage engine does not support transactions and row-level locking, which are essential for Galera's synchronous multi-master replication. Therefore, it is necessary to convert them to InnoDB format before migrating to the cluster.
{% endhint %}

{% embed url="<https://mariadb.com/kb/en/what-is-mariadb-galera-cluster/>" %}

```mermaid
graph TD
    subgraph dc["Datacenter — all nodes are primaries"]
        n1["🦭 MariaDB"] <--> n2["🦭 MariaDB"]
        n1 <--> n3["🦭 MariaDB"]
        n2 <--> n3
    end
    style n1 fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style n2 fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style n3 fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
```

## Supported versions

The supported version is the latest LTS (long term support) currently available. For more information, please consult MariaDB versions.

{% embed url="<https://mariadb.com/kb/en/release-notes>" %}

## Restrictions

This section is to list which feature / capabilities are available to customer, and how to request / perform them :

<table data-header-hidden><thead><tr><th width="184"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done to cegedim.cloud support team.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="278">Feature</th><th width="152" data-type="checkbox">Self service</th><th width="132" data-type="checkbox">On request</th><th>Comments</th></tr></thead><tbody><tr><td>SSH access</td><td>false</td><td>false</td><td>SSH access is disabled and reserved to cegedim.cloud administrators.</td></tr><tr><td>Change configuration file</td><td>false</td><td>true</td><td>On request via ticket.<br>Review by the cegedim.cloud team.</td></tr></tbody></table>

## Default settings

Some default MariaDB parameters configured by cegedim.cloud :

<table data-full-width="true"><thead><tr><th width="252">Setting</th><th width="216.33333333333331">Value</th><th>Description</th></tr></thead><tbody><tr><td>transaction_isolation</td><td>READ-COMMITTED</td><td>Type of transaction</td></tr><tr><td>max_connections</td><td>1000</td><td>Max allowed connections to the instance</td></tr><tr><td>innodb_buffer_pool_size</td><td>50% of RAM</td><td>Innodb buffer memory allocated to the instance</td></tr><tr><td>slow queries</td><td>disabled</td><td>Slow queries are not logged by default</td></tr></tbody></table>

{% embed url="<https://mariadb.com/kb/en/documentation/>" %}

## Backup <a href="#mariadbarchitecture-backup" id="mariadbarchitecture-backup"></a>

Backup policy for MariaDB is configured like so :

* Full backup every weekend (online)
* Differential backup every day (online)
* Binlog backup every two hours

Default backup retention for the full backups and dependent backups is two weeks.

## Security <a href="#mariadbarchitecture-security" id="mariadbarchitecture-security"></a>

### Authentication <a href="#mariadbarchitecture-authentication" id="mariadbarchitecture-authentication"></a>

MariaDB's authentication is internal user based.

### Authorizations <a href="#mariadbarchitecture-authorizations" id="mariadbarchitecture-authorizations"></a>

An administration user is provided to the customer when the provisioning is over.

{% hint style="warning" %}
The password of this user is not stored nor saved by cegedim.cloud.\
Please be sure to save it in your own vault.
{% endhint %}

## Monitoring <a href="#mariadbarchitecture-monitoring" id="mariadbarchitecture-monitoring"></a>

As part of our Managed Databases offer, MariaDB is specifically monitored on top of the underlying system to ensure service uptime and performances.

The following key MariaDB indicators are monitored and tracked :

* Number of aborted client connections
* Number of failed server connection attempts
* Number of refused connections due to internal server errors
* Maximum number of simultaneous connections opened


# MariaDB - Get started

## Request a read-only MariaDB replica

To request the addition of a MariaDB read-only replica, you need to create a request ticket via ITCare.

In the **Support** section of the left-hand side menu, click on the **Make a request** button.\
In the **Database** category, then **MariaDB**, select and fill in the form: **Setting up passive MariaDB replication**.

A support ticket will be created upon submission.

{% hint style="info" %}
Please allow up to 10 working days for your request to be processed.
{% endhint %}


# MariaDB - Upgrade

## **PaaS upgrade workflow** <a href="#redisupgradeinplace-redispaasupgrade" id="redisupgradeinplace-redispaasupgrade"></a>

### Request <a href="#mariadbupgradeinplace-request" id="mariadbupgradeinplace-request"></a>

The update of a mariaDB PaaS is the responsibility of **cegedim.cloud** and can be requested via a request ticket submitted from ITCare, specifying a time slot for the operation.

Please specify if the operation is to be carried out outside of business hours in order to plan an RFC.

It is recommended that you upgrade your non-production environments first in order to estimate the downtime generated by the operation and to test your applications using the new engine version.

### Process <a href="#mariadbupgradeinplace-process" id="mariadbupgradeinplace-process"></a>

The upgrade of a mariaDB deployment (single-instance or Galera Cluster) takes place in two fully automated steps:

* Update the Operating system first if required
  * Multiple updates depending on the scenario: Debian 10 → Debian 11 -> Debian 12
* Update of the mariaDB engine in the target version

Depending on the source and target versions of mariaDB, it may be necessary to first migrate the operating system to a version supported by **cegedim.cloud**

```mermaid
graph TD
    start["MariaDB X<br/>Debian X"] --> debian["Upgrade Debian<br/>(once, twice or not required)"]
    debian --> mariadb["Upgrade MariaDB"]
    mariadb --> done["MariaDB Y<br/>Debian Y"]

    debian -.->|Handled by cegedim.cloud| mariadb

    style start fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style debian fill:#ffe0b2,stroke:#e8820c,stroke-width:2px,color:#000
    style mariadb fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style done fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
```

### Impacts

* The duration of an update is variable depending on:
  * The configured cpu and ram resources
  * The amount of data whose headers must be modified by the mariaDB engine.
  * The amount of data to be reindexed following the change of C library, after an OS update (Debian).
* The backup mode:
  * Point-in-time Recovery (PITR) from Rubrik Software.

### Time references <a href="#mariadbupgradeinplace-timereferences" id="mariadbupgradeinplace-timereferences"></a>

As an average guideline, durations for each steps of an upgrade in place of a 10 GB database (standalone):

* Debian upgrade: 10 minutes on average
* mariaDB updated: 5 minutes on average

As an average guideline, durations for each steps of an upgrade in place of a 10 GB database (Cluster Galera):

* Debian upgrade: 10 minutes on average
* mariaDB updated: 5 minutes on average

## **OS / mariaDB support matrix** <a href="#mariadbupgradeinplace-os-mariadbsupportmatrixmatrice" id="mariadbupgradeinplace-os-mariadbsupportmatrixmatrice"></a>

Linux distributions supported by **cegedim.cloud** depending on the mariaDB version:

<table><thead><tr><th width="258">Versions de MariaDB</th><th>Distribution Linux supportée</th></tr></thead><tbody><tr><td>mariaDB 10.6</td><td>Debian 11</td></tr><tr><td>mariaDB 10.11</td><td>Debian 12</td></tr><tr><td>mariaDB 11.4</td><td>Debian 12</td></tr></tbody></table>

## **Supported mariaDB update paths** <a href="#mariadbupgradeinplace-supportedmariadbupdatepaths" id="mariadbupgradeinplace-supportedmariadbupdatepaths"></a>

If the operating system is updated, it may require a complete reindexing (also handled by **cegedim.cloud**) due to changes in the C library when the operating system is updated.

Depending on the amount of data, this operation may take some time.


# OpenSearch

Managed OpenSearch

## Description

OpenSearch is a community-driven, open source search and analytics suite derived from Apache 2.0 licensed Elasticsearch 7.10.2 & Kibana 7.10.2.

It consists of a search engine daemon, OpenSearch, and a visualization and user interface, OpenSearch Dashboards. It enables people to easily ingest, secure, search, aggregate, view, and analyze data.

These capabilities are popular for use cases such as application search, log analytics, and more. OpenSearch will continue to provide a secure, high-quality search and analytics suite with a rich roadmap of new and innovative functionality.

{% embed url="<https://opensearch.org/>" %}

## Platform as a Service

OpenSearch Cluster servers and service configuration are managed by **cegedim**<mark style="color:red;">**.**</mark><mark style="color:blue;">**cloud**</mark>. The product is available in ITCare in self-service.

Users have full access to the OpenSearch database and Dashboards. It is the users responsibility to manage the security of indexes and lifecycle.

OpenSearch is deployed as a cluster on-premise in our data centers.

The same level of service as the Compute offer is guaranteed : deployment of instances, maintenance in operational condition, flexibility, security and monitoring are thus ensured by our experts.

Sizing can be configured according to your needs.

The minimum number of node for a cluster is 3 servers but not recommended for production. It is advised to deploy at least 5 or more nodes for Production use.

|                        | Cluster                                              |
| ---------------------- | ---------------------------------------------------- |
| Instances              | <ul><li>3</li><li>5 (recommended)</li></ul>          |
| CPU (per instance)     | 2 - 16 vCPU                                          |
| RAM (per instance)     | 4 - 384 GB                                           |
| Supported version(s)   | <ul><li>2.19.0</li><li>3.3.0</li><li>3.5.0</li></ul> |
| Monitoring             | :white\_check\_mark: Option                          |
| 24x7 Monitoring        | :white\_check\_mark: Option                          |
| Backup                 | :white\_check\_mark: Option                          |
| Data replication (DRP) | :white\_check\_mark: Option                          |
| Availability           | 99.9%                                                |
| Multi-AZ deployment    | :white\_check\_mark:                                 |
| Self-service           | :white\_check\_mark:                                 |

For more information, please visit [OpenSearch - Features](/databases/opensearch/opensearch-features).

## Billing

Billing is processed monthly and based on the number of nodes plus additional costs for storage, backup, 24x7 monitoring.

Cost estimation for an OpenSearch cluster is available via your Technical Account Manager.


# OpenSearch - Features

## Topologies <a href="#opensearchclusterarchitecture-architecture" id="opensearchclusterarchitecture-architecture"></a>

OpenSearch cluster is available as:

* 3 nodes cluster - not recommended for Production use
* 5 or more nodes cluster - recommended for Production use

### 3 nodes topology <a href="#opensearchclusterarchitecture-3nodestopology-notrecommended" id="opensearchclusterarchitecture-3nodestopology-notrecommended"></a>

In the 3 servers topology, all server are playing the master role, two of them are also used as data nodes. Each index are by default replicated on those two data nodes.

### At least 5 nodes topology <a href="#opensearchclusterarchitecture-5-ormore-nodestopology-recommended" id="opensearchclusterarchitecture-5-ormore-nodestopology-recommended"></a>

With 5 to more servers, three node are used as masters only nodes and don't host any data. Depending of the Area, master nodes are dispatched across 2 or 3 Availability Zones. The remaining nodes host only data and are spread over two Availability Zones.

## Resiliency <a href="#opensearchclusterarchitecture-resiliency" id="opensearchclusterarchitecture-resiliency"></a>

In an Area with 3 Availability Zones, the cluster is resilient against one AZ failure.

In an Area with 2 Availability Zones, the cluster might fail if the Availability Zone containing two masters is not available.

## Features <a href="#opensearchclusterarchitecture-features" id="opensearchclusterarchitecture-features"></a>

This section lists which feature / capabilities are available to users, and how to request / perform them :

<table data-header-hidden data-full-width="false"><thead><tr><th width="166"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously using ITCare.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done by cegedim.cloud support team.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="257">Features</th><th width="142" data-type="checkbox">Self-service</th><th width="137.5" data-type="checkbox">On request</th><th>Comments</th></tr></thead><tbody><tr><td>SSH access</td><td>false</td><td>false</td><td>SSH access is disabled and reserved to cegedim.cloud administrators.</td></tr><tr><td>Change configuration file</td><td>false</td><td>true</td><td>On request via ticket.</td></tr><tr><td>Add nodes</td><td>true</td><td>false</td><td>Add two data nodes to an existing cluster (only available in clusters with dedicated masters)</td></tr><tr><td>Resize node</td><td>true</td><td>false</td><td>Resize a node of a cluster</td></tr><tr><td>Add ingest nodes</td><td>true</td><td>false</td><td>Add two ingest nodes to an existing cluster (only available in clusters with dedicated masters)</td></tr><tr><td>Delete nodes</td><td>true</td><td>false</td><td>Delete two nodes from an existing cluster (the nodes need to be in different availability zones, enough space must be available in the remaining nodes of the cluster, only available in clusters with dedicated masters)</td></tr></tbody></table>

## Security <a href="#opensearchclusterarchitecture-security" id="opensearchclusterarchitecture-security"></a>

### Authentication <a href="#opensearchclusterarchitecture-authentication" id="opensearchclusterarchitecture-authentication"></a>

Authentication uses OpenSearch internal security system.

It can be configured on request to accept Active Directory as an authentication backend.

### Authorizations <a href="#opensearchclusterarchitecture-authorizations" id="opensearchclusterarchitecture-authorizations"></a>

Authorizations is done using RBAC.

It can be configured on request to accept Active Directory as a backend role provider.

### Secured Transport <a href="#opensearchclusterarchitecture-securedtransport" id="opensearchclusterarchitecture-securedtransport"></a>

TLS/SSL is activated by default for the incoming and internal network flows.

### Passwords <a href="#opensearchclusterarchitecture-passwords" id="opensearchclusterarchitecture-passwords"></a>

This section explains how the password management is handled:

<table data-full-width="true"><thead><tr><th width="217">Password</th><th width="225" data-type="checkbox">Stored by cegedim.cloud</th><th width="187" data-type="checkbox">Stored by customer</th><th width="113" data-type="checkbox">Enforced</th><th>Comment</th></tr></thead><tbody><tr><td><strong>admin</strong> account</td><td>false</td><td>true</td><td>false</td><td><br></td></tr><tr><td><strong>ANY</strong> other account</td><td>false</td><td>true</td><td>false</td><td><br></td></tr><tr><td><strong>kibana</strong> account</td><td>true</td><td>false</td><td>true</td><td>Used by the dashboard server to connect to the cluster</td></tr><tr><td><strong>support</strong> account</td><td>true</td><td>false</td><td>true</td><td>Used by cegedim.cloud support team (it has limited access and cannot read index datas)</td></tr><tr><td><strong>centreon</strong> account</td><td>true</td><td>false</td><td>true</td><td>Used by cegedim.cloud monitoring system (it has only access to monitoring information)</td></tr><tr><td><strong>prometheus</strong> account</td><td>true</td><td>false</td><td>true</td><td>Used by cegedim.cloud metering system (it has only access to monitoring information)</td></tr></tbody></table>


# v2 - Breaking changes

## Overview

**OpenSearch** has several breaking changes, so you must verify your application compatibility using this link:

{% embed url="<https://opensearch.org/docs/latest/breaking-changes/>" %}

## Remove mapping type

This is the major breaking change and it is not specific to OpenSearch as it was alreay planned by ElasticSearch before the fork

{% embed url="<https://www.elastic.co/guide/en/elasticsearch/reference/7.17/removal-of-types.html>" %}

So you must be sure that your applications are not using anymore the "type" parameters.

Here are some solutions regarding products often use with elastic solutions and how to configure them to work with OpenSearch 2.x

### Fluentbit

{% embed url="<https://docs.fluentbit.io/manual/pipeline/outputs/elasticsearch>" %}

If the client is Fluentbit, the easiest solution is to set the parameter **Suppress\_Type\_Name** to On.

It is also possible to change the output plugin to the opensearch native one which is part of Fluentbit since version 1.9.

{% embed url="<https://docs.fluentbit.io/manual/pipeline/outputs/opensearch>" %}

The following article may prove useful for getting started with Fluentbit and OpenSearch:

{% embed url="<https://opensearch.org/blog/technical/2022/03/getting-started-with-fluent-bit-and-opensearch/>" %}

### Fluentd

If the client is Fluentd it's more tricky. There is also a **suppress\_type\_name** but the plugin is using this parameter only if detect an elastic version>=7.

So we need to add to more parameters:

* **verify\_es\_version\_at\_startup** to false to not let the plugin detect the version
* **default\_elasticsearch\_version** to '7'

{% embed url="<https://github.com/uken/fluent-plugin-elasticsearch>" %}

Here are for exemple the change to be done on the spec of the output plugin we're using in Kubernetes

<details>

<summary>Before</summary>

{% code lineNumbers="true" %}

```yaml
 elasticsearch:
    flatten_hashes: true
    host: ostest.es.cegedim.cloud
    include_tag_key: true
    log_es_400_reason: true
    logstash_format: true
    logstash_prefix: myit-app-prod-frontend
    password:
      valueFrom:
        secretKeyRef:
          key: myit-app-prod_password
          name: it-cloud-eb.es.cegedim.cloud
    port: 443
    prefer_oj_serializer: true
    reconnect_on_error: true
    request_timeout: 30s
    scheme: https
    suppress_type_name: true
    user: myit-app-prod
```

{% endcode %}

</details>

<details>

<summary>After</summary>

{% code lineNumbers="true" %}

```yaml
  elasticsearch:
    default_elasticsearch_version: "7"
    flatten_hashes: true
    host: ostest.es.cegedim.cloud
    include_tag_key: true
    log_es_400_reason: true
    logstash_format: true
    logstash_prefix: myit-app-prod-frontend
    password:
      valueFrom:
        secretKeyRef:
          key: myit-app-prod_password
          name: it-cloud-eb.es.cegedim.cloud
    port: 443
    prefer_oj_serializer: true
    reconnect_on_error: true
    request_timeout: 30s
    scheme: https
    suppress_type_name: true
    user: myit-app-prod
    verify_es_version_at_startup: false
```

{% endcode %}

</details>

There is also an output plugin for OpenSearch.

{% embed url="<https://docs.fluentd.org/output/opensearch>" %}

{% hint style="warning" %}
The OpenSearch Plugin is not yet available in Rancher Logging System
{% endhint %}


# v3 - Breaking changes

## v3 – Breaking Changes

OpenSearch 3.x introduces a significant set of changes that may impact the compatibility of your applications, ingestion pipelines, dashboards, and plugins.

These changes are mainly related to:

* the migration to **Apache Lucene 10**,
* the mandatory adoption of **Java 21**,
* the removal of legacy mechanisms (Security Manager, deprecated APIs),
* changes in **mappings**,
* updates in **OpenSearch Dashboards**,
* and the expanded introduction of **Workspaces**.

***

### 🔗 Official OpenSearch References

* Breaking Changes: <https://docs.opensearch.org/latest/breaking-changes/>
* OpenSearch 3.0 – What to Expect: <https://opensearch.org/blog/opensearch-3-0-what-to-expect/>
* Release Notes 3.0.0:\
  <https://github.com/opensearch-project/opensearch-build/blob/main/release-notes/opensearch-release-notes-3.0.0.md>

***

## 1. Migration to Apache Lucene 10

**Reference:** <https://opensearch.org/blog/opensearch-3-0-what-to-expect/>

OpenSearch 3.0 adopts **Lucene 10**, which introduces:

* internal changes to index structures,
* modifications in segment management,
* removal of older index formats,
* incompatibilities with indices created using older Lucene versions.

**Impact:**\
A **full reindex** may be required depending on your current version.

***

## 2. Mandatory Upgrade to Java 21 (JDK 21)

**Reference:** <https://opensearch.org/blog/opensearch-3-0-what-to-expect/>

OpenSearch 3.x now requires **Java 21**.

**Impact:**

* Runtime environments must be updated.
* Internal or third‑party plugins must be recompiled.
* Scripts relying on deprecated Java APIs must be updated.

***

## 3. Removal of the Java Security Manager

**Reference:** <https://opensearch.org/blog/opensearch-3-0-what-to-expect/>

The **Java Security Manager**, already deprecated, is fully removed.

**Impact:**

* Plugins relying on this mechanism must be rewritten.
* Some security controls must be redesigned.

***

## 4. Mapping Changes

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

OpenSearch 3.x introduces several important changes to **mappings**, mainly due to Lucene 10 and the cleanup of legacy APIs.

***

### 4.1 Complete Removal of Mapping Types

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

Mapping types (`_type`) are now fully removed.

**Impact:**

* Ingestion pipelines must no longer send a type.
* Requests using `/index/type/_doc` will fail.

***

### 4.2 Removal of Deprecated Mapping Parameters

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

The following parameters are no longer supported:

* `include_type_name`
* `numeric_detection`
* `date_detection` (partially modified)
* `fielddata` on certain field types
* `norms` on non‑text fields
* `index_options` (simplified)
* restrictions on `doc_values`

**Impact:**\
Mappings containing these parameters will fail to create or update.

***

### 4.3 Changes to Field Types

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* **text**: stricter rules for custom analyzers
* **keyword**: stricter behavior for `ignore_above`
* **date**: stricter parsing for custom formats
* **boolean**: non‑standard values no longer accepted
* **nested**: reinforced structural limitations

***

### 4.4 Changes to Analyzers and Tokenizers

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

With Lucene 10:

* some analyzers change behavior,
* some tokenizers are removed or renamed,
* custom analyzers must be updated for compatibility.

***

### 4.5 Stricter Mapping Update Rules

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* stricter validation rules,
* some dynamic fields can no longer be added,
* index templates must be updated.

***

## 5. Plugin Changes

**Reference:** <https://opensearch.org/blog/opensearch-3-0-what-to-expect/>

The core OpenSearch update introduces:

* changes in internal APIs,
* required adjustments for third‑party plugins,
* potential incompatibilities with plugins built for OpenSearch 1.x or 2.x.

**Detailed impacts:**

* Plugins must be recompiled with updated dependencies.
* Plugins using internal Lucene classes must be adapted.
* Security, analytics, and monitoring plugins are the most affected.
* Unmaintained plugins will no longer work.

***

## 6. OpenSearch Dashboards Changes (3.x)

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

OpenSearch Dashboards 3.x introduces major updates.

***

### 6.1 Node.js Runtime Upgrade

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

Dashboards 3.x requires **Node.js ≥ 14**.

***

### 6.2 Internal API Changes

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* stricter visualization APIs
* modified endpoints
* changes in saved object handling

***

### 6.3 Changes to the `.opensearch_dashboards` Index

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* automatic migration
* cleanup of deprecated fields
* stronger validation rules

***

### 6.4 Visualization and Plugin Compatibility

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* plugins built for 1.x / 2.x must be updated
* custom visualizations must be tested
* removed fields may break dashboards

***

### 6.5 Security Hardening

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* stricter CSP rules
* restrictions on inline scripts
* limitations on external iframes

***

### 6.6 Changes in Filters and Search

**Reference:** <https://docs.opensearch.org/latest/breaking-changes/>

* stricter filters
* explicit errors for unmapped fields
* DSL queries must be validated

***

## 7. Migration to Workspaces

**Reference:** <https://docs.opensearch.org/latest/dashboards/workspaces/>

Workspaces progressively replace the former *Spaces*.

***

### 7.1 What Workspaces Change

**Reference:** <https://docs.opensearch.org/latest/dashboards/workspaces/>

* stronger isolation of dashboards and visualizations
* granular permissions
* ability to associate multiple data sources
* clearer logical separation (teams, projects, environments)

***

### 7.2 User Impacts

**Reference:** <https://docs.opensearch.org/latest/dashboards/workspaces/>

* dashboards may be migrated to a default workspace
* shared dashboards may need reorganization
* RBAC permissions must be reviewed


# OpenSearch - Get started

## Deploy a cluster

Connect to ITCare, search for the Global Service to attach the cluster to and click on it.

Click **Create resource** on the left control panel and select **OpenSearch**.

Give the cluster a **unique name** and define a prefix name that will be used to name the virtual machines. Click **Next**.

Select **number of nodes** and **node size**. Click **Next**.

Select **storage volume**. Click **Next**.

Select the **region** and **area** to which you want to locate your cluster. Click **Next**.

Select **VLAN** you want to deploy your cluster into. Click **Next**.

Enable or disable additional options:

* Virtual machines and clusters monitoring
* 24/7 monitoring
* Backup
* Virtual machines replication (Disaster recovery)

Click **Next**.

Select the version and define an **administrator password** that will be used to manage your cluster.

{% hint style="warning" %}
Passwords are not saved by cegedim.cloud. Make sure to save your password.
{% endhint %}

Verify settings, here you can:

* Check virtual machine names to be created.
* Save your administrator password.
* Modify the management options.

Click **Submit**.

Once the cluster is ready, you will be notified by email with the information required to connect to the cluster.

{% hint style="info" %}
Cluster creation can take up to 2 hours based on the current load on automation.\
The cluster will then be be displayed in your Global Service, in the left control panel, under the related cluster section. The green arrow indicates that the cluster is active.
{% endhint %}

## Start a cluster

On the left control panel, click the name of the cluster. The cluster page is displayed.\
At the top of the cluster page, click the **Manage** button, then **Start** and confirm.

{% hint style="info" %}
Starting a cluster will start all virtual machines attached to the cluster.
{% endhint %}

An email notification will be sent when the service will be activated.

## Stop a cluster

At the top of the OpenSearch cluster page, click the **Manage** button, then **Stop**.

Input an RFC number for tracking (optional). Click on **Submit**.

{% hint style="warning" %}
Stopping a cluster will stop all virtual machines attached to the cluster and monitoring will be disabled.
{% endhint %}

An email notification will be sent when the cluster is stopped.

## Add Nodes

At the top of the cluster page, click the **Manage** button, then **Add Nodes**.

Select the number of nodes you want to add (even number) and select the new size (cpu/ram). Specify the data disk size.

An email notification will be sent when all node are added.

## Resize Nodes

At the top of the cluster page, click the **Manage** button, then **Resize Nodes**.

Select the nodes you want to resize and select the new size (cpu/ram)

{% hint style="info" %}
Each node will be sequentially resized and restarted.
{% endhint %}

An email notification will be sent when all node are resized.

## Delete Nodes

At the top of the cluster page, click the **Manage** button, then **Delete nodes**.

Select the nodes you want (2 minimum) to delete and click on the 'Next' button.

Copy/paste or type the nodes' names in the 'Confirm action' field and click on the 'Delete' button

{% hint style="info" %}
Beware that this action is only available for clusters with dedicated masters Each selected nodes need to be in different availability zones Enough space must be available in the remaining nodes of the cluster Each node will be sequentially deleted.
{% endhint %}

An email notification will be sent when all nodes are deleted.

## Delete a cluster

At the top of the cluster page, click the **Manage** button, then **Delete**.

This action will stop and **delete** all virtual machines. All CI will be removed and disappear from your Global service.

{% hint style="danger" %}
Please note that this action is not recoverable.
{% endhint %}

Input an RFC number for tracking (optional) then click **Submit**.

An email notification will be sent when the cluster is removed.

## Upgrade the cluster topology

The cluster topology upgrade is proposed for an Opensearch cluster initially consisting of three nodes (basic topology).

The upgrade is implemented in ITCare via **"Manage - Migrate to dedicated master"** option.

Migration allows to add two **Master** nodes, while specialising the existing (n-1) nodes to the **Data** role. The cluster will thus be composed of three **Master** nodes and the rest of the nodes dedicated to the **Data** role.

During the upgrade to a "Dedicated Master" topology, the cluster will continue to work, although it may temporarily enter a "Yellow" status. However, some cluster objects, such as dashboards, may be temporarily unavailable. Everything will return to normal once the migration is complete.

### Migration demo

{% embed url="<https://app.supademo.com/demo/clzgy1u4d16sb9x77615ojzre>" %}

## Add ingest nodes to the cluster

The functionality to add dedicated ingestion nodes is available for an OpenSearch cluster with a "dedicated master" topology (five or more nodes).

The deployment of dedicated ingestion nodes is implemented in ITCare through the **"Manage - Add Ingest Nodes"** option.

With these dedicated ingestion nodes, it is possible to isolate the data ingestion process, which helps minimize the impact on indexing or search performance, even when dealing with large volumes of incoming data. This improves the overall stability and performance of the cluster.

[Link to official documentation](https://opensearch.org/docs/latest/getting-started/ingest-data/)

### Ingestion nodes demo

{% embed url="<https://app.supademo.com/demo/clzlafini2qct9x77fnjgq4l6>" %}

## Set node attributes

### Node Attributes - Multi-Tier Architecture - Hot/Cold

The multi-tier architecture (**Hot-Warm-Cold**) in OpenSearch allows for optimization of costs, performance, and scalability based on specific application needs. This architecture enables data storage based on access frequency, distributing frequently accessed data to identified nodes (**Hot**), moderately accessed data to identified nodes (**Warm**), and infrequently accessed data to identified nodes (**Cold**). In addition to attribute differences, the number of nodes at each level can also vary to meet specific search query needs.

At **cegedim.cloud**, to meet the needs of our customers, we offer two levels of the multi-tier architecture (**Hot-Cold**). Node attribute configuration is available in ITCare via the **"Set node attributes"** action, accessible at each node level.

For more information on node attribute configuration, please refer to [the official documentation](https://opensearch.org/docs/latest/im-plugin/ism/policies/)

## Exceed Maximum Shard Limit

In Opensearch, each node has a default shard limit of **1000 shards**.

This limit is in place to help maintian the performance and stability of your cluster by controlling resource usage per node. Exceeding this limit, such as when creating new indexes, will result in error.

If you encounter this error, consider the following actions below to resolve it.

### Add More Data Nodes to the Cluster

Adding additional nodes can distribute the shards across more resources, reducing the load per node. Each additional node will bring its own 1000 shards limit, effectively increasing your cluster's overall shard capacity.

### Increase cluster\_max\_shard\_per\_node Setting

Adjust the *cluster.max\_shards\_per\_node* parameter to allow more shards per node if you have sufficient hardware resources (CPU, memory and storage). We recommend to not exceed 2000 shards per node to avoid overloading.

Use the following command to update the parameter:

```
PUT /_cluster/settings
{
    "persistent":
    {
        "cluster.max_shards_per_node":<desired_shard_limit>
    }
}
```

### Optimize Shard Allocation per Index

When creating new indices, carefully plan the number of shards to match the index's data size and expected growth.

Avoid over-sharding by:

* Using fewer, larger shards for smaller datasets.
* Periodically reviewing shard allocation to ensure efficient resource usage.

### Important Notes

You should regularly monitor shard and resource utilization in your cluster to ensure optimal performance.

A Grafana dashboard for OpenSearch is available for this effect in your Advanced Metrology platform.

You should ensure your nodes are equipped with sufficient resources before increasing shard limits.


# OpenSearch - Upgrade

## **Upgrade Process**

## **PaaS upgrade workflow** <a href="#opensearchupgradeinplace-opensearchpaasupgrade" id="opensearchupgradeinplace-opensearchpaasupgrade"></a>

### Request <a href="#opensearchupgradeinplace-request" id="opensearchupgradeinplace-request"></a>

The update of an OpenSearch PaaS can be done in self-service on the OpenSearch cluster's resource page in [ITCare](https://itcare.cegedim.cloud)

It is recommended that you upgrade your non-production environments first in order to estimate the downtime generated by the operation and to test your applications using the new version.

### Process <a href="#opensearchupgradeinplace-process" id="opensearchupgradeinplace-process"></a>

The upgrade of an OpenSearch deployment takes place in two fully automated steps:

* Update the Operating system first if required
* The upgrade is performed **node by node** to ensure service continuity.

{% hint style="warning" %}
Skipping to a major version requires to be up to date with minor versions. Reverting to a previous version is not supported
{% endhint %}

```mermaid
graph TD
    start["OpenSearch X<br/>Debian X"] --> debian["Upgrade Debian<br/>(if needed)"]
    debian --> node["Upgrade cluster's node<br/>(one node at a time)"]
    node --> validation["Post upgrade validation"]
    validation --> done["OpenSearch Y<br/>Debian Y"]

    debian -.->|Handled through self-service| validation

    style start fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style debian fill:#ffe0b2,stroke:#e8820c,stroke-width:2px,color:#000
    style node fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style validation fill:#ffe0b2,stroke:#e8820c,stroke-width:2px,color:#000
    style done fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
```

### Impacts

When upgrading OpenSearch, anticipate the following potential impacts:

* Data write might slow down
* Temporarily reduced performance
* Dashboard's page reload may be needed

### Time references <a href="#opensearchupgradeinplace-timereferences" id="opensearchupgradeinplace-timereferences"></a>

As an average guideline, durations for each steps of an upgrade in place of a 100 GB cluster :

* Debian upgrade: 10 minutes on average
* Backup: 5 minutes on average
* OpenSearch upgrade : 15 minutes on average
* Dashboard upgrade : 10 minutes on average
* Automatic validation tests : 15 minutes on average

These times are indicative and may vary depending on specific cluster configurations.

## **OS / Opensearch support matrix** <a href="#opensearchupgradeinplace-os-opensearchsupportmatrixmatrice" id="opensearchupgradeinplace-os-opensearchsupportmatrixmatrice"></a>

Linux distributions supported by **cegedim.cloud** depending on the Opensearch version:

<table><thead><tr><th width="223">Opensearch version</th><th>Debian distribution</th></tr></thead><tbody><tr><td>OpenSearch 2.15</td><td>Debian 12</td></tr><tr><td>OpenSearch 2.19</td><td>Debian 12</td></tr><tr><td>OpenSearch 3.3.0</td><td>Debian 12</td></tr><tr><td>OpenSearch 3.5.0</td><td>Debian 12</td></tr></tbody></table>


# PostgreSQL

Managed PostgreSQL

## Description

PostgreSQL is currently the leading open source RDBMS (Relational Database Management System), with a wide range of features and a large community supporting it.

cegedim.cloud provides fully managed PostgreSQL databases instances to let you build your applications without operating availability, security and resilience of PostgreSQL databases.

{% embed url="<https://www.postgresql.org/>" %}

## Platform as a Service

PostgreSQL is deployed on-premise in cegedim.clou&#x64;**'**&#x73; data centers.

The same level of service as the Compute offer is guaranteed : deployment of instances, maintenance in operational condition, flexibility, security and monitoring are thus ensured by our experts.

Two types of PostgreSQL deployments are available :

* **Standalone Instance**
* **High availability :** two PostgreSQL instances with automatic fail-over for improved resiliency

Sizing can be configured according to your needs.

<table data-full-width="false"><thead><tr><th width="267"></th><th>Standalone</th><th>High availability</th></tr></thead><tbody><tr><td>Instance</td><td>1</td><td>2</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>6 - 384 GB</td><td>6 - 384 GB</td></tr><tr><td>Supported Versions</td><td>12, 13, 14, 15, 16, 17, 18</td><td>12, 13, 14, 15, 16, 17, 18</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr><tr><td>Self-service</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

For more information, please visit [PostgreSQL - Features](/databases/postgresql/postgresql-features).

## Billing

Billing is processed monthly and based on the number of instances plus supplementary costs for storage, backup and 24x7 monitoring.

Cost estimation for a PostgreSQL instance is available via your Service Delivery Manager.


# PostgreSQL - Features

## Architecture <a href="#postgresqlarchitecture-architecture" id="postgresqlarchitecture-architecture"></a>

### Supported versions <a href="#postgresqlarchitecture-supportedversions" id="postgresqlarchitecture-supportedversions"></a>

Currently supported versions of PostgreSQL are : 12, 13, 14, 15, 16, 17, 18.

### Upgrade <a href="#postgresqlarchitecture-upgrade" id="postgresqlarchitecture-upgrade"></a>

To upgrade your PaaS PostgreSQL, please refer to this page: [PostgreSQL - Upgrade](/databases/postgresql/postgresql-upgrade)

### Topologies <a href="#postgresqlarchitecture-topologies" id="postgresqlarchitecture-topologies"></a>

cegedim.cloud supports two types of PostgreSQL deployments :

* **Single Instance** mode is providing a standard PostgreSQL instance
* **High Availability** is providing a multi-instances PostgreSQL instance, with improved resilience and scalability capabilities

### Regions <a href="#postgresqlarchitecture-regions" id="postgresqlarchitecture-regions"></a>

PostgreSQL is available on cegedim.cloud's data center :

* EB3 (Boulogne-Billancourt, France)
* EB4 (Boulogne-Billancourt, France)
* EB5 (Magny-les-Hameaux, France)
* ET1 (Labège, France)
* ET2 (Labège, France)

In some cases, when a second node is deployed (High availability), a secondary close by data center can also be used to ensure maximum resiliency :

* EB5 (Magny-les-Hameaux, France)
* ET2 (Balma, France)

### Resiliency <a href="#postgresqlarchitecture-resiliency" id="postgresqlarchitecture-resiliency"></a>

For High availability topology the PaaS is built to be DC resilient if it is possible.

Following , a sample of nodes placement:

```mermaid
graph LR
    subgraph dc1["Datacenter 1"]
        pg1["🐘 PostgreSQL<br/>Availability Zone A or B"]
    end
    subgraph dc2["Datacenter 2"]
        pg2["🐘 PostgreSQL<br/>Availability Zone C"]
    end

    pg1 <-->|High availability deployment| pg2

    style dc1 fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style dc2 fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style pg1 fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style pg2 fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
```

### High Availability Diagram <a href="#postgresqlarchitecture-highavailabilitydiagram" id="postgresqlarchitecture-highavailabilitydiagram"></a>

```mermaid
graph TD
    customer["👤 Customer"]
    clusterip["🌐 Cluster IP"]

    subgraph dc1["Datacenter 1"]
        primary[("🗄️ Primary")]
    end
    subgraph dc2["Datacenter 2"]
        replica[("🗄️ Replica")]
    end

    customer -->|PostgreSQL protocol tcp 5432| clusterip
    clusterip --> primary
    clusterip -.->|Failover| replica
    primary <-->|Streaming Replication| replica

    style customer fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style clusterip fill:#dde8f5,stroke:#000,stroke-width:2px,color:#000
    style dc1 fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style dc2 fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style primary fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style replica fill:#e8820c,stroke:#a85a00,stroke-width:2px,color:#000
```

### Features <a href="#postgresqlarchitecture-features" id="postgresqlarchitecture-features"></a>

This section is to list which feature / capabilities are available to customer, and how to request / perform them :

<table data-header-hidden><thead><tr><th width="174"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done to cegedim.cloud support team.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="254">Feature</th><th width="155" data-type="checkbox">Self-service</th><th width="148" data-type="checkbox">On request</th><th>Comments</th></tr></thead><tbody><tr><td>SSH access</td><td>false</td><td>false</td><td>SSH access is disabled and reserved to cegedim.cloud administrators.</td></tr><tr><td>Change configuration file</td><td>false</td><td>true</td><td>On request via ticket. Only possible if it doesn't affect monitoring and resilience.</td></tr><tr><td>Install extension</td><td>true</td><td>false</td><td>PostgreSQL extensions can now be installed in self service using ITCare provided your deployment is in version 15 or higher. Otherwise, request ticket still applies.</td></tr></tbody></table>

## Extensions

It's possible to add functionality to PostgreSQL through so-called extensions. These extensions can add new types, additional functions for administrators and "classic" users alike, or even complete applications.

Some of these extensions are developed within the PostgreSQL project itself, so they keep pace with the evolution of the various PostgreSQL versions. You can find a list here. Others are developed by third-party companies and follow their own pace, like [Timescaledb](https://docs.timescale.com/) or [Postgis](https://postgis.net/), to name but the best-known.

Once the PostgreSQL PaaS has been provisioned, you can install some of these extensions through ITCare. Below is the list of extensions supported by PostgreSQL PaaS from version 15 onwards:

* [btree\_gist](https://www.postgresql.org/docs/18/contrib.html)
* [citext](https://www.postgresql.org/docs/18/contrib.html)
* [fuzzystrmatch](https://www.postgresql.org/docs/18/contrib.html)
* [hstore](https://www.postgresql.org/docs/18/contrib.html)
* [pg\_trgm](https://www.postgresql.org/docs/18/contrib.html)
* [pgcrypto](https://www.postgresql.org/docs/18/contrib.html)
* [postgis](https://postgis.net/)
* [tablefunc](https://www.postgresql.org/docs/18/contrib.html)
* [timescaledb](https://docs.timescale.com/)
* [unaccent](https://www.postgresql.org/docs/18/contrib.html)
* [uuid-ossp](https://www.postgresql.org/docs/18/contrib.html)
* [vector](https://github.com/pgvector/pgvector)
* [postgres\_fdw](https://www.postgresql.org/docs/18/contrib.html)
* [oracle\_fdw](https://github.com/laurenz/oracle_fdw)

Please note that the installation of certain extensions may require a restart of PostgreSQL and therefore cause your PostgreSQL PaaS to be unavailable.

## Security <a href="#postgresqlarchitecture-security" id="postgresqlarchitecture-security"></a>

### Authentication <a href="#postgresqlarchitecture-authentication" id="postgresqlarchitecture-authentication"></a>

Customer is provided with a role whom he chooses the password.

The password of this user is not stored nor saved by cegedim.cloud. Please be sure to save it in your own vault.

### Authorizations <a href="#postgresqlarchitecture-authorizations" id="postgresqlarchitecture-authorizations"></a>

The role provided to the customer has the following authorizations:

* LOGIN
* CREATEROLE
* CREATEDB

So, the customer may create dedicated application role and databases.

### Secured Transport <a href="#postgresqlarchitecture-securedtransport" id="postgresqlarchitecture-securedtransport"></a>

Secured transport is an option while provisioning and is available only from version 13 and above.

If secured transport is selected, TLS/SSL will be enabled for the PostgreSQL protocol and only a TLS connection from the clients will be accepted.

### Data location <a href="#postgresqlarchitecture-datalocation" id="postgresqlarchitecture-datalocation"></a>

All datas are stored in cegedim.cloud data centers on encrypted storage arrays.

### Passwords <a href="#postgresqlarchitecture-passwords" id="postgresqlarchitecture-passwords"></a>

This section list the password management :

<table data-full-width="true"><thead><tr><th width="239">Passwords</th><th width="217" data-type="checkbox">Stored by cegedim.cloud</th><th width="184" data-type="checkbox">Stored by Customer</th><th width="100" data-type="checkbox">Enforced</th><th>Hashing algorithm</th></tr></thead><tbody><tr><td><strong>dedicated customer</strong> account</td><td>false</td><td>true</td><td>false</td><td>SCRAM-SHA-256</td></tr><tr><td><strong>ANY</strong> other account</td><td>false</td><td>true</td><td>false</td><td>SCRAM-SHA-256</td></tr><tr><td><strong>cegedim.cloud</strong> account</td><td>true</td><td>false</td><td>true</td><td>SCRAM-SHA-256</td></tr><tr><td><strong>monitoring</strong> account</td><td>true</td><td>false</td><td>true</td><td>SCRAM-SHA-256</td></tr></tbody></table>

## Backup <a href="#postgresqlarchitecture-backup" id="postgresqlarchitecture-backup"></a>

If backup is enabled during provisioning (enabled by default for a Service of Production type), the following backup policies will apply :

* Full backup once a week.
* Differential backups in between.
* Write-ahead (WAL) logs are archived.

Point-in-Time recovery is supported for 14 days on Object Storage.

## Monitoring <a href="#postgresqlarchitecture-monitoring" id="postgresqlarchitecture-monitoring"></a>

As part of our Managed Databases offer, PostgreSQL is specifically monitored on top of the underlying system to ensure service uptime and performances.

The following key PostgreSQL indicators are monitored and tracked :

* Connections
* Memory usage
* Transaction id wrapparround
* Health status


# PostgreSQL - Get started

## How to provision PostgreSQL ? <a href="#postgresqlhowtos-howtoprovisionpostgresql" id="postgresqlhowtos-howtoprovisionpostgresql"></a>

To get started, head over to ITCare and search your target Global Service where you will create your new PostgreSQL.

Search your Global service in the top search bar and click on it to display its information page.

Once inside your Global Service, click on the **Create Resource** button and then select **PostgreSQL.**

Go to **Managed databases** and select **PostgreSQL** and pick the required version.

Fill in the form then click **Next**. Select your customizations and click **Next**.

Review the synthesis before submitting the form.

{% hint style="info" %}
Provisioning can take up to 2 hours based on the current load on automation.
{% endhint %}

Once the deployment is ready, you will be notified by email.

## How to manage your PostgreSQL ?

On the resource page of your PostgreSQL, you can take any action available by using the Manage button in the upper right corner. This includes, starting, stopping, deleting, rebooting, resizing and much more.

## How to access your PostgreSQL cluster ? <a href="#postgresqlhowtos-howtoaccessyourpostgresqlcluster" id="postgresqlhowtos-howtoaccessyourpostgresqlcluster"></a>

When your cluster is created with **cegedim.cloud** ITCare, you obtained an sql role with credentials.

With these credentials, you may connect to the cluster with its name on tcp port 5432. You may use postgres database to connect to.

If your cluster is named "mycluster", here is an example on how to connect using Python:

{% code lineNumbers="true" %}

```python
import psycopg2

# Connect to the postgres database
conn = psycopg2.connect(database='postgres', user='myuser', password='mystrongpwd',host='mycluster.pg.cegedim.cloud')
# Open a cursor to perform database operations
cursor = conn.cursor()
# Execute a query
cursor.execute("SELECT datname from pg_database")
# Retrieve query results
records = cursor.fetchall()
# Print all results
for record in records:
  print(record)
```

{% endcode %}

### How to access your PostgreSQL cluster with TLS/SSL ? <a href="#postgresqlhowtos-howtoaccessyourpostgresqlclusterwithtls-ssl" id="postgresqlhowtos-howtoaccessyourpostgresqlclusterwithtls-ssl"></a>

When your cluster is created with **cegedim.cloud** ItCare, you obtained an sql role named "admin" with credentials.

If you choose to activate TLS, you have received the root certificate you should trust to and give to the library you used to connect, for example psycopg2.

With these credentials, you may connect to the cluster with its name on tcp port 5432. You may use postgres database to connect to.

If your cluster is named "mycluster" here is an example on how to connect using Python:

{% code lineNumbers="true" %}

```python
import psycopg2
 
# Connect to the postgres database
conn = psycopg2.connect(database='postgres', user='myuser', password='mystrongpwd', host='mycluster.pg.cegedim.cloud', sslmode='verify-full', sslrootcert='cegedimcloud.pg.crt')
# Open a cursor to perform database operations
cursor = conn.cursor()
# Execute a query
cursor.execute("SELECT datname from pg_database")
# Retrieve query results
records = cursor.fetchall()
# Print all results
for record in records:
  print(record)
```

{% endcode %}

## How to create a role ? <a href="#postgresqlhowtos-howtocreatearole" id="postgresqlhowtos-howtocreatearole"></a>

It is safer than to not use an admin role for applications. Once connected, you may create a regular role as the following (replace \<a\_role> and \<very\_strong\_password> with your own credentials)

```sql
create role <a_role> login password '<very_strong_password>';
```

## How to create a database ? <a href="#postgresqlhowtos-howtocreateadatabase" id="postgresqlhowtos-howtocreateadatabase"></a>

if you want create a database whom owner will be the role you have just created, use the following SQL requests :

```sql
grant <a_role> to admin;
create database <my_database> owner <a_role>;
```

## How to create a database with another encoding and/or collation ? <a href="#postgresqlhowtos-howtocreateadatabasewithanotherencodingand-orcollation" id="postgresqlhowtos-howtocreateadatabasewithanotherencodingand-orcollation"></a>

You may use the following SQL requests with template0 database as template database:

{% code overflow="wrap" %}

```sql
create database <my_database> owner <a_role> template template0 LC_COLLATE 'fr_FR.utf8';
create database <my_database> owner <a_role> template template0 encoding 'LATIN1' LC_COLLATE 'fr_FR';
```

{% endcode %}

## How to restore in self-service ? <a href="#postgresqlhowtos-howtorestoreinself-service" id="postgresqlhowtos-howtorestoreinself-service"></a>

The PostgreSQL PaaS has a functionality allowing to restore a PostgreSQL PaaS (source) to another PostgreSQL PaaS (destination) at a given time (using Point-In-Time Recovery) under the following constraints:

* the user must have access to the cloud of the source farm and the destination farm
* the source must be backuped (option chosen during creation)
* both source and destination must be active
* the source and destination must be different
* the source and destination must be in the same version of PostgreSQL
* the source and destination must be in version 12 or higher
* the target time must not be in the future (bounded on the right by the current time).
* the time target must not be less than 7 days (for non-production services) or 14 days (for production services) from the current time (bounded on the left by the retention of backups)

You can choose to include or exclude the time target in the restoration process.

## How to install the oracle\_fdw extension? <a href="#postgresqlhowtos-howtoinstall-oracle-fdw" id="postgresqlhowtos-howtoinstall-oracle-fdw"></a>

You can install the oracle\_fdw extension on your databases. This extension allows you to connect to a PostgreSQL deployment and read/write tables that are actually located on an Oracle server. To do this, using ITCare, go to the Manage menu, then Manage Extensions, select your database, then oracle\_fdw, and click the Submit button. Remember that according to best practices, you have created a role and a dedicated database:

```sql
create role myrole login;
alter role myrole password ‘********’;
grant myrole to admin;
create database customer owner myrole;
```

Once the extension is installed, you must create several objects in the database. You must have the following items to perform this operation:

* the username and password for the account (admin) that was provided to you when you created your PostgreSQL deployment.
* the role that will connect to the PostgreSQL database and access the Oracle database
* The SID of the Oracle database
* The username and password for the role that has the right to connect to the Oracle database and read/write the tables in question.
* The name and definition of the Oracle tables

For the rest of this example, we will assume that a table has been created in Oracle as follows:

```sql
CREATE TABLE person (
  id NUMBER(10, 0) PRIMARY KEY,
  name VARCHAR2(64),
  ts TIMESTAMP
);
```

Using your admin account on the customer database, you must create a mapping between your Oracle server, the Oracle database, and the Oracle role (the role that created the person table, for example)

```sql
CREATE SERVER oracle_server FOREIGN DATA WRAPPER oracle_fdw OPTIONS (dbserver ‘//myora.hosting.cegedim.cloud:1521/mysid’);
CREATE USER MAPPING FOR myrole SERVER oracle_server OPTIONS (user ‘orauser’, password ‘mypwd’);
GRANT USAGE on foreign server oracle_server to myrole;
```

Finally, with the myrole role, connected to the customer database (in PostgreSQL):

```sql
CREATE FOREIGN TABLE person (
    id BIGINT OPTIONS (key ‘true’) NOT NULL,
    name VARCHAR(64),
    ts TIMESTAMP WITHOUT TIME ZONE
)
SERVER oracle_server
OPTIONS (table ‘PERSON’);
select * from person;
 id |   name    |             ts            
----+-----------+----------------------------
  0 | Asterix   | 2025-10-08 09:17:26.591058
  1 | Obelix    | 2025-10-08 09:17:34.893623
  2 | Panoramix | 2025-10-08 09:17:47.758639
  3 | Idefix    | 2025-10-08 09:17:58.063794
(4 rows)
```

If an error occurs when declaring the correspondences between the server and the Oracle role, the admin role can make the following changes:

```sql
-- modify the foreign server retrospectively if a parameter has been entered incorrectly
alter server oracle_server OPTIONS (SET dbserver ‘//so19cust03.hosting.cegedim.cloud:1521/SO19CUSTO3’);
-- modify a user mapping
ALTER USER MAPPING FOR myrole SERVER oracle_server OPTIONS (SET password ‘theGoodPassword’);
```

The documentation for the oracle\_fdw extension is available [here](https://github.com/laurenz/oracle_fdw).

## How to install the postgres\_fdw extension? <a href="#postgresqlhowtos-howtoinstall-postgres-fdw" id="postgresqlhowtos-howtoinstall-postgres-fdw"></a>

You can install the postgres\_fdw extension on your databases. This extension allows you to read/write tables located in another PostgreSQL deployment. To do this, using ITCare, go to the Manage menu, then Manage Extensions on your pg16 deployment, select your database, then postgres\_fdw, and click the Submit button. Remember that according to best practices, you have created a role and a dedicated database on each of the PostgreSQL deployments:

On the pg15 server in version 15, for example (pg15.pg.cegedim.cloud)

```sql
create role rolea login;
alter role rolea password ‘***********’;
grant rolea to admin;
create database mydb owner rolea;
\c mydb
CREATE TABLE mytable (
    id INTEGER PRIMARY KEY,
    ts TIMESTAMP WITH TIME ZONE DEFAULT NOW()
);
alter table mytable owner rolea;
insert into mytable values(0);
insert into mytable values(1);
insert into mytable values(2);
insert into mytable values(3);
select * from mytable;
 id |              ts              
----+-------------------------------
  0 | 2025-10-07 09:00:47.607772+00
  1 | 2025-10-07 09:00:50.998144+00
  2 | 2025-10-07 09:00:53.639238+00
  3 | 2025-10-07 09:00:56.134559+00
(4 rows)
```

On the pg16 server (pg16.pg.cegedim.cloud):

```sql
create role roleb login;
alter role roleb password ‘**********’;
grant roleb to admin;
create database customer owner roleb;
```

With the admin role on the customer database of the pg16 deployment, create the mappings with the pg15 server and the rolea role:

```sql
create server pg15 foreign data wrapper postgres_fdw options (host ‘pg15.pg.cegedim.cloud’, dbname ‘mydb’);
create user mapping for roleb server pg15 options(user ‘rolea’, password ‘******’); -- use the password for the rolea role on the pg15 server
grant usage on foreign server pg15 to roleb;
```

With the roleb role on the pg16 deployment, customer database, import the definition of the mytable table:

```sql
-- import the definition of the mytable table from pg15
IMPORT FOREIGN SCHEMA public LIMIT TO (mytable) FROM SERVER pg15 INTO public;
-- the table is now accessible:
 select * from mytable;
 id |              ts              
----+------------------------- ------
  0 | 2025-10-07 09:00:47.607772+00
  1 | 2025-10-07 09:00:50.998144+00
  2 | 2025-10-07 09:00:53.639238+00
  3 | 2025-10-07 09:00:56.134559+00
(4 rows)
```

## Demos

### Restoring a PostgreSQL Database

The process of restoring a PostgreSQL database is an important step. Let's see how to proceed below:

{% @supademo/embed url="<https://app.supademo.com/demo/cm1rmtzz60fmxspgc0g7x73z0>" demoId="cm1rmtzz60fmxspgc0g7x73z0" %}


# PostgreSQL - Upgrade

## **PaaS upgrade workflow** <a href="#redisupgradeinplace-redispaasupgrade" id="redisupgradeinplace-redispaasupgrade"></a>

### Request <a href="#postgresqlupgradeinplace-request" id="postgresqlupgradeinplace-request"></a>

The update of a PostgreSQL PaaS is the responsibility of **cegedim.cloud** and can be requested via a [request ticket](https://itcare.cegedim.cloud/support?createTicket=true\&requestTypeIndex=3\&formName=DB_POSTGRES\&step=Request) submitted from ITCare, specifying a time slot for the operation.

Please specify if the operation is to be carried out outside of business hours in order to plan an RFC.

It is recommended that you upgrade your non-production environments first in order to estimate the downtime generated by the operation and to test your applications using the new engine version.

### Process <a href="#postgresqlupgradeinplace-process" id="postgresqlupgradeinplace-process"></a>

The upgrade of a PostgreSQL deployment (single-instance or high availability) takes place in two fully automated steps:

* Update the Operating system first if required
  * Multiple updates depending on the scenario: Debian 10 → Debian 11 -> Debian 12 -> Debian 13
* Update of the PostgreSQL engine in the target version

Depending on the source and target versions of PostgreSQL, it may be necessary to first migrate the operating system to a version supported by **cegedim.cloud** (for more information, check [#postgresqlupgradeinplace-os-postgresqlsupportmatrixmatrice](#postgresqlupgradeinplace-os-postgresqlsupportmatrixmatrice "mention")).

```mermaid
graph TD
    start["🐘 PostgreSQL X<br/>Debian X"] --> deb["Upgrade Debian<br/>(Once, twice or not required)"]
    deb --> pg["Upgrade PostgreSQL X to Y *"]
    pg --> done["🐘 PostgreSQL Y<br/>Debian Y"]

    deb -.->|Handled by cegedim.cloud| pg

    note["* switch to PITR backup mode<br/>if Y is >= 12"]

    style start fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style deb fill:#e8820c,stroke:#a85a00,stroke-width:2px,color:#000
    style pg fill:#1abc9c,stroke:#0e6655,stroke-width:2px,color:#000
    style done fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style note fill:#1abc9c,stroke:#0e6655,stroke-width:1px,color:#000
```

### Impacts

* The duration of an update is variable depending on:
  * The configured cpu and ram resources
  * The amount of data whose headers must be modified by the PostgreSQL engine.
  * The amount of data to be reindexed following a change of C library, after an OS update.
  * The amount of data on which to activate the checksum (data page checksum was activated since PaaS PostgreSQL 12 )
  * The amount of data to be vacuumed.
  * The amount of data to be backuped (a full backup is performed after migration process).
* The backup mode:
  * Point-in-time Recovery (PITR) from PostgreSQL 12 and higher.
    * The "dump" backup mode disappears in favour of the "PITR" and is only used in versions of PostgreSQL lower than version 12.

### Time references <a href="#postgresqlupgradeinplace-timereferences" id="postgresqlupgradeinplace-timereferences"></a>

As an average guideline, durations for each steps of an upgrade in place of a 100 GB [pgbench](https://www.postgresql.org/docs/current/pgbench.html) database:

* Debian upgrade: 10 minutes on average
* PostgreSQL reindexing: 5 minutes on average
* PostgreSQL upgrading: 1 minute on average
* PostgreSQL checksum: 3 minutes on average
* PostgreSQL vacuuming: 1 minute on average
* PostgreSQL full backup (PITR mode): 16 minutes on average

In PostgreSQL HA, we need to upgrade the replica too and synchronize this replica with the leader:

* PostgreSQL synchronizing: 4 minutes on average

Total average duration for a 100GB database: 40 minutes

## **OS / PostgreSQL support matrix** <a href="#postgresqlupgradeinplace-os-postgresqlsupportmatrixmatrice" id="postgresqlupgradeinplace-os-postgresqlsupportmatrixmatrice"></a>

Linux distributions supported by **cegedim.cloud** depending on the PostgreSQL version:

<table><thead><tr><th width="223">PostgreSQL version</th><th>Debian distribution</th></tr></thead><tbody><tr><td>PostgreSQL 12</td><td>Debian 10</td></tr><tr><td>PostgreSQL 13</td><td>Debian 11</td></tr><tr><td>PostgreSQL 14</td><td>Debian 11</td></tr><tr><td>PostgreSQL 15</td><td>Debian 11</td></tr><tr><td>PostgreSQL 16</td><td>Debian 12</td></tr><tr><td>PostgreSQL 17</td><td>Debian 13</td></tr><tr><td>PostgreSQL 18</td><td>Debian 13</td></tr></tbody></table>

## **Supported PostgreSQL update paths** <a href="#postgresqlupgradeinplace-supportedpostgresqlupdatepaths" id="postgresqlupgradeinplace-supportedpostgresqlupdatepaths"></a>

If the operating system is updated, it may require a complete reindexing (also handled by **cegedim.cloud**) due to changes in the C library when the operating system is updated.

Depending on the amount of data, this operation may take some time.

Below are the update paths supported by **cegedim.cloud**:

<table data-full-width="true"><thead><tr><th width="181">Version Source</th><th>PostgreSQL 13</th><th>PostgreSQL 14</th><th>PostgreSQL 15</th><th>PostgreSQL 16</th><th>PostgreSQL 17</th><th>PostgreSQL 18</th></tr></thead><tbody><tr><td>PostgreSQL 12</td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>*</strong></p><p>Debian 10 → Debian 11</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>*</strong></p><p>Debian 10 → Debian 11</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>*</strong></p><p>Debian 10 → Debian 11</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 10 → Debian 12</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>***</strong></p><p>Debian 10 → Debian 13</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>***</strong></p><p>Debian 10 → Debian 13</p></td></tr><tr><td>PostgreSQL 13</td><td></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>*</strong></p><p>Debian 11 → Debian 12</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 11 → Debian 13</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 11 → Debian 13</p></td></tr><tr><td>PostgreSQL 14</td><td></td><td></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>*</strong></p><p>Debian 11 → Debian 12</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 11 → Debian 13</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 11 → Debian 13</p></td></tr><tr><td>PostgreSQL 15</td><td></td><td></td><td></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>*</strong></p><p>Debian 11 → Debian 12</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 11 → Debian 13</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>**</strong></p><p>Debian 11 → Debian 13</p></td></tr><tr><td>PostgreSQL 16</td><td></td><td></td><td></td><td></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>***</strong></p><p>Debian 12 → Debian 13</p></td><td><p><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span><strong>***</strong></p><p>Debian 12 → Debian 13</p></td></tr><tr><td>PostgreSQL 17</td><td></td><td></td><td></td><td></td><td></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

**\*** An operating system upgrade is required

**\*\*** Two operating system upgrades are required

**\*\***\* Three operating system upgrades are required


# Redis

## Description

Redis which stands for Remote Dictionary Server, is a fast, open source, in-memory, key-value data store.

It provides built-in replication, different levels of on-disk persistence, and provides high availability with [Sentinel](https://redis.io/topics/sentinel).

A [wide range of developer tools for most popular languages](https://redis.io/clients) exists.

{% embed url="<http://redis.io/>" %}

## Platform as a Service

Redis is deployed on site in **cegedim.cloud** data centers.

**cegedim.cloud** guarantees the same level of service as the Compute offer: instance deployment, operational maintenance, flexibility, security and monitoring are all provided by our experts.

Two topologies are available:

* Standalone instance
* Sentinel cluster of 3 instances

Sizing can be configured to suit your needs.

<table data-full-width="false"><thead><tr><th width="267"></th><th width="237">Standalone</th><th>Cluster</th></tr></thead><tbody><tr><td>Instance(s)</td><td>1</td><td>3</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>4 - 384 GB</td><td>4 - 384 GB</td></tr><tr><td>Supported version(s)</td><td><ul><li>6.2</li><li>7.2</li></ul></td><td><ul><li>6.2</li><li>7.2</li></ul></td></tr><tr><td>TLS/SSL</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24x7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Data replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr><tr><td>Self-service</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr></tbody></table>

The Sentinel cluster topology is production-ready, with 3 instances distributed across all the Availability Zones in a target Area.

Each instance runs the Redis and Sentinel processes. One instance is primary and the other two are replicas.

For more information, please visit [Redis - Features](/databases/redis/redis-features).

## Billing

Billing is processed monthly and based on the number of nodes, plus additional costs for storage, backup and 24/7 monitoring.

Cost estimates for Redis are available via your Service Delivery Manager.


# Redis - Features

Redis is self-service deployable via our cloud platform management tool: ITCare.

## Topologies

Two topologies are available:

* Standalone instance
* Sentinel cluster

In both cases, you can choose whether or not to persist data on disk at the time of the creation request, see [#persistence](#persistence "mention")

### Standalone instance

Once deployed, the stand-alone instance can be accessed on listening port 6379.

### Sentinel cluster

The Redis Sentinel cluster is deployed on 3 instances distributed over all the Availability Zones of an Area.

Once deployed, the cluster is accessible on listening port 6379.

#### Special features in cluster mode

* Each instance runs Redis **and** Sentinel processes
* Sentinel listening port: 26379
* Of the 3 instances, one is primary and the other two are replicas
* Replicas are open read-only

## Persistence

Persistence refers to the writing of data to durable storage, such as a solid-state disk (SSD). Redis provides a range of persistence options. These include:

* **RDB** (Redis Database): RDB persistence performs point-in-time snapshots of your dataset at specified intervals.
* **AOF** (Append Only File): AOF persistence logs every write operation received by the server. These operations can then be replayed again at server startup, reconstructing the original dataset. Commands are logged using the same format as the Redis protocol itself.
* **No persistence**: You can disable persistence completely. This is sometimes used when caching.
* **RDB + AOF**: You can also combine both AOF and RDB in the same instance.

{% embed url="<https://redis.io/docs/management/persistence/>" %}

<table><thead><tr><th width="285">Scenario</th><th>Parameter</th></tr></thead><tbody><tr><td>if <strong>RDB</strong> is enabled</td><td><ul><li>save 3600 1</li><li>save 300 100</li><li>save 60 10000</li></ul></td></tr><tr><td>if <strong>AOF</strong> is enabled</td><td><ul><li>append fsync every sec</li></ul></td></tr></tbody></table>

### Resiliency <a href="#redisarchitecture-resiliency" id="redisarchitecture-resiliency"></a>

If the primary is down, a replica will be automatically promoted as the new primary and the other replica will be reconfigured automatically to follow the new master.

Sentinel will give you the master node and the replicas nodes.

## Features <a href="#redisarchitecture-caracteristiques" id="redisarchitecture-caracteristiques"></a>

This section is to list which feature / capabilities are available to customer, and how to request / perform them :

<table data-header-hidden><thead><tr><th width="176"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done to cegedim.cloud support team.</td></tr></tbody></table>

<table data-full-width="true"><thead><tr><th width="323">Features</th><th width="137" data-type="checkbox">Self Service</th><th width="145.5" data-type="checkbox">On Request</th><th>Comments</th></tr></thead><tbody><tr><td>SSH access</td><td>false</td><td>false</td><td>SSH access is disabled and reserved to cegedim.cloud administrators.</td></tr><tr><td>Redis/Sentinel access</td><td>true</td><td>true</td><td>Customer can log in with an account to Redis and Sentinel (password defined by customer in the provisioning wizard).</td></tr><tr><td>Change configuration file</td><td>false</td><td>true</td><td>On request via ticket.</td></tr></tbody></table>

## High level diagram

Looking at the image again: the arrowheads point **toward the Redis/Sentinel boxes** (left), not toward the client. The client initiates each interaction — it reads/writes data and queries Sentinel — so the arrows flow from client to the nodes.

My version has them reversed. Corrected:

```mermaid
graph LR
    client["👤 Client"]

    subgraph aza["Availability Zone A"]
        direction TB
        rA["📕 Redis (Primary)<br/>Port 6379"]
        sA["📒 Sentinel<br/>Port 26379"]
    end

    subgraph azb["Availability Zone B"]
        direction TB
        rB["📕 Redis (Replica)<br/>Port 6379"]
        sB["📒 Sentinel<br/>Port 26379"]
    end

    subgraph azc["Availability Zone C"]
        direction TB
        rC["📕 Redis (Replica)<br/>Port 6379"]
        sC["📒 Sentinel<br/>Port 26379"]
    end

    client -->|Read/Write data| rA
    client -->|Read only data| rB
    client -->|Read only data| rC
    client -->|Get master/replicas address| sA
    client -->|Get master/replicas address| sB
    client -->|Get master/replicas address| sC

    style client fill:#dde8f5,stroke:#000,stroke-width:2px,color:#000
    style aza fill:#eef2fb,stroke:#000,stroke-width:2px,color:#000
    style azb fill:#eef2fb,stroke:#000,stroke-width:2px,color:#000
    style azc fill:#eef2fb,stroke:#000,stroke-width:2px,color:#000
    style rA fill:#d62728,stroke:#8b0000,stroke-width:2px,color:#fff
    style rB fill:#d62728,stroke:#8b0000,stroke-width:2px,color:#fff
    style rC fill:#d62728,stroke:#8b0000,stroke-width:2px,color:#fff
    style sA fill:#f1c40f,stroke:#9a7d0a,stroke-width:2px,color:#000
    style sB fill:#f1c40f,stroke:#9a7d0a,stroke-width:2px,color:#000
    style sC fill:#f1c40f,stroke:#9a7d0a,stroke-width:2px,color:#000
```

## Configuration

### Product configuration <a href="#redisarchitecture-configurationduproduit" id="redisarchitecture-configurationduproduit"></a>

<table data-full-width="true"><thead><tr><th width="200">Parameter</th><th width="294">Custom value</th><th width="113.5" data-type="checkbox">Enforced</th><th>Comments</th></tr></thead><tbody><tr><td>bind</td><td>@IP 127.0.0.1</td><td>false</td><td>Listening address</td></tr><tr><td>timeout</td><td>300</td><td>false</td><td>Close the connection after a client is idle for N seconds (0 to disable)</td></tr><tr><td>logfile</td><td>/var/log/redis/redis-server.log</td><td>true</td><td>Log file path</td></tr><tr><td>supervised</td><td>systemd</td><td>true</td><td>Supervision interaction</td></tr></tbody></table>

If **AOF persistence** is active, the following parameters will be applied:

<table data-full-width="false"><thead><tr><th>Parameter</th><th>Custom value</th><th data-type="checkbox">Enforced</th></tr></thead><tbody><tr><td>appendonly</td><td>yes</td><td>false</td></tr><tr><td>dir</td><td>/var/lib/redis/persistance</td><td>true</td></tr><tr><td>appendfsync</td><td>everysec</td><td>false</td></tr></tbody></table>

if **RDB** is active, the following parameters will be applied:

<table data-full-width="false"><thead><tr><th>Parameter</th><th>Custom value</th><th data-type="checkbox">Enforced</th></tr></thead><tbody><tr><td>save</td><td>3600 1</td><td>false</td></tr><tr><td>save</td><td>300 100</td><td>false</td></tr><tr><td>save</td><td>60 10000</td><td>false</td></tr><tr><td>rdb_compression</td><td>yes</td><td>false</td></tr><tr><td>rdbchecksum</td><td>yes</td><td>false</td></tr><tr><td>dir</td><td>/var/lib/redis/persistance</td><td>true</td></tr></tbody></table>

### Kernel configuration <a href="#redisarchitecture-kernelconfiguration" id="redisarchitecture-kernelconfiguration"></a>

The following kernel parameters have been modified to optimize operating system performance for Redis :

* vm.overcommit\_memory = 1
* vm.swappiness = 1
* net.core.somaxconn = 65535

## Security <a href="#redisarchitecture-securite" id="redisarchitecture-securite"></a>

### Authentification <a href="#redisarchitecture-authentification" id="redisarchitecture-authentification"></a>

The authentication mode used is internal: Redis 6 ACL.

Passwords are hashed with SHA-256 and do not appear in plain text in the ACL file.

### Autorisations <a href="#redisarchitecture-autorisations" id="redisarchitecture-autorisations"></a>

Redis 6 ACLs are used to manage authorizations.

On Sentinel, the dedicated client account has rights to :

{% code overflow="wrap" %}

```
~* &* +@all -@dangerous +ACL|GETUSER +INFO +sentinel|GET-MASTER-ADDR-BY-NAME +sentinel|IS-MASTER-DOWN-BY-ADDR +sentinel|MASTER +sentinel|MASTERS +sentinel|MYID +sentinel|REPLICAS +sentinel|SLAVES +sentinel|SENTINELS
```

{% endcode %}

On Redis, the dedicated customer account has rights to :

{% code overflow="wrap" %}

```
~* &* +@all -@dangerous +ACL|GETUSER +INFO +CONFIG|GET +CONFIG|HELP
```

{% endcode %}

### Secure Transport <a href="#redisarchitecture-transportsecurise" id="redisarchitecture-transportsecurise"></a>

The customer can choose whether or not to activate TLS transport when requesting self-service creation via ITCare.

### Password <a href="#redisarchitecture-motsdepasse" id="redisarchitecture-motsdepasse"></a>

This section describes password management:

<table data-full-width="true"><thead><tr><th width="230.2">Password</th><th width="231" data-type="checkbox">Stored by cegedim.cloud</th><th data-type="checkbox">Stored by customer</th><th width="139" data-type="checkbox">Enforced</th><th>Hash</th></tr></thead><tbody><tr><td>customer account</td><td>false</td><td>true</td><td>false</td><td>SHA-256</td></tr><tr><td>ANY other account</td><td>false</td><td>true</td><td>false</td><td>SHA-256</td></tr><tr><td>cgdm_admin account</td><td>true</td><td>false</td><td>true</td><td>SHA-256</td></tr><tr><td>cgdm_monitor account</td><td>true</td><td>false</td><td>true</td><td>SHA-256</td></tr></tbody></table>

## Monitoring <a href="#redisarchitecture-surveillance" id="redisarchitecture-surveillance"></a>

The following items are monitored and are accessible in ITCare.

<table data-full-width="false"><thead><tr><th width="395">Alerts</th><th>Description</th></tr></thead><tbody><tr><td>DBS_REDIS_CLI_CLIENTS</td><td>Check connected clients count</td></tr><tr><td>DBS_REDIS_CLI_AOF_STATUS</td><td>Check aof status</td></tr><tr><td>DBS_REDIS_CLI_COMMANDS</td><td>Number of commands processed</td></tr><tr><td>DBS_REDIS_CLI_CONNECTIONS</td><td>Number of connections</td></tr><tr><td>DBS_REDIS_CLI_CPU</td><td>CPU usage</td></tr><tr><td>DBS_REDIS_CLI_MEMORY</td><td>Memory usage</td></tr><tr><td>DBS_REDIS_CLI_REPL_REPLICAS_COUNT</td><td>Check replicas count</td></tr><tr><td>DBS_REDIS_CLI_RDB_STATUS</td><td>RDB status</td></tr><tr><td>DBS_REDIS_SENTINEL_MASTER_UP</td><td>Checks the status of the master from Sentinel</td></tr><tr><td>DBS_REDIS_SENTINEL_SLAVES_COUNT</td><td>Check replicas count from Sentinel</td></tr><tr><td>DBS_REDIS_SENTINEL_SENTINELS_COUNT</td><td>Check Sentinelscount</td></tr><tr><td>DBS_REDIS_SENTINEL_QUORUM</td><td>Check quorum status</td></tr><tr><td>TLS_REDIS_CERT_EXPIRATION</td><td>Check Redis certificate expiration</td></tr><tr><td>TLS_SENTINEL_CERT_EXPIRATION</td><td>Check Sentinel certificate expiration</td></tr></tbody></table>


# Redis - Get started

## How do I provision a Redis PaaS?

To get started, go to ITCare and search for your target global service where you'll create your new Redis deployment.

Search for your Global Service in the top search bar and click on it to display its information page.

Once in your Global Service, click on the **Create Resource** button, select **Redis** and the required version.

Fill in the form:

* Select a topology
* Define the name of the future deployment
* Sizing
* Storage requirements for each instance
* Target location
* Target network
* Management options (backup, monitoring, 24/7, remote site replication)

Click Next once all fields have been filled in.

In the customization step :

* Enter the password for the administrator account to be provided
* Select the required persistence options
* Enable or disable TLS encryption

Then click on Next.

{% hint style="warning" %}
Passwords are not saved by cegedim.cloud. Be sure to save your password!
{% endhint %}

Review the summary before submitting the form.

{% hint style="info" %}
Provisioning can take up to 2 hours, depending on the current automation load.
{% endhint %}

Once the deployment is ready, you'll be notified by e-mail.

## How to connect to a standalone Redis instance?

This code describes how to connect to Redis when the topology is a single instance. This code is deliberately simplified (errors are not handled), and is intended for demonstration purposes only.

The Python language is used. We assume that the Redis instance is named pcluredis01.hosting.cegedim.cloud.

<details>

<summary>Python example without TLS</summary>

{% code overflow="wrap" lineNumbers="true" %}

```python
import redis
 
def main():
    try:
        myRedis = redis.Redis(host='pcluredis01.hosting.cegedim.cloud', port=6379, db=0, password='1MyStrongPassword!', username='redis', decode_responses=True)
        pong = myRedis.ping()
        print(pong) # should be True
        myRedis.set('mykey','myvalue')
        print(myRedis.get('mykey')) # should be myvalue
        myRedis.close()
    except Exception as ex:
        print(ex)
 
if __name__ == "__main__":
    main()
```

{% endcode %}

</details>

<details>

<summary>Python example with TLS</summary>

{% code overflow="wrap" lineNumbers="true" %}

```python
import redis
 
def main():
    try:
        myRedis = redis.Redis(host='pcluredis01.hosting.cegedim.cloud', port=6379, db=0, password='1MyStrongPassword!', username='redis', decode_responses=True)
        pong = myRedis.ping()
        print(pong) # should be True
        myRedis.set('mykey','myvalue')
        print(myRedis.get('mykey')) # should be myvalue
        myRedis.close()
    except Exception as ex:
        print(ex)
 
if __name__ == "__main__":
    main()
```

{% endcode %}

</details>

## How do I connect to a Redis cluster?

This code describes how to connect to Redis in a cluster topology (with Sentinel). This is deliberately simplified (errors are not handled), and is intended for demonstration purposes only.

The Python language is used.

We assume that the Redis cluster is named **redis-cluster** with a "**pclu"** prefix.\
There are therefore 3 instances in this cluster:

* pcluredis01.hosting.cegedim.cloud
* pcluredis02.hosting.cegedim.cloud
* pcluredis03.hosting.cegedim.cloud

Two samples are available, with and without TLS.

<details>

<summary>Python example without TLS</summary>

{% code overflow="wrap" lineNumbers="true" %}

```python
from redis.sentinel import Sentinel
import redis
 
def main():
    try:
        mySentinel = Sentinel(
          [
            ('pcluredis01.hosting.cegedim.cloud', 26379),
            ('pcluredis02.hosting.cegedim.cloud', 26379),
            ('pcluredis03.hosting.cegedim.cloud', 26379)
          ],
          sentinel_kwargs={
            'username': 'redis',
            'password': '1MyStrongPassword!',
            'socket_connect_timeout': 0.5
          }
        )
         
        master_host, master_port = mySentinel.discover_master('redis-cluster')
        print("Redis master address: {}, TCP port {}".format(master_host, master_port))
        myMaster = redis.Redis(
          host=master_host,
          port=master_port,
          db=0,
          password='1MyStrongPassword!',
          username='redis',
          decode_responses=True
        )
        pong = myMaster.ping()
        print(pong) # should be True
        myMaster.set('mykey','myvalue')
        print(myMaster.get('mykey')) # should be myvalue
        myMaster.close()
        replicas = mySentinel.discover_slaves('redis-cluster')
        for replica in replicas:
            replica_host = replica[0]
            replica_port = replica[1]
            myReplica = redis.Redis(host=replica_host, port=replica_port, db=0, password='1MyStrongPassword!', username='redis', decode_responses=True)
            print("replica address {} port {} mykey {}".format(replica_host, replica_port, myReplica.get('mykey'))) # should be myvalue
            myReplica.close()
         
    except Exception as ex:
        print(ex)
 
if __name__ == "__main__":
    main()
```

{% endcode %}

</details>

<details>

<summary>Python example with TLS</summary>

{% code overflow="wrap" lineNumbers="true" %}

```python
from redis.sentinel import Sentinel
import redis
 
def main():
    try:
        mySentinel = Sentinel(
          [
            ('pcluredis01.hosting.cegedim.cloud', 26379),
            ('pcluredis02.hosting.cegedim.cloud', 26379),
            ('pcluredis03.hosting.cegedim.cloud', 26379)
          ],
          sentinel_kwargs={
            'username': 'redis',
            'password': '1MyStrongPassword!',
            'ssl': True,
            'ssl_ca_certs': '/tmp/ca-redis.crt',
            'ssl_cert_reqs': None,
            'ssl_certfile': None,
            'ssl_keyfile': None,
            'ssl_check_hostname': False,
            'socket_connect_timeout': 0.5
          }
        )
         
        master_host, master_port = mySentinel.discover_master('redis-cluster')
        print("Redis master address: {}, TCP port {}".format(master_host, master_port))
        myMaster = redis.Redis(
          host=master_host,
          port=master_port,
          db=0,
          password='1MyStrongPassword!',
          username='redis',
          decode_responses=True,
          ssl=True,
          ssl_ca_certs='/tmp/ca-redis.crt'
        )
        pong = myMaster.ping()
        print(pong) # should be True
        myMaster.set('mykey','myvalue')
        print(myMaster.get('mykey')) # should be myvalue
        myMaster.close()
        replicas = mySentinel.discover_slaves('redis-cluster')
        for replica in replicas:
            replica_host = replica[0]
            replica_port = replica[1]
            myReplica = redis.Redis(host=replica_host, port=replica_port, db=0, password='1MyStrongPassword!', username='redis', decode_responses=True, ssl=True, ssl_ca_certs='/tmp/ca-redis.crt')
            print("replica address {} port {} mykey {}".format(replica_host, replica_port, myReplica.get('mykey'))) # should be myvalue
            myReplica.close()
         
    except Exception as ex:
        print(ex)
 
if __name__ == "__main__":
    main()
```

{% endcode %}

</details>


# Redis - Upgrade

## **PaaS upgrade workflow** <a href="#redisupgradeinplace-redispaasupgrade" id="redisupgradeinplace-redispaasupgrade"></a>

### Request <a href="#redisupgradeinplace-request" id="redisupgradeinplace-request"></a>

The update of a Redis PaaS is the responsibility of cegedim.cloud and can be requested via a request ticket submitted from ITCare.

Please specify a time slot to execute the upgrade and if the operation is to be carried out outside of business hours.

It is recommended that you upgrade your non-production environments first in order to estimate the downtime generated by the operation and to test your applications using the new engine version.

### Process <a href="#redisupgradeinplace-process" id="redisupgradeinplace-process"></a>

The upgrade of a Redis deployment (single-instance or high availability cluster) takes place in two fully automated steps:

* Update the operating system first if required
  * Multiple updates depending on the scenario: Debian 10 → Debian 11 → Debian 12
* Update of the Redis and Sentinel engine in the specified target version

```mermaid
graph TD
    start["Redis X<br/>Debian X"] --> debian["Upgrade Debian<br/>(once or not required)"]
    debian --> redis["Upgrade Redis agent"]
    redis --> sentinel["Upgrade Sentinel agent<br/>(if needed)"]
    sentinel --> done["Redis Y<br/>Debian Y"]

    debian -.->|Handled by cegedim.cloud| sentinel

    style start fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
    style debian fill:#ffe0b2,stroke:#e8820c,stroke-width:2px,color:#000
    style redis fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style sentinel fill:#c8e6c9,stroke:#2ca02c,stroke-width:2px,color:#000
    style done fill:#e8e8e8,stroke:#000,stroke-width:2px,color:#000
```

{% hint style="info" %}
Depending on the source and target versions of Redis, it may be necessary to first migrate the operating system to a version supported by cegedim.cloud (for more information, check OS / Redis support matrix below).
{% endhint %}

### Impacts

The duration of an update is variable and depends on:

* The topology
  * Standalone topology: Redis will be upgraded.
  * Sentinel topology: Redis and Sentinel on all nodes will be upgraded.
* The amount of operating system upgrade necessary

### Time references

* Debian operating system upgrade: 10 minutes on average
* Redis package upgrade : 5 minutes on average
* Sentinel package upgrade: 5 minutes on average

## OS / Redis support matrix

Linux distributions supported by cegedim.cloud depending on the Redis version:

| Redis version | Debian version                                     |
| ------------- | -------------------------------------------------- |
| 6.2.x         | Debian 10                                          |
| 6.2.x         | Debian 12 (deployments created after May 31, 2024) |
| 7.2.x         | Debian 12                                          |

{% hint style="info" %}
OS upgrades is required only if the PaaS Redis 6.2 was provisionned before May 31, 2024. After this date, the Redis PaaS has been updated to be deployed on Debian 12.
{% endhint %}


# SQL Server

**Microsoft SQL Server** is a relational database management system developed by Microsoft.

It is designed to store and retrieve data as requested by other software applications.\
The core features of SQL Server include:

* Data storage and retrieval: SQL Server provides a secure and scalable platform to store a large amount of structured and semi-structured data efficiently.
* Data querying and manipulation: It offers advanced querying capabilities, such as the ability to write complex queries using SQL language, join tables, create views, and retrieve data based on specific criteria.
* Business intelligence and analytics: SQL Server provides tools and services for data analysis, reporting, and visualization, allowing users to gain insights from the stored data to make data-driven decisions.
* Data security and integrity: It offers robust security features, like authentication, access control, and encryption, to protect sensitive data from unauthorized access or modifications.
* High availability and scalability: SQL Server supports features like clustering, failover, and replication to ensure continuous availability of data and support for growing demands by scaling up or out the database infrastructure.

## Platform as a Service

SQL Server is deployed on site in cegedim.cloud data centers.

The same level of service as the Compute offer is guaranteed: instance deployment, operational maintenance, flexibility, security and monitoring are all handled by our experts.

SQL Server 2016, 2017, 2019 and 2022 are available in self-service via our ITCare cloud management platform.

Two editions are supported: Standard and Enterprise.

Two topologies are available:

* Stand-alone instance
* Always On cluster

The **Always On** cluster topology is production-ready but is only available on demand. Only SQL Server 2022 Enterprise edition is available for self-service provisioning.

Sizing can be configured to suit your needs.

<table><thead><tr><th></th><th width="209.33333333333331">Stand-alone instance</th><th>Always On cluster</th></tr></thead><tbody><tr><td>Instances</td><td>1</td><td>3</td></tr><tr><td>CPU (per instance)</td><td>2 - 16 vCPU</td><td>2 - 16 vCPU</td></tr><tr><td>RAM (per instance)</td><td>8 - 384 GB</td><td>8 - 384 GB</td></tr><tr><td>Supported Version(s)</td><td><ul><li>2016</li><li>2017</li><li>2019</li><li>2022</li></ul></td><td><ul><li>2016</li><li>2017</li><li>2019</li><li>2022</li></ul></td></tr><tr><td>Backup</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>24/7 Monitoring</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Replication (DRP)</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span> Option</td></tr><tr><td>Availability</td><td>99.8%</td><td>99.9%</td></tr><tr><td>Multi-AZ deployment</td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td></tr><tr><td>Self-service</td><td><span data-gb-custom-inline data-tag="emoji" data-code="2705">✅</span></td><td><span data-gb-custom-inline data-tag="emoji" data-code="274c">❌</span></td></tr></tbody></table>

For more information, please read [SQL Server - Features](/databases/sql-server/sql-server-features).


# SQL Server - Features

## Architecture

### Topologies <a href="#sqlserverarchitecturefr-topologies" id="sqlserverarchitecturefr-topologies"></a>

Two topologies are available:

* Standalone Instance
* Always On Cluster

### Always On - Topology <a href="#sqlserverarchitecture-alwayson" id="sqlserverarchitecture-alwayson"></a>

The Always On cluster configuration is based on a 3-node topology:

#### **Active Nodes**

* Two nodes located on the same site.
* These nodes are configured to share the load or automatically failover in case of a failure.
* An anti-affinity rule ensures that the active nodes do not coexist on the same hypervisor host, thus enhancing resilience.

#### **Passive Node**

* Located on a secondary site to ensure disaster recovery (DR).
* This node does not handle any active requests and is reserved exclusively for failover in the event of active node failure.

#### Rules and Restrictions for the Passive Node <a href="#sqlserverarchitecture-alwayson-passiverules" id="sqlserverarchitecture-alwayson-passiverules"></a>

The passive node is subject to strict restrictions to comply with Microsoft License Mobility with Failover Rights:

* **No active workload:** The passive node cannot execute SQL queries, reports, or user workloads.
* **Allowed operations:**
  * Database consistency checks.
  * Full backups and transaction log backups.
  * Performance and resource monitoring.
* **Optimized licensing:** With Software Assurance, the use of the passive node is included at no additional cost, provided these restrictions are followed.

#### Benefits of Always On <a href="#sqlserverarchitecture-alwayson-advantages" id="sqlserverarchitecture-alwayson-advantages"></a>

* **Fault tolerance:** Synchronous replication ensures that data is available in real-time on active nodes.
* **Disaster recovery:** Deploying a passive node on a secondary site enhances security and business continuity.
* **Simplified maintenance:** Planned failovers allow updates or technical interventions without service interruption.

#### Monitoring and Compliance <a href="#sqlserverarchitecture-alwayson-monitoring" id="sqlserverarchitecture-alwayson-monitoring"></a>

Specific monitoring tailored for the Always On cluster is in place to:

* Ensure compliance with restrictions related to the passive node.
* Monitor performance and automatic failovers.
* Prevent risks of non-compliance with licensing rules.

### Regions <a href="#sqlserverarchitecture-regions" id="sqlserverarchitecture-regions"></a>

SQL Server is available on both cegedim.cloud's data centers:

* EB4 - Boulogne-Billancourt, France
* ET1 - Labège, France

As part of the Always On topology, an inactive node is automatically deployed in a nearby secondary site to enhance the resilience of the cluster:

* EB5 (Magny-les-Hameaux, France)
* ET2 (Balma, France)

### Hosting and Versions <a href="#sqlserverarchitecture-hostingandversion" id="sqlserverarchitecture-hostingandversion"></a>

<table><thead><tr><th width="160">Hosting type</th><th width="182">SQL Server version</th><th width="198">Operating System</th><th>SQL Server edition</th></tr></thead><tbody><tr><td>Virtual</td><td>2022</td><td>Windows Server 2022</td><td>Standard or Enterprise</td></tr><tr><td>Virtual</td><td>2019</td><td>Windows Server 2019</td><td>Standard or Enterprise</td></tr><tr><td>Virtual</td><td>2017</td><td>Windows Server 2019</td><td>Standard or Enterprise</td></tr><tr><td>Virtual</td><td>2016</td><td>Windows Server 2016</td><td>Standard or Enterprise</td></tr></tbody></table>

### File system <a href="#sqlserverarchitecture-filesystem" id="sqlserverarchitecture-filesystem"></a>

Filesystem layout:

<table><thead><tr><th width="102">Drive</th><th>Label</th><th width="171">Default size</th><th>Description</th></tr></thead><tbody><tr><td>D:\</td><td>MSSQL</td><td>30 GB</td><td>Root instance</td></tr><tr><td>E:\</td><td>MSSQL_USER_DATA</td><td>30 GB</td><td>User databases</td></tr><tr><td>F:\</td><td>MSSQL_USER_LOG</td><td>10 GB</td><td>User databases log</td></tr><tr><td>G:\</td><td>MSSQL_TEMPDB</td><td>10 GB</td><td>TempDB</td></tr></tbody></table>

### Virtual machine name restriction <a href="#sqlserverarchitecture-virtualmachinenamerestriction" id="sqlserverarchitecture-virtualmachinenamerestriction"></a>

Due to prefixes applied to Active Directory objects, the name of the virtual machine provisioned is **restricted to 13 characters maximum** for a cegedim.cloud PaaS SQL Server.

### Ports <a href="#sqlserverarchitecture-ports" id="sqlserverarchitecture-ports"></a>

Ports listing:

<table><thead><tr><th width="163.33333333333331">Port</th><th width="344">Description</th><th>Protocol</th></tr></thead><tbody><tr><td>1433</td><td>Server static port listener</td><td>TCP</td></tr><tr><td>1434</td><td>SQL Server Browser</td><td>UDP</td></tr><tr><td>2382</td><td>SQL Server Analysis Services Browser</td><td>UDP</td></tr><tr><td>2383</td><td>SQL Server Analysis Services listener</td><td>TCP</td></tr><tr><td>5022</td><td>SQL Server BDM/AG Endpoint</td><td>TCP</td></tr></tbody></table>

{% hint style="warning" %}
Only the SQL Server listener and SQL Server Browser ports are opened inbound in the Windows Firewall by default and enforced through a GPO on the Organization unit.
{% endhint %}

### Modules installed <a href="#sqlserverarchitecture-modulesinstalled" id="sqlserverarchitecture-modulesinstalled"></a>

List of modules installed by default during provisioning:

* Database engine
* Replication
* Full-text Search
* Client tools connectivity
* SDK

### Features <a href="#sqlserverarchitecture-features" id="sqlserverarchitecture-features"></a>

This section is to list which feature / capabilities are available to customer, and how to request / perform them:

<table data-header-hidden><thead><tr><th width="157"></th><th></th></tr></thead><tbody><tr><td><strong>Self Service</strong></td><td>Customer can perform action autonomously.</td></tr><tr><td><strong>On Request</strong></td><td>Customer can request for the action to be done to cegedim.cloud support team.</td></tr></tbody></table>

<table><thead><tr><th width="217">Features</th><th width="139" data-type="checkbox">Self Service</th><th width="144" data-type="checkbox">On Request</th><th>Comments</th></tr></thead><tbody><tr><td>Database Collation</td><td>true</td><td>false</td><td><br></td></tr><tr><td>Integration Services</td><td>true</td><td>true</td><td><br></td></tr><tr><td>Analysis Services</td><td>true</td><td>true</td><td><br></td></tr><tr><td>Reporting Services</td><td>true</td><td>true</td><td><br></td></tr><tr><td>Full-Text Search</td><td>true</td><td>true</td><td><br></td></tr><tr><td>Export, Import SQL Server backup</td><td>false</td><td>true</td><td><br></td></tr><tr><td>Create Always On cluster</td><td>true</td><td>true</td><td>Available exclusively for SQL Server 2022 Enterprise edition, consult your service delivery manager for guidance</td></tr></tbody></table>

## Security <a href="#sqlserverarchitecture-security" id="sqlserverarchitecture-security"></a>

### System login <a href="#sqlserverarchitecture-systemlogin" id="sqlserverarchitecture-systemlogin"></a>

The SQL Server PaaS runs exclusively in a Windows environment. The standard system login method is RDP (Remote Desktop Protocol).

In order to connect to the virtual machine, you need to have the required privileges either at the domain level or at the local machine level.

### Instance login <a href="#sqlserverarchitecture-instancelogin" id="sqlserverarchitecture-instancelogin"></a>

Authentication is configured by default in **mixed mode** which provides two login types:

* **SQL Server login**: instance level
* **Active directory user**: domain level - Embedded Windows authentication

Instance login is available locally or remotely:

* **Locally**: once connected in RDP, launch the local SQL Server Management Studio
* **Remotely**: launch the SQL Server Management Studio and specify the target instance

#### Locally <a href="#sqlserverarchitecture-locally" id="sqlserverarchitecture-locally"></a>

SSMS can use the Windows user credentials you're already logged with through RDP to login to the SQL Server instance.

Authentication with an SQL login is also possible locally.

#### Remotely <a href="#sqlserverarchitecture-remotely" id="sqlserverarchitecture-remotely"></a>

Specify a target instance in the server name field enforcing the tcp protocol: `tcp:HOSTNAME\INSTANCENAME`

Just select **"SQL Server Authentication"** and provide the SQL Login with the associated password.

### Authorizations

Authorizations for cegedim.cloud teams are managed by GPO.

### Authorization and passwords <a href="#sqlserverarchitecture-authorizationandpasswords" id="sqlserverarchitecture-authorizationandpasswords"></a>

This section list the password management for the SQL Server PaaS:

<table><thead><tr><th width="221">Password</th><th width="230" data-type="checkbox">Stored by cegedim.cloud</th><th width="191" data-type="checkbox">Stored by Customer</th><th data-type="checkbox">Enforced</th></tr></thead><tbody><tr><td><strong>admin</strong> account</td><td>false</td><td>true</td><td>false</td></tr><tr><td><strong>ANY</strong> other account</td><td>false</td><td>true</td><td>false</td></tr><tr><td><strong>cgdm_admin</strong> account</td><td>true</td><td>false</td><td>true</td></tr><tr><td><strong>monitoring</strong> account</td><td>true</td><td>false</td><td>true</td></tr></tbody></table>

#### Customers

Authorizations for customers are managed by the customers itself.

The customer that request a **SQL Server** instance through **ITCare** will be automatically granted to connect on the instance. He can grant access to any Active Directory user or group afterwards.

### Patching <a href="#sqlserverarchitecture-patching" id="sqlserverarchitecture-patching"></a>

Patchs are installed during "Patch parties" managed by cegedim.cloud every quarter.

An instance can be patched manually exceptionally if security or bug fixes requires it.

### Data location <a href="#sqlserverarchitecture-datalocation" id="sqlserverarchitecture-datalocation"></a>

Datas for cegedim.cloud's SQL Server PaaS are stored on the dedicated virtual machines created upon requesting a PaaS.

These virtual machines and the storage associated are hosted and managed in cegedim.cloud's own data centers.


# SQL Server - Get started

## Create an instance

To get started, connect to ITCare and search your target Global Service where you will create your new SQL Server. Once inside your Global Service, click on the **Create Resource** button in the top right corner.

Go to **Managed databases** and select **SQL Server**

Pick the desired version and edition.

* **Name**: Specify the new name for the SQL Server virtual machine.
  * In Always On Cluster mode, specify the name of the **Availability Group**.
  * **Prefix**: Provide a prefix to initialize the virtual machines in the cluster.
* **Sizing**: Select a **sizing** for your instance. Default value and lowest sizing is 2 CPUs / 4 GB RAM.
* **Storage**: Select the storage capacity required for SQL Server. Five disks are required.
  * Default and minimum storage is 30 GB for root instance and user datas disks, 10 GB for user log and tempdb disks.
* **Localization**: Select the **Region** you want to deploy to. Pick an **Area** in this Region and finally select an **Availability zone**.
* **Network**: Select the **VLAN** you want to deploy into. Ideally your backend VLAN.
* **Authentication**: Select the authentication domain you want to deploy into.
* **Management**: Activate management options.
  * Enable or disable Monitoring
  * Enable of disable 24/7 Monitoring
  * Enable backup of your virtual machine
  * Enable Replication of your virtual machines (on Disaster recovery site)

### **Customization** <a href="#sqlserverhowtos-stepcustomization" id="sqlserverhowtos-stepcustomization"></a>

Provide the administrator **password** that you will use for your SQL Server administrator user.

{% hint style="warning" %}
cegedim.cloud will **NOT** save this password so please save it somewhere safe in your vault.
{% endhint %}

* Confirm your password.
* Choose your SQL collation.
* Add key technologies available in SQL Server : SSIS, SSAS, SSRS

You can add a specific request before submission but it will delay the automated provisioning.

Click **Next** when done.

#### **Synthesis** <a href="#sqlserverhowtos-stepsynthesis" id="sqlserverhowtos-stepsynthesis"></a>

This page will resume your inputs, please check everything is correct before submitting.\
You can display and save your administrator password.

Once reviewed and verified, click **Submit**.

#### Notification <a href="#sqlserverhowtos-notification" id="sqlserverhowtos-notification"></a>

Once the deployment is ready, you will be notified by email.\
Provisioning can take up to 1 hours based on the current load on automation.

## Start a deployment

At the top of the resource page, click on the **Manage** button, then on **Start** and confirm.

{% hint style="info" %}
Cluster startup starts all virtual machines attached to the cluster.
{% endhint %}

An e-mail notification will be sent when the service is activated.

## Stop a deployment

At the top of the resource page, click on the **Manage** button, then on **Stop.**\
Enter an RFC number for tracking (optional). Click on **Submit**.

{% hint style="warning" %}
Shutting down a cluster will stop all virtual machines attached to the cluster, and monitoring will be disabled.
{% endhint %}

An e-mail notification will be sent when the cluster is shut down.

## Resize nodes

At the top of the resource page, click on the **Manage** button, then on **Resize.**\
Select the new size (CPU / RAM).

{% hint style="info" %}
Each node will be resized and restarted sequentially.

Resizing will interrupt the SQL Server service !
{% endhint %}

An e-mail notification will be sent when all nodes have been resized.

## Delete a deployment

At the top of the cluster page, click on the **Manage** button, then on **Delete**.\
This will stop and delete all virtual machines.

{% hint style="danger" %}
Please note that this action is not recoverable!
{% endhint %}

Enter an RFC number for tracking (optional), then click **Submit**.

An e-mail notification will be sent when the deployment is deleted.




---

[Next Page](/llms-full.txt/1)

