Zum Hauptinhalt springen

Verantwortlichkeitsmatrix (RACI) - Managed Kubernetes

RACI

Architecture & Infrastructure

ActivityClientCloud Temple
Define the overall architecture of the Kubernetes serviceCRA
Size the Kubernetes service (number of nodes, resources)CRA
Install the Kubernetes service with default configurationIRA
Configure the Kubernetes serviceCRA
Set up the base network for the Kubernetes serviceIRA
Deploy initial configuration for identities and accessCRA
Define scaling and high availability strategyCRA

Project and Business Application Management

ActivityClientCloud Temple
Create and manage Kubernetes projectsRAI*
Deploy and manage applications in KubernetesRAI*
Configure CI/CD pipelinesRAI*
Manage container images and registriesRAI*

These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Monitoring and performance

ActivityClientCloud Temple
Monitor Kubernetes service performanceIRA
Monitor application performanceRA
Manage alerts related to the Kubernetes serviceIRA
Manage alerts related to applicationsRA

Infrastructure Maintenance and Updates

ActivityClientCloud Temple
Update Kubernetes/OS serviceCRA
Apply security patches to KubernetesCRA
Update deployed applications (operators*)CRA

*Operator package included in Managed Kube – see sections: Managed Helm Packages

Security

ActivityClientCloud Temple
Manage security for the Kubernetes serviceRARA
Configure and manage pod security policiesRAI*
Manage SSL/TLS certificates for the Kubernetes serviceCRA
Manage SSL/TLS certificates for applicationsRAI*
Implement and manage Role-Based Access Control (RBAC)CR
Implement and manage Client-Based Role-Based Access Control (RBAC)RAI*

*These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Backup and Disaster Recovery

ActivityClientCloud Temple
Define the backup strategy for the Kubernetes serviceIRA
Implement and manage backups for the Kubernetes serviceIRA
Define the backup strategy for applicationsRA*I*
Implement and manage backups for applicationsRA*I*
Test disaster recovery procedures for the Kubernetes serviceCIRA
Test disaster recovery procedures for applicationsRA*CI*

*These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Support and Troubleshooting

ActivityClientCloud Temple
Provide level 1 support for infrastructureIRA
Provide level 2 and 3 support for infrastructureIRA
Resolve issues related to the Kubernetes serviceCRA
Resolve issues related to applicationsRAI

Capacity Management and Evolution

ActivityClientCloud Temple
Monitor Kubernetes resource usageCRA
Plan service capacity evolutionRAC
Implement capacity changesIRA
Manage application and resource evolutionRAI

Documentation and Compliance

ActivityClientCloud Temple
Maintain Kubernetes service documentationIRA
Maintain application documentationRAI
Ensure Kubernetes service complianceIRA
Ensure application complianceRAI
Conduct Kubernetes service auditsIRA
Conduct application auditsRAI

Basic Kubernetes Operators/CRD Management

ActivityClientCloud Temple
Provisioning of default Operator catalogCIRA
Updating OperatorsCIRA
Monitoring Operator statusCIRA
Troubleshooting Operator-related issuesCIRA
Managing Operator permissionsCIRA
Managing Operator resources (addition/removal)CIRA
Backup of Operator resource dataCIRA
Monitoring Operator resourcesCIRA
Restoration of Operator resource dataCIRA
Security auditing of OperatorsCIRA
Operator supportCIRA
License management for OperatorsCIRA
Management of specific support plans for OperatorsCIRA

*Operator package included in Managed Kube – see chapters: Managed Helm Packages

Management of Kubernetes Applications/Operators/CRDs (Business)

ActivityClientCloud Temple
Deployment of CRDsRA*I*
Update of OperatorsRAI
Monitoring of Operator statusRAI
Troubleshooting issues related to OperatorsRAI
Management of Operator permissionsRAI
Management of Operator resources (addition/removal)RAI
Backup of Operator resource dataRAI
Monitoring of Operator resourcesRAI
Restoration of Operator resource dataRAI
Security audit of OperatorsRAI
Support for OperatorsRAI
License management for OperatorsRAI
Management of specific support plans for OperatorsRAI

These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Application Support

ActivityClientCloud Temple
Application Support (external service)RAI

Application support may also be provided as part of an additional service.

RACI (synthetic)

  • Cloud Temple: responsible and accountable (RA) for the Kubernetes foundation, cluster security, infrastructure backups, and monitoring.
  • Client: responsible and accountable (RA) for application projects, business operators, CI/CD pipelines, and application backups.
  • "Gray zone": adaptations and extensions (IAM, specific operators, cluster compliance/security hardening) – billed on a project basis.