Role in the deployment¶
Internet2 Grouper manages the groups CyVerse authorizes against — the DE reads group membership through it rather than querying LDAP directly. Two deployments make it up:
| Deployment | Job |
|---|---|
grouper-loader |
Syncs subjects and groups from the directory on a schedule |
grouper-ws |
Web services the DE queries at request time |
Prerequisites¶
- Grouper database created.
- OpenLDAP running, with the
ou=Groupsbranch populated. - The
Groupersection of the deployment group variables filled in — loader URI and credentials, web service password, morph string, folder name prefix, and subject source configuration. See cluster resources.
Deploy¶
Ansible deploys both parts along with the other core services:
ansible-playbook -i /path/to/inventory \
--tags=feature-discovery,image-cache,grouper kubernetes.yml
To apply the manifests directly instead — from the cluster resources checkout, substituting the namespace the DE runs in:
kubectl apply -f resources/deployments/grouper-loader.yml -n <NAMESPACE>
kubectl apply -f resources/deployments/grouper-ws.yml -n <NAMESPACE>
Verify¶
kubectl -n <NAMESPACE> get pods -l app=grouper-ws
kubectl -n <NAMESPACE> logs deploy/grouper-loader --tail=100
The loader logs each sync. A loader that starts and then idles without syncing usually cannot reach either the database or the directory; check both before looking at Grouper's own configuration.