kubernetes
minikube
minikube start
--vm-driver='': Driver is one of: [virtualbox parallels vmwarefusion kvm2 vmware none] (defaults to auto-detect)
minikube service --url vote-app
concepts
docker: container, image, tags
kubernetes:
- nodes (formerly minions): machine (hardware or vm) units
- cluster: set of nodes
- pods: multiple containers, share one ip and volumes, run on same machine
- services: set of pods
- replication controllers: restart pods, load balancing, scaling
- replica set: replacement for replication controller,
selector is required
- labels: key-value
- volumes
- secrets
- namespaces
- cluster: set of grouped nodes, balancing, fallback
components
master node, part of cluster, watches over nodes:
- api server: frontend
- etcd: key-value store
- scheduler: assigns containers to nodes
- controller: notice and respond to changes
worker node:
- container runtime: f.e. docker
- kubelet: runs on nodes, watches containers
rollout / deployment
kubectl create or kubectl run.
deployments create their own replicasets.
deployment strategies:
-
recreate: destroy and rebuild, downtime
-
rolling update, default: each pod
-
kubectl apply -f <file>
-
kubectl rollout undo deployment/myapp-deployment
-
kubectl rollout status deployment/myapp-deployment
networking
- pods get ip adresses
- to prevent conflicts in the cluster need to install/configure s.th., not builtin
services
exposes port which forwards to several pods of same type.
- kinds
ClusterIP: default, exposes on a cluster-internal ip
NodePort: exposes publicly on each node at a static port
(curl <nodeIP>:<nodePort>), includes ClusterIP service
LoadBalancer: connects w/ cloud provider's load balancer
targetPort: on pod, what container provides, defaults to port
port: on service, like virtual server inside node, required
nodePort: on each node, 30.000-23.767, defaults to autogenerate
clusterIP: to be identified inside cluster
- matches to pods via selector, clusterwide
- balancing: random w/
SessionAffinity
tools
kubeadm
used to setup kubernetes cluster.
kubectx
show and select contexts (clusters), f.e.
kubectx # list all
kubectx foo # switch to "foo"
kubectx -c # show current
kubectx -h
kubens
show and select namespaces inside context.
kubens # list all
kubens foo # switch to "foo"
kubens -c # show current
kubens -h
kubectl
kubectl config use-context docker-for-desktop
kubectl cluster-info
kubectl get nodes
# create pod, deploy image
kubectl run nginx --image=nginx
kubectl get pods
kubectl get pods -o wide
kubectl get pods -o yaml
kubectl describe pods
kubectl get deployments
kubectl delete deployment nginx
kubectl get all
yaml
-
apiVersion: v1 for pods and services, app/v1 for replicasets and deployments
-
kind
-
metadata:name: cascades to subcomponents, that is pods will have name of replicaset or deployment, don't need to be unique, but probably a good idea
-
metadata:labels: used for selectors and custom categorizing
-
kubectl create -f <file>
-
kubectl create -f . processes all files in dir
-
kubectl replace -f <file> disruptive update
-
kubectl apply -f <file> create or in-place update
-
kubectl diff -f <file> show what apply would do
namespaces
kube-system
kube-public
default: playground, don't use on real-life cluster
- connect to service "db" via
connect("db"), from other namespave via
connect("db.<namespace>.svc.cluster.local")
- specify namespace via
kubectl --namespace or via yaml as metadata:namespace
kubectl create namespace myapp-dev or via yaml
kubectl config set-context $(kubectl config current-context) --namespace=myapp-dev
kubectl get pods --all-namespaces
ResourceQuota puts limits on namespaces
unsorted
Ingress does what Route does in okd
Helm is a thing
containerPort in pod def, does it obsolete service port defs?