2017-04-01ãã1ã¶æéã®è¨äºä¸è¦§
k8sjp.connpass.com ä»æ¥ã¯ããã§çºè¡¨ãã¦ãã¾ã Kubernetes Meetup Tokyo #4 https://t.co/2rxxAnKyAB #k8sjpâ ãªãªã·ãããµã (@_mpon) 2017å¹´4æ20æ¥ ECSããGKEã«ä¹ãæããã ææ³ Google Japanã®é£å ã§ãªãã¼ãä¼å ´ã§çºè¡¨ããã人ãã£ã¡ãããã kuberâ¦
Deisã®postgresãoff-clusterã«ãã(Cloud SQLãå©ç¨) - ã¾ã¼ã½ãã£ã¦èª°ãã¤ããã®ï¼ãDeisã®postgresãoff-clusterã«ãã(postgresql on GCEãå©ç¨) - ã¾ã¼ã½ãã£ã¦èª°ãã¤ããã®ï¼ã§Cloud SQLãdeisã®databaseã¨ãããã¨ãããã¦ããã©è§£æ±ºãã話ã Cloud Sâ¦
Proxy Protocolã¯L4ã«ãããx-forwarded-forã¿ãããªãã® 2010å¹´ããããããã¿ããã ã£ããã©ãæ¥ããããªããç¥ããã«çãã¦ããã HTTPããããè¦ãããã¼ããã©ã³ãµã¼ï¼L7ãã¼ããã©ã³ãµã¼ï¼ãªãx-forwarded-forã¨ãx-real-ipã¨ãã«IPã追è¨ãã¦ãããã¨â¦
Security Considerations - Deis Workflow Documentationã§å ¬å¼ã«IPå¶éããæ¹æ³ãç´¹ä»ããã¦ããã403ãåºãã ãªãã§403ã«ãªã£ã¡ããã®ããããã調ã¹ã¦ã¿ãã å ¬å¼éãã«ãã£ã¦ã403 å ¬å¼ãã¼ã¸ã«ããã£ããããããã°ã§ããã¨æ¸ãã¦ãããã確ãã«403ã«â¦
Clusterãä½ãæã«ããã©ã«ãã§ã¤ãã¦ããLBãå¤ã gloucd container clusters createãããã¨ãã«ã--disable-addons "HttpLoadBalancing"ãã¤ããããããããªãã¨GLBCãIngress Controllerã¨ãªã£ã¦ãã¾ããããã³ãã³ãã©ã¤ã³ããããå¤ããªãã clusterâ¦
ãã¾ããããã«ããã®ã kubernetesã§Ingressã§ããå ´åãIngress Controllerãå¿ è¦ãªãã ãã©ãGKEã®å ´åã¯ãã¹ã¿ã¼ãã¼ããã¤ã¾ãGCPã®ããã¼ã¸ããªé åã§ã¯ã©ã¹ã¿ã¼ä½ææã«ä¸ç·ã«ä½ãããããã«ãªã£ã¦ãã ã§ããããGLBC(GCE Load-Balancer Controller)â¦
Deisãverupãã æ¬æ¥ãDeis Workflowãverupãããã§ãããChangelogãè¦ã¦ãã¨Ingressã¨ãããã®ããªããå°å ¥ããã¦Deis/routerãªãã¦ããããã¿ãããªãã¨ãã ããããWhat is Ingress? Kubernetesã®ãããããããªã½ã¼ã¹ã®ã¿ã¤ãã®ãã¡ã®ä¸ã¤ã®Ingressâ¦
èæ¯ AWSã§VPCä½ã£ãããããã¨ãããã©ãGCPãã£ããã¨ãªãã£ã¦äººã¯è²ã éãã«æ¸æã ã¢ã«ã¦ã³ãã®é¢ä¿æ§ããããã¯ã¼ã¯ã®æ¦å¿µã®éããªã©ãç解ããã®ã§ã¾ã¨ãã AWSã¨GCPã®ã¢ã«ã¦ã³ãã®èãæ¹ã®éã AWSã®å ´åããã人éã«å¯¾ãã¦è²ã ãªAWSã¢ã«ã¦ã³ããä»ä¸â¦
PVCã¨ã¯ï¼ Kubernetesã®PersistentVolumeClaimsã®ç¥ã§ããã https://kubernetes.io/docs/user-guide/persistent-volumes/#persistentvolumeclaims A persistentVolumeClaim volume is used to mount a PersistentVolume into a pod. PersistentVolumes are â¦
ããã㨠mpon.hatenablog.com ååã¯Cloud SQLã使ã£ãããCloud SQLã¯ããã©ã«ããããã¯ã¼ã¯å¤ã«ããã®ã§ãCloud SQL Proxyããã¦ã¦éä¿¡ããããå¤é¨IPã許å¯ãããããªãã£ããDeisã®å ´åã ã¨ãproxyãã¦ããã¿ã¼ã³ã使ãããå¤é¨IPã許å¯ããæ¹æ³ã«ããâ¦
ããã㨠postgresãoff-clusterããã ã§ããã®postgresãã©ãã«ç«ã¦ããã¨ããã¨GCEã«ãã¦ããGCPã®mangaedãªCloud SQL(RDSã¿ãããªãã¤)ãããã®ã§ãã©ã£ã¡ã«ãããã¨ãããã¨ã§ãä»åã¯Cloud SQLã使ã£ã¦ã¿ãã Cloud SQL PostgreSQL beta Cloud SQLã®ãâ¦
å ¬å¼ãã¼ã¸ãåèã« Configuring Object Storage æ¬å½ã«ãããå¤ããã ããbucketã¯GCSã§ãããããä½ã£ã¦ããã権éã¨ãããªãããã¦ãªãã diff --git a/values.yml b/values.yml index c25cfb2..1d94aca 100644 --- a/values.yml +++ b/values.yml @@ -7,â¦
èæ¯ Deisã¯helmã³ãã³ãã§ã¤ã³ã¹ãã¼ã«ããã°ç°¡åã«å ¥ããã©ããã®ã¾ã¾ã ã¨ãã¼ã¿ä¿åå ãephemeralãªãã®ã«ãªã£ã¦ãã¾ãã®ã§ãã¡ãä»ã«ãproductionéç¨ã®ããã«ããæ¹ãè¨å®ãããã®ã§ã¾ã¨ããã 調ã¹æ¹ ã»ã¨ãã©deisã®å ¬å¼ãã¼ã¸ã«æ¸ãã¦ãã£ã installiâ¦
remote configãdeprecatedã«ãªã terraform0.9.0ããterraformã³ãã³ãå®è¡ããã¨deprecated warningãã§ã¦ãã¾ãã 3è¡ remote configã³ãã³ãããªããªã£ã¦initã³ãã³ããå°å ¥ããã backendã¨ããæ¦å¿µãå°å ¥ããterraform.tfstateãã¡ã¤ã«ãä¿åããè¨å®â¦
0.9.1 changlog :tada: https://github.com/hashicorp/terraform/blob/master/CHANGELOG.md#091-march-17-2017 provider/aws: Validate CIDR Blocks in SG and SG rule resources (#12765) planã§æªç¶ã«é²ãã ã¤ãééã£ã¦cidr_blocksã®æ¹ã«security_groupâ¦