4.8 KiB
4.8 KiB
| title | description | author | keywords |
|---|---|---|---|
| Kubernetes 101 | An introduction | Ricardo Band | kubernetes,container,basics |
Kubernetes 101
An introduction
Stuff you should already know
- Containers
- Container engines
- Bonus points for:
Agenda part 1 - The basics
- 🧑 Workloads aka your app
- 🛋️ Environment
- 📦 Containers
- 🏡 Pods
- 🏭 Deployments
- 🏪 Services
- 💾 Volumes
- 🌆 Namespaces
Agenda part 2 - Advanced topics
- 🏷️ Labels and 🔖 Taints
- 🏘️ ReplicaSets
- 🧰 DaemonSet
- 🗃️ StatefulSets
- 🌐 Ingress Controller
- 📑 Cluster DNS
- 💾 Container Storage Interface (CSI)
- 🕸️ Container Network Interface (CNI)
- 👮 Network Policies
🧑🛋️ Workloads and their environment
Example: Simple PHP app
📦 Containers
- Isolated environment
- Linux namespace and cgroups
- Networking?
- Persistant storage?
- Scheduling, Load balancing
🏡 Pods
- "Runnable unit of work"
- Holds Containers
- Connects to overlay network
- Container runtime interfaces (CRI)
- containerd, CRI-O, Docker
🏭 Deployment
- Manages:
- Pods
- Volumes
- Secrets
- Types:
- ReplicaSets
- DaemonSets
- StatefulSets
🏪 Services
💾 Volumes
🌆 Namepaces
- Isolates group of resources
- Names need to be unique
You survived, take a cookie!
🍪
💣 Hands on
Let's deploy a simple web app with a volume.
🏷️ Labels and 🔖 Taints
🏘️ ReplicaSets
- Maintain a stable set of replica Pods
- Pods are identical
- Good for scaling
- Finds Pods by their label 🏷️
🧰 DaemonSets
- Pods are started on every node of the cluster
- Useful for cluster wide services
🗃️ StatefulSets
- Fine control over storage
- Pods are started in order
- Pods have stable identities
- redis-1, redis-2, redis-3, ...
- Useful for clustered services
- E.g. primary pod needs to start first
🌐 Ingress Controller
- Load balancer
- Can be NGINX, HAProxy
- Different in Cloud kubernetes
- Handles HTTP(S) traffic to the cluster
- Kubernetes object:
Ingress - OpenShift object:
Route
📑 Cluster DNS
- Pods:
<pod-ip-address>.<namespace-name>.pod.cluster.local - Services:
<service-name>.<namespace-name>.svc.cluster.local - Pods behind Services:
<pod-ip-address>.<service-name>.<namespace-name>.svc.cluster.local - /etc/resolv.conf:
nameserver 2001:cafe:42:1::23 search <namespace>.svc.cluster.local svc.cluster.local cluster.local options ndots:5
💾 Container Storage Interface (CSI)
🕸️ Container Netrwork Interface (CNI)
👮 Network Policies
Kubernetes distribution
- 💻 On bare metal
- ⛅ In the cloud:
- Amazon (EKS, ECS)
- Google (GCP)
Still not enough?
- 🃏 Custom Resources
- 🔑 Secrets
- 📡 Control Plane
- 🔩 Operators
- 🕑 Jobs and CronJobs
- 🗺️ ConfigMaps
- 🔐 Pod Security Policies
- 🪪 Role Based Access Control (RBAC)
- 🪵 Resource Quotas
Sources
--
by Ricardo Band
mailto:email@ricardo.band
https://www.ricardo.band/