Skip to main content

Managed Kubernetes Public Documentation Portal

Description

Trustnest Managed Kubernetes (k8saas) is a service of the Thales Digital Platform (TDP).

K8saas aims to provide a service to run applications in development and production while minimizing operational costs while respecting high security constraints.

References

Getting Started

First ask for a cluster creation using Thales postit portal. If you are not familiar with this new portal, please let yourself be guided here

Then look at our GETTING STARTED documentation.

tip

You want to use k8saas from example ? --> discover multiple hello worlds projects like using WAF, SSO, persistent storage and more...

Features

Self-Service

FeaturesMaturityDiscoverInnovateIndustrialize
Add service account to your namespaceGA
Add your namespaces with HNSGA
Provide access to your teamGA
Onboarding: ask for further privilegesGA
Setting Grafana AlertingGA
Simplified services for application expositionGA
Stop & Start your AKS clusterEA
Use Gitops to deploy your workloadEA

Observability

FeaturesMaturityDiscoverInnovateIndustrialize
Cluster Monitoring with GrafanaGA
Centralized and dedicated log with Log analyticsGA
Role Base access reportDeprecated

Security

FeaturesMaturityDiscoverInnovateIndustrialize
Automatic AKS Operating System Nodes upgradeDeprecated
Automatic Backup with VeleroGA
BSS helperGA
Enforcing Policies with OPA GatekeeperGA
Managed Network Security GroupsGA
Trusted image registriesGA
Pod to Pod Encryption with LinkerdGA
Web application firewall with ModSecurityGA

Corporate Add-on

FeaturesMaturityDiscoverInnovateIndustrialize
Access to corporate add-on application from RIEGA
Access to corporate add-on application from TNAPGA
Corporate Add-onGA
Exposing your corporate add-on application using Thales private domainGA

Confidential Add-on

FeaturesMaturityDiscoverInnovateIndustrialize
Data encryption with Confidential Addon (by Ciphertrust)EA

Access Management

FeaturesMaturityDiscoverInnovateIndustrialize
Built-in roles base access with Thales identityGA
Built-in SSO for Thales employees (Oauth2)Deprecated
Private application exposition with NginxGA
SSO New Generation with PomeriumGA
TLS Certificate generation with Let's encryptGA
Workload Identity integrationExplorer

Performance

FeaturesMaturityDiscoverInnovateIndustrialize
Available Azure RegionGA
GPU for compute-intensive workloadsExplorer
Prioritize your workloads with priorityClassNameGA
Supported AKS VM typesGA
Azure NAT Gateway Support EA

Storages

FeaturesMaturityDiscoverInnovateIndustrialize
Persist data for your applicationsGA

Cost Optimization

FeaturesMaturityDiscoverInnovateIndustrialize
Cost Optimization FeatureEA
Dynamically scale your workload with KedaExplorer
Estimate and monitor your cloud spending.GA
Scheduled AKS ScalingEA
Use spot InstancesExplorer

Customization

FeaturesMaturityDiscoverInnovateIndustrialize
Additional Windows Node poolEA
Bring your own DNS domainGA
Deploy CustomResourceDefinition,ClusterRole and OperatorsEA

Advanced Observability Stack

FeaturesMaturityDiscoverInnovateIndustrialize
Transversal Observability Stack and Log sinkExplorer

EA:Early Access, GA:General Availability

Tutorial & Learning Section

Access to k8saas

Develop with k8saas

Write a Dockerfile

From Docker to Kubernetes / Use Kubernetes patterns

Use CI/CD with k8saas

Integrate k8saas with other trustnest services

Integrate k8saas with other cloud services

Use Project Pack (explorer)

Professional & Managed Services

Explore k8saas community

How to find out more about k8saas ?

Contribution Guide

Troubleshooting