EKS

AWS EKS ์Šคํ„ฐ๋”” 7์ฃผ์ฐจ - Automation

  • kkumtree

2023-06-10T15:13:19+09:00

EKS ์Šคํ„ฐ๋””๋„ ๋งˆ์ง€๋ง‰ 7์ฃผ์ฐจ๋ฅผ ๋งž์ดํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ์—๋Š” AWS Controller for k8s(ACK)์™€ flux๋ฅผ ๊ฐ€๋ณ๊ฒŒ ์‹ค์Šตํ•ด๋ณด๊ณ  ์ž๋™ํ™”์— ๋Œ€ํ•ด ๋ง›๋ณด๊ธฐ๋ฅผ ํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค. ์•ž์„œ ํ•™์Šตํ•ด๋ณธ IRSA ๊ฐœ๋… ์™ธ์—๋„ CRD(CustomResourceDefinition)์„ ํ™œ์šฉํ•ฉ๋‹ˆ๋‹ค. 1. ์‹ค์Šตํ™˜๊ฒฝ ๋ฐฐํฌ ์‹ค์Šต์„ ์œ„ํ•œ YAMLํŒŒ์ผ์ด ๋ณ€๊ฒฝ๋œ๊ฑฐ ๋ง๊ณ ๋Š” 6์ฃผ์ฐจ์™€ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค. curl -O https://s3.ap-northeast-2.amazonaws.com/cloudformation.cloudneta.net/K8S/eks-oneclick6.yaml # ์ดํ•˜ ์ค‘๋žต # CERT_ARN(ACM)์˜ ๊ฒฝ์šฐ์—๋Š” /etc/profile์— ํ™˜๊ฒฝ๋ณ€์ˆ˜ ์ €์žฅ์„ ์•ˆํ•ด๋‘ฌ์„œ # ์„ธ์…˜์ด ๋งŒ๋ฃŒ๋˜๋ฉด, ๋‹ค์‹œ ์žฌ์„ค์ • ํ•„์š” CERT_ARN=`aws acm list-certificates --query 'CertificateSummaryList[].CertificateArn[]' --output text` echo $CERT_ARN 2. ACK(AWS Controller for k8s) ์›น์ฝ˜์†”์— ์ ‘๊ทผํ•˜์ง€ ์•Š๊ณ ๋„, AWS ์„œ๋น„์Šค ๋ฆฌ์†Œ์Šค๋ฅผ ์ง์ ‘ k8s์—์„œ ์ •์˜ ๋ฐ ์‚ฌ์šฉ๊ฐ€๋Šฅ ์ˆœ์„œ: ACK ์ปจํŠธ๋กค๋Ÿฌ ์„ค์น˜ -> IRSA ์„ค์ • -> AWS ๋ฆฌ์†Œ์Šค ์ปจํŠธ๋กค ๊ฐ™์€ ํŒจํ„ด์œผ๋กœ ์ด๋ฃจ์–ด์ ธ์žˆ๋Š”๋ฐ, Cloudformation์„ ์“ฐ๋‹ค๋ณด๋‹ˆ ์ค‘๊ฐ„์ค‘๊ฐ„ ๋Œ€๊ธฐ ์‹œ๊ฐ„ ๋ฐœ์ƒ (23/05/29) GA: 17๊ฐœ ์„œ๋น„์Šค, Preview: 10๊ฐœ ์„œ๋น„์Šค 2-1.

AWS EKS ์Šคํ„ฐ๋”” 6์ฃผ์ฐจ - Security

  • kkumtree

2023-06-04T06:56:52+09:00

์ด๋ฒˆ์—๋Š” ๋ณด์•ˆ์„ ์œ„ํ•œ ์ธ์ฆ ๋ฐ ์ธ๊ฐ€, ๊ทธ๋ฆฌ๊ณ  IRSA๋ฅผ ์ค‘์‹ฌ์œผ๋กœ EKS์˜ ๋ณด์•ˆ์— ๋Œ€ํ•ด ํ•™์Šตํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค. kops ์Šคํ„ฐ๋”” ๋•Œ์—๋Š” ์ž˜ ๋ชฐ๋ž๋Š”๋ฐ, RBAC ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๋ณต๊ธฐํ•˜๋‹ค๋ณด๋‹ˆ… [4-1] projected Volume [4-2] AWS Load Balancer Controller IRSA ๋ฐ LB Pod mutating ์œ„์˜ ๋‘ ๊ฐ€์ง€๊ฐ€ ์ค‘์š”ํ•œ ํŒŒํŠธ๋ฅผ ์ฐจ์ง€ํ•˜๊ณ  ์žˆ์—ˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. Network(2์ฃผ์ฐจ)๊ฐ€ ๋งค๋ฒˆ ๋ญ”๊ฐ€ ์ผ๋ถ€๊ฐ€ ์•„๋ฆฌ์†กํ•˜์˜€๋‹ค๋ฉด Security๋Š” ๋ณต๊ธฐํ•˜๋‹ค๊ฐ€ ์ด๋ก ์ ์œผ๋กœ๋Š” ๊ฐ„๋‹จ(๊ณผ์—ฐ?)ํ•ด๋ณด์—ฌ๋„ ์‹ค์ œ ๊ตฌ๋™๋ฐฉ์‹ ์ดํ•ด ์ž์ฒด๊ฐ€ ์ดˆ๋ฐ˜์— ์•ˆ๋˜์„œ, ์‚ฌํ˜ ๋‚จ์ง“ ๊ฑธ๋ฆฐ ๋•์— ๋” ์–ด๋ ค์› ๋˜ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ๊ทธ ์™ธ myeks-bastion-2์— ์ ‘์† ์‹œ, ํ•จ๊ป˜ ์ง„ํ–‰ํ•  ๋•Œ๋Š” ssh {Public IP}๋กœ ์ž˜ ์ ‘์†๋˜๋Š” ๊ฑธ ๋ดค๋Š”๋ฐ ์ •์ž‘ ํ˜ผ์ž ํ•  ๋• ์ ‘์†์ด ๋˜์ง€์•Š์•˜์Šต๋‹ˆ๋‹ค.

AWS EKS ์Šคํ„ฐ๋”” 5์ฃผ์ฐจ - Autoscaling

  • kkumtree

2023-05-22T19:23:37+09:00

์ด๋ฒˆ ์ฃผ์ฐจ๋Š” ์˜คํ† ์Šค์ผ€์ผ๋ง์„ ๋ฉ”์ธ์œผ๋กœ ํ•˜์—ฌ, ์ˆ˜ํ‰/์ˆ˜์ง ํ”„๋กœ๋น„์ €๋‹์„ ํ•™์Šตํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค. ๋งˆ์ง€๋ง‰์—๋Š” ๊ณ ์„ฑ๋Šฅ ์˜คํ† ์Šค์ผ€์ผ๋Ÿฌ์ธ Karpenter๋ฅผ ๋ณ„๋„๋กœ ์‹ค์Šตํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค. ํŠนํžˆ.. HPA custom metrics(์‚ฌ์šฉ์ž ์ •์˜ ๋ฉ”ํŠธ๋ฆญ) ์ ์šฉ YAML ์„ค์ •๊ฐ’์„ CPU๋กœ ๋งž์ถ˜ ๊ฒƒ์„ ์žŠ๊ณ , ํ”„๋กœ๋น„์ €๋‹์„ ์ž˜๋ชป ์˜ˆ์ธกํ•œ ๊ฒƒ๋„ ํ•จ๊ป˜ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค. AutoScaling HPA: Horizontal Pod Autoscaler VPA: Vertical Pod Autoscaler CA: Cluster Autoscaler ๊ฐ CSP ์˜์กด์ , ์›Œ์ปค ๋…ธ๋“œ ๋ ˆ๋ฒจ์—์„œ์˜ ์˜คํ† ์Šค์ผ€์ผ๋ง 1. ์‹ค์Šต ํ™˜๊ฒฝ ๋ฐฐํฌ 4์ฃผ์ฐจ์˜ ์ดˆ๊ธฐ ๋ฐฐํฌ ๋‚ด์šฉ์— p8s ๋ฐ Grafana๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ๋ฐฐํฌ verticalPodAutoscaler ํ™œ์„ฑํ™” ์ถ”์ฒœ ๋Œ€์‹œ๋ณด๋“œ: 15757, 17900, 15172 curl -O https://s3.

AWS EKS ์Šคํ„ฐ๋”” 4์ฃผ์ฐจ - Observability

  • kkumtree

2023-05-21T06:13:52+09:00

์ด๋ฒˆ ์ฃผ์ฐจ์—๋Š” Observability์— ๋Œ€ํ•ด ์Šคํ„ฐ๋””๊ฐ€ ์ง„ํ–‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ž์› ๋ชจ๋‹ˆํ„ฐ๋ง ํˆด๋“ค์˜ ์ ์šฉ ๋ฐ ์‚ฌ์šฉ์ด ์ค‘์‹ฌ์ž…๋‹ˆ๋‹ค. ๊ทธ๋‚˜์ €๋‚˜ k8s 1.26์—์„œ metrics์˜ ์ผ๋ถ€ ๋ช…์นญ์ด ๋ฐ”๋€Œ๋Š” ๊ฑธ ๋ณด๊ณ  ์‹๊ฒํ–ˆ์Šต๋‹ˆ๋‹ค. (etcd_db_total_size_bytes ๋Œ€์‹ , apiserver_storage_db_total_size_in_bytes ์œผ๋กœ ๋ณ€๊ฒฝ) ๋˜ํ•œ kubecost์˜ ๊ฒฝ์šฐ, cloudformation ์Šคํƒ ์ œ๊ฑฐ ํ›„์—๋„ ๋ณผ๋ฅจ ๋ฐ์ดํ„ฐ๊ฐ€ ๋‚จ์•„์žˆ์–ด์„œ ๋ณ„๋„๋กœ ์‚ญ์ œํ•ด์•ผ ํ–ˆ์Šต๋‹ˆ๋‹ค. 1. ์‹ค์Šตํ™˜๊ฒฝ ๋ฐฐํฌ NAT๊ฒŒ์ดํŠธ์›จ์ด, EBS addon, IAM role, ISRA for LB/EFS, PreCommand ํฌํ•จ ๋…ธ๋“œ: t3.xlarge t3a.xlarge(AMD)๋Š” ์„œ์šธ ๋ฆฌ์ „ b AZ(ap-northeast-2b)์—์„œ ๋ฏธ์ง€์› ๋” ๋งŽ์€ ๊ฐ’๋“ค์ด ์ž…๋ ฅ๋˜์–ด์„œ, ์ƒ์„ฑ ์™„๋ฃŒ๊นŒ์ง€ ๋” ๋งŽ์€ ์‹œ๊ฐ„์ด ์†Œ์š” (์•ฝ 20์—ฌ๋ถ„ ์ด๋‚ด) curl -O https://s3.

AWS EKS ์Šคํ„ฐ๋”” 3์ฃผ์ฐจ - Storage

  • kkumtree

2023-05-12T05:36:38+09:00

์ด๋ฒˆ ์ฃผ์ฐจ์—๋Š” ์Šคํ† ๋ฆฌ์ง€์— ๋Œ€ํ•ด ์‹ค์Šต์„ ์ง„ํ–‰ํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค. ์ง€๋‚œ๋ฒˆ kOps ์Šคํ„ฐ๋””์—์„œ ๋‹ค๋ฃจ์—ˆ๋˜ ๋‚ด์šฉ์ด์ง€๋งŒ, ๋ถ€์กฑํ–ˆ๋˜ ๋‚ด์šฉ์„ ๋ณด์ถฉํ•˜๋ฉด์„œ ์ž‘์„ฑ์„ ํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค. ์ฃผ์š”ํ•œ ๋‚ด์šฉ์€… NodeAffinity๋ฅผ ์ด์šฉํ•œ ๋ผ๋ฒจ๋ง AWS EBS controller์˜ ๊ฒฝ์šฐ, AWS managed policy๋ฅผ ํ™œ์šฉ AWS Volume SnapShots Controller๋ฅผ ํ†ตํ•œ ๋ณผ๋ฅจ ๋ฐฑ์—… AWS EFS controller์—์„œ์˜ ๋™์  ํ”„๋กœ๋น„์ €๋‹ AWS EKS ์‹ ๊ทœ ๋…ธ๋“œ๊ทธ๋ฃน ์ƒ์„ฑ ๋ณ„๋„๋กœ kube-ops-view์˜ ๊ฒฝ์šฐ, ์›น์œผ๋กœ ํ™•์ธํ•  ์ˆ˜ ์žˆ์„ ๋•Œ๊นŒ์ง€ ์‹œ๊ฐ„์ด ์†Œ์š”๋œ๋‹ค๋Š” ์ ์ด ์žˆ์Šต๋‹ˆ๋‹ค. 1. ์‹ค์Šต ํ™˜๊ฒฝ ๋ฐฐํฌ 2์ฃผ์ฐจ์— ์‹ค์Šตํ–ˆ๋˜ ๋‚ด์šฉ๋“ค์„ ๋ฏธ๋ฆฌ ๋ฐฐํฌ AWS LB ExternalDNS kube-ops-view context ์ด๋ฆ„ ๋ณ€๊ฒฝ ์ง€๋‚œ ๋ฒˆ๊นŒ์ง€ pkos๊ฐ€ ๋œจ๋Š” ํ˜„์ƒ์ด ์žˆ์—ˆ๋Š”๋ฐ, ๋‹‰๋„ค์ž„์„ ๋ณ„๋„ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Œ EFS ์ƒ์„ฑ ๊ด€๋ จ cloudformation์ด ์ถ”๊ฐ€๋˜์—ˆ์Œ EFS FS ID ์กฐํšŒ๋ฅผ ํ•˜๊ธฐ ์œ„ํ•ด aws-cli ํ•„ํ„ฐ ํ™œ์šฉ (์ถœ์ฒ˜: AWS Docs) # ์‹ค์Šต YAML ํŒŒ์ผ curl -O https://s3.

  1. First page
  2. Previous page
  3. 1
  4. 2
  5. Next page
  6. Last page