Hands-On Microservices With Kubernetes: Build, Deploy, And Manage Scalable Microservices On Kubernetes
Book information
Description
Kubernetes is an open source container management and orchestration platform. It has been giving a decent competition to spring cloud environment, claiming to be the best environment for developing and running Microservices. Hands-on Microservices with Kubernetes will help you successfully create or evolve your system using the best practices. To start with, you will learn the synergy of both Kubernetes and microservices in detail. You will discover how to use Delinkcious, which will serve as a live lab throughout the book to explain the concepts in the context of a real-world application. Next, you will set up a CI/CD pipeline and configure microservices using Kubernetes ConfigMaps. Going ahead, you will get a hands-on experience for securing microservices, implementing REST and gRPC APIs as well as the Delinkcious data store. You will also explore the Fission and Kubeless project, run a serverless task on Kubernetes and manage and implement data-intensive tests. In addition to this, you will get to grips with deploying microservices on Kubernetes and the art of maintaining a well-monitored system. Towards the end, you will learn about Service Mesh and its working with Istio in a Delinkcious cluster. By the end of this book, you'll be able to implement microservices on Kubernetes with the help of the best tools and practices. Cover......Page 1 Title Page......Page 2 Copyright and Credits......Page 3 About Packt......Page 4 Contributors......Page 5 Table of Contents......Page 7 Preface......Page 19 Technical requirements......Page 24 Kubernetes – the container orchestration platform......Page 25 The state of Kubernetes......Page 26 Understanding the Kubernetes architecture......Page 27 The scheduler......Page 28 The kubelet......Page 29 Kubectl......Page 30 Packaging and deploying microservices......Page 31 Securing microservices......Page 34 Secrets......Page 35 Network policies......Page 36 Role-based access control......Page 37 Upgrading microservices......Page 38 Monitoring microservices......Page 39 Logging......Page 40 Installing Minikube......Page 41 Verifying your cluster......Page 43 Playing with your cluster......Page 44 Installing Helm......Page 45 Further reading......Page 47 Chapter 2: Getting Started with Microservices......Page 48 Programming in the small – less is more......Page 49 Employing interfaces and contracts......Page 52 Exposing your service via APIs......Page 53 Managing dependencies......Page 54 The uniformity versus flexibility trade-off......Page 55 Taking advantage of ownership......Page 56 Understanding Conway's law......Page 57 Matrix......Page 58 Troubleshooting across multiple services......Page 59 Choosing a source control strategy......Page 60 Multiple repos......Page 61 One data store per microservice......Page 62 Employing Command Query Responsibility Segregation......Page 64 Employing API composition......Page 65 Using sagas to manage transactions across multiple services......Page 66 Understanding the CAP theorem......Page 67 Applying the saga pattern to microservices......Page 68 Further reading......Page 69 Chapter 3: Delinkcious - the Sample Application......Page 70 LiteIDE......Page 71 Choosing Go for Delinkcious......Page 72 Getting to know Go kit......Page 73 Structuring microservices with Go kit......Page 74 Understanding transports......Page 75 Understanding endpoints......Page 76 Understanding middleware......Page 77 Generating the boilerplate......Page 78 The cmd subdirectory......Page 79 The pkg subdirectory......Page 80 Introducing the Delinkcious microservices......Page 81 The object model......Page 82 The service implementation......Page 84 Implementing the support functions......Page 87 Invoking the API via a client library......Page 90 Storing data......Page 94 Further reading......Page 97 Technical requirements......Page 98 Understanding a CI/CD pipeline......Page 99 Options for the Delinkcious CI/CD pipeline......Page 100 Spinnaker......Page 101 Tekton......Page 102 Rolling your own......Page 103 Building your images with CircleCI......Page 104 Reviewing the source tree......Page 105 Configuring the CI pipeline......Page 106 Understanding the build.sh script......Page 108 Dockerizing a Go service with a multi-stage Dockerfile......Page 110 Exploring the CircleCI UI......Page 111 Considering future improvements......Page 113 Deploying a Delinkcious microservice......Page 114 Argo CD utilizes GitOps......Page 116 Getting started with Argo CD......Page 117 Configuring Argo CD......Page 119 Exploring Argo CD......Page 121 Summary......Page 126 Further reading......Page 127 Technical requirements......Page 128 What is configuration all about?......Page 129 Convention over configuration......Page 130 Command-line flags......Page 131 Environment variables......Page 132 INI format......Page 133 XML format......Page 134 YAML format......Page 135 TOML format......Page 136 Proprietary formats......Page 137 Hybrid configuration and defaults......Page 139 Managing configuration dynamically......Page 140 When is dynamic configuration useful?......Page 141 Remote configuration store......Page 142 Configuring microservices with Kubernetes......Page 143 Working with Kubernetes ConfigMaps......Page 144 Creating and managing ConfigMaps......Page 148 Applying advanced configuration......Page 154 Kubernetes custom resources......Page 155 Summary......Page 158 Further reading......Page 159 Chapter 6: Securing Microservices on Kubernetes......Page 160 Applying sound security principles......Page 161 User accounts......Page 164 Service accounts......Page 165 Managing secrets with Kubernetes......Page 168 Understanding the three types of Kubernetes secret......Page 169 Creating your own secrets......Page 170 Passing secrets to containers......Page 171 Building a secure pod......Page 172 Managing permissions with RBAC......Page 174 Authenticating microservices......Page 178 Authorizing microservices......Page 182 Always pull images......Page 183 Using minimal base images......Page 184 Dividing and conquering your network......Page 185 Safeguarding your image registry......Page 187 Granting access to Kubernetes resources as needed......Page 188 Using quotas to minimize the blast radius......Page 189 Implementing security contexts......Page 191 Hardening your pods with security policies......Page 193 Authorization via RBAC......Page 194 Summary......Page 195 Further reading......Page 196 Technical requirements......Page 197 Getting familiar with Kubernetes services......Page 198 Service types in Kubernetes......Page 200 East-west versus north-south communication......Page 201 Building a Python-based API gateway service......Page 202 Implementing social login......Page 203 Routing traffic to internal microservices......Page 206 Utilizing base Docker images to reduce build time......Page 207 Adding ingress......Page 208 Finding the Delinkcious URL......Page 209 Getting an access token......Page 210 Hitting the Delinkcious API gateway from outside the cluster......Page 212 Implementing the news manager package......Page 214 Exposing NewsManager as a gRPC service......Page 217 Defining the gRPC service contract......Page 218 Generating service stubs and client libraries with gRPC......Page 219 Using Go-kit to build the NewsManager service......Page 220 Implementing the gRPC transport......Page 221 What is NATS?......Page 224 Deploying NATS in the cluster......Page 225 Sending link events with NATS......Page 226 Subscribing to link events with NATS......Page 229 Handling link events......Page 231 Understanding service meshes......Page 232 Further reading......Page 233 Technical requirements......Page 234 The Kubernetes storage model......Page 235 Volumes, persistent volumes, and provisioning......Page 236 Persistent volume claims......Page 237 In-tree and out-of-tree storage plugins......Page 240 Understanding CSI......Page 241 Storing data outside your Kubernetes cluster......Page 243 Understanding a StatefulSet......Page 244 StatefulSet components......Page 246 Orderliness......Page 248 Reviewing a large StatefulSet example......Page 249 A quick introduction to Cassandra......Page 250 Deploying Cassandra on Kubernetes using StatefulSets......Page 251 Storing your data in memory......Page 254 Understanding where the data is stored......Page 255 Using a deployment and service......Page 256 Helping the user service locate StatefulSet pods......Page 257 Managing schema changes......Page 259 An introduction to Redis......Page 260 Persisting events in the news service......Page 261 Further reading......Page 265 Technical requirements......Page 266 Serverless in the cloud......Page 268 Microservices and serverless functions......Page 269 Building, configuring, and deploying serverless functions......Page 270 Designing link checks......Page 271 Implementing link checks......Page 274 Serverless link checking with Nuclio......Page 277 A quick introduction to Nuclio......Page 278 Creating a link checker serverless function......Page 279 Deploying the link checker function with nuctl......Page 282 Deploying a function using the Nuclio dashboard......Page 284 Invoking the link-checker function directly......Page 285 Triggering link checking in LinkManager......Page 286 Kubernetes Jobs and CronJobs......Page 287 KNative......Page 288 Kubeless......Page 289 Summary......Page 290 Further reading......Page 291 Chapter 10: Testing Microservices......Page 292 Unit testing with Go......Page 293 Unit testing with Ginkgo and Gomega......Page 296 Designing for testability......Page 297 The art of mocking......Page 298 Implementing the LinkManager unit tests......Page 300 Should you test everything?......Page 302 Integration testing......Page 303 Running services......Page 304 Running the actual test......Page 305 Implementing database test helpers......Page 306 Checking errors......Page 310 Stopping a local service......Page 311 Writing a smoke test......Page 312 Running the test......Page 315 Telepresence......Page 316 Running a local link service via Telepresence......Page 317 Attaching to the local link service with GoLand for live debugging......Page 319 Isolating tests......Page 320 Cluster per developer......Page 321 Cross namespace/cluster......Page 322 Acceptance testing......Page 323 Performance testing......Page 324 Manual test data......Page 325 Summary......Page 326 Further reading......Page 327 Chapter 11: Deploying Microservices......Page 328 Kubernetes deployments......Page 329 Deploying to multiple environments......Page 331 Recreating deployment......Page 335 Rolling updates......Page 336 Blue-green deployment......Page 338 Adding deployment – the blue label......Page 340 Updating the link-manager service to match blue pods only......Page 341 Bumping the version number......Page 342 Letting CircleCI build the new image......Page 343 Deploying the new (green) version......Page 344 Verifying that the service now uses the green pods to serve requests......Page 346 Canary deployments......Page 347 Employing a basic canary deployment for Delinkcious......Page 349 Rolling back deployments......Page 353 Rolling back standard Kubernetes deployments......Page 354 Rolling back canary deployments......Page 355 Dealing with a rollback after a schema, API, or payload change......Page 356 Managing public APIs......Page 357 Managing cross-service dependencies......Page 358 Managing third-party dependencies......Page 359 Local development deployments......Page 360 Ko......Page 361 Ksync......Page 365 Draft......Page 367 Skaffold......Page 368 Tilt......Page 371 Summary......Page 378 Further reading......Page 379 Chapter 12: Monitoring, Logging, and Metrics......Page 380 Self-healing with Kubernetes......Page 381 Container failures......Page 382 Systemic failures......Page 384 Horizontal pod autoscaling......Page 385 Using the horizontal pod autoscaler......Page 386 Cluster autoscaling......Page 388 Vertical pod autoscaling......Page 389 What resources should you provision?......Page 391 Defining container limits......Page 392 Specifying resource quotas......Page 394 Rolling your own automated provisioning......Page 395 Getting performance right......Page 396 Performance and cost......Page 397 Logging......Page 398 The quest for the perfect Go logging interface......Page 399 Setting up a logger with Go-kit......Page 400 Using a logging middleware......Page 402 Centralized logging with Kubernetes......Page 405 Introducing the Kubernetes metrics API......Page 406 Understanding the Kubernetes metrics server......Page 407 Deploying Prometheus into the cluster......Page 409 Recording custom metrics from Delinkcious......Page 414 Embracing component failure......Page 418 Warnings versus alerts......Page 419 Fine-tuning noisy alerts......Page 420 Utilizing the Prometheus alert manager......Page 421 Distributed tracing......Page 422 Installing Jaeger......Page 423 Integrating tracing into your services......Page 425 Further reading......Page 427 Technical requirements......Page 428 Comparing monoliths to microservices......Page 430 Using a shared library to manage the cross-cutting concerns of microservices......Page 431 Using a service mesh to manage the cross-cutting concerns of microservices......Page 432 Understanding the relationship between Kubernetes and a service mesh......Page 433 Getting to know the Istio architecture......Page 434 Envoy......Page 435 Mixer......Page 436 Managing traffic with Istio......Page 437 Load balancing......Page 438 Handling failures......Page 439 Doing canary deployments......Page 441 Securing your cluster with Istio......Page 442 Authenticating users with Istio......Page 443 Authorizing requests with Istio......Page 444 Collecting metrics with Istio......Page 447 When should you avoid Istio?......Page 449 Removing mutual authentication between services......Page 450 Utilizing better canary deployments......Page 453 Automatic logging and error reporting......Page 454 Accommodating NATS......Page 456 Examining the Istio footprint......Page 457 Alternatives to Istio......Page 459 HashiCorp Consul......Page 460 Summary......Page 461 Further reading......Page 462 Chapter 14: The Future of Microservices and Kubernetes......Page 463 Microservices versus serverless functions......Page 464 gRPC and gRPC-Web......Page 465 HTTP/3 is coming......Page 466 The future of Kubernetes......Page 467 Abstracting the container runtime......Page 468 Abstracting storage......Page 469 The cloud provider interface......Page 470 Service mesh integration......Page 471 Serverless computing on Kubernetes......Page 472 Kubernetes and VMs......Page 473 Kata containers......Page 474 Using operators......Page 475 Federation......Page 477 Summary......Page 478 Further reading......Page 479 Other Books You May Enjoy......Page 480 Index......Page 483
Similar books
Kubernetes и сети. Многоуровневый подход
2024 · PDF
Quick Start Kubernetes
Reactive Microsystems - The Evolution of Microservices at Scale
2017 · PDF
MICROSERVICES From Design to Deployment
2016 · PDF
Mastering Kubernetes: Master The Art Of Container Management By Using The Power Of Kubernetes
2018 · PDF
Microservices: Science And Engineering
2020 · PDF
Developing Open Cloud Native Microservices - Your Java Code in Action.
2019 · PDF
The Complete Kubernetes Guide
2019 · PDF