Skip to content

Repository files navigation

EdgeStream Core

EdgeStream Core is the infrastructure automation layer of EdgeStream Hub.
It uses Ansible to apply system configuration generated by the EdgeStream API to a host machine.

EdgeStream Core is responsible for configuring and maintaining services such as:

  • Vector (log & telemetry processing)
  • VPN clients (WireGuard / OpenVPN)
  • NetFlow collectors
  • Network interfaces and routing
  • TLS certificates
  • System firewall rules
  • System services required by EdgeStream Hub

The repository contains Ansible playbooks, roles, and templates used to transform configuration data into a fully configured EdgeStream node.


Overview

EdgeStream Hub consists of three major components:

EdgeStream Web UI
        │
        ▼
EdgeStream API
        │
        ▼
Configuration Export (YAML)
        │
        ▼
EdgeStream Core (Ansible automation)
        │
        ▼
Configured Host System

Configuration Flow

  1. The user configures EdgeStream through the Web UI.
  2. The API writes configuration to:
/var/lib/edgestream/export/settings.yml
  1. A configuration job is queued.
  2. The Ansible runner executes the playbook from edgestream-core.
  3. System services and configuration files are updated.

Repository Structure

Typical layout:

edgestream-core
├── ansible.cfg
├── playbooks
│   └── configure.yml
├── roles
│   ├── core-settings
│   ├── network-settings
│   ├── vpn-settings
│   ├── vector-settings
│   └── netflow-settings
├── templates
│   └── ...
└── README.md

Key Directories

Directory Purpose
playbooks/ Main playbooks executed by the system
roles/ Modular configuration roles
templates/ Jinja2 templates used by roles
ansible.cfg Ansible runtime configuration

Playbooks

configure.yml

This is the primary playbook used by EdgeStream Hub.

It reads configuration exported by the API and applies the necessary roles to configure the system.

Example manual execution:

cd /opt/edgestream-core/playbooks
ansible-playbook configure.yml

Normally this is executed automatically by the EdgeStream job runner.


Roles

core-settings

Handles base system setup:

  • Required directories
  • Base service configuration
  • System paths and permissions

network-settings

Manages host networking:

  • Network interface configuration
  • Policy routing
  • DNS configuration
  • Firewall rules

vpn-settings

Manages VPN client connections.

Supported VPN types:

  • WireGuard
  • OpenVPN

Features include:

  • Split tunneling
  • Policy-based routing
  • Route-based kill switch
  • Automatic service lifecycle management

vector-settings

Configures Vector, the primary log ingestion pipeline.

Vector handles:

  • log collection
  • telemetry ingestion
  • routing and transformation
  • output sinks (databases, APIs, etc.)

Configuration is generated from EdgeStream source definitions.


netflow-settings

Configures the NetFlow/IPFIX collector.

Supported protocols:

  • NetFlow v5
  • NetFlow v7
  • NetFlow v9
  • IPFIX

The flow-collector service is automatically enabled when NetFlow sources are enabled in configuration.


Configuration Source

EdgeStream Core consumes configuration from:

/var/lib/edgestream/export/settings.yml

Example:

sources:
  - name: netflow
    type: netflow
    enabled: true
    settings:
      address: 0.0.0.0
      ports: 2055,2056,4739

Roles interpret this configuration and generate the appropriate service configuration files.


Running Ansible Manually

For debugging or development, you can run the playbook directly:

cd /opt/edgestream-core/playbooks
ansible-playbook configure.yml

Ensure the exported configuration exists:

/var/lib/edgestream/export/settings.yml

Logging

Automation logs are typically written to:

/var/log/edgestream-api/

Example:

edgestream-ansible-queue.log

Systemd logs can also be viewed using:

journalctl -u edgestream-ansible-queue

Idempotency

All roles are designed to be idempotent.

Running the playbook repeatedly should result in no changes if the system is already configured correctly.

Example output:

changed=0

Managed Services

EdgeStream Core manages the lifecycle of several services:

Service Purpose
vector log ingestion pipeline
flow-collector NetFlow collector
openvpn-client@* OpenVPN VPN profiles
wg-quick@* WireGuard VPN profiles

Services are automatically started, stopped, or restarted depending on configuration changes.


Security

The automation enforces several security practices:

  • strict file permissions
  • TLS certificate validation
  • service sandboxing
  • firewall configuration
  • policy-based routing for VPN traffic

Development

To modify automation behavior:

  1. Update Ansible roles or templates.
  2. Test changes locally:
ansible-playbook playbooks/configure.yml
  1. Commit changes to the repository.
  2. Deploy the updated package to EdgeStream systems.

Troubleshooting

Check configuration export:

cat /var/lib/edgestream/export/settings.yml

Run playbook with verbose output:

ansible-playbook -vv playbooks/configure.yml

View service logs:

journalctl -u edgestream-ansible-queue

📄 License

EdgeStream Core is licensed under the Functional Source License 1.1, ALv2 Future License (FSL-1.1-ALv2).

See:

  • LICENSE for full terms
  • COMMERCIAL.md for commercial licensing requirements

About

EdgeStream Core is the configuration system utilizing ansible to manage the EdgeStream Hub appliance

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages