Example sequence for deploying a physically separated ingestion and indexing topology with SOK.
The following is the example sequence of installing apps to deploy a new physical separation topology. For details for each step, see Configure physical separation of indexing and ingestion with SOK.
Note: This example uses the workload identity method to configure access to the SQS queue and S3 bucket. This method requires configuring a service account.
- Install Splunk Operator for Kubernetes (SOK).
- Configure a service account.
- Create the
Queue custom resource.
Create the external message queue and dead-letter queue. Then apply the Queue YAML manifest that references them.
- Create the
ObjectStorage custom resource.
Create the S3 bucket and grant the required access to the configured identity or credentials. Then apply the ObjectStorage YAML manifest that references the object-storage location.
The ObjectStorage resource does not create or manage the external bucket.
- Create the
IngestorCluster custom resource.
Apply the IngestorCluster YAML manifest. Configure it to reference the Queue and ObjectStorage resources.
The IngestorCluster receives and processes incoming data and publishes the processed data through SmartBus.
- Integrate the separate indexer cluster.
Configure the separate indexer cluster to retrieve processed data through the same SmartBus queue and object-storage location referenced by the IngestorCluster.
The separate indexer cluster is not managed by SOK.
- Optionally configure a Kubernetes HorizontalPodAutoscaler (HPA).
Configure the HPA to adjust the number of IngestorCluster replicas according to ingestion demand. See Scaling the ingestion tier with HPA.
Note:
The HPA is managed separately by the customer.