OpsCtl

Ops Control (a.k.a. OpsCtl) is a simple Dalet-provided utility that aims at simplifying DevOps day-to-day. Simply put, it is a wrapper on top of Ansible, Terraform and Helmfile utilities, calling those with the proper parameters, envrionment variables and many other things so DevOps people doesn't have to think about and you ensure proper deployments reproduceability.

OpsCtl does nothing more than Ansible or Terraform would do for you. It is swiss-army knife for DevOps.

But it'll handle painful things like secrets management (amongst others) so that you won't have to think about it, ever, or wonder about the exact command-line to be used, making things error-proof.

Supported Hosts

Flex deployment and administration requires a UNIX-compatible system. At present time, officially tested and supported desktop configurations are:

  1. MacOS (with Apple Silicon ARM64 architecture)
  2. Ubuntu Linux LTS 24.04+ (AMD64 and ARM64 architectures).

Installation on MacOS

This requires prior installation of Homebrew package manager.

Once available, Terraform can be installed through:

MacOS Installation

brew tap ooyala/fsre git@bitbucket.org:ooyalaflex/homebrew-tap.git
brew update
brew install opsctl

Installation on Ubuntu Linux

This requires administrative (i.e. root) privileges.

Ubuntu Installation

wget -O - 'https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x1131dee34455b48e0ec5904d342e0be283a8071f' | sudo gpg --dearmor -o /usr/share/keyrings/dalet-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/dalet-archive-keyring.gpg] http://packages.cs.dalet.cloud/ ubuntu main" | sudo tee /etc/apt/sources.list.d/dalet.list
sudo apt-get update
sudo apt-get install opsctl

Configuration

OpsCtl has a local configuration file, stored in $HOME/.opsctl.d/config. This file is mostly auto-generated at first use and filled-in with automatically detected parameters.

As for Ansible deployments to work successfully, the user's SSH profile must be provided manually once and for all. This is one of the key thing that can't be auto-discovered. One need to update the OpsCtl configuration file and update the following entries:

ansible:
  ssh:
    user: my_user_id
    key_file: /home/user/.ssh/id_ecdsa (or id_rsa, or whatever your private SSH key is)

This SSH private key must match the public SSH key on targeted servers.

Usage

OpsCtl comes bundled with many sub-commands, such as:

Usage:
  opsctl [command]

Ansible-oriented Commands:
  deploy       Run Ansible playbook
  inventory    Creates a local static inventory file from cloud-provider dynamic inventory
  lint         Perform static analysis of Ansible codebase
  update       Update Ansible roles/collections requirements without deployment
  vault        Manage Ansible-vault encrypted secrets

Helmfile-oriented Commands:
  happly       Apply Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
  hdestroy     Destroy Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
  hdiff        Diff Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
  hstatus      Display Helmfile configuration status (uses -- [ARGS] to extend it with helmfile's free args)
  hsync        sync Helmfile configuration status (uses -- [ARGS] to extend it with helmfile's free args)
  htemplate    template Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)

Terraform-oriented Commands:
  apply        Create or update Terraform-based infrastructure
  check        Perform static-analysis code sanity and security checks
  destroy      Destroy previously-created Terraform infrastructure
  fmt          Reformat Terraform's code in standard style
  import       Associate existing infrastructure with a Terraform resource
  init         Prepare Terraform workspace
  opa          Verifies Terraform IaC rules compliance against Open Policy Agent guidelines
  output       Extract the value of output variables from the state file
  plan         Show changes before applying Terraform's configuration
  show         Show the current Terraform state or plan
  state        Terraform state management
  validate     Check whether Terraform's configuration is valid

Kubernetes-oriented Commands:
  kconfig      Generate or update Kubectl configuration for this platform

Additional Commands:
  bitbucket    Open Bitbucket repository page
  completion   Generate the autocompletion script for the specified shell
  cost         Calculates theorical static infrastructure cost
  help         Help about any command
  login        Login/renew access credentials to platform's account
  maintenance  Control platform's maintenance state
  meta         Create and/or updates the platform metadata file
  open         Open links defined in META
  pagerduty    Open PagerDuty service page
  pr           Create a new pull request on BitBucket
  pull         Updates local configs and tools with upstream versions
  push         Updates upstream global config with platform specifics
  repo         Configure BitBucket repository with various generic settings
  secrets      Manage SOPS-encrypted secrets file
  self-upgrade Upgrade OpsCtl to the latest available version
  setup        Setup a proper deployment environment (download/install/upgrade 3rd-party plugins)
  template     Generate a base environment code
  version      Display OpsCtl version number

Initial Setup

OpsCtl is a wrapper on top of third-party tools, but you need those toolset at first. Well, don't worry, everything's bundled.

The setup sub-command will download everything for you: Age, multiple versions of Ansible (from 5.x to 13.x) including all necessary plugins and extensions, tfsec, checkov, Helm, Helmfile, InfraCost, Kubectl, Kubectx, Kubens, MdBook, Mozilla SOPS, Saml2Aws, Talisman, Terraform and many others.

Once run, every required utility will be downloaded into your $HOME/.opsctl.d/plugins directory (10 GB of disk space is recommended).

It is highly suggested that you update your favorite shell's profile configuration file (e.g. $HOME/.bashrc) to update the PATH environment variable, e.g.:

export PATH=$HOME/.opsctl.d/plugins/bin:$PATH
export PATH=$HOME/.opsctl.d/plugins/python/common/bin:$PATH

Updates

Both opsctl and the underlying third-party utilities evolve over time and you need to ensure to always being up-to-date.

When it comes to opsctl itself, one can update simply through:

opsctl self-upgrade

Third-party managed toolset can be updated to latest versions through:

opsctl setup -u