Platform Metadata

OpsCtl uses a custom META.yml file, to be located at the root of your Git deployment project codebase to describe all of the project's metadata. It describes multiple things related to platform usage, infrastructure provider and access settings, secrets management, licensing and suport information and application version, domain information and such ...

This further allows OpsCtl to wrap around many third-party tools usage to determine exactly how to interact with your system when it comes to deployment and maintenance options.

A typical project deployment tree structure would be the following:

$ tree -L 1
.
├── META.yml        <- the project metadata file
├── ansible         <- folder with ansible-specifics platform configuration settings
└── terraform       <- folder with terraform-specifics platform configuration settings

Metadata File Generation

The platform metadata file is pure YAML, as described in the following section.

It's generation might be long and complex and that's why OpsCtl comes with an automatic generation utility:

$ opsctl meta -i

will prompt you with an interactive CLI to help you render your first metadata file from template.

Further calls to:

$ opsctl meta

will provide syntax and sanity checks ensuring that whatever you could have edited the file with remains compatible.

Metadata File Format

The following table provides an exhaustive list of all supported YAML fields and parameters:

ParameterTypeRequiredDefaultDescription or example
customer.namestringyes''free text, e.g. ACME
customer.regionstringyes''US-WEST, US-EAST, CALA, EMEA, APAC
customer.countrystringyes''free text, e.g. France, USA
infra.ccstringno''free text, cost center
infra.cost.pricefloat64no''numeric value
infra.cost.currencystringyes''free text, e.g. EUR, USD
infra.providerstringyes''ali, aws, azure, gcp, kowabunga, onprem, ovh
infra.dchboolyesfalseDalet Cloud Hosted ?
infra.remote_accessstringyes''bastion, customer-vpn, netgate, netgate-apac, netgate-emea, netgate-na, rdp
infra.remote_detailsstringno''URL link with instructions and details regarding remote access
infra.satelliteboolnofalseDoes environment has satellite nodes ? (hybrid environment)
aws.regionstringno''free text, e.g. us-east-1
aws.role_arnstringno''free text, e.g. arn:aws:iam::123456789:role/admin
azure.resource_groupstringno''free text
kowabunga.endpointstringno''Kowabunga API endpoint URL
kowabunga.ownerstringno''free text, platform owner name
kowabunga.emailstringno''free text, platform owner email
kowabunga.regionstringno''free text, platform region
requirement.ansible.min_versionstringno''free text, minimum Ansible version to deploy with
requirement.ansible.versionstringno''free text, default Ansible version to deploy with (e.g. 2.12, 2.13 ...)
requirement.terraform.versionstringno''free text, default Terraform version to deploy with
product.namestringyes''amberfin, atlas, brio, control-tower, cubeng, flex, galaxy, iris, kvirt, mediacortex, pyramid
product.licensestringyes''perpetual, subscription, demo
product.support_levelstringyes''none, starter, plus, ultimate
product.monitored.enabledboolyesfalseIs platform Dalet-monitored (Managed Services plan) ?
product.monitored.control_towerboolyesfalseIs platform connected to Dalet Control Tower ?
secrets.providerstringyes''aws, vault, file, input
secrets.sm.custom_profileboolnofalseEnabled when different from Dalet default one
secrets.sm.regionstringyes''AWS region for Secrets Manager
secrets.sm.role_arnstringnofalseAWS role ARN for Secrets Manager
secrets.idstringyes''Secrets key to be used
secrets.vault_key_suffixstringnoansible_vaultfree text, none or environment tag
secrets.sops_created_at_suffixstringnosops_created_atfree text, can be none or environment tag
secrets.sops_public_key_suffixstringnosops_public_keyfree text, can be none or environment tag
secrets.sops_secret_key_suffixstringnosops_secret_keyfree text, can be none or environment tag
environments[].tagstringyes''free text, e.g. dev, prod ...
environments[].namestringyes''free text, e.g. 'flex-acme-prod'
environments[].descriptionstringyes''free text, e.g. 'ACME Flex Production platform'
environments[].activeboolyesfalseIs the platform active and maintained ?
environments[].versionstringyes''Flex version, e.g. 2025.1.0
environments[].fqdn.prefixstringyes''Platform FQDN prefix, e.g. 'flex'
environments[].fqdn.domainstringyes''Platform FQDN, e.g. 'acme.com
environments[].os.namestringyesUbuntuOS Name: Ubuntu, Devian, RedHat, Centos, AmazonLinux2
environments[].os.versionstringyes''OS version number
environments[].inventory.staticboolyesfalseDo we host static or dynamic inventory file
environments[].pagerduty.enabledboolyesfalseIs platform connected to PagerDuty for alerting ?
environments[].pagerduty.service_idboolyesfalsePagerDuty service ID to be used
environments[].kubernetes.enabledboolnofalseDoes the platform uses Kubernetes backend ?
environments[].kubernetes.typestringno''Which Kubernetes flavor are we using ? (auto, eks, gke, ack, aks, okgs, atlas )
environments[].kubernetes.versionstringno''Which Kubernetes version are we using ?
environments[].kubernetes.clusterstringno''Name of the Kubernetes cluster
environments[].kubernetes.controller.endpointstringno''Public DNS endpoint used to reach out the Kubernetes cluster, if not auto-discovered
environments[].kubernetes.controller.masterstringno''IP address of the master controller to pull user kubeconfigs from (Atlas use-case)
environments[].flex.urls.corestringno''Core Flex URL
environments[].flex.urls.grafanastringno''Grafana Flex URL
environments[].flex.urls.kibanastringno''Kibana Flex URL
environments[].flex.urls.prometheusstringno''Prometheus Flex URL
environments[].flex.urls.alertmanagerstringno''AlertManager Flex URL
environments[].flex.transcode.enabledboolnofalseDoes Flex platform uses FSP ?
environments[].flex.transcode.k8s_fspboolnofalseDoes Flex platform uses elastic FSP on Kubernetes ?
environments[].flex.dbaasboolnofalseDoes Flex platform uses database-as-a-service ?
environments[].flex.lbaasboolnofalseDoes Flex platform uses lad-balancer-as-a-service ?