This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
product separate from Palo Alto Networks Cortex XCOR.
Palo Alto Networks Telemetry Pipeline architecture
Learn how Palo Alto Networks Telemetry Pipeline components create and run pipelines in a cluster.
Palo Alto Networks Telemetry Pipeline uses different components to create, modify, and
run pipelines.
Palo Alto Networks Telemetry Pipeline is built on Kubernetes. You can either
install Palo Alto Networks Telemetry Pipeline in an
existing Kubernetes cluster or in a Linux environment. If you install Palo Alto Networks
Telemetry Pipeline in a Linux environment, the installer automatically deploys a K3s
cluster, then installs Palo Alto Networks Telemetry Pipeline components in that cluster.
Each Palo Alto Networks Telemetry Pipeline installation includes a Core Operator, which is a
Kubernetes operator
that creates and modifies pipelines. A different component called a Core Instance
creates and updates the custom resources that the Core Operator uses when it creates
or modifies pipelines. The Core Instance also syncs the status of your cluster
with the Palo Alto Networks Telemetry Pipeline backend.
Each pipeline is a workload that runs within your cluster and contains one or more Pods.
By default, pipelines run as
Deployments,
but other workload types are
supported as well.
You can use Pipeline CLI and the
Palo Alto Networks Telemetry Pipeline web interface to configure your
Palo Alto Networks Telemetry Pipeline installation and to create and modify pipelines.