Setting up Vespa Cloud Enclave requires:
Register at Vespa Cloud or use an existing tenant. Note that the tenant must be on a paid plan.
One account can host all your Vespa applications, there is no need for multiple tenants or accounts.
The AWS account you intend to use for Vespa Cloud Enclave must be prepared for deploying Vespa applications using either Terraform or Cloudformation.
Use Terraform to set up the necessary resources using the modules published by the Vespa team.
Start with the Terraform examples that match your deployment:
dev zone.test and staging zones, and several production zones.Set tenant_name to your Vespa Cloud tenant and configure the AWS providers for the regions you will use.
Include a zone module for each Vespa Cloud zone you will deploy to, including test and staging for the deployment pipeline.
For a multi-AZ production zone such as prod.aws-us-east-1, use
modules/zone_multi_az.
Use modules/zone for single-AZ zones.
The multi-AZ module always provisions networking in the AZs used by Vespa Cloud's configuration servers.
Set azs to any additional AWS AZ IDs your applications need, such as use1-az1.
Set primary_zone_az to one of the provisioned AZ IDs and keep it unchanged after applying Terraform;
changing it forces VPC replacement.
If you are unfamiliar with Terraform: It is a tool to manage resources and their configuration in various cloud providers, like AWS and GCP. Terraform has published an AWS tutorial, and we strongly encourage enclave users to read and follow the Terraform recommendations for CI/CD.
The Terraform module we provide is regularly updated to add new required resources or extra permissions for Vespa Cloud to automate the operations of your applications. In order for your enclave applications to use the new features you must re-apply your terraform templates with the latest release. The notification system will let you know when a new release is available.
Once the AWS account is configured, contact support@vespa.ai stating which tenant should be on-boarded to use Vespa Cloud Enclave. Also include the AWS account ID to associate with the tenant.
By default, all applications are deployed on resources in Vespa Cloud accounts. To deploy in your enclave account, update deployment.xml to reference the AWS account you onboarded:
<deployment version="1.0" cloud-account="aws:123456789012">
<dev />
</deployment>
Useful resources are getting started and migrating to Vespa Cloud - put deployment.xml next to services.xml.
After a successful deployment to the dev environment, iterate on the configuration to implement your application on Vespa. The dev environment is ideal for this, with rapid deployment cycles.
For production serving, deploy to the prod environment - follow the steps in production deployment.
For a multi-AZ deployment, select the production region and its
availability-zone elements in deployment.xml.
Each selected AZ must have networking provisioned by the Terraform zone module.
To tear down a Vespa Cloud Enclave system, do the steps above in reverse order:
It is important to undeploy the Vespa application(s) first. There will be a delay between when the application is deleted and all its supporting cloud resources are removed. After running the Terraform, Vespa Cloud cannot manage the resources allocated, so you must clean up these yourself.