Skip to content

docs(variants): document the slim platform variants - #718

Open
Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
mainfrom
docs/slim-variants
Open

Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
mainfrom
docs/slim-variants

Conversation

@lexfrei

Copy link
Copy Markdown
Contributor

This documents the three slim platform variants added in cozystack/cozystack#4595: isp-slim, isp-slim-generic and isp-hosted-slim.

The variants page gets them in the comparison table and one section each. It also explains the Cilium load balancer setup that replaces MetalLB there, and has a table of which packages to add to bundles.enabledPackages to bring back applications, monitoring, etcd, SeaweedFS and backups. The platform package, generic install, distribution and Ansible pages list the new names.

Only docs/next is touched, since the variants are not in a release yet.

@netlify

netlify Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for cozystack ready!

Name Link
🔨 Latest commit 25bfd46
🔍 Latest deploy log https://app.netlify.com/projects/cozystack/deploys/6abc540dd869fa00083453a2
😎 Deploy Preview https://deploy-preview-718--cozystack.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e03809c9-738a-4ca2-9a19-58b42ec01cea


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Describe the minimal platform variants, what they install, and which
packages to add to bundles.enabledPackages to bring back applications,
monitoring, etcd, SeaweedFS and backups on top of them.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>

@IvanHunters IvanHunters left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review: #718

VERDICT: approve | Head SHA: 25bfd46ede2de0efe0d8b59fb37937ec799bae46


Review Summary

PR: cozystack/website#718 | Title: docs(variants): document the slim platform variants | Author: lexfrei | Scope: +125/-27 lines across 5 files | Type: Documentation only (docs/next) | Revision: 25bfd46


Findings

Clear: Content Accuracy and Structure

All three slim variants (isp-slim, isp-slim-generic, isp-hosted-slim) are documented consistently across 5 documentation files: (1) ansible.md—variant list with -generic clarification for k3s; (2) kubernetes-distribution.md—variant prompt updated to 1-7; (3) generic.md—isp-slim-generic references with CNI notes; (4) platform-package.md—variants, networking parameters, gateway config updated; (5) variants.md—table expansion with new sections.

YAML examples validated: Cilium load balancer pool config (lines 210-221) valid; Platform Package example (lines 225-239) syntactically correct; isp-slim-generic correctly inherits from generic.md.

Link references correct: Table links at 153-155 reference all three slim variants; sections exist at 163 (isp-slim), 213 (isp-slim-generic), 217 (isp-hosted-slim).

Feature table accurate: Expanded from 4 to 7 columns; opt-in status correct for Managed Applications, Operators, Monitoring, Backups on slim variants; Storage/Networking/Virtualization columns reflect slim capabilities (Cilium alone, no Kube-OVN, no KubeVirt); "Backups" row separated from monitoring (good clarification).

Technical accuracy verified: Networking Cilium-only without Kube-OVN; pod CIDR from nodes not cluster parameters; networking.encryption.enabled unsupported with render failure noted; warning against switching existing clusters to slim (line 252) correctly placed.

Clear: Gateway Configuration Updates

The gateway.http2 description (line 107) correctly extends "Cozystack manages Cilium" from (isp-full, isp-full-generic) to (isp-full, isp-full-generic, isp-slim, isp-slim-generic) because isp-hosted/isp-hosted-slim use host Cilium while slim variants do manage Cilium.

Clear: Package Dependency Table

Lines 241-250 map components to packages for slim variants: application pattern (app + operator) correct; monitoring lists all dependencies; backups complete; special notes for Harbor (SeaweedFS) and Valkey (redis-operator); Multus and MetalLB correctly unavailable on isp-hosted-slim.

Clear: Generic Kubernetes Guide Updates

generic.md additions are correct: line 43 adds isp-slim-generic reference with link; line 52 clarifies Cilium-only vs. Kube-OVN+Cilium; line 61 notes pod CIDR still needed but works differently.


Issues

No critical issues found. All content is factually accurate, properly structured, and internally consistent.


Observations

Strengths: (1) Comprehensive slim variant documentation with clear use cases; (2) Consistent variant naming across 5 files; (3) Well-structured component/package dependency table; (4) Warning about cluster migration included; (5) Valid YAML examples; (6) Proper inter-section linking.


Recommendation

Status: APPROVE

This PR documents three new platform variants from cozystack/cozystack#4595 with accurate, complete, well-organized content providing clear deployment guidance, architecture differences, component enabling, and migration warnings. No revisions needed.


Files Reviewed

  • content/en/docs/next/install/ansible.md — Variant parameter documentation ✓
  • content/en/docs/next/install/cozystack/kubernetes-distribution.md — Variant selection prompt ✓
  • content/en/docs/next/install/kubernetes/generic.md — Generic Kubernetes guide ✓
  • content/en/docs/next/operations/configuration/platform-package.md — Platform configuration ✓
  • content/en/docs/next/operations/configuration/variants.md — Variants reference ✓

Review completed: 2026-10-01 | Reviewer: Primary Agent (Haiku) | Model: claude-haiku-4-5-20251001

Aleksei Sviridkin (lexfrei) added a commit to cozystack/cozystack that referenced this pull request Oct 1, 2026
## What this PR does

This adds three minimal platform variants for small installs, such as
arm64 labs, where isp-full is too heavy. They are `isp-slim` for Talos,
`isp-slim-generic` for k3s, kubeadm or RKE2, and `isp-hosted-slim` for
clusters where the host provides CNI and storage.

A slim variant installs only the base platform: the engine, API and
dashboard, tenants, ingress and Gateway API. The two non-hosted variants
also get LINSTOR. objectstorage-controller stays on too, because
cozystack-controller watches BucketClaim unconditionally and crash-loops
without that CRD. Everything else is opt-in through
`bundles.enabledPackages`, including every paas and naas application and
its operator, monitoring, backups, etcd, SeaweedFS, metrics-server, VPA,
Multus and MetalLB. The iaas bundle is refused, so there are no VMs and
no managed Kubernetes. With the stock preset a slim variant emits 20
Packages (15 for hosted), where isp-full emits 77.

On the two non-hosted slim variants, networking is Cilium alone. Without
VMs nothing needs Kube-OVN, and Cilium L2 announcements take the place
of MetalLB. The admin creates a `CiliumLoadBalancerIPPool` and a
`CiliumL2AnnouncementPolicy`, or uses `publishing.externalIPs`. Pod
ranges come from `node.spec.podCIDR`, which Talos and k3s allocate by
default. `networking.encryption` only drives Kube-OVN IPsec, so the slim
variants refuse it instead of silently ignoring it.

The tenant application needs its own slim variant. The default one waits
on the monitoring, etcd and SeaweedFS applications, so on slim
cozystack-basics and tenant-root would never become ready. tenant-rd and
cozystack-basics still reference the default variant's artifacts by
name. Those artifacts exist anyway, because the PackageSource builds
them for every variant.

The full variants don't change. I rendered isp-full, isp-full-generic
and isp-hosted against main and got byte-identical Packages. The only
new output there is the slim variant in the tenant-application
PackageSource.

Things to know before using it:

- An opt-in package does not pull in its dependencies. The presets and
the docs list the chains. A package enabled without its chain stays
`DependenciesNotReady`.
- Slim is for new installs. Switching a live isp-full cluster to
isp-slim moves the networking Package from `kubeovn-cilium` to `cilium`,
the operator removes the Kube-OVN release, and running pods lose
networking. The other Packages are kept by `helm.sh/resource-policy:
keep`, so the switch doesn't make the cluster smaller either.
- No e2e suite runs a slim variant yet. Helm unit tests cover the
presets, opt-in, OIDC, the networking values and both refusals, and a
dependency check over every emitted Package passes for all three
presets.

I installed isp-slim from a build of this branch on a fresh three-node
Talos 1.13 cluster (amd64). All Packages and HelmReleases went Ready,
with no Kube-OVN, MetalLB, monitoring, backup or KubeVirt pods. From
outside, the dashboard and the API answered by name with valid
certificates. A LoadBalancer Service got an address from a Cilium pool
and answered through L2 announcements. Pod-to-pod traffic across nodes,
cluster DNS and a replicated LINSTOR volume worked. Opting in
postgres-operator and postgres-application gave a Ready Postgres. That
run found the BucketClaim crash-loop above, which is fixed here. The
base platform used about 215m CPU and 3.2 GiB of memory, not counting
the Kubernetes control plane.

### Screenshots

Not a UI change.

### Downstream repositories

- [ ] No downstream repository is affected by this change
- [x] [cozystack/website](https://github.com/cozystack/website) -
follow-up: cozystack/website#718
- [ ]
[cozystack/terraform-provider-cozystack](https://github.com/cozystack/terraform-provider-cozystack)
- follow-up:
- [x]
[cozystack/ansible-cozystack](https://github.com/cozystack/ansible-cozystack)
- follow-up: cozystack/ansible-cozystack#79
- [x] [cozystack/ccp](https://github.com/cozystack/ccp) - follow-up:
cozystack/ccp#23
- [ ] [cozystack/talm](https://github.com/cozystack/talm) - follow-up:
- [ ] [cozystack/cozyhr](https://github.com/cozystack/cozyhr) -
follow-up:
- [ ] [cozystack/cozy-proxy](https://github.com/cozystack/cozy-proxy) -
follow-up:
- [ ]
[cozystack/cozystack-telemetry-server](https://github.com/cozystack/cozystack-telemetry-server)
- follow-up:
- [ ]
[cozystack/external-apps-example](https://github.com/cozystack/external-apps-example)
- follow-up:
- [ ] [cozystack/examples](https://github.com/cozystack/examples) -
follow-up:
- [ ] [cozystack/community](https://github.com/cozystack/community) -
follow-up:

### Release note

```release-note
feat(platform): add the isp-slim, isp-slim-generic and isp-hosted-slim variants. They install only the base platform (engine, dashboard, tenants, ingress, gateway, and LINSTOR outside hosted) with Cilium-only networking and no MetalLB; applications, operators, monitoring, backups, etcd and SeaweedFS are opt-in through bundles.enabledPackages, and the iaas bundle is not available.
```


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added the `isp-slim`, `isp-slim-generic`, and `isp-hosted-slim`
platform variants, with support for PaaS and NaaS bundles.
* Slim variants use Cilium networking and include a reduced set of
packages by default. Additional packages and their dependencies can be
enabled as needed.
* **Limitations**
* IaaS and the platform encryption toggle are not supported on slim
variants. Cilium-native encryption is not configured.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants