OpsCtl
Ops Control (a.k.a. OpsCtl) is a simple Dalet-provided utility that aims at simplifying DevOps day-to-day. Simply put, it is a wrapper on top of Ansible, Terraform and Helmfile utilities, calling those with the proper parameters, envrionment variables and many other things so DevOps people doesn't have to think about and you ensure proper deployments reproduceability.
OpsCtl does nothing more than Ansible or Terraform would do for you. It is swiss-army knife for DevOps.
But it'll handle painful things like secrets management (amongst others) so that you won't have to think about it, ever, or wonder about the exact command-line to be used, making things error-proof.
Supported Hosts
Flex deployment and administration requires a UNIX-compatible system. At present time, officially tested and supported desktop configurations are:
- MacOS (with Apple Silicon ARM64 architecture)
- Ubuntu Linux LTS 24.04+ (AMD64 and ARM64 architectures).
Installation on MacOS
This requires prior installation of Homebrew package manager.
Once available, Terraform can be installed through:
brew tap ooyala/fsre git@bitbucket.org:ooyalaflex/homebrew-tap.git
brew update
brew install opsctl
Installation on Ubuntu Linux
This requires administrative (i.e. root) privileges.
wget -O - 'https://keyserver.ubuntu.com/pks/lookup?op=get&search=0x1131dee34455b48e0ec5904d342e0be283a8071f' | sudo gpg --dearmor -o /usr/share/keyrings/dalet-archive-keyring.gpg
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/dalet-archive-keyring.gpg] http://packages.cs.dalet.cloud/ ubuntu main" | sudo tee /etc/apt/sources.list.d/dalet.list
sudo apt-get update
sudo apt-get install opsctl
Configuration
OpsCtl has a local configuration file, stored in $HOME/.opsctl.d/config. This file is mostly auto-generated at first use and filled-in with automatically detected parameters.
As for Ansible deployments to work successfully, the user's SSH profile must be provided manually once and for all. This is one of the key thing that can't be auto-discovered. One need to update the OpsCtl configuration file and update the following entries:
ansible:
ssh:
user: my_user_id
key_file: /home/user/.ssh/id_ecdsa (or id_rsa, or whatever your private SSH key is)
This SSH private key must match the public SSH key on targeted servers.
Usage
OpsCtl comes bundled with many sub-commands, such as:
Usage:
opsctl [command]
Ansible-oriented Commands:
deploy Run Ansible playbook
inventory Creates a local static inventory file from cloud-provider dynamic inventory
lint Perform static analysis of Ansible codebase
update Update Ansible roles/collections requirements without deployment
vault Manage Ansible-vault encrypted secrets
Helmfile-oriented Commands:
happly Apply Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
hdestroy Destroy Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
hdiff Diff Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
hstatus Display Helmfile configuration status (uses -- [ARGS] to extend it with helmfile's free args)
hsync sync Helmfile configuration status (uses -- [ARGS] to extend it with helmfile's free args)
htemplate template Helmfile configuration (uses -- [ARGS] to extend it with helmfile's free args)
Terraform-oriented Commands:
apply Create or update Terraform-based infrastructure
check Perform static-analysis code sanity and security checks
destroy Destroy previously-created Terraform infrastructure
fmt Reformat Terraform's code in standard style
import Associate existing infrastructure with a Terraform resource
init Prepare Terraform workspace
opa Verifies Terraform IaC rules compliance against Open Policy Agent guidelines
output Extract the value of output variables from the state file
plan Show changes before applying Terraform's configuration
show Show the current Terraform state or plan
state Terraform state management
validate Check whether Terraform's configuration is valid
Kubernetes-oriented Commands:
kconfig Generate or update Kubectl configuration for this platform
Additional Commands:
bitbucket Open Bitbucket repository page
completion Generate the autocompletion script for the specified shell
cost Calculates theorical static infrastructure cost
help Help about any command
login Login/renew access credentials to platform's account
maintenance Control platform's maintenance state
meta Create and/or updates the platform metadata file
open Open links defined in META
pagerduty Open PagerDuty service page
pr Create a new pull request on BitBucket
pull Updates local configs and tools with upstream versions
push Updates upstream global config with platform specifics
repo Configure BitBucket repository with various generic settings
secrets Manage SOPS-encrypted secrets file
self-upgrade Upgrade OpsCtl to the latest available version
setup Setup a proper deployment environment (download/install/upgrade 3rd-party plugins)
template Generate a base environment code
version Display OpsCtl version number
Initial Setup
OpsCtl is a wrapper on top of third-party tools, but you need those toolset at first. Well, don't worry, everything's bundled.
The setup sub-command will download everything for you: Age, multiple versions of Ansible (from 5.x to 13.x) including all necessary plugins and extensions, tfsec, checkov, Helm, Helmfile, InfraCost, Kubectl, Kubectx, Kubens, MdBook, Mozilla SOPS, Saml2Aws, Talisman, Terraform and many others.
Once run, every required utility will be downloaded into your $HOME/.opsctl.d/plugins directory (10 GB of disk space is recommended).
It is highly suggested that you update your favorite shell's profile configuration file (e.g. $HOME/.bashrc) to update the PATH environment variable, e.g.:
export PATH=$HOME/.opsctl.d/plugins/bin:$PATH
export PATH=$HOME/.opsctl.d/plugins/python/common/bin:$PATH
Updates
Both opsctl and the underlying third-party utilities evolve over time and you need to ensure to always being up-to-date.
When it comes to opsctl itself, one can update simply through:
opsctl self-upgrade
Third-party managed toolset can be updated to latest versions through:
opsctl setup -u