#kubernetes (2020-03)
Archive: https://archive.sweetops.com/kubernetes/
2020-03-02
2020-03-03
data:image/s3,"s3://crabby-images/2bd80/2bd8051324042f9726131c1dca5e6d27f857be76" alt="johncblandii avatar"
At a Rancher rodeo (mini-conference) today. @ me if you have any questions you’d like answered.
2020-03-04
data:image/s3,"s3://crabby-images/764fb/764fbd29857032a6cfbf02803371d06f2db3f003" alt="Andrea avatar"
Hi all, let me know if you have any tips on providing k8s credentials (namespace specific) to Jenkins, for deploying a couple of applications
data:image/s3,"s3://crabby-images/764fb/764fbd29857032a6cfbf02803371d06f2db3f003" alt="Andrea avatar"
I admin a bunch of EKS clusters and I’m not sure whether I should provide certificates, add “every” AWS user needed to the “aws-auth” configmap, or what else…
data:image/s3,"s3://crabby-images/764fb/764fbd29857032a6cfbf02803371d06f2db3f003" alt="Andrea avatar"
I say “provide credentials to Jenkins” but it could be some developers too in the future
data:image/s3,"s3://crabby-images/764fb/764fbd29857032a6cfbf02803371d06f2db3f003" alt="Andrea avatar"
docs are pretty vast, so a quick insight of what works for you in a similar situation, might be all I need to get started
data:image/s3,"s3://crabby-images/44902/449029945fc1a4b20fc4380407df7a1de709e0f8" alt="curious deviant avatar"
Hey Andrea, how I have solved for something similar is to use roles to give out EKS access to users. Basically you create a bunch of groups/roles in your IDP and they map them to AWS roles (via SAML etc., we had SSO setup). Populate your aws-auth configmap with references to the AWS roles. Add your users to the appropriate IDP group and see the magic work ..
data:image/s3,"s3://crabby-images/764fb/764fbd29857032a6cfbf02803371d06f2db3f003" alt="Andrea avatar"
alright, I’ll investigate that - thanks for your input!
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
maybe already mentioned but in a pinch k2tf is a nifty way to convert existing kubernetes deployments/resources into kubernetes terraform provider ready tf manifests: https://github.com/sl1pm4t/k2tf
Kubernetes YAML to Terraform HCL converter. Contribute to sl1pm4t/k2tf development by creating an account on GitHub.
2020-03-05
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
data:image/s3,"s3://crabby-images/de8fc/de8fcc7e544ada5369d06c59fcb42004b2a51639" alt="attachment image"
Here are 15 interesting takeaways from the CNCF annual survey.
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
hello guys. I’m trying to add CSI driver for EKS like described here https://docs.aws.amazon.com/eks/latest/userguide/ebs-csi.html but I’m getting error like this
Warning ProvisioningFailed 7m57s persistentvolume-controller storageclass.storage.k8s.io "ebs-sc" not found
Normal ExternalProvisioning 2m2s (x25 over 7m55s) persistentvolume-controller waiting for a volume to be created, either by external provisioner "ebs.csi.aws.com" or manually created by system administrator
Normal Provisioning 72s (x9 over 6m47s) ebs.csi.aws.com_ebs-csi-controller-f89d5544-wd646_e578127d-8c7b-4ac6-8aac-065a4165b629 External provisioner is provisioning volume for claim "default/ebs-claim"
Warning ProvisioningFailed 62s (x9 over 6m37s) ebs.csi.aws.com_ebs-csi-controller-f89d5544-wd646_e578127d-8c7b-4ac6-8aac-065a4165b629 failed to provision volume with StorageClass "ebs-sc": rpc error: code = DeadlineExceeded desc = context deadline exceeded
Does anyone know what is that?
data:image/s3,"s3://crabby-images/703f1/703f16033ebe0e670b09b496ca98cfe4d690b1a9" alt="bradym avatar"
It looks like you’re trying to use the ebs-sc storageclass before it’s been defined.
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
I don’t think so, bacause it is defined here
kubectl apply -k "github.com/kubernetes-sigs/aws-ebs-csi-driver/deploy/kubernetes/overlays/stable/?ref=master"
data:image/s3,"s3://crabby-images/703f1/703f16033ebe0e670b09b496ca98cfe4d690b1a9" alt="bradym avatar"
That URL returns a 404
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
here
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
it is example app to test that my driver works
data:image/s3,"s3://crabby-images/703f1/703f16033ebe0e670b09b496ca98cfe4d690b1a9" alt="bradym avatar"
But if you used the kubectl
command you posted above, it won’t work as that is not a valid URL… so kubectl apply
would try to apply the 404 response from github.. which clearly isn’t going to work
data:image/s3,"s3://crabby-images/703f1/703f16033ebe0e670b09b496ca98cfe4d690b1a9" alt="bradym avatar"
Looking at the github repo, I’m guessing what you want is:
kubectl apply -k <https://github.com/kubernetes-sigs/aws-ebs-csi-driver/blob/master/deploy/kubernetes/overlays/stable/kustomization.yaml>
CSI driver for Amazon EBS https://aws.amazon.com/ebs/ - kubernetes-sigs/aws-ebs-csi-driver
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
command above is working
data:image/s3,"s3://crabby-images/703f1/703f16033ebe0e670b09b496ca98cfe4d690b1a9" alt="bradym avatar"
Huh, no idea then.
data:image/s3,"s3://crabby-images/d593f/d593fb633541525ba68d89fab148a8ee508f62c0" alt="Maxim Tishchenko avatar"
I’m continuing to digging
2020-03-09
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Kubernetes apps, the easy way . Contribute to alexellis/arkade development by creating an account on GitHub.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Looks interesting
data:image/s3,"s3://crabby-images/9f7d3/9f7d37e6df4fb280d718c728e563fdba7ce5b9ba" alt="Chris Fowles avatar"
yeh saw that last week - i’ve been using k3sup for my home pi cluster project and it’s pretty nice
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Hah, I just looked a bit closer. It literally uses a go package for every chart. https://github.com/alexellis/arkade/tree/master/cmd/apps
Kubernetes apps, the easy way . Contribute to alexellis/arkade development by creating an account on GitHub.
2020-03-11
data:image/s3,"s3://crabby-images/5108e/5108e52407799dcbc4bd8caaeaf6c8d9c53901b2" alt="rbadillo avatar"
Hi Guys,
Is anybody here having issues creating EKS Clusters using terraform ?
We are seeing this error:
module.eks_cluster.aws_eks_cluster.eks_cluster: Still creating... [11m20s elapsed]
module.eks_cluster.aws_eks_cluster.eks_cluster: Still creating... [11m30s elapsed]
Error: unexpected state 'FAILED', wanted target 'ACTIVE'. last error: %!s(<nil>)
on ../../../../modules/eks/eks_control_plane/main.tf line 405, in resource "aws_eks_cluster" "eks_cluster":
405: resource "aws_eks_cluster" "eks_cluster" {
AWS just released EKS v1.15 last night and we think it maybe related.
data:image/s3,"s3://crabby-images/73029/73029a7e61c7e3bfc1ff4f8b1d44aa03b9f79940" alt="Pablo Costa avatar"
data:image/s3,"s3://crabby-images/73029/73029a7e61c7e3bfc1ff4f8b1d44aa03b9f79940" alt="Pablo Costa avatar"
The only thing noteworthy of your attention is to enable the secrets encryption—right below the network settings—and do remember that, at the current juncture, you can only set this at the cluster creation time (that is, not supported via cluster config updates)
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
can you redeploy a sidecar container in the pod w/o redeploying the entire pod?
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
i.e. updating a waf sidecar agent version in our ingress daemonset
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
alternatively, a zero downtime rolling deploy of the daemonset would work too :P
2020-03-12
data:image/s3,"s3://crabby-images/c3045/c30457671c549c83747cff024180a42acd53f85a" alt="tolstikov avatar"
TL;DR: Azure and Digital Ocean don’t charge for the compute resources used for the control plane, making AKS and DO the cheapest for running many, smaller clusters. For running fewer, larger clusters GKE is the most affordable option. Also, running on spot/preemptible/low-priority nodes or long-term committed nodes makes a massive impact across all of the platforms.
data:image/s3,"s3://crabby-images/21b14/21b1448f806ed0ce1c929c6147f8e65119dcebda" alt="Nikola Velkovski avatar"
Hello Peeps, is there any way to run a shell in a failing container on k8s ?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
CHange the entrypoint to just run:
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
/bin/sh -c "sleep inf"
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
and disable probes
data:image/s3,"s3://crabby-images/21b14/21b1448f806ed0ce1c929c6147f8e65119dcebda" alt="Nikola Velkovski avatar"
just saw this, thanks
data:image/s3,"s3://crabby-images/21b14/21b1448f806ed0ce1c929c6147f8e65119dcebda" alt="Nikola Velkovski avatar"
will try it out next time
data:image/s3,"s3://crabby-images/21b14/21b1448f806ed0ce1c929c6147f8e65119dcebda" alt="Nikola Velkovski avatar"
so far all that I was able to find was to run a shell on a running one
data:image/s3,"s3://crabby-images/c30bb/c30bb5a512018f67960ef254c3f49af568093f63" alt="Jonathan avatar"
Not really afaik. One way of debugging the container is to run an infinite loop as the entrypoint instead of the intended startup script. then you can run the startup script in the shell and see what is happening
2020-03-14
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
So I ran across this nifty repo of all the kubernetes schemas https://github.com/instrumenta/kubernetes-json-schema I don’t know what I’m using it for yet but its a nice resource to be aware of regardless
Schemas for every version of every object in every version of Kubernetes - instrumenta/kubernetes-json-schema
2020-03-24
data:image/s3,"s3://crabby-images/9dcb2/9dcb21fc8b97bc99c54633f8353227f74ec9ba10" alt="Roderik van der Veer avatar"
How would i configure a stateful set (mongo replicaset) with 3 replicas with statically created PV’s?
My best guess is create 3 PV’s with a label usage: mongo
and then use ReadWriteOnce and
selector:
matchLabels:
usage: mongo
2020-03-25
data:image/s3,"s3://crabby-images/bef0a/bef0ab8a8f47fbd57aa7553b6e8029dff04dfeba" alt="Hemanth avatar"
Anyone has tried this - https://bf.eralabs.io/learnkubernetesbybuilding10projects.html Is it worth getting it ?
Get huge savings and learn new technologies. Deals up to 80% OFF.
data:image/s3,"s3://crabby-images/8a381/8a3810bd25852254138ad01824f62424958b5723" alt="setheryops avatar"
Hmm…id be interested in seeing if anyone else has read through that
2020-03-27
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Adding @discourse_forum bot
data:image/s3,"s3://crabby-images/437c5/437c5f7ff80749c4e31740314c290186d75e89b6" alt="discourse_forum avatar"
@discourse_forum has joined the channel
2020-03-29
data:image/s3,"s3://crabby-images/9f7d3/9f7d37e6df4fb280d718c728e563fdba7ce5b9ba" alt="Chris Fowles avatar"
data:image/s3,"s3://crabby-images/ec232/ec2321665d39c32f5ea01103592229976b528a98" alt="attachment image"
Lens IDE for Kubernetes. The only system you’ll ever need to take control of your Kubernetes clusters. It’s open source and free. Download it today!
data:image/s3,"s3://crabby-images/9f7d3/9f7d37e6df4fb280d718c728e563fdba7ce5b9ba" alt="Chris Fowles avatar"
@Erik Osterman (Cloud Posse) - they managed to opensource it
data:image/s3,"s3://crabby-images/ec232/ec2321665d39c32f5ea01103592229976b528a98" alt="attachment image"
Lens IDE for Kubernetes. The only system you’ll ever need to take control of your Kubernetes clusters. It’s open source and free. Download it today!
data:image/s3,"s3://crabby-images/0d11f/0d11f7eab212d5e9cf9019c8f41978fe3989c056" alt="jeremypruitt avatar"
Nifty. This looks a bit like infra.app, yeah?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
thanks @Chris Fowles!
data:image/s3,"s3://crabby-images/3c547/3c54718d528a1cd5e01420b9e569bdf089661131" alt="roth.andy avatar"
Looks nice. Might end up switching back and forth between this and k9s a lot since k9s makes it easy to manage port-forwards
2020-03-30
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
looks like loghouse (https://github.com/flant/loghouse) has updated their kubernetes logging solution recently. Its worth looking into as an elk alternative (it uses clickhouse for the database). I’ve tested it out at one time and it worked well enough but I wasn’t able to get it into the project as they were asking for Elastic so I gave ‘em EFK instead (boo).
Ready to use log management solution for Kubernetes storing data in ClickHouse and providing web UI. - flant/loghouse
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
curious what peoples thoughts are on ambassador edge stack? https://www.getambassador.io/docs/ I used ambassador api gateway before and loved it (often said it was my fave ingress controller). toyed around with ambassador edge stack this weekend, didn’t get terribly far but I wasn’t super pleased - lots of bells and whistles, seemingly yet another cli tool you need to install (edgectl). I appreciated the simplicity of their original api gateway.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Hrmmm haven’t tried it. Is GumGum using it?
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
@Erik Osterman (Cloud Posse) maybe? I know when @Corey Gale poc’d it, edge stack hadn’t come out yet.
data:image/s3,"s3://crabby-images/c507d/c507d852eaeac34729732d723f2a8889f5503219" alt="Corey Gale avatar"
We are considering it for putting Google auth in front of our services but haven’t put it in prod yet
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Btw @btai see that the oidc proxy project moved to its own org?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Wonder if that makes the future more or less certain
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
@Erik Osterman (Cloud Posse) i ended up writing my own
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
How come?
data:image/s3,"s3://crabby-images/e471b/e471bc22e77bf7730ed2046efb99c305a4f8df4f" alt="btai avatar"
@Erik Osterman (Cloud Posse) it was couple hundred lines of code and does exactly what i need
2020-03-31
data:image/s3,"s3://crabby-images/77573/775736e2a1eb9753b309e3adf8e46283f2484067" alt="Nelson Jeppesen avatar"
Can someone explain why envvars
are leaking between pods in the same namespace? When I run kubectl exec -n default -it $somepod -- bash -c set
I see envvars for ALL the pods in that namespace
data:image/s3,"s3://crabby-images/77573/775736e2a1eb9753b309e3adf8e46283f2484067" alt="Nelson Jeppesen avatar"
I’m very concerned but I’m having trouble finding information on this behavior
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
I’d look at the deployment before the pod
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
deployments will have the replicasets which will have the pods (generically)
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
you certain that they aren’t simply being mapped into the deployments via a configmap?
data:image/s3,"s3://crabby-images/c4007/c4007ac3f2ea7b77860a98a8551d584856b49862" alt="Zachary Loeber avatar"
that would be a reasonable explanation
data:image/s3,"s3://crabby-images/77573/775736e2a1eb9753b309e3adf8e46283f2484067" alt="Nelson Jeppesen avatar"
I don’t think so
data:image/s3,"s3://crabby-images/77573/775736e2a1eb9753b309e3adf8e46283f2484067" alt="Nelson Jeppesen avatar"
I’m looking at each envvar and seeing how they are defined right now
data:image/s3,"s3://crabby-images/77573/775736e2a1eb9753b309e3adf8e46283f2484067" alt="Nelson Jeppesen avatar"
Nope, def not config maps
data:image/s3,"s3://crabby-images/a132c/a132c6a1e4e413ab585c2fd84a913e8b79ac5e7a" alt="Vucomir Ianculov avatar"
hi, i’m logging on a way to “enable maintainance mode” on application running in EKS and using AWS ALB, in the past i used ansible to with-list some ip addresses and display a maintainance page for ip’s not in the list, can this be done in K8s, from what i was search i did not find anything like this maybe someone can give me a hint on what to test