By combining OpenStack with open source cloud technologies, ITU, dNation, and Vanilla Core created a sovereign platform that keeps public sector infrastructure open, portable, and under operator control

image

International Telecommunication Union (ITU) is United Nations specialized agency for digital technologies. Together with dNation and Vanilla Core they built Sovereign Cloud hosting GovStack application (public sector digitalization software) for multiple tenants.

Architecture

Requirements

ITU was looking for a solution matching following requirements:

  1. No Vendor Lock-in
  2. Infrastructure as a Service (IaaS) and Kubernetes as a Service (KaaS)
  3. Strong isolation of environments (tenants)
  4. GovStack Application
  5. Ability to run AI workloads

Addressing Requirements: No Vendor Lock-in, IaaS, Strong Isolation

To address no vendor lock-in, IaaS and strong isolation requirements, OpenStack by OpenInfra has been chosen as the cornerstone of whole solution.

OpenStack provides:

  • True sovereignty without any vendor lock-in, all sourced code is available under Apache 2.0 license
  • IaaS
  • Ability to transparently handle hardware and network failures
  • Isolation between workloads, including network traffic

Yaook distribution of OpenStack has been used for seamless installation and operations. Yaook has been developed by ALASCA (Association for Operational, Open Cloud Infrastructures e.V.) non-profit consortium.

Sovereign Cloud Stack (SCS) non-profit is a European initiative that creates an open, transparent and vendor-neutral cloud ecosystem. Part of its activities covered by Forum SCS-Standards are to define, document and develop standards and certifications to ensure expected level of quality of sovereign clusters. Yaook is the SCS certified solution.

Yaook runs OpenStack containerized within Kubernetes running on bare metal nodes:

Yaook’s architecture allows:

  • Automatically transfer a set of bare metal machines to an operational OpenStack cluster
  • Release management – all OpenStack components are tested together and then atomically released as a single package using standard Kubernetes deploy mechanisms

ALASCA Arko is a standardized platform for efficient monitoring of hybrid cloud infrastructures. We are using it for constant cluster monitoring, alerting and supporting Day 2 operations.

Arko follows these design principles:

  • Intuitive: Green, orange and red colors signaling whether your action is needed
  • Relevant information only: Provides only metrics relevant for area of interest
  • Hierarchical (drill-down): Details needed? Just click on it.

Addressing Requirements: KaaS

VanillaStack has been used to meet KaaS requirement. It follows these basic principles:

Addressing Requirements: GovStack

GovStack is a toolkit for the digitalization of public sector infrastructure so everyone can access government services using trusted digital technologies that fit their lives and needs.

Deployed Sovereign Cluster hosts multiple tenants, each of them running their own instance of GovStack, utilizing OpenStack’s built-in separation capabilities.

Addressing Requirements: AI workloads

Deployed Sovereign Cluster contains nodes with GPUs as well. To run AI workload with full performance, VMs have direct access to GPU (via PCI Passthrough).

If you have any questions

Do not hesitate to contact us: