Skip to content

Commit e67b022

Browse files
Merge branch 'main' into feat/update-k8s-eol-data
2 parents 29d4800 + 0cccea1 commit e67b022

12 files changed

+699
-181
lines changed

Standards/scs-0114-v1-volume-type-standard.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
2-
title: Volume Type Standard
2+
title: SCS Volume Types
33
type: Standard
4-
status: Draft
5-
track: IaaS
4+
status: Stable
5+
stabilized_at: 2024-11-13
6+
track: IaaS
67
---
78

89
## Introduction

Standards/scs-0115-v1-default-rules-for-security-groups.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
title: Default Rules for Security Groups
33
type: Standard
4-
status: Draft
4+
status: Stable
5+
stabilized_at: 2024-11-13
56
track: IaaS
67
---
78

Standards/scs-0116-v1-key-manager-standard.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
2-
title: Key Manager Standard
2+
title: SCS Key Manager Standard
33
type: Standard
4-
status: Draft
4+
status: Stable
5+
stabilized_at: 2024-11-13
56
track: IaaS
67
---
78

Standards/scs-0117-v1-volume-backup-service.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
title: Volume Backup Functionality
33
type: Standard
4-
status: Draft
4+
status: Stable
5+
stabilized_at: 2024-11-13
56
track: IaaS
67
---
78

Standards/scs-0121-v1-Availability-Zones-Standard.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
2-
title: Availability Zones Standard
2+
title: SCS Availability Zones
33
type: Standard
4-
status: Draft
4+
status: Stable
5+
stabilized_at: 2024-11-13
56
track: IaaS
67
---
78

Standards/scs-0121-w1-Availability-Zones-Standard.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: "SCS Availability Zone Standard: Implementation and Testing Notes"
2+
title: "SCS Availability Zones: Implementation and Testing Notes"
33
type: Supplement
44
track: IaaS
55
status: Draft

Drafts/node-to-node-encryption.md renamed to Standards/scs-0122-v1-node-to-node-encryption.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: _End-to-End Encryption between Customer Workloads_
33
type: Decision Record
4-
status: Proposal
4+
status: Draft
55
track: IaaS
66
---
77

Lines changed: 82 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,82 @@
1+
---
2+
title: Mandatory and Supported IaaS Services
3+
type: Standard
4+
status: Draft
5+
track: IaaS
6+
---
7+
8+
## Introduction
9+
10+
To be SCS-compliant a Cloud Service Provider (CSP) has to fulfill all SCS standards.
11+
Some of those standards are broad and consider all APIs of all services on the IaaS-Layer like the consideration of a [role standard](https://github.com/SovereignCloudStack/issues/issues/396).
12+
There exist many services on that layer and for a first step they need to be limited to have a clear scope for the standards and the Cloud Service Providers following them.
13+
For this purpose, this standard will establish lists for mandatory services whose APIs have to be present in a SCS cloud as well as supported services, which APIs are considered by some standards and may even be tested for their integration but are optional in a sense that their omission will not violate SCS conformance.
14+
15+
## Motivation
16+
17+
There are many OpenStack APIs and their corresponding services that can be deployed on the IaaS level.
18+
These services have differences in the quality of their implementation and liveness and some of them may be easily omitted when creating an IaaS deployment.
19+
To fulfill all SCS-provided standards only a subset of these APIs are required.
20+
Some more but not all remaining OpenStack APIs are also supported additionally by the SCS project and may be part of its reference implementation.
21+
This results in different levels of support for specific services.
22+
This document will give readers insight about how the SCS classifies the OpenStack APIs accordingly.
23+
If a cloud provides all mandatory and any number of supported OpenStack APIs, it can be tested for SCS-compliance.
24+
Any unsupported APIs will not be tested.
25+
26+
## Mandatory IaaS APIs
27+
28+
The following IaaS APIs MUST be present in SCS-compliant IaaS deployments and could be implemented with the corresponding OpenStack services:
29+
30+
| Mandatory API | corresponding OpenStack Service | description |
31+
|-----|-----|-----|
32+
| **block-storage** | Cinder | Block Storage service |
33+
| **compute** | Nova | Compute service |
34+
| **identity** | Keystone | Identity service |
35+
| **image** | Glance | Image service |
36+
| **load-balancer** | Octavia | Load-balancer service |
37+
| **network** | Neutron | Networking service |
38+
| **s3** | S3 API object storage | Object Storage service |
39+
40+
:::caution
41+
42+
S3 API implementations may differ in certain offered features.
43+
CSPs must publicly describe, which implementation they use in their deployment.
44+
Users should always research whether a needed feature is supported in the offered implementation.
45+
46+
:::
47+
48+
The endpoints of services MUST be findable through the `catalog list` of the identity API[^1].
49+
50+
[^1]: [Integrate into the service catalog of Keystone](https://docs.openstack.org/keystone/latest/contributor/service-catalog.html)
51+
52+
## Supported IaaS APIs
53+
54+
The following IaaS APIs MAY be present in SCS-compliant IaaS deployment, e.g. implemented thorugh the corresponding OpenStack services, and are considered in the SCS standards.
55+
56+
| Supported API | corresponding OpenStack Service | description |
57+
|-----|-----|-----|
58+
| **bare-metal** | Ironic | Bare Metal provisioning service |
59+
| **billing** | Cloudkitty | Rating/Billing service |
60+
| **dns** | Designate | DNS service |
61+
| **ha** | Masakari | Instances High Availability service |
62+
| **key-manager** | Barbican | Key Manager service |
63+
| **object-store** | Swift | Object Store with different possible backends |
64+
| **orchestration** | Heat | Orchestration service |
65+
| **shared-file-systems** | Manila | Shared File Systems service |
66+
| **telemetry** | Ceilometer | Telemetry service |
67+
| **time-series-databse** | Gnocchi | Time Series Database service |
68+
69+
## Unsupported IaaS APIs
70+
71+
All other OpenStack services, whose APIs are not mentioned in the mandatory or supported lists will not be tested for their compatibility and conformance in SCS clouds by the SCS community.
72+
Those services MAY be integrated into IaaS deployments by a Cloud Service Provider on their own responsibility but the SCS will not assume they are present and potential issues that occur during deployment or usage have to be handled by the CSP on their own accord.
73+
The SCS standard offers no guarantees for compatibility or reliability of services categorized as unsupported.
74+
75+
## Related Documents
76+
77+
[The OpenStack Services](https://www.openstack.org/software/)
78+
79+
## Conformance Tests
80+
81+
The presence of the mandatory OpenStack APIs will be tested in [this test-script](https://github.com/SovereignCloudStack/standards/blob/mandatory-and-supported-IaaS-services/Tests/iaas/mandatory-services/mandatory-iaas-services.py).
82+
The test will further check, whether the object store endpoint is compatible to s3.

0 commit comments

Comments
 (0)