Skip to main content

Responsibility Assignment Matrix (RACI) - Managed Kubernetes

RACI

Architecture & Infrastructure

ActivityClientCloud Temple
Define the overall architecture of the Kubernetes serviceCRA
Size the Kubernetes service (number of nodes, resources)CRA
Install the Kubernetes service with default configurationIRA
Configure the Kubernetes serviceCRA
Set up the base network for the Kubernetes serviceIRA
Deploy initial configuration for identities and accessCRA
Define scaling and high availability strategyCRA

Project and Business Applications Management

ActivityClientCloud Temple
Create and manage Kubernetes projectsRAI*
Deploy and manage applications in KubernetesRAI*
Configure CI/CD pipelinesRAI*
Manage container images and registriesRAI*

These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Monitoring and Performance

ActivityClientCloud Temple
Monitor Kubernetes service performanceIRA
Monitor application performanceRA
Manage alerts related to the Kubernetes serviceIRA
Manage alerts related to applicationsRA

Infrastructure Maintenance and Updates

ActivityClientCloud Temple
Update Kubernetes/OS serviceCRA
Apply security patches to KubernetesCRA
Update deployed applications (operators*)CRA

*Operator package included in Managed Kube - see sections: Managed Helm Packages

Security

ActivityClientCloud Temple
Manage security for the Kubernetes serviceRARA
Configure and manage pod security policiesRAI*
Manage SSL/TLS certificates for the Kubernetes serviceCRA
Manage SSL/TLS certificates for applicationsRAI*
Implement and manage Role-Based Access Control (RBAC) for base rolesCR
Implement and manage Role-Based Access Control (RBAC) for client rolesRAI*

*These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Backup and Disaster Recovery

ActivityClientCloud Temple
Define the backup strategy for the Kubernetes serviceIRA
Implement and manage backups for the Kubernetes serviceIRA
Define the backup strategy for applicationsRA*I*
Implement and manage backups for applicationsRA*I*
Test disaster recovery procedures for the Kubernetes serviceCIRA
Test disaster recovery procedures for applicationsRA*CI*

*These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Support and Troubleshooting

ActivityClientCloud Temple
Provide level 1 support for infrastructureIRA
Provide level 2 and 3 support for infrastructureIRA
Resolve issues related to the Kubernetes serviceCRA
Resolve issues related to applicationsRAI

Capacity Management and Evolution

ActivityClientCloud Temple
Monitor Kubernetes resource usageCRA
Plan service capacity evolutionRAC
Implement capacity changesIRA
Manage application and resource evolutionRAI

Documentation and Compliance

ActivityClientCloud Temple
Maintain Kubernetes service documentationIRA
Maintain application documentationRAI
Ensure Kubernetes service complianceIRA
Ensure application complianceRAI
Conduct Kubernetes service auditsIRA
Conduct application auditsRAI

Basic Kubernetes Operators/CRDs Management

ActivityClientCloud Temple
Provisioning of default Operators catalogCIRA
Updating OperatorsCIRA
Monitoring Operators statusCIRA
Troubleshooting Operator-related issuesCIRA
Managing Operator permissionsCIRA
Managing Operator resources (addition/removal)CIRA
Backing up Operator resources dataCIRA
Monitoring Operator resourcesCIRA
Restoring Operator resources dataCIRA
Security auditing of OperatorsCIRA
Operator supportCIRA
License management for OperatorsCIRA
Management of specific support plans for OperatorsCIRA

Operator package included in Managed Kube – see sections: Managed Helm Packages

Kubernetes Application/Operator/CRD Management (Business)

ActivityClientCloud Temple
Deployment of CRDsRA*I*
Updating OperatorsRAI
Monitoring Operator statusRAI
Troubleshooting Operator-related issuesRAI
Managing Operator permissionsRAI
Managing Operator resources (addition/removal)RAI
Backing up Operator resource dataRAI
Monitoring Operator resourcesRAI
Restoring Operator resource dataRAI
Security auditing of OperatorsRAI
Supporting OperatorsRAI
License management for OperatorsRAI
Management of specific support plans for OperatorsRAI

These responsibilities may be delegated to Cloud Temple via a complementary managed services contract.

Application Support

ActivityClientCloud Temple
Application Support (external service)RAI

Application support may also be provided as part of a complementary service.

RACI (synthetic)

  • Cloud Temple: responsible and accountable (RA) for the Kubernetes foundation, cluster security, infrastructure backups, and monitoring.
  • Client: responsible and accountable (RA) for application projects, business operators, CI/CD pipelines, and application backups.
  • "Grey zone": adaptations and extensions (IAM, specific operators, cluster compliance/security hardening) — billed on a project basis.