Jellyfish Installer (Cogito Software Orchestrator)
What is the Jellyfish Installer?
Jellyfish runs as a set of services, and each version has compatibility requirements. The Jellyfish Installer, also called the Cogito Software Orchestrator, is a semi-autonomous installer and update tool designed to help operators deploy and connect those services on Docker, Kubernetes or a similar container platform. It installs the services, and updates them when your operators choose a new release.
The same tool deploys anything from a single-host trial to a production service across two datacentres and a witness site. Your operators use it through a web portal, and your automation can use its API.
Benefits of Using the Jellyfish Installer
- Brings your PKI online from a standing start – where no PKI exists yet, the Installer can run a minimal bootstrap PKI so it can deploy Jellyfish. The bootstrap PKI uses self-signed certificates and is not for production. Once Jellyfish is running, your team must replace those certificates with ones from your production PKI.
- Works with your automation – the Installer runs as an API server, and its web portal gives access to all of the API’s functions. Automation and monitoring tools can use the same API. Agent skills, available on request, give an AI agent the context to work through that API, and Cogito Group recommends them for deploying and testing in a lab or CI/CD environment.
- Consistent updates – every Jellyfish release includes a manifest of the services it needs. Cogito Group built the update process to work only from a release manifest, so your services deploy as a consistent working set.
- Clustered deployments for high availability – clustering gives Jellyfish high availability and failover. A Mono-Cluster keeps serving with half its services down. A Trio-Cluster stays reliable through a maintenance window and keeps high availability if you lose a datacentre.
- Release-based updates and downgrades – your operators choose a target release on the Update page and install it. If they choose an older release, the page shows that a downgrade is about to run. A quick update runs database migration scripts, so your team should plan how to switch the active database leader and roll the database back.
- Works in restricted networks – a mirror Installer that manages no deployment of its own, typically in a DMZ, can proxy and cache the Cogito Group image registry, so other deployments get the latest Jellyfish services without direct exposure to the internet. For an offline site, operators upload the latest Jellyfish images to one Installer and the others use it as their source.
- Lab and QA environments on one host – Encapsulation mode lets several Jellyfish deployments share one host. Isolation mode stops a sandbox sharing services or data with any other deployment.
How Does It Help Your Operators Maintain Jellyfish?
Your operators install, update and check the health of Jellyfish containers from the Installer’s web portal. To install, they choose a release and click Bootstrap. The Installer queues the installation jobs, and the Queue page shows their progress. To update, they choose a target release and click Install in the Quick Update menu, or update or downgrade individual services within a release.
The Deployment page lists the deployed containers and their status, so operators can check that each one is healthy and not flapping between offline and healthy. Remote Control lists the Installers in the same local cluster and opens any other one through the one the operator is using, so they do not need a separate portal open for each.
Operators build clusters from the Installer’s Consul page or its API, which Cogito Group recommends over configuring cluster agents by hand. Connecting the Installer to the Cogito Group registry is the easiest way to keep deployments up to date, and its built-in registry can pass those images on to other Installers and machines in your environment. When the Installer runs as a container, operators update it by replacing the container with one from the newer image. The Installer keeps its persistent data in its assets directory and orchestrator.json, so removing the old container does not destroy it.
How Does the Jellyfish Installer Work?
The Installer runs as a server with its own web portal and API. When an operator chooses a Jellyfish release, the Installer reads that release’s manifest and deploys the listed services as containers, provided their images are available. The images can come from the Cogito Group registry, from another Installer acting as a mirror, or from images your team downloads from the Jellyfish Cloud and loads into the Installer.
For a Mono-Cluster or Trio-Cluster, your operators use the Installer’s Consul page or its API to join the deployments into clusters. Services on one node can then use services on another, and the Jellyfish database replicates across the cluster’s database nodes.
Which Deployment Is Right for You?
The Installer builds three deployment architectures. Cogito Group recommends the Trio-Cluster for production. The other two suit labs, QA, testing, development, sandboxing and automation.
Architecture | What you get | Suited to |
|---|---|---|
All-in-One | Every core Jellyfish service, plus any optional services, on one Docker host under one Installer. The simplest deployment, with no clustering, high availability or failover. | Trials, demos and labs |
Mono-Cluster | Two deployments of the same services joined in one cluster, and the database replicates between them. Half the services can be down without interrupting service, and the cluster supports blue-green deployment. | Trialling high availability |
Trio-Cluster | A two-node cluster running the Jellyfish services in each of two datacentres, and a database cluster with two nodes in each datacentre plus a witness at a third site. The witness acts as the tie-breaker for all three clusters. The service keeps high availability if you lose a datacentre, or if you lose a server to a hardware fault when each node of those two-node clusters runs on its own physical server. | Production |
[Insert image: jellyfish-installer-trio-cluster.png]
Figure 1: A Trio-Cluster across two datacentres and a witness site
Your team can also zone a Trio-Cluster. Zoning places services on specific hosts, with firewalls between them that restrict end users to the outward-facing Jellyfish services. Zoning adds deployments and Docker hosts, which makes it expensive, so it is worth considering only when the deployment faces the public internet or you want to reduce the security footprint of services that face the wider organisation.
How Do I Get Started?
The Installer comes in four forms: a portable release, a Docker image, an RPM package for Red Hat Enterprise Linux and a Linux binary. For most users, Cogito Group recommends running the Installer with the Docker Compose file supplied in the portable release. The portable release comes pre-configured for training, labs and testing. For production, Cogito Group suggests designing your own compose file or compose override file, and recommends enabling Encapsulation mode for most production deployments.
The RPM package comes with a public key file so your team can validate the package signature. Cogito Group does not recommend the raw Linux binary, as it is the least flexible and most complex way to deploy.
The Installer needs access to the Jellyfish images. They come from the Cogito Group registry, which Security Services Support can give you access to, from another Installer with access to the images, or from a bundle of image tarballs your team loads into the Installer’s internal registry. Bundles are available from the Docker Image Download page in your Jellyfish Cloud deployment, such as SecureSME, Stingray or NZTaaS.
Your operators will find installation, clustering and update guidance in the Jellyfish Installer user guide. The guide does not cover Kubernetes, although Cogito Group says its instructions are directly relevant to a Kubernetes deployment. Contact Cogito Group Security Services Support for details on accessing the Installer and the Jellyfish images.
About Cogito Group
Cogito Group is an award-winning, Australian owned and operated ICT company, specialising in authentication, cloud security, identity management and data protection. Cogito Group protect the authentication methods used to access information using Identity and other security technologies. Cogito Group protect data not only from unauthorised access and disclosure, but also from being altered by an unauthorised third party or a trusted insider with malicious intent. This assists in the detection and prevention of fraud or other malicious activities by third parties or trusted insiders.