PapiHack/ofn-devops-assessment

My exercise solution of OpenFn DevOps Technical Task

★ 0Forks 0ShellGitHub ↗Compare

README

🚀 OpenFn DevOps Technical Task — Submission

This repository contains my proposed solution for deploying the OpenFn platform (Lightning, Worker, Postgres) in a highly secure government environment that is completely disconnected from the internet (air-gapped).

In line with the project requirements, the focus has been on operational simplicity, low resource consumption (suited to the server’s 8 GB of RAM) and complete autonomy for a local IT maintenance technician, achieved through a pragmatic approach based on Docker Compose.

📁 Project Structure

  • bundle/: Contains the technical piping for the connected machine.

    • build-bundle.sh: The Bash script that automates the downloading, saving and packaging of components.

    • docker-compose.yml: The multi-container configuration has been set up and is ready for production.

    • .env.complete.example: Default template configuration for environment variables/secrets

  • RUNBOOK.md: A step-by-step user guide for the Ministry’s IT officer covering installation, validation and troubleshooting (specifically regarding the Crash Loop).

  • DECISIONS.md: A brief strategic note outlining the rationale behind my architectural choices (image management, secrets, updates, observability) and the associated trade-offs.

🛠️ How to test the solution (Evaluator’s guide)

You can simulate the entire deployment workflow directly on your local machine in two main steps:

Step 1: Package/Bundle Generation (Connected machine / Jump Host)

Navigate to the bundle/ directory and run the build script:

cd bundle
chmod +x build-bundle.sh
./build-bundle.sh

📢 Expected result:

The script will download the stable images, export them, inject a .env.example template, and generate two files in the project root directory: openfn-lightning-airgap-bundle.tar.gz and its security fingerprint, openfn-lightning-airgap-bundle.tar.gz.sha256.

Step 2: System simulation (Offline mode)

To test the behaviour of the Ministry’s IT agent:

  • Move the two generated files (.tar.gz and .sha256) to a completely empty folder or an isolated VM.

  • (Optional) Disable your Wi-Fi/Internet connection to ensure 100% offline operation.

  • Follow the step-by-step instructions provided in the RUNBOOK.md file carefully to verify the checksum, load the images, configure the secrets and validate the application startup.

⏱️ Elapsed time

Note for the assessor: To help you mark this exercise, here is the actual time spent on this task.

  • Total time spent: ~5 hours

    • Research & Understanding the brief: ~30 mins

    • Writing the packaging script and composition: ~2 hours

    • Drafting the documentation (Runbook, Decisions & README): ~2 hours

    • Polishing (docs enhancement, code cleaning, etc) : ~30 mins

Author

Contributors

PapiHack

Issues