Skip to main content

Responsibility Matrix (RACI) - Managed Kubernetes

RACI

Architecture & Infrastructure

ActivityClientCloud Temple
Define the overall Kubernetes service architectureCRA
Size the Kubernetes service (number of nodes, resources)CRA
Install the Kubernetes service with a default configurationIRA
Configure the Kubernetes serviceCRA
Configure the base network of the Kubernetes serviceIRA
Deploy the initial identity and access configurationCRA
Define the scaling and high availability strategyCRA

Project and Business Application Management

ActivityClientCloud Temple
Create and manage Kubernetes projectsRAI*
Deploy and manage applications in KubernetesRAI*
Configure CI/CD pipelinesRAI*
Manage container images and registriesRAI*

*These responsibilities can be delegated to Cloud Temple through an additional managed services contract.

Monitoring and Performance

ActivityClientCloud Temple
Monitor Kubernetes service performanceIRA
Monitor application performanceRA
Manage Kubernetes service alertsIRA
Manage application alertsRA

Infrastructure Maintenance and Updates

ActivityClientCloud Temple
Update Kubernetes/OS serviceCRA
Apply security patches to KubernetesCRA
Update deployed applications (operators*)CRA

*Operator package included on Managed Kube - see chapters: Managed Helm Packages

Security

ActivityClientCloud Temple
Manage Kubernetes service securityRARA
Configure and manage pod security policiesRAI*
Manage SSL/TLS certificates for the Kubernetes serviceCRA
Manage SSL/TLS certificates for applicationsRAI*
Implement and manage basic role-based access control (RBAC)CR
Implement and manage client role-based access control (RBAC)RAI*

*These responsibilities can be delegated to Cloud Temple via an additional managed services contract.

Backup and Disaster Recovery

ActivityClientCloud Temple
Define the backup strategy for the Kubernetes serviceIRA
Implement and manage backups for the Kubernetes serviceIRA
Define the backup strategy for applicationsRA*I*
Implement and manage backups for applicationsRA*I*
Test disaster recovery procedures for the Kubernetes serviceCIRA
Test disaster recovery procedures for applicationsRA*CI*

*These responsibilities can be delegated to Cloud Temple via a supplementary managed services contract.

Support and Issue Resolution

ActivityClientCloud Temple
Provide Level 1 support for infrastructureIRA
Provide Level 2 and Level 3 support for infrastructureIRA
Resolve Kubernetes service issuesCRA
Resolve application issuesRAI

Capacity Management and Evolution

ActivityClientCloud Temple
Monitor Kubernetes resource usageCRA
Plan service capacity evolutionRAC
Implement capacity changesIRA
Manage application and resource evolutionRAI

Documentation and Compliance

ActivityClientCloud Temple
Maintain Kubernetes service documentationIRA
Maintain application documentationRAI
Ensure Kubernetes service complianceIRA
Ensure application complianceRAI
Conduct Kubernetes service auditsIRA
Conduct application auditsRAI

Basic Kubernetes Operators/CRDs Management

ActivityClientCloud Temple
Provisioning of the default Operator catalogCIRA
Operator updatesCIRA
Monitoring Operator statusCIRA
Operator issue resolutionCIRA
Operator permissions managementCIRA
Operator resource management (add/remove)CIRA
Backup of Operator resource dataCIRA
Operator resource monitoringCIRA
Restoration of Operator resource dataCIRA
Operator security auditCIRA
Operator supportCIRA
Operator license managementCIRA
Management of specific support plans for operatorsCIRA

*Operator package included on Managed Kube - see chapters: Managed Helm Packages

Management of Kubernetes applications/operators/CRDs (business)

ActivityClientCloud Temple
Deployment of CRDsRA*I*
Operator updatesRAI
Operator status monitoringRAI
Operator issue resolutionRAI
Operator permissions managementRAI
Operator resource management (add/remove)RAI
Backup of Operator resource dataRAI
Operator resource supervisionRAI
Restoration of Operator resource dataRAI
Operator security auditRAI
Operator supportRAI
Operator license managementRAI
Management of specific operator support plansRAI

*These responsibilities can be delegated to Cloud Temple via an additional managed services contract.

Application Support

ActivityClientCloud Temple
Application support (external service)RAI

Application support can also be provided as part of an additional service.

RACI (summary)

  • Cloud Temple: responsible and executor (RA) of the Kubernetes platform, cluster security, infrastructure backup, monitoring.
  • Client: responsible and executor (RA) of application projects, business operators, CI/CD pipelines, application backups.
  • "Grey" area: adaptations and extensions (IAM, specific operators, cluster compliance/security hardening) - billed on a project basis.