Files
flagger/tutorials/contour-progressive-delivery.html
T
2020-08-20 06:16:09 +00:00

274 lines
41 KiB
HTML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<title>Contour Canary Deployments | Flagger</title>
<meta name="description" content="Progressive Delivery operator for Kubernetes (Canary, A/B Testing and Blue/Green deployments)">
<link rel="icon" href="/favicon.png">
<link rel="stylesheet" href="/website.css">
<meta name="keywords" content="gitops kubernetes flagger istio linkerd appmesh contour gloo nginx">
<meta name="twitter:card" content="summary_large_image">
<meta name="twitter:title" content="Flagger">
<meta name="twitter:description" content="Progressive delivery Kubernetes operator (Canary, A/B Testing and Blue/Green deployments)">
<meta name="twitter:image:src" content="https://flagger.app/flagger-overview.png">
<link rel="preload" href="/assets/css/0.styles.a0ada997.css" as="style"><link rel="preload" href="/assets/js/app.9b46ae46.js" as="script"><link rel="preload" href="/assets/js/2.ba5bf77c.js" as="script"><link rel="preload" href="/assets/js/19.bb9498f7.js" as="script"><link rel="prefetch" href="/assets/js/10.bf6f38d4.js"><link rel="prefetch" href="/assets/js/11.3af38cfe.js"><link rel="prefetch" href="/assets/js/12.eca4b89c.js"><link rel="prefetch" href="/assets/js/13.9104349a.js"><link rel="prefetch" href="/assets/js/14.a4f3d810.js"><link rel="prefetch" href="/assets/js/15.aada2caa.js"><link rel="prefetch" href="/assets/js/16.3012a10b.js"><link rel="prefetch" href="/assets/js/17.a98b6aa9.js"><link rel="prefetch" href="/assets/js/18.e5188926.js"><link rel="prefetch" href="/assets/js/20.2b1bebf5.js"><link rel="prefetch" href="/assets/js/21.e1068843.js"><link rel="prefetch" href="/assets/js/22.1c5d14b9.js"><link rel="prefetch" href="/assets/js/23.b3dcc355.js"><link rel="prefetch" href="/assets/js/24.4f54d289.js"><link rel="prefetch" href="/assets/js/25.914acd1d.js"><link rel="prefetch" href="/assets/js/26.b2d4f402.js"><link rel="prefetch" href="/assets/js/27.ea9f1f9c.js"><link rel="prefetch" href="/assets/js/28.deae273d.js"><link rel="prefetch" href="/assets/js/29.ce4011f4.js"><link rel="prefetch" href="/assets/js/3.8b254d5d.js"><link rel="prefetch" href="/assets/js/30.edda19d9.js"><link rel="prefetch" href="/assets/js/31.fbfb336c.js"><link rel="prefetch" href="/assets/js/32.591c3f2b.js"><link rel="prefetch" href="/assets/js/33.c456709f.js"><link rel="prefetch" href="/assets/js/34.5a071e36.js"><link rel="prefetch" href="/assets/js/35.fc27c09e.js"><link rel="prefetch" href="/assets/js/36.144098aa.js"><link rel="prefetch" href="/assets/js/4.26a3069c.js"><link rel="prefetch" href="/assets/js/5.0c32bdf9.js"><link rel="prefetch" href="/assets/js/6.ee5ffca3.js"><link rel="prefetch" href="/assets/js/7.6bf27a87.js"><link rel="prefetch" href="/assets/js/8.8b72a8d3.js"><link rel="prefetch" href="/assets/js/9.7919fc1d.js">
<link rel="stylesheet" href="/assets/css/0.styles.a0ada997.css">
</head>
<body>
<div id="app" data-server-rendered="true"><div class="theme-container"><header class="navbar"><div class="sidebar-button"><svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" role="img" viewBox="0 0 448 512" class="icon"><path fill="currentColor" d="M436 124H12c-6.627 0-12-5.373-12-12V80c0-6.627 5.373-12 12-12h424c6.627 0 12 5.373 12 12v32c0 6.627-5.373 12-12 12zm0 160H12c-6.627 0-12-5.373-12-12v-32c0-6.627 5.373-12 12-12h424c6.627 0 12 5.373 12 12v32c0 6.627-5.373 12-12 12zm0 160H12c-6.627 0-12-5.373-12-12v-32c0-6.627 5.373-12 12-12h424c6.627 0 12 5.373 12 12v32c0 6.627-5.373 12-12 12z"></path></svg></div> <a href="/" class="home-link router-link-active"><!----> <span class="site-name">Flagger</span></a> <div class="links"><div class="search-box"><input aria-label="Search" autocomplete="off" spellcheck="false" value=""> <!----></div> <nav class="nav-links can-hide"><div class="nav-item"><a href="https://docs.flagger.app" target="_blank" rel="noopener noreferrer" class="nav-link external">
Docs
<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a></div><div class="nav-item"><a href="https://github.com/weaveworks/flagger/blob/master/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class="nav-link external">
Changelog
<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a></div> <a href="https://github.com/weaveworks/flagger" target="_blank" rel="noopener noreferrer" class="repo-link">
GitHub
<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a></nav></div></header> <div class="sidebar-mask"></div> <aside class="sidebar"><nav class="nav-links"><div class="nav-item"><a href="https://docs.flagger.app" target="_blank" rel="noopener noreferrer" class="nav-link external">
Docs
<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a></div><div class="nav-item"><a href="https://github.com/weaveworks/flagger/blob/master/CHANGELOG.md" target="_blank" rel="noopener noreferrer" class="nav-link external">
Changelog
<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a></div> <a href="https://github.com/weaveworks/flagger" target="_blank" rel="noopener noreferrer" class="repo-link">
GitHub
<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a></nav> <ul class="sidebar-links"><li><a href="/" class="sidebar-link">Home</a></li><li><section class="sidebar-group depth-0"><a href="/intro/" class="sidebar-heading clickable"><span>Introduction</span> <!----></a> <ul class="sidebar-links sidebar-group-items"><li><a href="/intro/" class="sidebar-link">Get Started</a></li><li><a href="/intro/faq.html" class="sidebar-link">FAQ</a></li></ul></section></li><li><section class="sidebar-group depth-0"><a href="/install/flagger-install-on-kubernetes" class="sidebar-heading clickable"><span>Install</span> <!----></a> <ul class="sidebar-links sidebar-group-items"><li><a href="/install/flagger-install-on-kubernetes.html" class="sidebar-link">On Kubernetes</a></li><li><a href="/install/flagger-install-on-google-cloud.html" class="sidebar-link">On GKE Istio</a></li><li><a href="/install/flagger-install-on-eks-appmesh.html" class="sidebar-link">On EKS App Mesh</a></li></ul></section></li><li><section class="sidebar-group depth-0"><a href="/usage/how-it-works" class="sidebar-heading clickable"><span>Usage</span> <!----></a> <ul class="sidebar-links sidebar-group-items"><li><a href="/usage/how-it-works.html" class="sidebar-link">How it works</a></li><li><a href="/usage/deployment-strategies.html" class="sidebar-link">Deployment Strategies</a></li><li><a href="/usage/metrics.html" class="sidebar-link">Metrics Analysis</a></li><li><a href="/usage/webhooks.html" class="sidebar-link">Webhooks</a></li><li><a href="/usage/alerting.html" class="sidebar-link">Alerting</a></li><li><a href="/usage/monitoring.html" class="sidebar-link">Monitoring</a></li></ul></section></li><li><section class="sidebar-group depth-0"><a href="/tutorials/istio-progressive-delivery" class="sidebar-heading clickable open"><span>Tutorials</span> <!----></a> <ul class="sidebar-links sidebar-group-items"><li><a href="/tutorials/istio-progressive-delivery.html" class="sidebar-link">Istio Canaries</a></li><li><a href="/tutorials/istio-ab-testing.html" class="sidebar-link">Istio A/B Testing</a></li><li><a href="/tutorials/linkerd-progressive-delivery.html" class="sidebar-link">Linkerd Canaries</a></li><li><a href="/tutorials/appmesh-progressive-delivery.html" class="sidebar-link">App Mesh Canaries</a></li><li><a href="/tutorials/nginx-progressive-delivery.html" class="sidebar-link">NGINX Ingress Canaries</a></li><li><a href="/tutorials/gloo-progressive-delivery.html" class="sidebar-link">Gloo Canaries</a></li><li><a href="/tutorials/contour-progressive-delivery.html" class="active sidebar-link">Contour Canaries</a><ul class="sidebar-sub-headers"><li class="sidebar-sub-header"><a href="/tutorials/contour-progressive-delivery.html#prerequisites" class="sidebar-link">Prerequisites</a></li><li class="sidebar-sub-header"><a href="/tutorials/contour-progressive-delivery.html#bootstrap" class="sidebar-link">Bootstrap</a></li><li class="sidebar-sub-header"><a href="/tutorials/contour-progressive-delivery.html#expose-the-app-outside-the-cluster" class="sidebar-link">Expose the app outside the cluster</a></li><li class="sidebar-sub-header"><a href="/tutorials/contour-progressive-delivery.html#automated-canary-promotion" class="sidebar-link">Automated canary promotion</a></li><li class="sidebar-sub-header"><a href="/tutorials/contour-progressive-delivery.html#automated-rollback" class="sidebar-link">Automated rollback</a></li><li class="sidebar-sub-header"><a href="/tutorials/contour-progressive-delivery.html#a-b-testing" class="sidebar-link">A/B Testing</a></li></ul></li><li><a href="/tutorials/kubernetes-blue-green.html" class="sidebar-link">Kubernetes Blue/Green</a></li><li><a href="/tutorials/canary-helm-gitops.html" class="sidebar-link">Canaries with Helm charts and GitOps</a></li></ul></section></li><li><section class="sidebar-group depth-0"><a href="/dev/dev-guide" class="sidebar-heading clickable"><span>Dev</span> <!----></a> <ul class="sidebar-links sidebar-group-items"><li><a href="/dev/dev-guide.html" class="sidebar-link">Development Guide</a></li><li><a href="/dev/release-guide.html" class="sidebar-link">Release Guide</a></li><li><a href="/dev/upgrade-guide.html" class="sidebar-link">Upgrade Guide</a></li></ul></section></li></ul> </aside> <main class="page"> <div class="theme-default-content content__default"><h1 id="contour-canary-deployments"><a href="#contour-canary-deployments" aria-hidden="true" class="header-anchor">#</a> Contour Canary Deployments</h1> <p>This guide shows you how to use <a href="https://projectcontour.io/" target="_blank" rel="noopener noreferrer">Contour<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a> ingress controller and Flagger to automate canary releases and A/B testing.</p> <p><img src="https://raw.githubusercontent.com/weaveworks/flagger/master/docs/diagrams/flagger-contour-overview.png" alt="Flagger Contour Overview"></p> <h2 id="prerequisites"><a href="#prerequisites" aria-hidden="true" class="header-anchor">#</a> Prerequisites</h2> <p>Flagger requires a Kubernetes cluster <strong>v1.11</strong> or newer and Contour <strong>v1.0</strong> or newer.</p> <p>Install Contour on a cluster with LoadBalancer support:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -f https://projectcontour.io/quickstart/contour.yaml
</code></pre></div><p>The above command will deploy Contour and an Envoy daemonset in the <code>projectcontour</code> namespace.</p> <p>Install Flagger using Kustomize (kubectl 1.14) in the <code>projectcontour</code> namespace:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -k github.com/weaveworks/flagger//kustomize/contour
</code></pre></div><p>The above command will deploy Flagger and Prometheus configured to scrape the Contour's Envoy instances.</p> <p>Or you can install Flagger using Helm:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>helm repo <span class="token function">add</span> flagger https://flagger.app
helm upgrade -i flagger flagger/flagger <span class="token punctuation">\</span>
--namespace projectcontour <span class="token punctuation">\</span>
--set <span class="token assign-left variable">meshProvider</span><span class="token operator">=</span>contour <span class="token punctuation">\</span>
--set prometheus.install<span class="token operator">=</span>true
</code></pre></div><p>You can also enable Slack, Discord, Rocket or MS Teams notifications,
see the alerting <a href="/usage/alerting.html">docs</a>.</p> <h2 id="bootstrap"><a href="#bootstrap" aria-hidden="true" class="header-anchor">#</a> Bootstrap</h2> <p>Flagger takes a Kubernetes deployment and optionally a horizontal pod autoscaler (HPA),
then creates a series of objects (Kubernetes deployments, ClusterIP services and Contour HTTPProxy).
These objects expose the application in the cluster and drive the canary analysis and promotion.</p> <p>Create a test namespace:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl create ns <span class="token builtin class-name">test</span>
</code></pre></div><p>Install the load testing service to generate traffic during the canary analysis:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -k github.com/weaveworks/flagger//kustomize/tester
</code></pre></div><p>Create a deployment and a horizontal pod autoscaler:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -k github.com/weaveworks/flagger//kustomize/podinfo
</code></pre></div><p>Create a canary custom resource (replace <code>app.example.com</code> with your own domain):</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> flagger.app/v1beta1
<span class="token key atrule">kind</span><span class="token punctuation">:</span> Canary
<span class="token key atrule">metadata</span><span class="token punctuation">:</span>
<span class="token key atrule">name</span><span class="token punctuation">:</span> podinfo
<span class="token key atrule">namespace</span><span class="token punctuation">:</span> test
<span class="token key atrule">spec</span><span class="token punctuation">:</span>
<span class="token comment"># deployment reference</span>
<span class="token key atrule">targetRef</span><span class="token punctuation">:</span>
<span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> apps/v1
<span class="token key atrule">kind</span><span class="token punctuation">:</span> Deployment
<span class="token key atrule">name</span><span class="token punctuation">:</span> podinfo
<span class="token comment"># HPA reference</span>
<span class="token key atrule">autoscalerRef</span><span class="token punctuation">:</span>
<span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> autoscaling/v2beta1
<span class="token key atrule">kind</span><span class="token punctuation">:</span> HorizontalPodAutoscaler
<span class="token key atrule">name</span><span class="token punctuation">:</span> podinfo
<span class="token key atrule">service</span><span class="token punctuation">:</span>
<span class="token comment"># service port</span>
<span class="token key atrule">port</span><span class="token punctuation">:</span> <span class="token number">80</span>
<span class="token comment"># container port</span>
<span class="token key atrule">targetPort</span><span class="token punctuation">:</span> <span class="token number">9898</span>
<span class="token comment"># Contour request timeout</span>
<span class="token key atrule">timeout</span><span class="token punctuation">:</span> 15s
<span class="token comment"># Contour retry policy</span>
<span class="token key atrule">retries</span><span class="token punctuation">:</span>
<span class="token key atrule">attempts</span><span class="token punctuation">:</span> <span class="token number">3</span>
<span class="token key atrule">perTryTimeout</span><span class="token punctuation">:</span> 5s
<span class="token comment"># define the canary analysis timing and KPIs</span>
<span class="token key atrule">analysis</span><span class="token punctuation">:</span>
<span class="token comment"># schedule interval (default 60s)</span>
<span class="token key atrule">interval</span><span class="token punctuation">:</span> 30s
<span class="token comment"># max number of failed metric checks before rollback</span>
<span class="token key atrule">threshold</span><span class="token punctuation">:</span> <span class="token number">5</span>
<span class="token comment"># max traffic percentage routed to canary</span>
<span class="token comment"># percentage (0-100)</span>
<span class="token key atrule">maxWeight</span><span class="token punctuation">:</span> <span class="token number">50</span>
<span class="token comment"># canary increment step</span>
<span class="token comment"># percentage (0-100)</span>
<span class="token key atrule">stepWeight</span><span class="token punctuation">:</span> <span class="token number">5</span>
<span class="token comment"># Contour Prometheus checks</span>
<span class="token key atrule">metrics</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> request<span class="token punctuation">-</span>success<span class="token punctuation">-</span>rate
<span class="token comment"># minimum req success rate (non 5xx responses)</span>
<span class="token comment"># percentage (0-100)</span>
<span class="token key atrule">thresholdRange</span><span class="token punctuation">:</span>
<span class="token key atrule">min</span><span class="token punctuation">:</span> <span class="token number">99</span>
<span class="token key atrule">interval</span><span class="token punctuation">:</span> 1m
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> request<span class="token punctuation">-</span>duration
<span class="token comment"># maximum req duration P99 in milliseconds</span>
<span class="token key atrule">thresholdRange</span><span class="token punctuation">:</span>
<span class="token key atrule">max</span><span class="token punctuation">:</span> <span class="token number">500</span>
<span class="token key atrule">interval</span><span class="token punctuation">:</span> 30s
<span class="token comment"># testing</span>
<span class="token key atrule">webhooks</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> acceptance<span class="token punctuation">-</span>test
<span class="token key atrule">type</span><span class="token punctuation">:</span> pre<span class="token punctuation">-</span>rollout
<span class="token key atrule">url</span><span class="token punctuation">:</span> http<span class="token punctuation">:</span>//flagger<span class="token punctuation">-</span>loadtester.test/
<span class="token key atrule">timeout</span><span class="token punctuation">:</span> 30s
<span class="token key atrule">metadata</span><span class="token punctuation">:</span>
<span class="token key atrule">type</span><span class="token punctuation">:</span> bash
<span class="token key atrule">cmd</span><span class="token punctuation">:</span> <span class="token string">&quot;curl -sd 'test' http://podinfo-canary.test/token | grep token&quot;</span>
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> load<span class="token punctuation">-</span>test
<span class="token key atrule">url</span><span class="token punctuation">:</span> http<span class="token punctuation">:</span>//flagger<span class="token punctuation">-</span>loadtester.test/
<span class="token key atrule">type</span><span class="token punctuation">:</span> rollout
<span class="token key atrule">timeout</span><span class="token punctuation">:</span> 5s
<span class="token key atrule">metadata</span><span class="token punctuation">:</span>
<span class="token key atrule">cmd</span><span class="token punctuation">:</span> <span class="token string">&quot;hey -z 1m -q 10 -c 2 -host app.example.com http://envoy.projectcontour&quot;</span>
</code></pre></div><p>Save the above resource as podinfo-canary.yaml and then apply it:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -f ./podinfo-canary.yaml
</code></pre></div><p>The canary analysis will run for five minutes while validating the HTTP metrics and rollout hooks every half a minute.</p> <p>After a couple of seconds Flagger will create the canary objects:</p> <div class="language-bash extra-class"><pre class="language-bash"><code><span class="token comment"># applied </span>
deployment.apps/podinfo
horizontalpodautoscaler.autoscaling/podinfo
canary.flagger.app/podinfo
<span class="token comment"># generated</span>
deployment.apps/podinfo-primary
horizontalpodautoscaler.autoscaling/podinfo-primary
service/podinfo
service/podinfo-canary
service/podinfo-primary
httpproxy.projectcontour.io/podinfo
</code></pre></div><p>After the boostrap, the podinfo deployment will be scaled to zero and the traffic to <code>podinfo.test</code>
will be routed to the primary pods.
During the canary analysis, the <code>podinfo-canary.test</code> address can be used to target directly the canary pods.</p> <h2 id="expose-the-app-outside-the-cluster"><a href="#expose-the-app-outside-the-cluster" aria-hidden="true" class="header-anchor">#</a> Expose the app outside the cluster</h2> <p>Find the external address of Contour's Envoy load balancer:</p> <div class="language-bash extra-class"><pre class="language-bash"><code><span class="token builtin class-name">export</span> <span class="token assign-left variable">ADDRESS</span><span class="token operator">=</span><span class="token string">&quot;<span class="token variable"><span class="token variable">$(</span>kubectl -n projectcontour get svc/envoy -ojson <span class="token punctuation">\</span>
<span class="token operator">|</span> jq -r <span class="token string">&quot;.status.loadBalancer.ingress[].hostname&quot;</span><span class="token variable">)</span></span>&quot;</span>
<span class="token builtin class-name">echo</span> <span class="token variable">$ADDRESS</span>
</code></pre></div><p>Configure your DNS server with a CNAME record (AWS) or A record (GKE/AKS/DOKS)
and point a domain e.g. <code>app.example.com</code> to the LB address.</p> <p>Create a HTTPProxy definition and include the podinfo proxy generated by Flagger
(replace <code>app.example.com</code> with your own domain):</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">apiVersion</span><span class="token punctuation">:</span> projectcontour.io/v1
<span class="token key atrule">kind</span><span class="token punctuation">:</span> HTTPProxy
<span class="token key atrule">metadata</span><span class="token punctuation">:</span>
<span class="token key atrule">name</span><span class="token punctuation">:</span> podinfo<span class="token punctuation">-</span>ingress
<span class="token key atrule">namespace</span><span class="token punctuation">:</span> test
<span class="token key atrule">spec</span><span class="token punctuation">:</span>
<span class="token key atrule">virtualhost</span><span class="token punctuation">:</span>
<span class="token key atrule">fqdn</span><span class="token punctuation">:</span> app.example.com
<span class="token key atrule">includes</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> podinfo
<span class="token key atrule">namespace</span><span class="token punctuation">:</span> test
<span class="token key atrule">conditions</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">prefix</span><span class="token punctuation">:</span> /
</code></pre></div><p>Save the above resource as podinfo-ingress.yaml and then apply it:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl apply -f ./podinfo-ingress.yaml
</code></pre></div><p>Verify that Contour processed the proxy definition with:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl -n <span class="token builtin class-name">test</span> get httpproxies
NAME FQDN STATUS
podinfo valid
podinfo-ingress app.example.com valid
</code></pre></div><p>Now you can access podinfo UI using your domain address.</p> <p>Note that you should be using HTTPS when exposing production workloads on internet.
You can obtain free TLS certs from Let's Encrypt, read this <a href="https://github.com/stefanprodan/eks-contour-ingress" target="_blank" rel="noopener noreferrer">guide<svg xmlns="http://www.w3.org/2000/svg" aria-hidden="true" x="0px" y="0px" viewBox="0 0 100 100" width="15" height="15" class="icon outbound"><path fill="currentColor" d="M18.8,85.1h56l0,0c2.2,0,4-1.8,4-4v-32h-8v28h-48v-48h28v-8h-32l0,0c-2.2,0-4,1.8-4,4v56C14.8,83.3,16.6,85.1,18.8,85.1z"></path> <polygon fill="currentColor" points="45.7,48.7 51.3,54.3 77.2,28.5 77.2,37.2 85.2,37.2 85.2,14.9 62.8,14.9 62.8,22.9 71.5,22.9"></polygon></svg></a>
on how to configure cert-manager to secure Contour with TLS certificates.</p> <h2 id="automated-canary-promotion"><a href="#automated-canary-promotion" aria-hidden="true" class="header-anchor">#</a> Automated canary promotion</h2> <p>Flagger implements a control loop that gradually shifts traffic to the canary while measuring
key performance indicators like HTTP requests success rate, requests average duration and pod health.
Based on analysis of the KPIs a canary is promoted or aborted.</p> <p><img src="https://raw.githubusercontent.com/weaveworks/flagger/master/docs/diagrams/flagger-canary-steps.png" alt="Flagger Canary Stages"></p> <p>A canary deployment is triggered by changes in any of the following objects:</p> <ul><li>Deployment PodSpec (container image, command, ports, env, resources, etc)</li> <li>ConfigMaps and Secrets mounted as volumes or mapped to environment variables</li></ul> <p>Trigger a canary deployment by updating the container image:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl -n <span class="token builtin class-name">test</span> <span class="token builtin class-name">set</span> image deployment/podinfo <span class="token punctuation">\</span>
<span class="token assign-left variable">podinfod</span><span class="token operator">=</span>stefanprodan/podinfo:3.1.1
</code></pre></div><p>Flagger detects that the deployment revision changed and starts a new rollout:</p> <div class="language-text extra-class"><pre class="language-text"><code>kubectl -n test describe canary/podinfo
Status:
Canary Weight: 0
Failed Checks: 0
Phase: Succeeded
Events:
New revision detected! Scaling up podinfo.test
Waiting for podinfo.test rollout to finish: 0 of 1 updated replicas are available
Pre-rollout check acceptance-test passed
Advance podinfo.test canary weight 5
Advance podinfo.test canary weight 10
Advance podinfo.test canary weight 15
Advance podinfo.test canary weight 20
Advance podinfo.test canary weight 25
Advance podinfo.test canary weight 30
Advance podinfo.test canary weight 35
Advance podinfo.test canary weight 40
Advance podinfo.test canary weight 45
Advance podinfo.test canary weight 50
Copying podinfo.test template spec to podinfo-primary.test
Waiting for podinfo-primary.test rollout to finish: 1 of 2 updated replicas are available
Routing all traffic to primary
Promotion completed! Scaling down podinfo.test
</code></pre></div><p>When the canary analysis starts, Flagger will call the pre-rollout webhooks before routing traffic to the canary.</p> <p><strong>Note</strong> that if you apply new changes to the deployment during the canary analysis, Flagger will restart the analysis.</p> <p>You can monitor all canaries with:</p> <div class="language-bash extra-class"><pre class="language-bash"><code><span class="token function">watch</span> kubectl get canaries --all-namespaces
NAMESPACE NAME STATUS WEIGHT LASTTRANSITIONTIME
<span class="token builtin class-name">test</span> podinfo Progressing <span class="token number">15</span> <span class="token number">2019</span>-12-20T14:05:07Z
</code></pre></div><p>If youve enabled the Slack notifications, you should receive the following messages:</p> <p><img src="https://raw.githubusercontent.com/weaveworks/flagger/master/docs/screens/slack-canary-notifications.png" alt="Flagger Slack Notifications"></p> <h2 id="automated-rollback"><a href="#automated-rollback" aria-hidden="true" class="header-anchor">#</a> Automated rollback</h2> <p>During the canary analysis you can generate HTTP 500 errors or high latency to test if Flagger pauses the rollout.</p> <p>Trigger a canary deployment:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl -n <span class="token builtin class-name">test</span> <span class="token builtin class-name">set</span> image deployment/podinfo <span class="token punctuation">\</span>
<span class="token assign-left variable">podinfod</span><span class="token operator">=</span>stefanprodan/podinfo:3.1.2
</code></pre></div><p>Exec into the load tester pod with:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl -n <span class="token builtin class-name">test</span> <span class="token builtin class-name">exec</span> -it deploy/flagger-loadtester <span class="token function">bash</span>
</code></pre></div><p>Generate HTTP 500 errors:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>hey -z 1m -c <span class="token number">5</span> -q <span class="token number">5</span> http://app.example.com/status/500
</code></pre></div><p>Generate latency:</p> <div class="language-bash extra-class"><pre class="language-bash"><code><span class="token function">watch</span> -n <span class="token number">1</span> <span class="token function">curl</span> http://app.example.com/delay/1
</code></pre></div><p>When the number of failed checks reaches the canary analysis threshold, the traffic is routed back to the primary,
the canary is scaled to zero and the rollout is marked as failed.</p> <div class="language-text extra-class"><pre class="language-text"><code>kubectl -n projectcontour logs deploy/flagger -f | jq .msg
New revision detected! Starting canary analysis for podinfo.test
Pre-rollout check acceptance-test passed
Advance podinfo.test canary weight 5
Advance podinfo.test canary weight 10
Advance podinfo.test canary weight 15
Halt podinfo.test advancement success rate 69.17% &lt; 99%
Halt podinfo.test advancement success rate 61.39% &lt; 99%
Halt podinfo.test advancement success rate 55.06% &lt; 99%
Halt podinfo.test advancement request duration 1.20s &gt; 500ms
Halt podinfo.test advancement request duration 1.45s &gt; 500ms
Rolling back podinfo.test failed checks threshold reached 5
Canary failed! Scaling down podinfo.test
</code></pre></div><p>If youve enabled the Slack notifications, youll receive a message if the progress deadline is exceeded,
or if the analysis reached the maximum number of failed checks:</p> <p><img src="https://raw.githubusercontent.com/weaveworks/flagger/master/docs/screens/slack-canary-failed.png" alt="Flagger Slack Notifications"></p> <h2 id="a-b-testing"><a href="#a-b-testing" aria-hidden="true" class="header-anchor">#</a> A/B Testing</h2> <p>Besides weighted routing, Flagger can be configured to route traffic to the canary based on HTTP match conditions.
In an A/B testing scenario, you'll be using HTTP headers or cookies to target a certain segment of your users.
This is particularly useful for frontend applications that require session affinity.</p> <p><img src="https://raw.githubusercontent.com/weaveworks/flagger/master/docs/diagrams/flagger-abtest-steps.png" alt="Flagger A/B Testing Stages"></p> <p>Edit the canary analysis, remove the max/step weight and add the match conditions and iterations:</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">analysis</span><span class="token punctuation">:</span>
<span class="token key atrule">interval</span><span class="token punctuation">:</span> 1m
<span class="token key atrule">threshold</span><span class="token punctuation">:</span> <span class="token number">5</span>
<span class="token key atrule">iterations</span><span class="token punctuation">:</span> <span class="token number">10</span>
<span class="token key atrule">match</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">headers</span><span class="token punctuation">:</span>
<span class="token key atrule">x-canary</span><span class="token punctuation">:</span>
<span class="token key atrule">exact</span><span class="token punctuation">:</span> <span class="token string">&quot;insider&quot;</span>
<span class="token key atrule">webhooks</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> load<span class="token punctuation">-</span>test
<span class="token key atrule">url</span><span class="token punctuation">:</span> http<span class="token punctuation">:</span>//flagger<span class="token punctuation">-</span>loadtester.test/
<span class="token key atrule">metadata</span><span class="token punctuation">:</span>
<span class="token key atrule">cmd</span><span class="token punctuation">:</span> <span class="token string">&quot;hey -z 1m -q 5 -c 5 -H 'X-Canary: insider' -host app.example.com http://envoy.projectcontour&quot;</span>
</code></pre></div><p>The above configuration will run an analysis for ten minutes targeting users that have a <code>X-Canary: insider</code> header.</p> <p>You can also use a HTTP cookie. To target all users with a cookie set to <code>insider</code>, the match condition should be:</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">match</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">headers</span><span class="token punctuation">:</span>
<span class="token key atrule">cookie</span><span class="token punctuation">:</span>
<span class="token key atrule">suffix</span><span class="token punctuation">:</span> <span class="token string">&quot;insider&quot;</span>
<span class="token key atrule">webhooks</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">name</span><span class="token punctuation">:</span> load<span class="token punctuation">-</span>test
<span class="token key atrule">url</span><span class="token punctuation">:</span> http<span class="token punctuation">:</span>//flagger<span class="token punctuation">-</span>loadtester.test/
<span class="token key atrule">metadata</span><span class="token punctuation">:</span>
<span class="token key atrule">cmd</span><span class="token punctuation">:</span> <span class="token string">&quot;hey -z 1m -q 5 -c 5 -H 'Cookie: canary=insider' -host app.example.com http://envoy.projectcontour&quot;</span>
</code></pre></div><p>Trigger a canary deployment by updating the container image:</p> <div class="language-bash extra-class"><pre class="language-bash"><code>kubectl -n <span class="token builtin class-name">test</span> <span class="token builtin class-name">set</span> image deployment/podinfo <span class="token punctuation">\</span>
<span class="token assign-left variable">podinfod</span><span class="token operator">=</span>stefanprodan/podinfo:3.1.3
</code></pre></div><p>Flagger detects that the deployment revision changed and starts the A/B test:</p> <div class="language-text extra-class"><pre class="language-text"><code>kubectl -n projectcontour logs deploy/flagger -f | jq .msg
New revision detected! Starting canary analysis for podinfo.test
Advance podinfo.test canary iteration 1/10
Advance podinfo.test canary iteration 2/10
Advance podinfo.test canary iteration 3/10
Advance podinfo.test canary iteration 4/10
Advance podinfo.test canary iteration 5/10
Advance podinfo.test canary iteration 6/10
Advance podinfo.test canary iteration 7/10
Advance podinfo.test canary iteration 8/10
Advance podinfo.test canary iteration 9/10
Advance podinfo.test canary iteration 10/10
Copying podinfo.test template spec to podinfo-primary.test
Waiting for podinfo-primary.test rollout to finish: 1 of 2 updated replicas are available
Routing all traffic to primary
Promotion completed! Scaling down podinfo.test
</code></pre></div><p>The web browser user agent header allows user segmentation based on device or OS.</p> <p>For example, if you want to route all mobile users to the canary instance:</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">match</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">headers</span><span class="token punctuation">:</span>
<span class="token key atrule">user-agent</span><span class="token punctuation">:</span>
<span class="token key atrule">prefix</span><span class="token punctuation">:</span> <span class="token string">&quot;Mobile&quot;</span>
</code></pre></div><p>Or if you want to target only Android users:</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">match</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">headers</span><span class="token punctuation">:</span>
<span class="token key atrule">user-agent</span><span class="token punctuation">:</span>
<span class="token key atrule">prefix</span><span class="token punctuation">:</span> <span class="token string">&quot;Android&quot;</span>
</code></pre></div><p>Or a specific browser version:</p> <div class="language-yaml extra-class"><pre class="language-yaml"><code><span class="token key atrule">match</span><span class="token punctuation">:</span>
<span class="token punctuation">-</span> <span class="token key atrule">headers</span><span class="token punctuation">:</span>
<span class="token key atrule">user-agent</span><span class="token punctuation">:</span>
<span class="token key atrule">suffix</span><span class="token punctuation">:</span> <span class="token string">&quot;Firefox/71.0&quot;</span>
</code></pre></div><p>For an in-depth look at the analysis process read the <a href="/usage/how-it-works.html">usage docs</a>.</p></div> <footer class="page-edit"><!----> <!----></footer> <div class="page-nav"><p class="inner"><span class="prev">
<a href="/tutorials/gloo-progressive-delivery.html" class="prev">
Gloo Canaries
</a></span> <span class="next"><a href="/tutorials/kubernetes-blue-green.html">
Kubernetes Blue/Green
</a>
</span></p></div> </main></div><div class="global-ui"></div></div>
<script src="/assets/js/app.9b46ae46.js" defer></script><script src="/assets/js/2.ba5bf77c.js" defer></script><script src="/assets/js/19.bb9498f7.js" defer></script>
</body>
</html>