#kubernetes (2021-04)
Archive: https://archive.sweetops.com/kubernetes/
2021-04-01
2021-04-05
data:image/s3,"s3://crabby-images/8c560/8c56078a6790ba9e0cdf965fd62956716fb8e437" alt="Allen Vailliencourt avatar"
Single-node K8S cluster for testing on GCP? What would you all think is the best option? Throw minikube on it?
data:image/s3,"s3://crabby-images/6ed29/6ed2936fc5e2cb980f4b7bc052d9c7bf1978299e" alt="Issif avatar"
k3s works fine
data:image/s3,"s3://crabby-images/8c560/8c56078a6790ba9e0cdf965fd62956716fb8e437" alt="Allen Vailliencourt avatar"
didn’t even think about that! Thanks!
data:image/s3,"s3://crabby-images/8e71d/8e71dd08d02c4d20f657a457e6ef5dbb81bfb5be" alt="Veyron avatar"
if you are using ubuntu it comes with a production ready kubernetes server api called micro-k8s with a ton of official plugins supported. K3s is also fine for this.
sudo snap install microk8s --classic --channel=1.19
MicroK8s is the simplest production-grade upstream K8s. Lightweight and focused. Single command install on Linux, Windows and macOS. Made for devops, great for edge, appliances and IoT. Full high availability Kubernetes with autonomous clusters.
2021-04-06
2021-04-08
2021-04-20
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
is it possible to mix ALB scheme types (internal, internet-facing) on the same alb-controller ?
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
do you need two different controllers?
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
are the internal-albs required to use private subnets?
2021-04-21
data:image/s3,"s3://crabby-images/3b53e/3b53ea6b11e119174198d99f5b4978101468b2e8" alt="Thomas Hoefkens avatar"
We have deployed alpine images on EKS Fargate nodes, and have also associated a service account to an IAM role which has access to DynamoDb and some other services. When deploying the containers, we can see that AWS has automatically set these env vars on all containers
AWS_ROLE_ARN=arn:aws:iam::1111111:role/my-role
AWS_WEB_IDENTITY_TOKEN_FILE=/var/run/secrets/eks.amazonaws.com/serviceaccount/token
But if we execute this command with the cli
aws sts get-caller-identity
or
aws dynamodb list-tables
the command simply hangs and does not return any results.
We have followed the docs on setting up the iam roles for the EKS (k8s) service accounts - is there anything more we need to do to check the connectivity from the containers to the DynamoDb for example? (please note, from Lambda or so we can access DynamoDb - an endpoint exists for the necessary services)
When I execute this on the pod:
aws sts assume-role-with-web-identity \ --role-arn $AWS_ROLE_ARN \ --role-session-name mh9test \ --web-identity-token
``
`
file://$AWS_WEB_IDENTITY_TOKEN_FILE \ --duration-seconds 1000
I get this error: Connect timeout on endpoint URL: “sts.amazonaws.com” which is strange because the vpc endpoint is sts.eu-central-1.amazonaws.com I can also not ping endpoint addresses such as ec2.eu-central-1.amazonaws.com
data:image/s3,"s3://crabby-images/6bcb5/6bcb53303b5e7bc88ad648e0e77395748e33de6e" alt="Markus Muehlberger avatar"
First thing to check would be the route tables to make sure any VPC endpoints are actually used.
I’m guessing you don’t have any NAT gateways in the VPC, otherwise the containers should use the public internet to reach the endpoint.
Second thing to check is security groups and network ACLs.
data:image/s3,"s3://crabby-images/3b53e/3b53ea6b11e119174198d99f5b4978101468b2e8" alt="Thomas Hoefkens avatar"
so for the containers to reach the VPC endpoints (in the case of no internet gateway) we would have to set up a nat gateway?
data:image/s3,"s3://crabby-images/703a7/703a7c5cc070f94b8b6faf58e577550955aeb084" alt="imran hussain avatar"
Hi I think he means add some VPCE endpoints so you do not leave the AWS Network.
data:image/s3,"s3://crabby-images/3b53e/3b53ea6b11e119174198d99f5b4978101468b2e8" alt="Thomas Hoefkens avatar"
VPC endpoints were already in place.. still I was not able to ping these VPC endpoints by private DNS name from within a container…
data:image/s3,"s3://crabby-images/6bcb5/6bcb53303b5e7bc88ad648e0e77395748e33de6e" alt="Markus Muehlberger avatar"
Usually when you can’t ping AWS services from within the network you either have the security groups (outbound) or network ACLs (both directions) set up incorrectly or (because you don’t have a NAT gateway) the VPC endpoints are not correctly attached to the route tables.
data:image/s3,"s3://crabby-images/6bcb5/6bcb53303b5e7bc88ad648e0e77395748e33de6e" alt="Markus Muehlberger avatar"
One final thing that could also be is that you don’t have DNS hostnames enabled in the VPC.
2021-04-23
2021-04-29
data:image/s3,"s3://crabby-images/d4d96/d4d9617f570221e9b13c4096a098a6f0a565e4e7" alt="meirfi avatar"
Hay all,
we are facing a strange behaver of WeaveCNI in our AWS EKS cluster. for some reason our CoreDNS getting NXDOMAIN, which mean that the POD are not able to resolve the URL of the services in the cluster. after long investigation we found out that the only way to solve the DNS issue is by restarting all WeaveCNI POD.
any one have encountered the same behaver ? thanks.
data:image/s3,"s3://crabby-images/1e7fb/1e7fb012e9114db9a49ef4fb0140243909a277f1" alt="Matt Gowie avatar"
Don’t use WeaveCNI, so have no idea, but I believe the Weaveworks folks have their own Slack so it might make sense to post there?
data:image/s3,"s3://crabby-images/e779e/e779ec8c3071e62e54f99ddfcc0c4044858611b5" alt="Brad McCoy avatar"
Join us in the Microsoft reactor next week for a technical demonstration of provisioning AKS with Terraform and then deploying microservices with Helm!
https://www.meetup.com/Microsoft-Reactor-Sydney/events/277886892/