1694 lines
92 KiB
HTML
1694 lines
92 KiB
HTML
|
|
||
|
<!DOCTYPE HTML>
|
||
|
<html lang="zh-cn" >
|
||
|
<head>
|
||
|
<meta charset="UTF-8">
|
||
|
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
|
||
|
<title>2.2.14 Ingress · Kubernetes Handbook</title>
|
||
|
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
|
||
|
<meta name="description" content="">
|
||
|
<meta name="generator" content="GitBook 3.2.2">
|
||
|
<meta name="author" content="Jimmy Song">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/style.css">
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-splitter/splitter.css">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-page-toc-button/plugin.css">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-image-captions/image-captions.css">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-page-footer-ex/style/plugin.css">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-search-plus/search.css">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-highlight/website.css">
|
||
|
|
||
|
|
||
|
|
||
|
<link rel="stylesheet" href="../gitbook/gitbook-plugin-fontsettings/website.css">
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
<meta name="HandheldFriendly" content="true"/>
|
||
|
<meta name="viewport" content="width=device-width, initial-scale=1, user-scalable=no">
|
||
|
<meta name="apple-mobile-web-app-capable" content="yes">
|
||
|
<meta name="apple-mobile-web-app-status-bar-style" content="black">
|
||
|
<link rel="apple-touch-icon-precomposed" sizes="152x152" href="../gitbook/images/apple-touch-icon-precomposed-152.png">
|
||
|
<link rel="shortcut icon" href="../gitbook/images/favicon.ico" type="image/x-icon">
|
||
|
|
||
|
|
||
|
<link rel="next" href="configmap.html" />
|
||
|
|
||
|
|
||
|
<link rel="prev" href="cronjob.html" />
|
||
|
|
||
|
|
||
|
</head>
|
||
|
<body>
|
||
|
|
||
|
<div class="book">
|
||
|
<div class="book-summary">
|
||
|
|
||
|
|
||
|
<div id="book-search-input" role="search">
|
||
|
<input type="text" placeholder="輸入並搜尋" />
|
||
|
</div>
|
||
|
|
||
|
|
||
|
<nav role="navigation">
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="summary">
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.1" data-path="../">
|
||
|
|
||
|
<a href="../">
|
||
|
|
||
|
|
||
|
1. 前言
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2" data-path="./">
|
||
|
|
||
|
<a href="./">
|
||
|
|
||
|
|
||
|
2. 概念原理
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.2.1" data-path="concepts.html">
|
||
|
|
||
|
<a href="concepts.html">
|
||
|
|
||
|
|
||
|
2.1 设计理念
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2" data-path="objects.html">
|
||
|
|
||
|
<a href="objects.html">
|
||
|
|
||
|
|
||
|
2.2 主要概念
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.1" data-path="pod-overview.html">
|
||
|
|
||
|
<a href="pod-overview.html">
|
||
|
|
||
|
|
||
|
2.2.1 Pod
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.1.1" data-path="pod.html">
|
||
|
|
||
|
<a href="pod.html">
|
||
|
|
||
|
|
||
|
2.2.1.1 Pod解析
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.2" data-path="node.html">
|
||
|
|
||
|
<a href="node.html">
|
||
|
|
||
|
|
||
|
2.2.2 Node
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.3" data-path="namespace.html">
|
||
|
|
||
|
<a href="namespace.html">
|
||
|
|
||
|
|
||
|
2.2.3 Namespace
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.4" data-path="service.html">
|
||
|
|
||
|
<a href="service.html">
|
||
|
|
||
|
|
||
|
2.2.4 Service
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.5" data-path="volume.html">
|
||
|
|
||
|
<a href="volume.html">
|
||
|
|
||
|
|
||
|
2.2.5 Volume和Persistent Volume
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.6" data-path="deployment.html">
|
||
|
|
||
|
<a href="deployment.html">
|
||
|
|
||
|
|
||
|
2.2.6 Deployment
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.7" data-path="secret.html">
|
||
|
|
||
|
<a href="secret.html">
|
||
|
|
||
|
|
||
|
2.2.7 Secret
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.8" data-path="statefulset.html">
|
||
|
|
||
|
<a href="statefulset.html">
|
||
|
|
||
|
|
||
|
2.2.8 StatefulSet
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.9" data-path="daemonset.html">
|
||
|
|
||
|
<a href="daemonset.html">
|
||
|
|
||
|
|
||
|
2.2.9 DaemonSet
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.10" data-path="serviceaccount.html">
|
||
|
|
||
|
<a href="serviceaccount.html">
|
||
|
|
||
|
|
||
|
2.2.10 ServiceAccount
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.11" data-path="replicaset.html">
|
||
|
|
||
|
<a href="replicaset.html">
|
||
|
|
||
|
|
||
|
2.2.11 ReplicationController和ReplicaSet
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.12" data-path="job.html">
|
||
|
|
||
|
<a href="job.html">
|
||
|
|
||
|
|
||
|
2.2.12 Job
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.13" data-path="cronjob.html">
|
||
|
|
||
|
<a href="cronjob.html">
|
||
|
|
||
|
|
||
|
2.2.13 CronJob
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter active" data-level="1.2.2.14" data-path="ingress.html">
|
||
|
|
||
|
<a href="ingress.html">
|
||
|
|
||
|
|
||
|
2.2.14 Ingress
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.15" data-path="configmap.html">
|
||
|
|
||
|
<a href="configmap.html">
|
||
|
|
||
|
|
||
|
2.2.15 ConfigMap
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.16" data-path="horizontal-pod-autoscaling.html">
|
||
|
|
||
|
<a href="horizontal-pod-autoscaling.html">
|
||
|
|
||
|
|
||
|
2.2.16 Horizontal Pod Autoscaling
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.2.2.17" data-path="label.html">
|
||
|
|
||
|
<a href="label.html">
|
||
|
|
||
|
|
||
|
2.2.17 Label
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3" data-path="../guide/">
|
||
|
|
||
|
<a href="../guide/">
|
||
|
|
||
|
|
||
|
3. 用户指南
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.3.1" data-path="../guide/resource-configuration.html">
|
||
|
|
||
|
<a href="../guide/resource-configuration.html">
|
||
|
|
||
|
|
||
|
3.1 资源配置
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.3.1.1" data-path="../guide/configure-liveness-readiness-probes.html">
|
||
|
|
||
|
<a href="../guide/configure-liveness-readiness-probes.html">
|
||
|
|
||
|
|
||
|
3.1.1 配置Pod的liveness和readiness探针
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.1.2" data-path="../guide/configure-pod-service-account.html">
|
||
|
|
||
|
<a href="../guide/configure-pod-service-account.html">
|
||
|
|
||
|
|
||
|
3.1.2 配置Pod的Service Account
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.2" data-path="../guide/command-usage.html">
|
||
|
|
||
|
<a href="../guide/command-usage.html">
|
||
|
|
||
|
|
||
|
3.2 命令使用
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.3.2.1" data-path="../guide/using-kubectl.html">
|
||
|
|
||
|
<a href="../guide/using-kubectl.html">
|
||
|
|
||
|
|
||
|
3.2.1 使用kubectl
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.3" data-path="../guide/cluster-management.html">
|
||
|
|
||
|
<a href="../guide/cluster-management.html">
|
||
|
|
||
|
|
||
|
3.3 集群管理
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.3.3.1" data-path="../guide/managing-tls-in-a-cluster.html">
|
||
|
|
||
|
<a href="../guide/managing-tls-in-a-cluster.html">
|
||
|
|
||
|
|
||
|
3.3.1 管理集群中的TLS
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.4" data-path="../guide/access-kubernetes-cluster.html">
|
||
|
|
||
|
<a href="../guide/access-kubernetes-cluster.html">
|
||
|
|
||
|
|
||
|
3.4 访问 Kubernetes 集群
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.3.4.1" data-path="../guide/access-cluster.html">
|
||
|
|
||
|
<a href="../guide/access-cluster.html">
|
||
|
|
||
|
|
||
|
3.4.1 访问集群
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.4.2" data-path="../guide/authenticate-across-clusters-kubeconfig.html">
|
||
|
|
||
|
<a href="../guide/authenticate-across-clusters-kubeconfig.html">
|
||
|
|
||
|
|
||
|
3.4.2 使用 kubeconfig 文件配置跨集群认证
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.4.3" data-path="../guide/connecting-to-applications-port-forward.html">
|
||
|
|
||
|
<a href="../guide/connecting-to-applications-port-forward.html">
|
||
|
|
||
|
|
||
|
3.4.3 通过端口转发访问集群中的应用程序
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.4.4" data-path="../guide/service-access-application-cluster.html">
|
||
|
|
||
|
<a href="../guide/service-access-application-cluster.html">
|
||
|
|
||
|
|
||
|
3.4.4 使用 service 访问群集中的应用程序
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.3.5" data-path="../guide/application-development-deployment-flow.html">
|
||
|
|
||
|
<a href="../guide/application-development-deployment-flow.html">
|
||
|
|
||
|
|
||
|
3.5 在kubernetes中开发部署应用
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.3.5.1" data-path="../guide/deploy-applications-in-kubernetes.html">
|
||
|
|
||
|
<a href="../guide/deploy-applications-in-kubernetes.html">
|
||
|
|
||
|
|
||
|
3.5.1 适用于kubernetes的应用开发部署流程
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4" data-path="../practice/">
|
||
|
|
||
|
<a href="../practice/">
|
||
|
|
||
|
|
||
|
4. 最佳实践
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1" data-path="../practice/install-kbernetes1.6-on-centos.html">
|
||
|
|
||
|
<a href="../practice/install-kbernetes1.6-on-centos.html">
|
||
|
|
||
|
|
||
|
4.1 在CentOS上部署kubernetes1.6集群
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.1" data-path="../practice/create-tls-and-secret-key.html">
|
||
|
|
||
|
<a href="../practice/create-tls-and-secret-key.html">
|
||
|
|
||
|
|
||
|
4.1.1 创建TLS证书和秘钥
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.2" data-path="../practice/create-kubeconfig.html">
|
||
|
|
||
|
<a href="../practice/create-kubeconfig.html">
|
||
|
|
||
|
|
||
|
4.1.2 创建kubeconfig文件
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.3" data-path="../practice/etcd-cluster-installation.html">
|
||
|
|
||
|
<a href="../practice/etcd-cluster-installation.html">
|
||
|
|
||
|
|
||
|
4.1.3 创建高可用etcd集群
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.4" data-path="../practice/kubectl-installation.html">
|
||
|
|
||
|
<a href="../practice/kubectl-installation.html">
|
||
|
|
||
|
|
||
|
4.1.4 安装kubectl命令行工具
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.5" data-path="../practice/master-installation.html">
|
||
|
|
||
|
<a href="../practice/master-installation.html">
|
||
|
|
||
|
|
||
|
4.1.5 部署master节点
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.6" data-path="../practice/node-installation.html">
|
||
|
|
||
|
<a href="../practice/node-installation.html">
|
||
|
|
||
|
|
||
|
4.1.6 部署node节点
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.7" data-path="../practice/kubedns-addon-installation.html">
|
||
|
|
||
|
<a href="../practice/kubedns-addon-installation.html">
|
||
|
|
||
|
|
||
|
4.1.7 安装kubedns插件
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.8" data-path="../practice/dashboard-addon-installation.html">
|
||
|
|
||
|
<a href="../practice/dashboard-addon-installation.html">
|
||
|
|
||
|
|
||
|
4.1.8 安装dashboard插件
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.9" data-path="../practice/heapster-addon-installation.html">
|
||
|
|
||
|
<a href="../practice/heapster-addon-installation.html">
|
||
|
|
||
|
|
||
|
4.1.9 安装heapster插件
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.1.10" data-path="../practice/efk-addon-installation.html">
|
||
|
|
||
|
<a href="../practice/efk-addon-installation.html">
|
||
|
|
||
|
|
||
|
4.1.10 安装EFK插件
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.2" data-path="../practice/service-discovery-and-loadbalancing.html">
|
||
|
|
||
|
<a href="../practice/service-discovery-and-loadbalancing.html">
|
||
|
|
||
|
|
||
|
4.2 服务发现与负载均衡
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.4.2.1" data-path="../practice/traefik-ingress-installation.html">
|
||
|
|
||
|
<a href="../practice/traefik-ingress-installation.html">
|
||
|
|
||
|
|
||
|
4.2.1 安装Traefik ingress
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.2.2" data-path="../practice/distributed-load-test.html">
|
||
|
|
||
|
<a href="../practice/distributed-load-test.html">
|
||
|
|
||
|
|
||
|
4.2.2 分布式负载测试
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.2.3" data-path="../practice/network-and-cluster-perfermance-test.html">
|
||
|
|
||
|
<a href="../practice/network-and-cluster-perfermance-test.html">
|
||
|
|
||
|
|
||
|
4.2.3 网络和集群性能测试
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.2.4" data-path="../practice/edge-node-configuration.html">
|
||
|
|
||
|
<a href="../practice/edge-node-configuration.html">
|
||
|
|
||
|
|
||
|
4.2.4 边缘节点配置
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3" data-path="../practice/operation.html">
|
||
|
|
||
|
<a href="../practice/operation.html">
|
||
|
|
||
|
|
||
|
4.3 运维管理
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3.1" data-path="../practice/service-rolling-update.html">
|
||
|
|
||
|
<a href="../practice/service-rolling-update.html">
|
||
|
|
||
|
|
||
|
4.3.1 服务滚动升级
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3.2" data-path="../practice/app-log-collection.html">
|
||
|
|
||
|
<a href="../practice/app-log-collection.html">
|
||
|
|
||
|
|
||
|
4.3.2 应用日志收集
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3.3" data-path="../practice/configuration-best-practice.html">
|
||
|
|
||
|
<a href="../practice/configuration-best-practice.html">
|
||
|
|
||
|
|
||
|
4.3.3 配置最佳实践
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3.4" data-path="../practice/monitor.html">
|
||
|
|
||
|
<a href="../practice/monitor.html">
|
||
|
|
||
|
|
||
|
4.3.4 集群及应用监控
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3.5" data-path="../practice/jenkins-ci-cd.html">
|
||
|
|
||
|
<a href="../practice/jenkins-ci-cd.html">
|
||
|
|
||
|
|
||
|
4.3.5 使用Jenkins进行持续构建与发布
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.3.6" data-path="../practice/data-persistence-problem.html">
|
||
|
|
||
|
<a href="../practice/data-persistence-problem.html">
|
||
|
|
||
|
|
||
|
4.3.6 数据持久化问题
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.4" data-path="../practice/storage.html">
|
||
|
|
||
|
<a href="../practice/storage.html">
|
||
|
|
||
|
|
||
|
4.4 存储管理
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.4.4.1" data-path="../practice/glusterfs.html">
|
||
|
|
||
|
<a href="../practice/glusterfs.html">
|
||
|
|
||
|
|
||
|
4.4.1 GlusterFS
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.4.4.1.1" data-path="../practice/using-glusterfs-for-persistent-storage.html">
|
||
|
|
||
|
<a href="../practice/using-glusterfs-for-persistent-storage.html">
|
||
|
|
||
|
|
||
|
4.4.1.1 使用GlusterFS做持久化存储
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.4.4.1.2" data-path="../practice/storage-for-containers-using-glusterfs-with-openshift.html">
|
||
|
|
||
|
<a href="../practice/storage-for-containers-using-glusterfs-with-openshift.html">
|
||
|
|
||
|
|
||
|
4.4.1.2 在OpenShift中使用GlusterFS做持久化存储
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.5" data-path="../usecases/">
|
||
|
|
||
|
<a href="../usecases/">
|
||
|
|
||
|
|
||
|
5. 领域应用
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1" data-path="../usecases/microservices.html">
|
||
|
|
||
|
<a href="../usecases/microservices.html">
|
||
|
|
||
|
|
||
|
5.1 微服务架构
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1.1" data-path="../usecases/istio.html">
|
||
|
|
||
|
<a href="../usecases/istio.html">
|
||
|
|
||
|
|
||
|
5.1.1 Istio
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1.1.1" data-path="../usecases/istio-installation.html">
|
||
|
|
||
|
<a href="../usecases/istio-installation.html">
|
||
|
|
||
|
|
||
|
5.1.1.1 安装istio
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1.1.2" data-path="../usecases/configuring-request-routing.html">
|
||
|
|
||
|
<a href="../usecases/configuring-request-routing.html">
|
||
|
|
||
|
|
||
|
5.1.1.2 配置请求的路由规则
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1.2" data-path="../usecases/linkerd.html">
|
||
|
|
||
|
<a href="../usecases/linkerd.html">
|
||
|
|
||
|
|
||
|
5.1.2 Linkerd
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1.2.1" data-path="../usecases/linkerd-user-guide.html">
|
||
|
|
||
|
<a href="../usecases/linkerd-user-guide.html">
|
||
|
|
||
|
|
||
|
5.1.2.1 Linkerd 使用指南
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.5.1.3" data-path="../usecases/service-discovery-in-microservices.html">
|
||
|
|
||
|
<a href="../usecases/service-discovery-in-microservices.html">
|
||
|
|
||
|
|
||
|
5.1.3 微服务中的服务发现
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.5.2" data-path="../usecases/big-data.html">
|
||
|
|
||
|
<a href="../usecases/big-data.html">
|
||
|
|
||
|
|
||
|
5.2 大数据
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.5.2.1" data-path="../usecases/spark-on-kubernetes.html">
|
||
|
|
||
|
<a href="../usecases/spark-on-kubernetes.html">
|
||
|
|
||
|
|
||
|
5.2.1 Spark on Kubernetes
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.6" data-path="../develop/">
|
||
|
|
||
|
<a href="../develop/">
|
||
|
|
||
|
|
||
|
6. 开发指南
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.6.1" data-path="../develop/developing-environment.html">
|
||
|
|
||
|
<a href="../develop/developing-environment.html">
|
||
|
|
||
|
|
||
|
6.1 开发环境搭建
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.6.2" data-path="../develop/testing.html">
|
||
|
|
||
|
<a href="../develop/testing.html">
|
||
|
|
||
|
|
||
|
6.2 单元测试和集成测试
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.6.3" data-path="../develop/client-go-sample.html">
|
||
|
|
||
|
<a href="../develop/client-go-sample.html">
|
||
|
|
||
|
|
||
|
6.3 client-go示例
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.6.4" data-path="../develop/contribute.html">
|
||
|
|
||
|
<a href="../develop/contribute.html">
|
||
|
|
||
|
|
||
|
6.4 社区贡献
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.7" data-path="../appendix/">
|
||
|
|
||
|
<a href="../appendix/">
|
||
|
|
||
|
|
||
|
7. 附录
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
<ul class="articles">
|
||
|
|
||
|
|
||
|
<li class="chapter " data-level="1.7.1" data-path="../appendix/docker-best-practice.html">
|
||
|
|
||
|
<a href="../appendix/docker-best-practice.html">
|
||
|
|
||
|
|
||
|
7.1 Docker最佳实践
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.7.2" data-path="../appendix/issues.html">
|
||
|
|
||
|
<a href="../appendix/issues.html">
|
||
|
|
||
|
|
||
|
7.2 问题记录
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
<li class="chapter " data-level="1.7.3" data-path="../appendix/tricks.html">
|
||
|
|
||
|
<a href="../appendix/tricks.html">
|
||
|
|
||
|
|
||
|
7.3 使用技巧
|
||
|
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
</ul>
|
||
|
|
||
|
</li>
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
<li class="divider"></li>
|
||
|
|
||
|
<li>
|
||
|
<a href="https://www.gitbook.com" target="blank" class="gitbook-link">
|
||
|
本書使用 GitBook 釋出
|
||
|
</a>
|
||
|
</li>
|
||
|
</ul>
|
||
|
|
||
|
|
||
|
</nav>
|
||
|
|
||
|
|
||
|
</div>
|
||
|
|
||
|
<div class="book-body">
|
||
|
|
||
|
<div class="body-inner">
|
||
|
|
||
|
|
||
|
|
||
|
<div class="book-header" role="navigation">
|
||
|
|
||
|
|
||
|
<!-- Title -->
|
||
|
<h1>
|
||
|
<i class="fa fa-circle-o-notch fa-spin"></i>
|
||
|
<a href=".." >2.2.14 Ingress</a>
|
||
|
</h1>
|
||
|
</div>
|
||
|
|
||
|
|
||
|
|
||
|
|
||
|
<div class="page-wrapper" tabindex="-1" role="main">
|
||
|
<div class="page-inner">
|
||
|
|
||
|
<div class="search-plus" id="book-search-results">
|
||
|
<div class="search-noresults">
|
||
|
|
||
|
<section class="normal markdown-section">
|
||
|
|
||
|
<h1 id="ingress解析">Ingress解析</h1>
|
||
|
<h2 id="前言">前言</h2>
|
||
|
<p>这是kubernete官方文档中<a href="https://kubernetes.io/docs/concepts/services-networking/ingress/" target="_blank">Ingress Resource</a>的翻译,后面的章节会讲到使用<a href="https://github.com/containous/traefik" target="_blank">Traefik</a>来做Ingress controller,文章末尾给出了几个相关链接。</p>
|
||
|
<p><strong>术语</strong></p>
|
||
|
<p>在本篇文章中你将会看到一些在其他地方被交叉使用的术语,为了防止产生歧义,我们首先来澄清下。</p>
|
||
|
<ul>
|
||
|
<li>节点:Kubernetes集群中的一台物理机或者虚拟机。</li>
|
||
|
<li>集群:位于Internet防火墙后的节点,这是kubernetes管理的主要计算资源。</li>
|
||
|
<li>边界路由器:为集群强制执行防火墙策略的路由器。 这可能是由云提供商或物理硬件管理的网关。</li>
|
||
|
<li>集群网络:一组逻辑或物理链接,可根据Kubernetes<a href="https://kubernetes.io/docs/admin/networking/" target="_blank">网络模型</a>实现群集内的通信。 集群网络的实现包括Overlay模型的 <a href="https://github.com/coreos/flannel#flannel" target="_blank">flannel</a> 和基于SDN的<a href="https://kubernetes.io/docs/admin/ovs-networking/" target="_blank">OVS</a>。</li>
|
||
|
<li>服务:使用标签选择器标识一组pod成为的Kubernetes<a href="https://kubernetes.io/docs/user-guide/services/" target="_blank">服务</a>。 除非另有说明,否则服务假定在集群网络内仅可通过虚拟IP访问。</li>
|
||
|
</ul>
|
||
|
<h2 id="什么是ingress?">什么是Ingress?</h2>
|
||
|
<p>通常情况下,service和pod仅可在集群内部网络中通过IP地址访问。所有到达边界路由器的流量或被丢弃或被转发到其他地方。从概念上讲,可能像下面这样:</p>
|
||
|
<pre><code> internet
|
||
|
|
|
||
|
------------
|
||
|
[ Services ]
|
||
|
</code></pre><p>Ingress是授权入站连接到达集群服务的规则集合。</p>
|
||
|
<pre><code> internet
|
||
|
|
|
||
|
[ Ingress ]
|
||
|
--|-----|--
|
||
|
[ Services ]
|
||
|
</code></pre><p>你可以给Ingress配置提供外部可访问的URL、负载均衡、SSL、基于名称的虚拟主机等。用户通过POST Ingress资源到API server的方式来请求ingress。 <a href="https://kubernetes.io/docs/concepts/services-networking/ingress/#ingress-controllers" target="_blank">Ingress controller</a>负责实现Ingress,通常使用负载平衡器,它还可以配置边界路由和其他前端,这有助于以HA方式处理流量。</p>
|
||
|
<h2 id="先决条件">先决条件</h2>
|
||
|
<p>在使用Ingress resource之前,有必要先了解下面几件事情。Ingress是beta版本的resource,在kubernetes1.1之前还没有。你需要一个<code>Ingress Controller</code>来实现<code>Ingress</code>,单纯的创建一个<code>Ingress</code>没有任何意义。</p>
|
||
|
<p>GCE/GKE会在master节点上部署一个ingress controller。你可以在一个pod中部署任意个自定义的ingress controller。你必须正确地annotate每个ingress,比如 <a href="https://github.com/kubernetes/ingress/tree/master/controllers/nginx#running-multiple-ingress-controllers" target="_blank">运行多个ingress controller</a> 和 <a href="https://github.com/kubernetes/ingress/blob/master/controllers/gce/BETA_LIMITATIONS.md#disabling-glbc" target="_blank">关闭glbc</a>.</p>
|
||
|
<p>确定你已经阅读了Ingress controller的<a href="https://github.com/kubernetes/ingress/blob/master/controllers/gce/BETA_LIMITATIONS.md" target="_blank">beta版本限制</a>。在非GCE/GKE的环境中,你需要在pod中<a href="https://github.com/kubernetes/ingress/tree/master/controllers" target="_blank">部署一个controller</a>。</p>
|
||
|
<h2 id="ingress-resource">Ingress Resource</h2>
|
||
|
<p>最简化的Ingress配置:</p>
|
||
|
<pre><code class="lang-yaml"><span class="hljs-number">1</span>: apiVersion: extensions/v1beta1
|
||
|
<span class="hljs-number">2</span>: kind: Ingress
|
||
|
<span class="hljs-number">3</span>: metadata:
|
||
|
<span class="hljs-number">4</span>: name: test-ingress
|
||
|
<span class="hljs-number">5</span>: spec:
|
||
|
<span class="hljs-number">6</span>: rules:
|
||
|
<span class="hljs-number">7</span>: - http:
|
||
|
<span class="hljs-number">8</span>: paths:
|
||
|
<span class="hljs-number">9</span>: - path: /testpath
|
||
|
<span class="hljs-number">10</span>: backend:
|
||
|
<span class="hljs-number">11</span>: serviceName: test
|
||
|
<span class="hljs-number">12</span>: servicePort: <span class="hljs-number">80</span>
|
||
|
</code></pre>
|
||
|
<p><em>如果你没有配置Ingress controller就将其POST到API server不会有任何用处</em></p>
|
||
|
<p><strong>配置说明</strong></p>
|
||
|
<p><strong>1-4行</strong>:跟Kubernetes的其他配置一样,ingress的配置也需要<code>apiVersion</code>,<code>kind</code>和<code>metadata</code>字段。配置文件的详细说明请查看<a href="https://kubernetes.io/docs/user-guide/deploying-applications" target="_blank">部署应用</a>, <a href="https://kubernetes.io/docs/user-guide/configuring-containers" target="_blank">配置容器</a>和 <a href="https://kubernetes.io/docs/user-guide/working-with-resources" target="_blank">使用resources</a>.</p>
|
||
|
<p><strong>5-7行</strong>: Ingress <a href="https://github.com/kubernetes/community/blob/master/contributors/devel/api-conventions.md#spec-and-status" target="_blank">spec</a> 中包含配置一个loadbalancer或proxy server的所有信息。最重要的是,它包含了一个匹配所有入站请求的规则列表。目前ingress只支持http规则。</p>
|
||
|
<p><strong>8-9行</strong>:每条http规则包含以下信息:一个<code>host</code>配置项(比如for.bar.com,在这个例子中默认是*),<code>path</code>列表(比如:/testpath),每个path都关联一个<code>backend</code>(比如test:80)。在loadbalancer将流量转发到backend之前,所有的入站请求都要先匹配host和path。</p>
|
||
|
<p><strong>10-12行</strong>:正如 <a href="https://kubernetes.io/docs/user-guide/services" target="_blank">services doc</a>中描述的那样,backend是一个<code>service:port</code>的组合。Ingress的流量被转发到它所匹配的backend。</p>
|
||
|
<p><strong>全局参数</strong>:为了简单起见,Ingress示例中没有全局参数,请参阅资源完整定义的<a href="https://releases.k8s.io/master/pkg/apis/extensions/v1beta1/types.go" target="_blank">api参考</a>。 在所有请求都不能跟spec中的path匹配的情况下,请求被发送到Ingress controller的默认后端,可以指定全局缺省backend。</p>
|
||
|
<h2 id="ingress-controllers">Ingress controllers</h2>
|
||
|
<p>为了使Ingress正常工作,集群中必须运行Ingress controller。 这与其他类型的控制器不同,其他类型的控制器通常作为<code>kube-controller-manager</code>二进制文件的一部分运行,在集群启动时自动启动。 你需要选择最适合自己集群的Ingress controller或者自己实现一个。 示例和说明可以在<a href="https://github.com/kubernetes/ingress/tree/master/controllers" target="_blank">这里</a>找到。</p>
|
||
|
<h2 id="在你开始前">在你开始前</h2>
|
||
|
<p>以下文档描述了Ingress资源中公开的一组跨平台功能。 理想情况下,所有的Ingress controller都应该符合这个规范,但是我们还没有实现。 GCE和nginx控制器的文档分别在<a href="https://github.com/kubernetes/ingress/blob/master/controllers/gce/README.md" target="_blank">这里</a>和<a href="https://github.com/kubernetes/ingress/blob/master/controllers/nginx/README.md" target="_blank">这里</a>。<strong>确保您查看控制器特定的文档,以便您了解每个文档的注意事项。</strong></p>
|
||
|
<h2 id="ingress类型">Ingress类型</h2>
|
||
|
<h3 id="单service-ingress">单Service Ingress</h3>
|
||
|
<p>Kubernetes中已经存在一些概念可以暴露单个service(查看<a href="https://kubernetes.io/docs/concepts/services-networking/ingress/#alternatives" target="_blank">替代方案</a>),但是你仍然可以通过Ingress来实现,通过指定一个没有rule的默认backend的方式。</p>
|
||
|
<p>ingress.yaml定义文件:</p>
|
||
|
<pre><code class="lang-Yaml"><span class="hljs-attr">apiVersion:</span> extensions/v1beta1
|
||
|
<span class="hljs-attr">kind:</span> Ingress
|
||
|
<span class="hljs-attr">metadata:</span>
|
||
|
<span class="hljs-attr"> name:</span> test-ingress
|
||
|
<span class="hljs-attr">spec:</span>
|
||
|
<span class="hljs-attr"> backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> testsvc
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
</code></pre>
|
||
|
<p>使用<code>kubectl create -f</code>命令创建,然后查看ingress:</p>
|
||
|
<pre><code class="lang-bash">$ kubectl get ing
|
||
|
NAME RULE BACKEND ADDRESS
|
||
|
<span class="hljs-built_in">test</span>-ingress - testsvc:80 107.178.254.228
|
||
|
</code></pre>
|
||
|
<p> <code>107.178.254.228</code>就是Ingress controller为了实现Ingress而分配的IP地址。<code>RULE</code>列表示所有发送给该IP的流量都被转发到了<code>BACKEND</code>所列的Kubernetes service上。</p>
|
||
|
<h3 id="简单展开">简单展开</h3>
|
||
|
<p>如前面描述的那样,kubernete pod中的IP只在集群网络内部可见,我们需要在边界设置一个东西,让它能够接收ingress的流量并将它们转发到正确的端点上。这个东西一般是高可用的loadbalancer。使用Ingress能够允许你将loadbalancer的个数降低到最少,例如,假如你想要创建这样的一个设置:</p>
|
||
|
<pre><code>foo.bar.com -> 178.91.123.132 -> / foo s1:80
|
||
|
/ bar s2:80
|
||
|
</code></pre><p>你需要一个这样的ingress:</p>
|
||
|
<pre><code class="lang-yaml"><span class="hljs-attr">apiVersion:</span> extensions/v1beta1
|
||
|
<span class="hljs-attr">kind:</span> Ingress
|
||
|
<span class="hljs-attr">metadata:</span>
|
||
|
<span class="hljs-attr"> name:</span> test
|
||
|
<span class="hljs-attr">spec:</span>
|
||
|
<span class="hljs-attr"> rules:</span>
|
||
|
<span class="hljs-attr"> - host:</span> foo.bar.com
|
||
|
<span class="hljs-attr"> http:</span>
|
||
|
<span class="hljs-attr"> paths:</span>
|
||
|
<span class="hljs-attr"> - path:</span> /foo
|
||
|
<span class="hljs-attr"> backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s1
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
<span class="hljs-attr"> - path:</span> /bar
|
||
|
<span class="hljs-attr"> backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s2
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
</code></pre>
|
||
|
<p>使用<code>kubectl create -f</code>创建完ingress后:</p>
|
||
|
<pre><code class="lang-bash">$ kubectl get ing
|
||
|
NAME RULE BACKEND ADDRESS
|
||
|
<span class="hljs-built_in">test</span> -
|
||
|
foo.bar.com
|
||
|
/foo s1:80
|
||
|
/bar s2:80
|
||
|
</code></pre>
|
||
|
<p>只要服务(s1,s2)存在,Ingress controller就会将提供一个满足该Ingress的特定loadbalancer实现。 这一步完成后,您将在Ingress的最后一列看到loadbalancer的地址。</p>
|
||
|
<h3 id="基于名称的虚拟主机">基于名称的虚拟主机</h3>
|
||
|
<p>Name-based的虚拟主机在同一个IP地址下拥有多个主机名。</p>
|
||
|
<pre><code>foo.bar.com --| |-> foo.bar.com s1:80
|
||
|
| 178.91.123.132 |
|
||
|
bar.foo.com --| |-> bar.foo.com s2:80
|
||
|
</code></pre><p>下面这个ingress说明基于<a href="https://tools.ietf.org/html/rfc7230#section-5.4" target="_blank">Host header</a>的后端loadbalancer的路由请求:</p>
|
||
|
<pre><code class="lang-Yaml"><span class="hljs-attr">apiVersion:</span> extensions/v1beta1
|
||
|
<span class="hljs-attr">kind:</span> Ingress
|
||
|
<span class="hljs-attr">metadata:</span>
|
||
|
<span class="hljs-attr"> name:</span> test
|
||
|
<span class="hljs-attr">spec:</span>
|
||
|
<span class="hljs-attr"> rules:</span>
|
||
|
<span class="hljs-attr"> - host:</span> foo.bar.com
|
||
|
<span class="hljs-attr"> http:</span>
|
||
|
<span class="hljs-attr"> paths:</span>
|
||
|
<span class="hljs-attr"> - backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s1
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
<span class="hljs-attr"> - host:</span> bar.foo.com
|
||
|
<span class="hljs-attr"> http:</span>
|
||
|
<span class="hljs-attr"> paths:</span>
|
||
|
<span class="hljs-attr"> - backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s2
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
</code></pre>
|
||
|
<p><strong>默认backend</strong>:一个没有rule的ingress,如前面章节中所示,所有流量都将发送到一个默认backend。你可以用该技巧通知loadbalancer如何找到你网站的404页面,通过制定一些列rule和一个默认backend的方式。如果请求header中的host不能跟ingress中的host匹配,并且/或请求的URL不能与任何一个path匹配,则流量将路由到你的默认backend。</p>
|
||
|
<h3 id="tls">TLS</h3>
|
||
|
<p>你可以通过指定包含TLS私钥和证书的<a href="https://kubernetes.io/docs/user-guide/secrets" target="_blank">secret</a>来加密Ingress。 目前,Ingress仅支持单个TLS端口443,并假定TLS termination。 如果Ingress中的TLS配置部分指定了不同的主机,则它们将根据通过SNI TLS扩展指定的主机名(假如Ingress controller支持SNI)在多个相同端口上进行复用。 TLS secret中必须包含名为<code>tls.crt</code>和<code>tls.key</code>的密钥,这里面包含了用于TLS的证书和私钥,例如:</p>
|
||
|
<pre><code class="lang-Yaml"><span class="hljs-attr">apiVersion:</span> v1
|
||
|
<span class="hljs-attr">data:</span>
|
||
|
tls.crt: base64 encoded cert
|
||
|
tls.key: base64 encoded key
|
||
|
<span class="hljs-attr">kind:</span> Secret
|
||
|
<span class="hljs-attr">metadata:</span>
|
||
|
<span class="hljs-attr"> name:</span> testsecret
|
||
|
<span class="hljs-attr"> namespace:</span> default
|
||
|
<span class="hljs-attr">type:</span> Opaque
|
||
|
</code></pre>
|
||
|
<p>在Ingress中引用这个secret将通知Ingress controller使用TLS加密从将客户端到loadbalancer的channel:</p>
|
||
|
<pre><code class="lang-yaml"><span class="hljs-attr">apiVersion:</span> extensions/v1beta1
|
||
|
<span class="hljs-attr">kind:</span> Ingress
|
||
|
<span class="hljs-attr">metadata:</span>
|
||
|
<span class="hljs-attr"> name:</span> <span class="hljs-literal">no</span>-rules-map
|
||
|
<span class="hljs-attr">spec:</span>
|
||
|
<span class="hljs-attr"> tls:</span>
|
||
|
<span class="hljs-attr"> - secretName:</span> testsecret
|
||
|
<span class="hljs-attr"> backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s1
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
</code></pre>
|
||
|
<p>请注意,各种Ingress controller支持的TLS功能之间存在差距。 请参阅有关<a href="https://github.com/kubernetes/ingress/blob/master/controllers/nginx/README.md#https" target="_blank">nginx</a>,<a href="https://github.com/kubernetes/ingress/blob/master/controllers/gce/README.md#tls" target="_blank">GCE</a>或任何其他平台特定Ingress controller的文档,以了解TLS在你的环境中的工作原理。</p>
|
||
|
<p>Ingress controller启动时附带一些适用于所有Ingress的负载平衡策略设置,例如负载均衡算法,后端权重方案等。更高级的负载平衡概念(例如持久会话,动态权重)尚未在Ingress中公开。 你仍然可以通过<a href="https://github.com/kubernetes/contrib/tree/master/service-loadbalancer" target="_blank">service loadbalancer</a>获取这些功能。 随着时间的推移,我们计划将适用于跨平台的负载平衡模式加入到Ingress资源中。</p>
|
||
|
<p>还值得注意的是,尽管健康检查不直接通过Ingress公开,但Kubernetes中存在并行概念,例如<a href="https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/" target="_blank">准备探查</a>,可以使你达成相同的最终结果。 请查看特定控制器的文档,以了解他们如何处理健康检查(<a href="https://github.com/kubernetes/ingress/blob/master/controllers/nginx/README.md" target="_blank">nginx</a>,<a href="https://github.com/kubernetes/ingress/blob/master/controllers/gce/README.md#health-checks" target="_blank">GCE</a>)。</p>
|
||
|
<h2 id="更新ingress">更新Ingress</h2>
|
||
|
<p>假如你想要向已有的ingress中增加一个新的Host,你可以编辑和更新该ingress:</p>
|
||
|
<pre><code class="lang-Bash">$ kubectl get ing
|
||
|
NAME RULE BACKEND ADDRESS
|
||
|
<span class="hljs-built_in">test</span> - 178.91.123.132
|
||
|
foo.bar.com
|
||
|
/foo s1:80
|
||
|
$ kubectl edit ing <span class="hljs-built_in">test</span>
|
||
|
</code></pre>
|
||
|
<p>这会弹出一个包含已有的yaml文件的编辑器,修改它,增加新的Host配置。</p>
|
||
|
<pre><code class="lang-yaml"><span class="hljs-attr">spec:</span>
|
||
|
<span class="hljs-attr"> rules:</span>
|
||
|
<span class="hljs-attr"> - host:</span> foo.bar.com
|
||
|
<span class="hljs-attr"> http:</span>
|
||
|
<span class="hljs-attr"> paths:</span>
|
||
|
<span class="hljs-attr"> - backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s1
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
<span class="hljs-attr"> path:</span> /foo
|
||
|
<span class="hljs-attr"> - host:</span> bar.baz.com
|
||
|
<span class="hljs-attr"> http:</span>
|
||
|
<span class="hljs-attr"> paths:</span>
|
||
|
<span class="hljs-attr"> - backend:</span>
|
||
|
<span class="hljs-attr"> serviceName:</span> s2
|
||
|
<span class="hljs-attr"> servicePort:</span> <span class="hljs-number">80</span>
|
||
|
<span class="hljs-attr"> path:</span> /foo
|
||
|
..
|
||
|
</code></pre>
|
||
|
<p>保存它会更新API server中的资源,这会触发ingress controller重新配置loadbalancer。</p>
|
||
|
<pre><code class="lang-bash">$ kubectl get ing
|
||
|
NAME RULE BACKEND ADDRESS
|
||
|
<span class="hljs-built_in">test</span> - 178.91.123.132
|
||
|
foo.bar.com
|
||
|
/foo s1:80
|
||
|
bar.baz.com
|
||
|
/foo s2:80
|
||
|
</code></pre>
|
||
|
<p>在一个修改过的ingress yaml文件上调用<code>kubectl replace -f</code>命令一样可以达到同样的效果。</p>
|
||
|
<h2 id="跨可用域故障">跨可用域故障</h2>
|
||
|
<p>在不通云供应商之间,跨故障域的流量传播技术有所不同。 有关详细信息,请查看相关Ingress controller的文档。 有关在federation集群中部署Ingress的详细信息,请参阅<a href="">federation文档</a>。</p>
|
||
|
<h2 id="未来计划">未来计划</h2>
|
||
|
<ul>
|
||
|
<li>多样化的HTTPS/TLS模型支持(如SNI,re-encryption)</li>
|
||
|
<li>通过声明来请求IP或者主机名</li>
|
||
|
<li>结合L4和L7 Ingress</li>
|
||
|
<li>更多的Ingress controller</li>
|
||
|
</ul>
|
||
|
<p>请跟踪<a href="https://github.com/kubernetes/kubernetes/pull/12827" target="_blank">L7和Ingress的proposal</a>,了解有关资源演进的更多细节,以及<a href="https://github.com/kubernetes/ingress/tree/master" target="_blank">Ingress repository</a>,了解有关各种Ingress controller演进的更多详细信息。</p>
|
||
|
<h2 id="替代方案">替代方案</h2>
|
||
|
<p>你可以通过很多种方式暴露service而不必直接使用ingress:</p>
|
||
|
<ul>
|
||
|
<li>使用<a href="https://kubernetes.io/docs/user-guide/services/#type-loadbalancer" target="_blank">Service.Type=LoadBalancer</a></li>
|
||
|
<li>使用<a href="https://kubernetes.io/docs/user-guide/services/#type-nodeport" target="_blank">Service.Type=NodePort</a></li>
|
||
|
<li>使用<a href="https://github.com/kubernetes/contrib/tree/master/for-demos/proxy-to-service" target="_blank">Port Proxy</a></li>
|
||
|
<li>部署一个<a href="https://github.com/kubernetes/contrib/tree/master/service-loadbalancer" target="_blank">Service loadbalancer</a> 这允许你在多个service之间共享单个IP,并通过Service Annotations实现更高级的负载平衡。</li>
|
||
|
</ul>
|
||
|
<h2 id="参考">参考</h2>
|
||
|
<p><a href="https://kubernetes.io/docs/concepts/services-networking/ingress/" target="_blank">Kubernetes Ingress Resource</a></p>
|
||
|
<p><a href="http://dockone.io/article/957" target="_blank">使用NGINX Plus负载均衡Kubernetes服务</a></p>
|
||
|
<p><a href="http://www.cnblogs.com/276815076/p/6407101.html" target="_blank">使用 NGINX 和 NGINX Plus 的 Ingress Controller 进行 Kubernetes 的负载均衡</a></p>
|
||
|
<p><a href="https://blog.osones.com/en/kubernetes-ingress-controller-with-traefik-and-lets-encrypt.html" target="_blank">Kubernetes : Ingress Controller with Træfɪk and Let's Encrypt</a></p>
|
||
|
<p><a href="https://blog.osones.com/en/kubernetes-traefik-and-lets-encrypt-at-scale.html" target="_blank">Kubernetes : Træfɪk and Let's Encrypt at scale</a></p>
|
||
|
<p><a href="https://docs.traefik.io/user-guide/kubernetes/" target="_blank">Kubernetes Ingress Controller-Træfɪk</a></p>
|
||
|
<p><a href="http://blog.kubernetes.io/2016/03/Kubernetes-1.2-and-simplifying-advanced-networking-with-Ingress.html" target="_blank">Kubernetes 1.2 and simplifying advanced networking with Ingress</a> </p>
|
||
|
<footer class="page-footer-ex"> <span class="page-footer-ex-copyright">for GitBook</span>           <span class="page-footer-ex-footer-update">update
|
||
|
2017-05-18 15:53:36
|
||
|
</span></footer>
|
||
|
|
||
|
</section>
|
||
|
|
||
|
</div>
|
||
|
<div class="search-results">
|
||
|
<div class="has-results">
|
||
|
|
||
|
<h1 class="search-results-title"><span class='search-results-count'></span> results matching "<span class='search-query'></span>"</h1>
|
||
|
<ul class="search-results-list"></ul>
|
||
|
|
||
|
</div>
|
||
|
<div class="no-results">
|
||
|
|
||
|
<h1 class="search-results-title">No results matching "<span class='search-query'></span>"</h1>
|
||
|
|
||
|
</div>
|
||
|
</div>
|
||
|
</div>
|
||
|
|
||
|
</div>
|
||
|
</div>
|
||
|
|
||
|
</div>
|
||
|
|
||
|
|
||
|
|
||
|
<a href="cronjob.html" class="navigation navigation-prev " aria-label="Previous page: 2.2.13 CronJob">
|
||
|
<i class="fa fa-angle-left"></i>
|
||
|
</a>
|
||
|
|
||
|
|
||
|
<a href="configmap.html" class="navigation navigation-next " aria-label="Next page: 2.2.15 ConfigMap">
|
||
|
<i class="fa fa-angle-right"></i>
|
||
|
</a>
|
||
|
|
||
|
|
||
|
|
||
|
</div>
|
||
|
|
||
|
<script>
|
||
|
var gitbook = gitbook || [];
|
||
|
gitbook.push(function() {
|
||
|
gitbook.page.hasChanged({"page":{"title":"2.2.14 Ingress","level":"1.2.2.14","depth":3,"next":{"title":"2.2.15 ConfigMap","level":"1.2.2.15","depth":3,"path":"concepts/configmap.md","ref":"concepts/configmap.md","articles":[]},"previous":{"title":"2.2.13 CronJob","level":"1.2.2.13","depth":3,"path":"concepts/cronjob.md","ref":"concepts/cronjob.md","articles":[]},"dir":"ltr"},"config":{"plugins":["github","codesnippet","splitter","page-toc-button","image-captions","page-footer-ex","editlink","-lunr","-search","search-plus","livereload"],"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"pluginsConfig":{"github":{"url":"https://github.com/rootsongjc/kubernetes-handbook"},"editlink":{"label":"编辑本页","multilingual":false,"base":"https://github.com/rootsongjc/kubernetes-handbook/blob/master/"},"livereload":{},"page-footer-ex":{"copyright":"for GitBook","update_format":"YYYY-MM-DD HH:mm:ss","update_label":"update"},"splitter":{},"codesnippet":{},"fontsettings":{"theme":"white","family":"sans","size":2},"highlight":{},"page-toc-button":{},"sharing":{"facebook":true,"twitter":true,"google":false,"weibo":false,"instapaper":false,"vk":false,"all":["facebook","google","twitter","weibo","instapaper"]},"theme-default":{"styles":{"website":"styles/website.css","pdf":"styles/pdf.css","epub":"styles/epub.css","mobi":"styles/mobi.css","ebook":"styles/ebook.css","print":"styles/print.css"},"showLevel":false},"search-plus":{},"image-captions":{"variable_name":"_pictures"}},"page-footer-ex":{"copyright":"Jimmy Song","update_label":"最后更新:","update_format":"YYYY-MM-DD HH:mm:ss"},"theme":"default","author":"Jimmy Song","pdf":{"pageNumbers":true,"fontSize":12,"fontFamily":"Arial","paperSize":"a4","chapterMark":"pagebreak","pageBreaksBefore":"/","margin":{"right":62,"left":62,"top":56,"bottom":56}},"structure":{"langs":"LANGS.md","readme":"README.md","glossary":"GLOSSARY.md","summary":"SUMMARY.md"},"variables":{"_pictures":[{"backlink":"index.html#fig1.1.1","level":"1.1","list_caption":"Figure: wercker status","alt":"wercker status","nro":1,"url":"https://app.wercker.com/status/b8b69e593784e17ddcfd1286adfd8f3c/s/master","index":1,"caption_template":"Figure: _CAPTION_","label":"wercker status","attributes":{},"title":"wercker status","skip":false,"key":"1.1.1"},{"backlink":"concepts/index.html#fig1.2.1","level":"1.2","list_caption":"Figure: Borg架构","alt":"Borg架构","nro":2,"url":"../images/borg.png","index":1,"caption_template":"Figure: _CAPTION_","label":"Borg架构","attributes":{},"skip":false,"key":"1.2.1"},{"backlink":"concepts/index.html#fig1.2.2","level":"1.2","list_caption":"Figure: Kubernetes架构","alt":"Kubernetes架构","nro":3,"url":"../images/architecture.png","index":2,"caption_template":"Figure: _CAPTION_","label":"Kubernetes架构","attributes":{},"skip":false,"key":"1.2.2"},{"backlink":"concepts/index.html#fig1.2.3","level":"1.2","list_caption":"Figure: kubernetes整体架构示意图","alt":"kubernetes整体架构示意图","nro":4,"url":"../images/kubernetes-whole-arch.png","index":3,"caption_template":"Figure: _CAPTION_","label":"kubernetes整体架构示意图","attributes":{},"skip":false,"key":"1.2.3"},{"backlink":"concepts/index.html#fig1.2.4","level":"1.2","list_caption":"Figure: Kubernetes master架构示意图","alt":"Kubernetes master架构示意图","nro":5,"url":"../images/kubernetes-master-arch.png","index":4,"caption_template":"Figure: _CAPTION_","label":"Kubernetes master架构示意图","attributes":{},"skip":false,"key":"1.2.4"},{"backlink":"concepts/index.html#fig1.2.5","level":"1.2","list_caption":"Figure: kubernetes node架构示意图","alt":"kubernetes node架构示意图","nro":6,"url":"../images/kubernetes-node-arch.png","index":5,"caption_template":"Figure: _CAPTION_","label":"kubernetes node架构示意图","attributes":{},"skip":false,"key":"1.2.5"},{"backlink":"concepts/index.html#fig1.2.6","level":"1.2","list_caption":"Figure: Kubernetes分层架
|
||
|
});
|
||
|
</script>
|
||
|
</div>
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook.js"></script>
|
||
|
<script src="../gitbook/theme.js"></script>
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-github/plugin.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-splitter/splitter.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-page-toc-button/plugin.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-editlink/plugin.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-search-plus/jquery.mark.min.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-search-plus/search.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-livereload/plugin.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-sharing/buttons.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
<script src="../gitbook/gitbook-plugin-fontsettings/fontsettings.js"></script>
|
||
|
|
||
|
|
||
|
|
||
|
</body>
|
||
|
</html>
|
||
|
|