diff --git a/.gitignore b/.gitignore index 21ae9d25..29ad9ad8 100644 --- a/.gitignore +++ b/.gitignore @@ -3,6 +3,7 @@ *~ prepare-vms/tags prepare-vms/infra +prepare-vms/www slides/*.yml.html slides/autopilot/state.yaml slides/index.html diff --git a/README.md b/README.md index 7bac0675..7a16bcdb 100644 --- a/README.md +++ b/README.md @@ -39,7 +39,7 @@ your own tutorials. All these materials have been gathered in a single repository because they have a few things in common: -- some [common slides](slides/common/) that are re-used +- some [shared slides](slides/shared/) that are re-used (and updated) identically between different decks; - a [build system](slides/) generating HTML slides from Markdown source files; diff --git a/k8s/consul.yaml b/k8s/consul.yaml index a0454bb0..8b254adb 100644 --- a/k8s/consul.yaml +++ b/k8s/consul.yaml @@ -72,7 +72,7 @@ spec: terminationGracePeriodSeconds: 10 containers: - name: consul - image: "consul:1.4.4" + image: "consul:1.5" args: - "agent" - "-bootstrap-expect=3" diff --git a/k8s/efk.yaml b/k8s/efk.yaml index a3204f5b..48d6c1ce 100644 --- a/k8s/efk.yaml +++ b/k8s/efk.yaml @@ -51,7 +51,7 @@ spec: effect: NoSchedule containers: - name: fluentd - image: fluent/fluentd-kubernetes-daemonset:v1.3-debian-elasticsearch-1 + image: fluent/fluentd-kubernetes-daemonset:v1.4-debian-elasticsearch-1 env: - name: FLUENT_ELASTICSEARCH_HOST value: "elasticsearch" diff --git a/k8s/ingress.yaml b/k8s/ingress.yaml index 65639357..e322bc10 100644 --- a/k8s/ingress.yaml +++ b/k8s/ingress.yaml @@ -1,14 +1,14 @@ -apiVersion: extensions/v1beta1 +apiVersion: networking.k8s.io/v1beta1 kind: Ingress metadata: name: cheddar spec: rules: - - host: cheddar.A.B.C.D.nip.io + - host: px.3.123.33.38.nip.io http: paths: - path: / backend: - serviceName: cheddar + serviceName: px-lighthouse servicePort: 80 diff --git a/k8s/insecure-dashboard.yaml b/k8s/insecure-dashboard.yaml index 5ced8947..44ec1d65 100644 --- a/k8s/insecure-dashboard.yaml +++ b/k8s/insecure-dashboard.yaml @@ -12,11 +12,6 @@ # See the License for the specific language governing permissions and # limitations under the License. -# Configuration to deploy release version of the Dashboard UI compatible with -# Kubernetes 1.8. -# -# Example usage: kubectl create -f - # ------------------- Dashboard Secret ------------------- # apiVersion: v1 @@ -95,7 +90,7 @@ subjects: # ------------------- Dashboard Deployment ------------------- # kind: Deployment -apiVersion: apps/v1beta2 +apiVersion: apps/v1 metadata: labels: k8s-app: kubernetes-dashboard @@ -114,12 +109,13 @@ spec: spec: containers: - name: kubernetes-dashboard - image: k8s.gcr.io/kubernetes-dashboard-amd64:v1.8.3 + image: k8s.gcr.io/kubernetes-dashboard-amd64:v1.10.1 ports: - containerPort: 8443 protocol: TCP args: - --auto-generate-certificates + - --enable-skip-login # Uncomment the following line to manually specify Kubernetes API server Host # If not specified, Dashboard will attempt to auto discover the API server and connect # to it. Uncomment only if the default does not work. diff --git a/k8s/kubernetes-dashboard.yaml b/k8s/kubernetes-dashboard.yaml index 73fcc239..ee6977bf 100644 --- a/k8s/kubernetes-dashboard.yaml +++ b/k8s/kubernetes-dashboard.yaml @@ -12,11 +12,6 @@ # See the License for the specific language governing permissions and # limitations under the License. -# Configuration to deploy release version of the Dashboard UI compatible with -# Kubernetes 1.8. -# -# Example usage: kubectl create -f - # ------------------- Dashboard Secret ------------------- # apiVersion: v1 @@ -95,7 +90,7 @@ subjects: # ------------------- Dashboard Deployment ------------------- # kind: Deployment -apiVersion: apps/v1beta2 +apiVersion: apps/v1 metadata: labels: k8s-app: kubernetes-dashboard @@ -114,7 +109,7 @@ spec: spec: containers: - name: kubernetes-dashboard - image: k8s.gcr.io/kubernetes-dashboard-amd64:v1.8.3 + image: k8s.gcr.io/kubernetes-dashboard-amd64:v1.10.1 ports: - containerPort: 8443 protocol: TCP diff --git a/k8s/metrics-server.yaml b/k8s/metrics-server.yaml index 5ca8441d..5864e25d 100644 --- a/k8s/metrics-server.yaml +++ b/k8s/metrics-server.yaml @@ -82,7 +82,7 @@ spec: emptyDir: {} containers: - name: metrics-server - image: k8s.gcr.io/metrics-server-amd64:v0.3.1 + image: k8s.gcr.io/metrics-server-amd64:v0.3.3 imagePullPolicy: Always volumeMounts: - name: tmp-dir diff --git a/k8s/persistent-consul.yaml b/k8s/persistent-consul.yaml index ff9d5955..64c35065 100644 --- a/k8s/persistent-consul.yaml +++ b/k8s/persistent-consul.yaml @@ -74,7 +74,7 @@ spec: terminationGracePeriodSeconds: 10 containers: - name: consul - image: "consul:1.4.4" + image: "consul:1.5" volumeMounts: - name: data mountPath: /consul/data diff --git a/k8s/portworx.yaml b/k8s/portworx.yaml index e968b5fe..4a196441 100644 --- a/k8s/portworx.yaml +++ b/k8s/portworx.yaml @@ -1,4 +1,340 @@ -# SOURCE: https://install.portworx.com/?kbver=1.11.2&b=true&s=/dev/loop4&c=px-workshop&stork=true&lh=true +# SOURCE: https://install.portworx.com/?kbver=1.15.2&b=true&s=/dev/loop4&c=px-workshop&stork=true&lh=true&st=k8s&mc=false +# SOURCE: https://install.portworx.com/?kbver=1.15.2&b=true&s=/dev/loop4&c=px-workshop&stork=true&lh=true&st=k8s&mc=false +--- +kind: Service +apiVersion: v1 +metadata: + name: portworx-service + namespace: kube-system + labels: + name: portworx +spec: + selector: + name: portworx + type: NodePort + ports: + - name: px-api + protocol: TCP + port: 9001 + targetPort: 9001 + - name: px-kvdb + protocol: TCP + port: 9019 + targetPort: 9019 + - name: px-sdk + protocol: TCP + port: 9020 + targetPort: 9020 + - name: px-rest-gateway + protocol: TCP + port: 9021 + targetPort: 9021 +--- +apiVersion: apiextensions.k8s.io/v1beta1 +kind: CustomResourceDefinition +metadata: + name: volumeplacementstrategies.portworx.io +spec: + group: portworx.io + versions: + - name: v1beta2 + served: true + storage: true + - name: v1beta1 + served: false + storage: false + scope: Cluster + names: + plural: volumeplacementstrategies + singular: volumeplacementstrategy + kind: VolumePlacementStrategy + shortNames: + - vps + - vp +--- +apiVersion: v1 +kind: ServiceAccount +metadata: + name: px-account + namespace: kube-system +--- +kind: ClusterRole +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: node-get-put-list-role +rules: +- apiGroups: [""] + resources: ["secrets"] + verbs: ["get", "list"] +- apiGroups: [""] + resources: ["nodes"] + verbs: ["watch", "get", "update", "list"] +- apiGroups: [""] + resources: ["pods"] + verbs: ["delete", "get", "list", "watch", "update"] +- apiGroups: [""] + resources: ["persistentvolumeclaims", "persistentvolumes"] + verbs: ["get", "list"] +- apiGroups: [""] + resources: ["configmaps"] + verbs: ["get", "list", "update", "create"] +- apiGroups: ["extensions"] + resources: ["podsecuritypolicies"] + resourceNames: ["privileged"] + verbs: ["use"] +- apiGroups: ["portworx.io"] + resources: ["volumeplacementstrategies"] + verbs: ["get", "list"] +--- +kind: ClusterRoleBinding +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: node-role-binding +subjects: +- kind: ServiceAccount + name: px-account + namespace: kube-system +roleRef: + kind: ClusterRole + name: node-get-put-list-role + apiGroup: rbac.authorization.k8s.io +--- +apiVersion: v1 +kind: Namespace +metadata: + name: portworx +--- +kind: Role +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: px-role + namespace: portworx +rules: +- apiGroups: [""] + resources: ["secrets"] + verbs: ["get", "list", "create", "update", "patch"] +--- +kind: RoleBinding +apiVersion: rbac.authorization.k8s.io/v1 +metadata: + name: px-role-binding + namespace: portworx +subjects: +- kind: ServiceAccount + name: px-account + namespace: kube-system +roleRef: + kind: Role + name: px-role + apiGroup: rbac.authorization.k8s.io +--- +apiVersion: extensions/v1beta1 +kind: DaemonSet +metadata: + name: portworx + namespace: kube-system + annotations: + portworx.com/install-source: "https://install.portworx.com/?kbver=1.15.2&b=true&s=/dev/loop4&c=px-workshop&stork=true&lh=true&st=k8s&mc=false" +spec: + minReadySeconds: 0 + updateStrategy: + type: RollingUpdate + rollingUpdate: + maxUnavailable: 1 + template: + metadata: + labels: + name: portworx + spec: + affinity: + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: px/enabled + operator: NotIn + values: + - "false" + - key: node-role.kubernetes.io/master + operator: DoesNotExist + hostNetwork: true + hostPID: false + initContainers: + - name: checkloop + image: alpine + command: [ "sh", "-c" ] + args: + - | + if ! grep -q loop4 /proc/partitions; then + echo 'Could not find "loop4" in /proc/partitions. Please create it first.' + exit 1 + fi + containers: + - name: portworx + image: portworx/oci-monitor:2.1.3 + imagePullPolicy: Always + args: + ["-c", "px-workshop", "-s", "/dev/loop4", "-secret_type", "k8s", "-b", + "-x", "kubernetes"] + env: + - name: "AUTO_NODE_RECOVERY_TIMEOUT_IN_SECS" + value: "1500" + - name: "PX_TEMPLATE_VERSION" + value: "v4" + + livenessProbe: + periodSeconds: 30 + initialDelaySeconds: 840 # allow image pull in slow networks + httpGet: + host: 127.0.0.1 + path: /status + port: 9001 + readinessProbe: + periodSeconds: 10 + httpGet: + host: 127.0.0.1 + path: /health + port: 9015 + terminationMessagePath: "/tmp/px-termination-log" + securityContext: + privileged: true + volumeMounts: + - name: diagsdump + mountPath: /var/cores + - name: dockersock + mountPath: /var/run/docker.sock + - name: containerdsock + mountPath: /run/containerd + - name: criosock + mountPath: /var/run/crio + - name: crioconf + mountPath: /etc/crictl.yaml + - name: etcpwx + mountPath: /etc/pwx + - name: optpwx + mountPath: /opt/pwx + - name: procmount + mountPath: /host_proc + - name: sysdmount + mountPath: /etc/systemd/system + - name: journalmount1 + mountPath: /var/run/log + readOnly: true + - name: journalmount2 + mountPath: /var/log + readOnly: true + - name: dbusmount + mountPath: /var/run/dbus + restartPolicy: Always + serviceAccountName: px-account + volumes: + - name: diagsdump + hostPath: + path: /var/cores + - name: dockersock + hostPath: + path: /var/run/docker.sock + - name: containerdsock + hostPath: + path: /run/containerd + - name: criosock + hostPath: + path: /var/run/crio + - name: crioconf + hostPath: + path: /etc/crictl.yaml + type: FileOrCreate + - name: etcpwx + hostPath: + path: /etc/pwx + - name: optpwx + hostPath: + path: /opt/pwx + - name: procmount + hostPath: + path: /proc + - name: sysdmount + hostPath: + path: /etc/systemd/system + - name: journalmount1 + hostPath: + path: /var/run/log + - name: journalmount2 + hostPath: + path: /var/log + - name: dbusmount + hostPath: + path: /var/run/dbus +--- +kind: Service +apiVersion: v1 +metadata: + name: portworx-api + namespace: kube-system + labels: + name: portworx-api +spec: + selector: + name: portworx-api + type: NodePort + ports: + - name: px-api + protocol: TCP + port: 9001 + targetPort: 9001 + - name: px-sdk + protocol: TCP + port: 9020 + targetPort: 9020 + - name: px-rest-gateway + protocol: TCP + port: 9021 + targetPort: 9021 +--- +apiVersion: extensions/v1beta1 +kind: DaemonSet +metadata: + name: portworx-api + namespace: kube-system +spec: + minReadySeconds: 0 + updateStrategy: + type: RollingUpdate + rollingUpdate: + maxUnavailable: 100% + template: + metadata: + labels: + name: portworx-api + spec: + affinity: + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: px/enabled + operator: NotIn + values: + - "false" + - key: node-role.kubernetes.io/master + operator: DoesNotExist + hostNetwork: true + hostPID: false + containers: + - name: portworx-api + image: k8s.gcr.io/pause:3.1 + imagePullPolicy: Always + readinessProbe: + periodSeconds: 10 + httpGet: + host: 127.0.0.1 + path: /status + port: 9001 + restartPolicy: Always + serviceAccountName: px-account + + +--- apiVersion: v1 kind: ConfigMap metadata: @@ -11,7 +347,7 @@ data: "apiVersion": "v1", "extenders": [ { - "urlPrefix": "http://stork-service.kube-system.svc:8099", + "urlPrefix": "http://stork-service.kube-system:8099", "apiVersion": "v1beta1", "filterVerb": "filter", "prioritizeVerb": "prioritize", @@ -34,8 +370,8 @@ metadata: name: stork-role rules: - apiGroups: [""] - resources: ["pods"] - verbs: ["get", "list", "delete"] + resources: ["pods", "pods/exec"] + verbs: ["get", "list", "delete", "create", "watch"] - apiGroups: [""] resources: ["persistentvolumes"] verbs: ["get", "list", "watch", "create", "delete"] @@ -48,14 +384,14 @@ rules: - apiGroups: [""] resources: ["events"] verbs: ["list", "watch", "create", "update", "patch"] + - apiGroups: ["stork.libopenstorage.org"] + resources: ["*"] + verbs: ["get", "list", "watch", "update", "patch", "create", "delete"] - apiGroups: ["apiextensions.k8s.io"] resources: ["customresourcedefinitions"] - verbs: ["create", "list", "watch", "delete"] + verbs: ["create", "get"] - apiGroups: ["volumesnapshot.external-storage.k8s.io"] - resources: ["volumesnapshots"] - verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] - - apiGroups: ["volumesnapshot.external-storage.k8s.io"] - resources: ["volumesnapshotdatas"] + resources: ["volumesnapshots", "volumesnapshotdatas"] verbs: ["get", "list", "watch", "create", "update", "patch", "delete"] - apiGroups: [""] resources: ["configmaps"] @@ -72,6 +408,9 @@ rules: - apiGroups: ["*"] resources: ["statefulsets", "statefulsets/extensions"] verbs: ["list", "get", "watch", "patch", "update", "initialize"] + - apiGroups: ["*"] + resources: ["*"] + verbs: ["list", "get"] --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 @@ -131,7 +470,10 @@ spec: - --leader-elect=true - --health-monitor-interval=120 imagePullPolicy: Always - image: openstorage/stork:1.1.3 + image: openstorage/stork:2.2.4 + env: + - name: "PX_SERVICE_NAME" + value: "portworx-api" resources: requests: cpu: '0.1' @@ -168,16 +510,13 @@ metadata: rules: - apiGroups: [""] resources: ["endpoints"] - verbs: ["get", "update"] + verbs: ["get", "create", "update"] - apiGroups: [""] resources: ["configmaps"] verbs: ["get"] - apiGroups: [""] resources: ["events"] verbs: ["create", "patch", "update"] - - apiGroups: [""] - resources: ["endpoints"] - verbs: ["create"] - apiGroups: [""] resourceNames: ["kube-scheduler"] resources: ["endpoints"] @@ -197,7 +536,7 @@ rules: - apiGroups: [""] resources: ["replicationcontrollers", "services"] verbs: ["get", "list", "watch"] - - apiGroups: ["app", "extensions"] + - apiGroups: ["apps", "extensions"] resources: ["replicasets"] verbs: ["get", "list", "watch"] - apiGroups: ["apps"] @@ -253,7 +592,7 @@ spec: - --policy-configmap=stork-config - --policy-configmap-namespace=kube-system - --lock-object-name=stork-scheduler - image: gcr.io/google_containers/kube-scheduler-amd64:v1.11.2 + image: gcr.io/google_containers/kube-scheduler-amd64:v1.15.2 livenessProbe: httpGet: path: /healthz @@ -280,229 +619,61 @@ spec: hostPID: false serviceAccountName: stork-scheduler-account --- -kind: Service -apiVersion: v1 -metadata: - name: portworx-service - namespace: kube-system - labels: - name: portworx -spec: - selector: - name: portworx - ports: - - name: px-api - protocol: TCP - port: 9001 - targetPort: 9001 ---- apiVersion: v1 kind: ServiceAccount metadata: - name: px-account + name: px-lh-account namespace: kube-system --- kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: - name: node-get-put-list-role + name: px-lh-role + namespace: kube-system rules: -- apiGroups: [""] - resources: ["nodes"] - verbs: ["watch", "get", "update", "list"] -- apiGroups: [""] - resources: ["pods"] - verbs: ["delete", "get", "list"] -- apiGroups: [""] - resources: ["persistentvolumeclaims", "persistentvolumes"] - verbs: ["get", "list"] -- apiGroups: [""] - resources: ["configmaps"] - verbs: ["get", "list", "update", "create"] -- apiGroups: ["extensions"] - resources: ["podsecuritypolicies"] - resourceNames: ["privileged"] - verbs: ["use"] + - apiGroups: [""] + resources: ["pods"] + verbs: ["list", "get"] + - apiGroups: + - extensions + - apps + resources: + - deployments + verbs: ["get", "list"] + - apiGroups: [""] + resources: ["secrets"] + verbs: ["get", "create", "update"] + - apiGroups: [""] + resources: ["configmaps"] + verbs: ["get", "create", "update"] + - apiGroups: [""] + resources: ["nodes"] + verbs: ["get", "list", "watch"] + - apiGroups: [""] + resources: ["services"] + verbs: ["create", "get", "list", "watch"] + - apiGroups: ["stork.libopenstorage.org"] + resources: ["clusterpairs","migrations","groupvolumesnapshots"] + verbs: ["get", "list", "create", "update", "delete"] + - apiGroups: ["monitoring.coreos.com"] + resources: + - alertmanagers + - prometheuses + - prometheuses/finalizers + - servicemonitors + verbs: ["*"] --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: node-role-binding -subjects: -- kind: ServiceAccount - name: px-account - namespace: kube-system -roleRef: - kind: ClusterRole - name: node-get-put-list-role - apiGroup: rbac.authorization.k8s.io ---- -apiVersion: v1 -kind: Namespace -metadata: - name: portworx ---- -kind: Role -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: px-role - namespace: portworx -rules: -- apiGroups: [""] - resources: ["secrets"] - verbs: ["get", "list", "create", "update", "patch"] ---- -kind: RoleBinding -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: px-role-binding - namespace: portworx -subjects: -- kind: ServiceAccount - name: px-account - namespace: kube-system -roleRef: - kind: Role - name: px-role - apiGroup: rbac.authorization.k8s.io ---- -apiVersion: extensions/v1beta1 -kind: DaemonSet -metadata: - name: portworx - namespace: kube-system - annotations: - portworx.com/install-source: "https://install.portworx.com/?kbver=1.11.2&b=true&s=/dev/loop4&c=px-workshop&stork=true&lh=true" -spec: - minReadySeconds: 0 - updateStrategy: - type: RollingUpdate - rollingUpdate: - maxUnavailable: 1 - template: - metadata: - labels: - name: portworx - spec: - affinity: - nodeAffinity: - requiredDuringSchedulingIgnoredDuringExecution: - nodeSelectorTerms: - - matchExpressions: - - key: px/enabled - operator: NotIn - values: - - "false" - - key: node-role.kubernetes.io/master - operator: DoesNotExist - hostNetwork: true - hostPID: false - containers: - - name: portworx - image: portworx/oci-monitor:1.4.2.2 - imagePullPolicy: Always - args: - ["-c", "px-workshop", "-s", "/dev/loop4", "-b", - "-x", "kubernetes"] - env: - - name: "PX_TEMPLATE_VERSION" - value: "v4" - - livenessProbe: - periodSeconds: 30 - initialDelaySeconds: 840 # allow image pull in slow networks - httpGet: - host: 127.0.0.1 - path: /status - port: 9001 - readinessProbe: - periodSeconds: 10 - httpGet: - host: 127.0.0.1 - path: /health - port: 9015 - terminationMessagePath: "/tmp/px-termination-log" - securityContext: - privileged: true - volumeMounts: - - name: dockersock - mountPath: /var/run/docker.sock - - name: etcpwx - mountPath: /etc/pwx - - name: optpwx - mountPath: /opt/pwx - - name: proc1nsmount - mountPath: /host_proc/1/ns - - name: sysdmount - mountPath: /etc/systemd/system - - name: diagsdump - mountPath: /var/cores - - name: journalmount1 - mountPath: /var/run/log - readOnly: true - - name: journalmount2 - mountPath: /var/log - readOnly: true - - name: dbusmount - mountPath: /var/run/dbus - restartPolicy: Always - serviceAccountName: px-account - volumes: - - name: dockersock - hostPath: - path: /var/run/docker.sock - - name: etcpwx - hostPath: - path: /etc/pwx - - name: optpwx - hostPath: - path: /opt/pwx - - name: proc1nsmount - hostPath: - path: /proc/1/ns - - name: sysdmount - hostPath: - path: /etc/systemd/system - - name: diagsdump - hostPath: - path: /var/cores - - name: journalmount1 - hostPath: - path: /var/run/log - - name: journalmount2 - hostPath: - path: /var/log - - name: dbusmount - hostPath: - path: /var/run/dbus ---- -apiVersion: v1 -kind: ServiceAccount -metadata: - name: px-lh-account - namespace: kube-system ---- -kind: Role -apiVersion: rbac.authorization.k8s.io/v1 -metadata: - name: px-lh-role - namespace: kube-system -rules: -- apiGroups: [""] - resources: ["configmaps"] - verbs: ["get", "create", "update"] ---- -kind: RoleBinding -apiVersion: rbac.authorization.k8s.io/v1 metadata: name: px-lh-role-binding namespace: kube-system subjects: -- kind: ServiceAccount - name: px-lh-account - namespace: kube-system + - kind: ServiceAccount + name: px-lh-account + namespace: kube-system roleRef: - kind: Role + kind: ClusterRole name: px-lh-role apiGroup: rbac.authorization.k8s.io --- @@ -518,14 +689,12 @@ spec: ports: - name: http port: 80 - nodePort: 32678 - name: https port: 443 - nodePort: 32679 selector: tier: px-web-console --- -apiVersion: apps/v1beta2 +apiVersion: apps/v1beta1 kind: Deployment metadata: name: px-lighthouse @@ -549,7 +718,7 @@ spec: spec: initContainers: - name: config-init - image: portworx/lh-config-sync:0.2 + image: portworx/lh-config-sync:0.4 imagePullPolicy: Always args: - "init" @@ -558,8 +727,9 @@ spec: mountPath: /config/lh containers: - name: px-lighthouse - image: portworx/px-lighthouse:1.5.0 + image: portworx/px-lighthouse:2.0.4 imagePullPolicy: Always + args: [ "-kubernetes", "true" ] ports: - containerPort: 80 - containerPort: 443 @@ -567,13 +737,16 @@ spec: - name: config mountPath: /config/lh - name: config-sync - image: portworx/lh-config-sync:0.2 + image: portworx/lh-config-sync:0.4 imagePullPolicy: Always args: - "sync" volumeMounts: - name: config mountPath: /config/lh + - name: stork-connector + image: portworx/lh-stork-connector:0.2 + imagePullPolicy: Always serviceAccountName: px-lh-account volumes: - name: config diff --git a/k8s/postgres.yaml b/k8s/postgres.yaml index d2868cd9..75ac4b8e 100644 --- a/k8s/postgres.yaml +++ b/k8s/postgres.yaml @@ -15,7 +15,7 @@ spec: schedulerName: stork containers: - name: postgres - image: postgres:10.5 + image: postgres:11 volumeMounts: - mountPath: /var/lib/postgresql/data name: postgres diff --git a/prepare-vms/lib/commands.sh b/prepare-vms/lib/commands.sh index dba89594..5fb3ed76 100644 --- a/prepare-vms/lib/commands.sh +++ b/prepare-vms/lib/commands.sh @@ -33,9 +33,14 @@ _cmd_cards() { ../../lib/ips-txt-to-html.py settings.yaml ) + ln -sf ../tags/$TAG/ips.html www/$TAG.html + ln -sf ../tags/$TAG/ips.pdf www/$TAG.pdf + info "Cards created. You can view them with:" info "xdg-open tags/$TAG/ips.html tags/$TAG/ips.pdf (on Linux)" info "open tags/$TAG/ips.html (on macOS)" + info "Or you can start a web server with:" + info "$0 www" } _cmd deploy "Install Docker on a bunch of running VMs" @@ -536,6 +541,50 @@ _cmd_weavetest() { sh -c \"./weave --local status | grep Connections | grep -q ' 1 failed' || ! echo POD \"" } +_cmd webssh "Install a WEB SSH server on the machines (port 1080)" +_cmd_webssh() { + TAG=$1 + need_tag + pssh " + sudo apt-get update && + sudo apt-get install python-tornado python-paramiko -y" + pssh " + [ -d webssh ] || git clone https://github.com/jpetazzo/webssh" + pssh " + for KEYFILE in /etc/ssh/*.pub; do + read a b c < \$KEYFILE; echo localhost \$a \$b + done > webssh/known_hosts" + pssh "cat >webssh.service < +But we need to know exactly the scenarios that they can handle.* diff --git a/slides/k8s/record.md b/slides/k8s/record.md new file mode 100644 index 00000000..a76fc903 --- /dev/null +++ b/slides/k8s/record.md @@ -0,0 +1,169 @@ +# Recording deployment actions + +- Some commands that modify a Deployment accept an optional `--record` flag + + (Example: `kubectl set image deployment worker worker=alpine --record`) + +- That flag will store the command line in the Deployment + + (Technically, using the annotation `kubernetes.io/change-cause`) + +- It gets copied to the corresponding ReplicaSet + + (Allowing to keep track of which command created or promoted this ReplicaSet) + +- We can view this information with `kubectl rollout history` + +--- + +## Using `--record` + +- Let's make a couple of changes to a Deployment and record them + +.exercise[ + +- Roll back `worker` to image version 0.1: + ```bash + kubectl set image deployment worker worker=dockercoins/worker:v0.1 --record + ``` + +- Promote it to version 0.2 again: + ```bash + kubectl set image deployment worker worker=dockercoins/worker:v0.2 --record + ``` + +- View the change history: + ```bash + kubectl rollout history deployment worker + ``` + +] + +--- + +## Pitfall #1: forgetting `--record` + +- What happens if we don't specify `--record`? + +.exercise[ + +- Promote `worker` to image version 0.3: + ```bash + kubectl set image deployment worker worker=dockercoins/worker:v0.3 + ``` + +- View the change history: + ```bash + kubectl rollout history deployment worker + ``` + +] + +-- + +It recorded version 0.2 instead of 0.3! Why? + +--- + +## How `--record` really works + +- `kubectl` adds the annotation `kubernetes.io/change-cause` to the Deployment + +- The Deployment controller copies that annotation to the ReplicaSet + +- `kubectl rollout history` shows the ReplicaSets' annotations + +- If we don't specify `--record`, the annotation is not updated + +- The previous value of that annotation is copied to the new ReplicaSet + +- In that case, the ReplicaSet annotation does not reflect reality! + +--- + +## Pitfall #2: recording `scale` commands + +- What happens if we use `kubectl scale --record`? + +.exercise[ + +- Check the current history: + ```bash + kubectl rollout history deployment worker + ``` + +- Scale the deployment: + ```bash + kubectl scale deployment worker --replicas=3 --record + ``` + +- Check the change history again: + ```bash + kubectl rollout history deployment worker + ``` + +] + +-- + +The last entry in the history was overwritten by the `scale` command! Why? + +--- + +## Actions that don't create a new ReplicaSet + +- The `scale` command updates the Deployment definition + +- But it doesn't create a new ReplicaSet + +- Using the `--record` flag sets the annotation like before + +- The annotation gets copied to the existing ReplicaSet + +- This overwrites the previous annotation that was there + +- In that case, we lose the previous change cause! + +--- + +## Updating the annotation directly + +- Let's see what happens if we set the annotation manually + +.exercise[ + +- Annotate the Deployment: + ```bash + kubectl annotate deployment worker kubernetes.io/change-cause="Just for fun" + ``` + +- Check that our annotation shows up in the change history: + ```bash + kubectl rollout history deployment worker + ``` + +] + +-- + +Our annotation shows up (and overwrote whatever was there before). + +--- + +## Using change cause + +- It sounds like a good idea to use `--record`, but: + + *"Incorrect documentation is often worse than no documentation."* +
+ (Bertrand Meyer) + +- If we use `--record` once, we need to either: + + - use it every single time after that + + - or clear the Deployment annotation after using `--record` +
+ (subsequent changes will show up with a `` change cause) + +- A safer way is to set it through our tooling diff --git a/slides/k8s/rollout.md b/slides/k8s/rollout.md index 958ad5e2..5783c020 100644 --- a/slides/k8s/rollout.md +++ b/slides/k8s/rollout.md @@ -265,6 +265,8 @@ Note the `3xxxx` port. --- +class: extra-details + ## Changing rollout parameters - We want to: @@ -294,6 +296,8 @@ spec: --- +class: extra-details + ## Applying changes through a YAML patch - We could use `kubectl edit deployment worker` diff --git a/slides/k8s/statefulsets.md b/slides/k8s/statefulsets.md index 9692eef0..6c7c15a9 100644 --- a/slides/k8s/statefulsets.md +++ b/slides/k8s/statefulsets.md @@ -345,7 +345,7 @@ spec: we figure out the minimal command-line to run our Consul cluster.* ``` -consul agent -data=dir=/consul/data -client=0.0.0.0 -server -ui \ +consul agent -data-dir=/consul/data -client=0.0.0.0 -server -ui \ -bootstrap-expect=3 \ -retry-join=`X.X.X.X` \ -retry-join=`Y.Y.Y.Y` diff --git a/slides/k8s/versions-k8s.md b/slides/k8s/versions-k8s.md index 6eda0bb2..e939876f 100644 --- a/slides/k8s/versions-k8s.md +++ b/slides/k8s/versions-k8s.md @@ -1,7 +1,7 @@ ## Versions installed -- Kubernetes 1.15.0 -- Docker Engine 18.09.7 +- Kubernetes 1.15.2 +- Docker Engine 19.03.1 - Docker Compose 1.24.1 diff --git a/slides/kube-twodays.yml b/slides/kube-twodays.yml index 33416a8d..0c1ef38a 100644 --- a/slides/kube-twodays.yml +++ b/slides/kube-twodays.yml @@ -1,5 +1,6 @@ title: | - Kubernetes Training + Deploying and Scaling Microservices + with Kubernetes #chat: "[Slack](https://dockercommunity.slack.com/messages/C7GKACWDV)" #chat: "[Gitter](https://gitter.im/jpetazzo/workshop-yyyymmdd-city)" @@ -7,7 +8,7 @@ chat: "In person!" gitrepo: github.com/jpetazzo/container.training -slides: http://kube-2019-08.container.training/ +slides: http://container.training/ exclude: - self-paced @@ -18,8 +19,8 @@ chapters: - k8s/intro.md - shared/about-slides.md - shared/toc.md -# DAY 1 -- - shared/prereqs.md +- + - shared/prereqs.md - shared/connecting.md - k8s/versions-k8s.md - shared/sampleapp.md @@ -28,7 +29,8 @@ chapters: - shared/composedown.md - k8s/concepts-k8s.md - k8s/kubectlget.md -- - k8s/kubectlrun.md +- + - k8s/kubectlrun.md - k8s/logs-cli.md - shared/declarative.md - k8s/declarative.md @@ -39,50 +41,51 @@ chapters: #- k8s/buildshiprun-selfhosted.md - k8s/buildshiprun-dockerhub.md - k8s/ourapponkube.md -- - k8s/setup-k8s.md +- + - k8s/kubectlproxy.md + - k8s/localkubeconfig.md + - k8s/accessinternal.md + - k8s/setup-k8s.md - k8s/dashboard.md #- k8s/kubectlscale.md - k8s/scalingdockercoins.md - shared/hastyconclusions.md - k8s/daemonset.md -- - k8s/rollout.md +- + - k8s/rollout.md - k8s/healthchecks.md - k8s/healthchecks-more.md + - k8s/record.md +- + - k8s/namespaces.md - k8s/ingress.md -# DAY 2 -- - k8s/namespaces.md - - k8s/netpol.md - - k8s/authn-authz.md -- - k8s/logs-centralized.md - - k8s/prometheus.md -- - k8s/volumes.md - #- k8s/build-with-docker.md - #- k8s/build-with-kaniko.md - - k8s/configuration.md - - k8s/statefulsets.md -- - k8s/local-persistent-volumes.md - - k8s/portworx.md -- - k8s/whatsnext.md - - k8s/links.md - - shared/thankyou.md -# EXTRA -- - | - # (Extra material) - - k8s/kubectlproxy.md - - k8s/localkubeconfig.md - - k8s/accessinternal.md - k8s/kustomize.md - k8s/helm.md - k8s/create-chart.md - - k8s/create-more-charts.md - - k8s/extending-api.md - - k8s/operators.md - - k8s/operators-design.md -- - | - # (Extra material) - - k8s/csr-api.md - - k8s/openid-connect.md - - k8s/podsecuritypolicy.md - #- k8s/gitworkflows.md +- + - k8s/netpol.md + - k8s/authn-authz.md + #- k8s/csr-api.md + #- k8s/openid-connect.md + #- k8s/podsecuritypolicy.md +- + - k8s/volumes.md + #- k8s/build-with-docker.md + #- k8s/build-with-kaniko.md + - k8s/configuration.md + - k8s/logs-centralized.md + - k8s/prometheus.md +- + - k8s/statefulsets.md + - k8s/local-persistent-volumes.md + - k8s/portworx.md + #- k8s/extending-api.md + #- k8s/operators.md + #- k8s/operators-design.md + #- k8s/staticpods.md #- k8s/owners-and-dependents.md - - k8s/staticpods.md + #- k8s/gitworkflows.md +- + - k8s/whatsnext.md + - k8s/links.md + - shared/thankyou.md