CloudNative Days Tokyo 2019 1D3 ã»ãã·ã§ã³ã®ã¹ã©ã¤ãã§ãã #CNDT2019 #OSDT2019 #RoomD
èæ¯ Kubernetesç°å¢ã§GitOpsãå°å ¥ããã«ããããSecretã®æ±ããã©ãããããã¨ãã課é¡ã«ç´é¢ãã¾ããã GitOpsã§ã¯ãKubernetesã®ãããã§ã¹ããã¡ã¤ã«ã¯Gitã§ç®¡çããã®ã§ã工夫ããªãã¨Secretããã®ã¾ã¾ã³ããããããã¨ã«ãªã£ã¦ãã¾ãã¾ãã Secretã®å¤ã¯base64ã§ã¨ã³ã³ã¼ãããã¦ããã ããªã®ã§ãç°¡åã«ãã³ã¼ãã§ãã¦ãã¾ãããããã®ã¾ã¾ã³ããããããã¨ã¯å¥½ã¾ããããã¾ããã ããã§å¯¾å¿æ¹æ³ã調æ»ããçµæãSealedSecretã¨ãããã®ãè¦ã¤ãæ¤è¨¼ããã®ã§ãæ¬çªç°å¢ã§ãæç¨ãªä½¿ãæ¹ãã¾ã¨ãããã¨ã«ãã¾ããã æºå kubesealã®ã¤ã³ã¹ãã¼ã« ã¾ãæåã«ãkubesealãã¤ã³ã¹ãã¼ã«ããå¿ è¦ãããã¾ãã æé ã¯ä»¥ä¸ã®ãªã³ã¯ã«è¼ã£ã¦ããã®ã§ããã²ã覧ãã ããã sealed-secrets - releases ããã§ã¯ãMacã§ã®æé ãã
Kubernetesã®ç£è¦ ã¯ã©ã¹ã¿ã®ç¶æ ç£è¦ãCPUã»ã¡ã¢ãªãªã©ã®ãªã½ã¼ã¹ç£è¦ãå種ã¯ã¨ãªãã¢ã¯ã»ã¹ã®ãã§ãã¯ãªã©ãè¦ç¹ãæããã°ããªã®ãªãåéãªã®ã§ã使ç¨ãããã¼ã«ã«ãã£ã¦ä½æ¥ã®é£æ度ã大ããå·¦å³ããã¦ãã¾ãã ä»åãPixieãå°å ¥ãã¦ã¿ã¦ä½¿ãå¿å°ãè¯ãã£ãã®ã§ãå¸æã®ããã«æ©è½ãããã¤ãç´¹ä»ãã¦ããã¾ãã ã¢ã¯ã»ã¹ç´å¾ã®å ¨ä½å ãããªæãã®ããã·ã¥ãã¼ãã«ãªã£ã¦ãã¾ããHTTPãã©ãã£ãã¯ã®å¯è¦åã¯è¦ã¦ããã ãã§ã¯ã¯ã¯ã¯ãã¾ãã Namespaceãã¨ã®ãªã½ã¼ã¹ç£è¦ Podã®ãªã½ã¼ã¹ä½¿ç¨ç¶æ³ããã£ã¹ã¯ã¢ã¯ã»ã¹ã確èªã§ãã¾ãã HTTPã®ãã°ç£è¦ Redisã®ã³ãã³ããã°ã»ãã©ãã£ãã¯ã®å¯è¦å ä»ã«ãæ§ã ãªç£è¦ç¨ã®ãã³ãã¬ã¼ããç¨æããã¦ãã¾ãð ã¤ã³ã¹ãã¼ã«æ¹æ³ Kubernetesã¯å°å ¥æ¸ã¿ã¨ä»®å®ãã¦ãSelf-hostedã§ã¯ãªãã¯ã©ã¦ãçPixieã®ã¤ã³ã¹ãã¼ã«æé ã®ã¿å ±æ
"Service mesh data plane vs. control plane" by Matt Klein ã®æ¥æ¬èªè¨³microservicesenvoyistioServiceMeshLinkerd ãã®è¨äºã¯Envoyã®ä½è ã§ããMatt Kleinããã®ä»¥ä¸ã®è¨äºã Service mesh data plane vs. control plane æ¬äººã®è¨±å¯ããã¦æ¥æ¬èªè¨³ãããã®ã«ãªãã¾ãã Sure! Please credit me as the original author and link to the original article. Thank you! â Matt Klein (@mattklein123) 2018å¹´5æ30æ¥ Envoyã®åå¨ãç¥ã£ã¦ä»¥éãservice meshã«é¢ãã¦èå³ãæã£ã¦ããããã¨èª¿ã¹ã¦ããã®ã§ãããã¾ã çºå±éä¸ä¸ã®åéã®
ã«ã¹ã¿ã ã³ã³ããã¼ã©ã¼ã®åºç¤ ããã§ã¯ã«ã¹ã¿ã ã³ã³ããã¼ã©ã¼ãéçºããä¸ã§å¿ è¦ã¨ãªãKubernetesã®åºç¤ç¥èã解説ãã¾ãã Declarative Kubernetesã«ããã¦ãã£ã¨ãéè¦ãªã³ã³ã»ãããDeclarative(宣è¨ç) APIã§ãã ä¾ãã°ãKubernetesä¸ã«Nginxããããã¤ãããå ´åã¯ã以ä¸ã®ãããªYAMLå½¢å¼ã§è¨è¿°ããããããã§ã¹ããç¨æãã¦ãDeploymentãªã½ã¼ã¹ãä½æãã¾ãã apiVersion: apps/v1 kind: Deployment metadata: name: nginx-deployment spec: selector: matchLabels: app.kubernetes.io/name: nginx replicas: 3 template: metadata: labels: app.kubernetes.io/
ããã«ã¡ã¯ãCacoo ãã¼ã ã®æ¨æï¼@cohheiï¼ã§ããCacoo ãã¼ã ã§ã¯ã Kubernetes ã«ããã¢ã¼ããã¯ãã£ã® microservices åã«åãçµãã§ãã¾ããä»åã¯ç§ãã¡ Cacoo ãã¼ã ã microservices åã«ãã£ã¦è§£æ±ºãããã¨ãã¦ãã課é¡ã¨åãçµã¿ã®å 容ããã®ææã«ã¤ãã¦ãç´¹ä»ãã¾ãã ãã®è¨äºã§ã¯ä»¥ä¸ã®å 容ãå«ã¿ã¾ãã Cacoo ã®éçºãã¼ã ãã©ããªèª²é¡ãæ±ãã¦ããã ä½æ microservices ã®éãé¸ãã ã ã©ããªæè¡ãé¸ãã ã microservices åãã¦ã©ãã ã£ãã ç¾ç¶ã®èª²é¡ 課é¡ï¼å¤ããã¬ã¼ã ã¯ã¼ã¯ã¨ã¢ããªã·ãã¯ãªã¢ããªã±ã¼ã·ã§ã³ Cacoo ã¯2009å¹´ã«ãã¼ã¿çããªãªã¼ã¹ãããæ´å²ã®ãããããã¯ãã§ãã¢ããªã·ãã¯ãªã¢ããªã±ã¼ã·ã§ã³ä¸ã§ãã¹ã¦ã®æ©è½ãå®è¡ããã¦ãã¾ããã ãã®ãããããããã®ã³ã¼ãã®ä¾åé¢ä¿ãååã«ç解
ã¯ããã« ãKubeCon + CloudNativeConãã§ã®ã»ãã¥ãªãã£ã«é¢ããã»ãã·ã§ã³ã§ç´¹ä»ãããããIstioãã¯ããã¨ããService Meshãããã¯ãã®Workload Identityã¨ãã¦æ¡ç¨ããããã¨ãæè¿ã«ãªãCloud Nativeã³ãã¥ããã£ã§SPIFFEã®åãè³ã«ãããã¨ãå¤ããªã£ã¦ãã¾ãããæ¬è¨äºã§ã¯ãSPIFFEãæ±ããããèæ¯ãSPIFFEã®æ¦è¦ãKubernetesã¸ã®å°å ¥æ¹æ³ãªã©ãç´¹ä»ãã¦ããã¾ãã SPIFFEãæ±ããããèæ¯ ãã¤ã¯ããµã¼ãã¹ã¢ã¼ããã¯ãã£ãã³ã³ãããªã¼ã±ã¹ãã¬ã¼ã¿ã¼ãã¯ã©ã¦ãã³ã³ãã¥ã¼ãã£ã³ã°ã®ãããªåæ£ã·ã¹ãã ãå©ç¨ãã¦ããç°å¢ã§ã¯ããµã¼ãã¹ã®ã¹ã±ã¼ãªã³ã°ãªã©ã«ä¼´ããã¼ããã¢ããªã±ã¼ã·ã§ã³ãé »ç¹ãã¤åçã«åæ£é ç½®ããããããã¢ããªã±ã¼ã·ã§ã³ã«å²ãå½ã¦ãããIPã¢ãã¬ã¹ãçæéã§å¤åãã¦ãã¾ãã ãã®ãããªç°å¢ã§ã¯ããããã¯
â»æ¬è¨äºã¯2022å¹´1æ26æ¥ã«å ¬éãããè¨äºã®ç¿»è¨³çã§ãã çè ï¼Dylan Lau (@aidiruu), Platform DXãã¼ã Zero Touch Production (ZTP)ã¯ãæ¬çªç°å¢ã«å ãããããã¹ã¦ã®å¤æ´ããèªååãå®å ¨ãªãããã·ãã¾ãã¯ç£æ»å¯è½ãªBreak-glassï¼ç·æ¥ã¢ã¯ã»ã¹ï¼ã·ã¹ãã ã«ãã£ã¦ãããªãããã¨ããæ¦å¿µã§ãã人çºçãã¹ã«èµ·å ããæ¬çªç°å¢ã§ã®é害ã«ã¯ã次ã®ãããªãã¾ãã¾ãªç¨®é¡ãããã¾ãã æ§æã¨ã©ã¼ ã¹ã¯ãªããã¨ã©ã¼ ééã£ãç°å¢ã§ã®ã³ãã³ãå®è¡ ZTPã¯ãããã®ã¨ã©ã¼ã«ããé害çºçã®ãªã¹ã¯ã軽æ¸ã§ãã¾ããã¡ã«ã«ãªã§ã¯ãZTPç°å¢ã¸ã®ç§»è¡ã«åãçµãã§ãã¾ããæåã®ã¹ãããã¯ãä¸æçãªå½¹å²ä»ä¸ã·ã¹ãã ã§ããCarrierãå®è£ ãããã¨ã§ãã ãã®è¨äºã§ã¯ã以ä¸ã«ã¤ãã¦èª¬æãã¾ãã ZTPã®éè¦æ§ ZTPãå®è£ ããããã»ã¹ã¨Carrierãå§ããç
HomeUser GuideAll-in-one ImageGithub ActionInstallationkwok in Clusterkwok out of Clusterkwokctl Manage ClustersManage Nodes and Pods Toolskwok CLIkwokctl CLI ConfigurationAPI reference ExtensionsCEL ExpressionsGo TemplateMetricsResourceUsage Pod InteractionAttachExecLogsPortForwardStages Examples kwokctl AdvancedAdmissionAuditingAuthorizationPlatform-Specific BinariesSnapshot kwokctl IntegrationA
対象ã¨ãªãåã ã®Podã®IPã¢ãã¬ã¹ãç´æ¥å¸°ã£ã¦ããService DNSã©ã¦ã³ãããã³ã®ã¤ã¡ã¼ã¸ ãã¼ããã©ã³ã·ã³ã°ããããã®IPã¢ãã¬ã¹ã¯ä¸è¦ StatefulSetãHeadlessServiceãå©ç¨ãã¦ããå ´åãPodåã§IPã¢ãã¬ã¹ãå¼ããã¨ãã§ããï¼Kubernetesã®è¨è¨çã«ãStatefulSetå ã®åPodãç´æ¥æå®ããã®ã¯ãã³ã»ã³ã¹ï¼ ã»ããã¢ãã HeadlessServiceã®ããã㤠apiVersion: v1 kind: Service metadata: name: sample-headless spec: type: ClusterIP clusterIP: None ports: - name: "http-port" protocol: "TCP" port: 80 targetPort: 80 selector: app: sample-app
èªå Envoy ã¤ã³ã¸ã§ã¯ã·ã§ã³ã使ç¨ã㦠Google Kubernetes Engine Pod ãè¨å®ãã æ¦è¦ ãµã¼ãã¹ ã¡ãã·ã¥ã§ã¯ãã¢ããªã±ã¼ã·ã§ã³ ã³ã¼ãã§ãããã¯ã¼ã¯æ§æãèªèããå¿ è¦ã¯ããã¾ãããã¢ããªã±ã¼ã·ã§ã³ã¯ãã¼ã¿ãã¬ã¼ã³ãä»ãã¦éä¿¡ãè¡ãã¾ãããã¼ã¿ãã¬ã¼ã³ã¯ããµã¼ãã¹ ãããã¯ã¼ãã³ã°ãå¦çããã³ã³ããã¼ã« ãã¬ã¼ã³ã«ãã£ã¦æ§æããã¾ãããã®ã¬ã¤ãã§ã¯ãCloud Service Mesh ãã³ã³ããã¼ã« ãã¬ã¼ã³ã«ãEnvoy ãµã¤ãã«ã¼ ãããã·ããã¼ã¿ãã¬ã¼ã³ã«ãªãã¾ãã Google ããã¼ã¸ã Envoy ãµã¤ãã«ã¼ ã¤ã³ã¸ã§ã¯ã¿ã¯ãEnvoy ãµã¤ãã«ã¼ ãããã·ã Google Kubernetes Engine Pod ã«è¿½å ãã¾ããEnvoy ãµã¤ãã«ã¼ ã¤ã³ã¸ã§ã¯ã¿ã¯ããããã·ã追å ããã¨ãã«ãã¢ããªã±ã¼ã·ã§ã³ ãã©ãã£ãã¯ãå¦çããClo
Kubernetesä¸ã§gRPCãµã¼ãã¹ãåãããã¨ãå¤ããªã£ã¦ãã¦ããï¼ãé©åã«ãã¼ããã©ã³ã¹ãããï¼ãªã¯ã¨ã¹ããè½ã¨ãããµã¼ãã¹ããããã¤ããããã«ããã¤ã注æãããã¨ãããã®ã§ç°¡åã«ã¾ã¨ãã¦ããï¼ ä»¥ä¸ã®2ã¤ãæèããï¼ Kubernetes Serviceã¯L4ã®Load balancerï¼LBï¼ã§ããã㨠gRPCã¯ã³ãã¯ã·ã§ã³ã使ãã¾ããã㨠Kubernetesã®Podã¯æ»ãã ãä½ãããããç¹°ãè¿ãï¼Kubernetesã®Podã«ã¯ããããå é¨IPãã¢ãµã¤ã³ããããï¼ãã®IPã¯Podãæ°ããä½æããã度ã«å¤ããï¼IPãå¤ãã£ã¦ãPodã«ã¢ã¯ã»ã¹ããããã«Kubernetesã§ã¯Serviceãã¤ããï¼Serviceã¯Podãæ½è±¡åãVirtual IPï¼VIPï¼ãæä¾ããï¼VIPã使ããã¨ã§Podã®IPãå¤ãã£ã¦ãPodã«ã¢ã¯ã»ã¹ãããã¨ãã§ããï¼ VIPã¯Network i
Perfect for EdgeK3s is a highly available, certified Kubernetes distribution designed for production workloads in unattended, resource-constrained, remote locations or inside IoT appliances. Simplified & SecureK3s is packaged as a single <70MB binary that reduces the dependencies and steps needed to install, run and auto-update a production Kubernetes cluster. Optimized for ARMBoth ARM64 and ARMv7
kind is a tool for running local Kubernetes clusters using Docker container ânodesâ. kind was primarily designed for testing Kubernetes itself, but may be used for local development or CI. If you have go 1.16+ and docker, podman or nerdctl installed go install sigs.k8s.io/[email protected] && kind create cluster is all you need! kind consists of: Go packages implementing cluster creation, image build,
社å ã§Kubernetesãã³ãºãªã³ããã£ã¦ã¿ãã®ã§ãããåãã åå è 6人ãããã³ãã³åºã¦ãã質åã«çããªãããã£ã¦ãæè¦æé4æéã»ã©ã§ããã SpeakerDeckã«ãè³æãä¸ãã¦ãã¾ãã https://speakerdeck.com/ktam1219/yaruze-kuberneteshanzuon (2019/07/11追è¨) ç¶ç·¨æ¸ãã¾ããï¼ -> ä»åº¦ã¯ããã¾ãã´ãããªãï¼ï¼ãããã¨ã´ããKubernetesãã³ãºãªã³ããã®ãã¨ã« ãã³ãºãªã³ã®ç®æ¨ Kubernetesã¨ãåéã«ãªã ã¤ã¡ã¼ã¸ãæ´ã 触ã£ã¦ã¿ã(ãã¼ã«ã«ã»EKSã»ã¡ãã£ã¨GKE) æ§ç¯ã»éç¨ãã§ãããããªæ°åã«ãªã å··ã«ããµããKubernetesã®è¨äºã»ã¹ã©ã¤ããç解ã§ããããã«ãªã EKSãã¡ã¤ã³ã«ãªã£ã¦ããã®ã¯ãä¼ç¤¾ã®æ¥åã§AWSã使ããã¨ãå¤ãããã§ãã ç´ç²ã«Kubernetesãåå¼·ãããã ããª
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}