14 karma · joined September 17, 2014
For baking the machine, we use Ansible under the covers and have a set of Lisp scripts to manage everything. As for image formats: qcow2, raw, vhd (and vmdk in the .ova file).
Not trying to hijack Gravitational's thread, please contact me (email in profile, or 'aw-' on FreeNode) if you want to discuss more.
I recommend running the webhooks (external service) as an entirely different application from your internal services. If it's a nodejs app, and your main internal app is nodejs, then you'll need to run 2 nodejs processes (and not as root).
Also if you can, try running the webhooks service on an entirely different machine (vm?) - and have it talk to Jenkins through the network (ex: as others have suggested with a message queue or API call).
If you're filtering by IP (might be troublesome if GitHub's IP range changes), most of the above will be overkill.
Edit: to answer your last question: security is a process, whether it's full-time or not depends on how much you care. Edit 2: fix typo
Ex-GitHubber specializing in infrastructure design, automation, disaster recovery, capacity planning, and scalability.
I'm not interested in AWS or other cloud platforms, since I prefer working with bare-metal and VM deployments, switches, routers, and hardware appliances.
Tech stack: Linux/BSD, PicoLisp, Ansible, Cisco, *SQL, Redis, HAProxy, Nginx, Lua...
Contact:
GitHub: https://github.com/aw
Email: alexwilliamsca at gmail dot com
Website: http://alexwilliams.ca
Business: https://unscramble.co.jp
I'm always open to interesting projects, so let's talk!
I think ReadMe's approach is pretty good, and I applaud them for making the move.
Our aim is a bit different from others, as we focus exclusively on "actual" on-premises (local virtual machines), as opposed to "on someone else's premises" (AWS).
[1] http://blog.unscramble.co.jp/post/128610241043/production-re...