Kubernetes
ä»åã¯MicroK8sã§PG-Stromã³ã³ãããåããã¦ã¿ããã¨æãã¾ãã MicroK8sã¯ãã®ããã°ã§ä½åº¦ãåãä¸ããããã«ãKubernetesã¯ã©ã¹ã¿ã¼ãç°¡åã«ã»ããã¢ãããããã¨ãã§ãããã¼ã«ã§ãã microk8s.io PG-Stromã¯PostgreSQLãã¼ã¿ãã¼ã¹ã®æ¡å¼µæ©è½ã§ããGPUâ¦
ä»åã®ãã¿ã¯ä»¥ååããããªè¨äºãæ¸ããã®ã§ããã®ã¢ãããã¼ãçã§ãã 次ã®è¨äºãä½µãã¦ã覧ãã ããã2019å¹´ããã®è¨äºã§ããä»ãã ãããéãã¾ãã tech.virtualtech.jp ãã¦ãæ¬é¡ã«å ¥ãåã«ãããããã£ãã説æãã¾ãã MicroK8sã¨ã¯ MicroK8sã¨ã¯Uâ¦
Kubesharkã¨ã¯ å³ã¯å ¬å¼ ããæç² Kubesharkã¯Kubernetesã®ããã®è¦³æ¸¬æ§ã»ç£è¦ãã¼ã«ã§ããã¤ã¯ããµã¼ãã¹ã®åç解æãç°å¸¸ã®æ¤åºãªã©ãå®ç¾ãããã¼ã«ã§ãã WiresharkãBPF Compiler Collectionï¼BCCï¼ãã¼ã«ãªã©ãçµã¿åããããKubernetesãæèãããã®â¦
é£è¼ç®æ¬¡ Kubernetesã¯ã©ã¹ã¿ã¼ã§IPv4/IPv6 Dual-stackãµãã¼ããæå¹ã«ãã IPv6ãã§ãã¯ç¨ã®ã¤ã¡ã¼ã¸ãä½æãã IPv4/IPv6ã§ãµã¼ãã¹ãåããã³ã³ããã¤ã¡ã¼ã¸ã使ã£ã¦Kubernetesã§å®è¡ (ä»å) ã¤ã¡ã¼ã¸ã使ã£ã¦ã¢ããªã±ã¼ã·ã§ã³ãå®è¡ãã¦ã¿ã ååããã¹â¦
Kubernetesï¼æ£ç¢ºã«ã¯ã¯ã©ã¹ã¿ãããã¯ã¼ã¯ï¼ã¯ããã©ã«ãè¨å®ã¯IPv4ã®ã¢ãã¬ã¹ã®ã¿ãå©ç¨ããããã§ãã ã¨ããæ¡ä»¶ã§å¿ è¦ã«ãªã£ããããKubernetesã®IPv6å¨ãã調ã¹ããã¨ã«ãã¾ããã ä»åã®å 容ã¯ï¼åã«åãã¦ããã°ã«ãããã¨æãã¾ãã å 容 Kuberneteâ¦
æ¬è¨äºã«ã¤ã㦠ãã®è¨äºã§æ¸ããã¦ããå 容ã¯Restrict a Container's Syscalls with seccompããã¼ã¹ã«ãã¦ãã¾ããããã®ããã¥ã¡ã³ãã®ãã¡ååã®æå®ããä»»æã®Seccompãããã¡ã¤ã«ã使ã£ã¦Podãä½æããæ©è½ã¯1.25ã§ããã©ã«ãã§ä½¿ããããã«ãªã£ãæ©è½â¦
Kubernetes 1.24ããªãªã¼ã¹ãããdockershimã³ã³ãã¼ãã³ããåé¤ããã¾ããã ããã¯Kubernetes 1.24以éã®ãã¼ã¸ã§ã³ã§Dockerãã©ã³ã¿ã¤ã ã¨ãã¦ä½¿ããã¨ãã§ããªããã¨ãæå³ãã¾ãã ã¨ããã§ãdockershimãåé¤ããããã¨ã¯çµæ§åããåç¥ããã¦ãã¾ãâ¦
ãã®ããã°ã§ã¯KubeVirtã«ã¤ãã¦ä½åº¦ãåãä¸ãã¦ãã¾ããã 主ã«kubeadmã§ã¯ã©ã¹ã¿ã¼ãä½ã£ã¦ãKubeVirtãå°å ¥ããæé ããç´¹ä»ãã¦ãã¾ãã tech.virtualtech.jp ã¡ãªã¿ã«ãªãKubeVirtãé »ç¹ã«åãä¸ãããã¨ããã¨ãçè ãKubeVirtã«å人çã«èå³ããããâ¦
ãããã Ubuntu 22.04ã§kubeadmã§Kubernetesã¯ã©ã¹ã¿ã¼ãä½ã£ã¦ã¿ãã®ã§ããã[WARNING SystemVerification]: missing optional cgroups: blkioãªãã¦ããè¦åãåºã¾ãããã»ããã¢ããå¾ã®KubernetesãKubernetes APIã®åããããããç¶æ³ã«ãªãã¾ããã â¦
Pod Securityã¯ãæ°ããPodãä½æãããã¨ãã«Kubernetes Pod Security Standardsã«å¯¾ãããã§ãã¯ãå®è¡ããã¢ãããã·ã§ã³ã³ã³ããã¼ã©ã¼ã§ãã 端çã«ããã¨ãPodãä½æããã¨ãã®ã»ãã¥ãªãã£ä¸ã®ã«ã¼ã«ãå®ç¾©ãã¦ãããã«å¾ãããããã®ãã®ã§ããPod Sâ¦
ãªãPod Security Standardsãå¿ è¦ãªã®ã Kubernetesã¯ä¾¿å©ãªã®ã§ãããããã©ã«ãè¨å®ã®ã¾ã¾ã®Kubernetesã¯è¯ãè¨ãã°èªç±æ§ãé«ããï¼ããã¦ï¼æªãè¨ãã°ã»ãã¥ãªãã£ãç·©ãã¨ããè©ä¾¡ããã¦ãã¾ãã¾ãã Kubernetesã®ã»ãã¥ãªãã£ãé«ããæ段ã®æ段ã®ä¸â¦
Amazon EKS Anywhere ã¯ããã©ã¤ãã¼ãã®ãªã³ãã¬ãã¹ç°å¢ã§Kubernetesã¯ã©ã¹ã¿ã¼ãä½æããã³éç¨ã§ããããã«ãããAWS ããµãã¼ãå¯è½ãªAmazon EKSã®ããã®æ°ãããããã¤ãªãã·ã§ã³ã§ããååã示ãããã«ãã©ãã§ããEKSã®ãããªç°å¢ãããç®æãã¦éçºâ¦
Knativeã¨ã¯ Knativeã¨ã¯ãKubernetesä¸ã«ãµã¼ãã¬ã¹ã³ã³ãã¥ã¼ãã£ã³ã°ã®åºç¤ãæ§ç¯ããããªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ã§ãã ã¤ãã³ããããªã¬ã¼ã«ãã¦ã³ã³ãããèµ·åãã¦ãè² è·ã«å¿ãã³ã³ããå®è¡æ°ãèªç±ã«å¢æ¸ãããã¹ã±ã¼ã©ããªãã£ãæä¾ãã¾ããKnatiâ¦
ååãMultipassã使ã£ã¦æå ã®ç°å¢ã§Kubernetesãåããã¨ããè¨äºãæ¸ãã¾ããã tech.virtualtech.jp ä»åã¯ä½ã£ãã¯ã©ã¹ã¿ã¼ããã°ã¤ã³ããã«ä½¿ããã便å©ã ããã¨ããå°ãã¿ã§ãã Multipass VMã«sshå ¬ééµèªè¨¼ Multipassã§VMãä½ãã«ã¯æ¬¡ã®ãããªæãâ¦
Multipassã¯Ubuntuãéçºã»ãµãã¼ãããCanonicalãä½æãããã¯ã©ã¤ã¢ã³ãã«ã¤ã³ã¹ãã¼ã«ãã¦Ubuntu VMãç°¡åã«ãããã¤ã§ãããã¼ã«ã§ããWindows, macOS, Linuxã«å¯¾å¿ãã¦ãã¾ãã 以åã¾ã§ã¯Ubuntu VMãä½ãããã¼ã«ã ã£ãã®ã§ãããæè¿DockerãKuberneâ¦
ã¨ããæ¡ä»¶ã§GitOpsã«ã¤ãã¦èª¿æ»ãã¦ããããã®èª¿æ»ã®ä¸ã§Oktetoã¨ãã便å©ãªãµã¼ãã¹ããã£ãã®ã§ããç´¹ä»ãããã¨æãã¾ãã Oktetoã¨ã¯ å ¬å¼ãµã¤ãã«ã¯æ¬¡ã®ããã«æ¸ããã¦ãã¾ãã Make Development Fasterï¼éçºãããéãããï¼ Instantly spin up pre-â¦
Rancher 2.6ã¯Enterpriseåãã®æ©è½ãå¤æ°è¿½å ãããã¨èãã¦ãã¦æ°ã«ãªã£ã¦ãã¾ãããç¹ã«æ°ã«ãªã£ã¦ããã®ã¯Continuous Deliveryæ©è½ã§ãã www.suse.com Rancher 2.6以åãRancherãéãã¦ãã³ã³ããã§DevOpsãã®ãããªãã¨ãããæ¹æ³ã¯ç¨æããã¦ãã¾ãâ¦
ããã¾ã§æ¬ããã°ã§ã¯KubeVirtãä½åãåãä¸ãã¦ãã¾ããããä»åã¯ãã«ããã¼ãã®Kubernetesã¯ã©ã¹ã¿ã¼ã§KubeVirtãåããã¦ã¿ã¾ãã ã¾ãKubeadmã§Kubernetesã®ãã«ããã¼ãã¯ã©ã¹ã¿ã¼ãä½ã KubeVirtãã»ããã¢ããããåã«ãå ¬å¼ã®ããã¥ã¡ã³ããªã©ãåâ¦
KubeVirtã®GPUã¹ã±ã¸ã¥ã¼ãªã³ã°ã®æ¤è¨¼ã®ããã«Tesla P100ã®ã»ãTesla T4ãç¨æãã¦ããã£ãã®ã§ãããTesla T4ã¯Kubernetesã¯ã©ã¹ã¿ã¼ã«ã¯èªèããã¦ãããã®ã®ããã®ãªã½ã¼ã¹ãè¦æ±ãã¦VMIãä½ããã¨ããã¨æ¬¡ã®ãããªã¤ãã³ããã°ãçºçãã¦VMIãä½æã§ããªâ¦
KubeVirtã§ä½ãã§ããã®ããå¼ãç¶ã調æ»ãã¦ãã¾ãã å æ¥ãNVIDIAã®Teslaãè²·ã£ã¦ããã£ãã®ã§ãKubeVirtã§NVIDIA GPUãVMã«ã¹ã±ã¸ã¥ã¼ãªã³ã°ãã¦Python+Tensorflowã§å©ç¨ã§ããã確èªãã¦ã¿ã¾ãããçµæãåé¡ãªãå©ç¨ãããã¨ãã§ãã¾ããã Tensorflowâ¦
KubeVirtã¯ã¢ããªã±ã¼ã·ã§ã³ãä»®æ³ãã·ã³ã§åä½ããããããLinuxã ãã§ãªãWindowsãªã©ãåãããã¨ãã§ãã¾ãã è¿å¹´ã®Windowsã¯ã³ãã³ããã¼ã¹ã«ããã¢ã¯ã»ã¹ãè²ã ã¨ã§ããããã«ãªã£ã¦ã¯ãã¾ãããã¾ã ã¾ã Windowsã¯GUIã§æä½ããæ¹ãå¤ãã¨æãã¾ããâ¦
è¤æ°ã®Kubernetesã¯ã©ã¹ã¿ã¼ããã£ãæãkubeconfigãæå®ãã¦ã³ãã³ããå®è¡ããã¨æãã®ã§ãããæ¯åkubeconfigãæå®ããã®ã¯ã¡ãã£ã¨ãã¡ããã¡ããã¦å«ã ãªãã¨æããå¹ççãªæ¹æ³ããªãã調ã¹ããã¨ã«ãã¾ããã % ku get no --kubeconfig=$HOME/.kubeâ¦
ããã¾ã§ãKubernetesã«KuberVirtãå°å ¥ããä»®æ³ãã·ã³ãå©ç¨ã§ããããã«ãã¾ããã tech.virtualtech.jp ååã¯KubeVirt VMã«Kubernetesã®ãµã¼ãã¹ãé©ç¨ãã¾ããã tech.virtualtech.jp ä»åã¯KubeVirtã®ããªã¥ã¼ã å²ãå½ã¦ã«ã¤ãã¦è©¦ãã¾ããã ããããâ¦
å æ¥ã®è¨äºã§Kubernetes + KubeVirtã®ç°å¢ãä½ãã¾ããã ä½ã£ãã ãã§ã¯ã¡ãã£ã¨ãã£ãããªãæ°ãããã®ã§ãã¾ãKubeVirt VMä¸ã§ã¢ããªã±ã¼ã·ã§ã³ãå°å ¥ãããã¨ããã®ã¢ããªã±ã¼ã·ã§ã³ãKubernetes Serviceã使ã£ã¦å ¬éãããã¨ã試ãã¦ã¿ã¾ããå ¬å¼ããã¥â¦
è¦ç´ Kubernetes (API)ã§ä»®æ³ãã·ã³ãæ±ãã ä»®æ³ãã·ã³ã§ã¢ããªã±ã¼ã·ã§ã³ãå®è¡ã§ãã ä»®æ³ãã·ã³(QEMU-KVM)ã§ã§ãããã¨ã¯ãããããããã åã½ããã¦ã§ã¢ã®æ¦è¦ Kubeadmã¯Kubernetesã¯ã©ã¹ã¿ã¼ãä½æãããã¼ã«ã®ä¸ã¤ã§ããKubernetesã¯å¤§è¦æ¨¡ãªã³ã³ãâ¦
ããã»ãã¥ãªãã£ãèæ ®ããKubernetesãç®æãã¦ããããã調ã¹ã¦ããã¨ããã§ãã ä»åã¯SELinuxãæå¹ãªç¶æ ã§Kubernetesãåããã¦ã¿ããã¨ã«ãã¾ããã 対象ã®ãã¼ã¸ã§ã³ã«ã¤ã㦠Fedoraã¯33ãCentOSã¯7.9ããã³8.3ã®ã¢ãããã¼ãé©ç¨ãããã¼ã¸ã§ã³ãâ¦
OpenShiftã¯ãã¼ã¹ã«Kubernetesã使ã£ã¦ããã¨ã¯ãããæ§ã ãªè£½åãçµã¿åããããã³ã³ããã¼ã®çµ±åç°å¢ã§ããããã使ããã¨æãã¨ã»ããã¢ããããã®ã¯ãªããªãé£ããã®ãäºå®ã§ãã Kubernetesãã¡ãã£ã¨è©¦ãããã®ãã¼ã«ã¨ãã¦minikubeããã£ãããã«ãOâ¦
ã¡ãã£ã¨åã«ããããªè¨äºãè¦ã¤ãã¾ããã blog.appsecco.com ç¹å®ã®Kubernetesãã¼ã ã¹ãã¼ã¹ã«æ¸ãæãã®æ¨©éãæã¤ã¢ã«ã¦ã³ãã使ããhostpathãã¦ã³ãã使ããã¨ã§ãã¹ãã®ã·ã§ã«ã«ä¾µå ¥ã§ããã¨ããå ±åã«ãªã£ã¦ãã¾ãã ãã®å¾ç·¨ã¯ãPod security Poliâ¦
Kubernetesã®åºæ¬è¨è¨ã§ã¯ä¸ã¤ã®Podã«ã¯ä¸ã¤ã®NICãæä¾ãããå¤é¨ããã®ã¢ã¯ã»ã¹ãå é¨çãªéä¿¡ãªã©ãå ¨ã¦ãã®ã¤ã³ã¿ã¼ãã§ã¤ã¹ãçµç±ãã¦è¡ãã¾ãã ä¸æ¹ãKubernetesã§Multus CNIã使ãã¨ãPodã«å¯¾ãã¦è¤æ°ã®Interfaceãä»ä¸ã§ãã¾ãã Multus CNIãã»ãâ¦
æ¬ç¨¿ã®å 容ã¯ä»¥ä¸ãHow To Inspect Kubernetes Networkingãã®è¨äºã®ååé¨åãåèã«ãKubernetes 1.18.6ãCRIã¨ãã¦DockerãCNIã¨ãã¦Flannelã§åä½ç¢ºèªãããã®ãã¾ã¨ãã¦ãã¾ãã www.digitalocean.com åæ¸ã Kubernetesã¯ããµã¼ãã¼ãã¼ãã®ã¯ã©ã¹ã¿ã¼â¦