Rachel's Yard

| A New Continuation
Aug 2 2016

For the sake of humanity, let's point out the caveats first:

  1. If you ever change the CA or apiserver TLS certificate, remember to delete default secret tokens for ALL namespaces, and recreate services/pods. Your applications in each pods can access the API with a serviceaccount credentials, and it is only generated once. Therefore, if you change the TLS certs, the old secrets will be invalid.
  2. If you are running multiple master components, remember to add --apiserver-count=<count> flag in your kube-apiserver. Otherwise, apiserver will fight to get control of the service endpoints.

Now, let's get to the topic.

Billions of $$$ are awesome, but how do you invest? (joke

Docker is awesome (late to the party again), but how to manage?

TL;DR Kubernetes is a management tool (sort of) of containers.

I will just skip the introduction, since there are many articles out there already.

Installing Kubernetes

The best way of running Kubernetes is to deploy it on CoreOS, period.

https://coreos.com/kubernetes/docs/latest/getting-started.html

See, all other OSs are too heavyweight. CoreOS (other than SmartOS) is highly specialized to run containers, so there's that. Plus, folks at Quay.io is kind enough to have kubelet image ready. Kubelet is a binary that contains all the components that you will need to run Kubernetes (Golang is awesome), and Quay/CoreOS team makes it running in a rkt container, which makes updates/upgrades easy.

Of course, all components are stateless. Persistent states are stored in a etcd cluster (that seems to be the trend).

What's my environment?

An obligatory graph of architecture:

Kubernetes

Here are my cloud-config files for my deployment on OpenNebula: https://coreos-opennebula.s3.fmt01.sdapi.net/cloud-config/

What am I running?

Currently only a project written for an econ professor, but I will containerize more of my projects.

Ingress

The nginx controller on kubernetes/contrib kind of blows. So I (sort of) compiled the newest nginx and CHACHA20 ciphers:

Docker: https://hub.docker.com/r/zllovesuki/nginx-slim/

Git: https://git.fm/zllovesuki/nginx-slim/

You will need to recompile the controller with this tag.

Weightless Theme
Rocking Basscss
RSS