Canarie Installer suitability for Shib "quick start"?
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 27 10:56:41 EST 2017
> I'm writing to get your thoughts about the Canarie Installer. What's good,
> what's "not good," what's missing? Other issues? (Here's a web page. It
> offers a "test drive" of the installer rather than describing it. I haven't tried
> doing the test drive (yet).
I had a good conversation with Chris Phillips about it after running some tests with it myself to get a feel for it, and the feedback I had was that I see it really as consisting of two separate pieces, one of which is something we need to work with more closely and eventually perhaps include, and the other that I think is best left out of our sphere for now.
The front-end GUI is the piece I'm interested in us both being able to leverage, but also (as Rod said) that I think we should try and more formally support by standardizing the property interface between our current installer and that front-end with an eye toward eventually expanding that set of properties and implementing additional features in the installer to take over some of the work that's currently being done by including hardcoded example files in the CANARIE tool.
The part I'm not as comfortable with is the "back-end" of it, which is a set of non-trivial shell scripts that actually provision a VM and install all the software. That's just too limiting in terms of platform for us to maintain all that, and I just don't think that's where our time is best spent. I think we should try and make our installer do more, so that those bits can do less, and then over time we can re-evaluate where that boundary should be.
It may be that eventually we need to dump ant and start fresh with a new installer strategy, but for now that's what we've got, and it works on all platforms, so I think that's the foundation we have to work from.
The other thing CANARIE has is a self-contained test environment that spins up with Vagrant with an IdP, SP, LDAP, and discovery tool. That is very interesting to me, and I can see the value of pointing people to that as a learning tool. In a perfect world I'd like to have something like that ourselves, so it's possible that could happen, but it would mean dedicating some resources to that.
> If the newbie has a non-vanilla LDAP or other "interesting" configuration
> issue, then s/he is not part of the target audience for the "Quick Start"
> installation and "Quick Start" Deployer's Guide.
This is where I will say that this idea that there are a lot of non-vanilla, non-interesting configurations is a fantasy of people who don't know how this stuff works. But it highlights that one of our goals needs to be to make some of the non-vanilla things become vanilla. We need standard ways of doing things, and some of that is just a matter of documentation. Just because there are 10 ways to do something doesn't mean we have to document all 10 equally.
-- Scott
More information about the dev
mailing list