78
Resilient Microservices with Kubernetes Mete Atamel Developer Advocate for Google Cloud @meteatamel

Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Embed Size (px)

Citation preview

Page 1: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Resilient Microservices with KubernetesMete AtamelDeveloper Advocate for Google Cloud

@meteatamel

Page 2: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Resilient Microservices with KubernetesMete Atamel

ROME 24-25 MARCH 2017

Page 3: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Confidential & ProprietaryGoogle Cloud Platform 3

Mete AtamelDeveloper Advocate for Google Cloud

@meteatamel

[email protected]

meteatamel.wordpress.com

Please send talk feedback: bit.ly/atamel

Page 4: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Agenda

IntroductionThe Monolith and Microservices

ContainersWhat are containers? How do they help?

KubernetesWhat is Kubernetes? How does it help with management of containers?

Kubernetes building blocksDeployments, pods, labels, selectors, services, replica sets and more

@meteatamel

Page 5: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

The Monolith

@meteatamel

Page 6: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

What is the Monolith? @meteatamel

APP SERVER

Module Module Module

DB

Page 7: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Problems with the Monolith

Unnecessary coupling among modules

All at once update policy, ignores different development velocities

Unable to scale independently

No ownership for the whole system

Difficult debugging/testing, hard to run on a single development machine

@meteatamel

Page 8: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

From The Monolith to Microservices

@meteatamel

Page 9: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

What is a Microservice?

Microservice

DB

@meteatamel

Microservice

DB

Microservice

DB

Page 10: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

New problems

Multiple independent systems to worry about instead of one

Debugging and testing is still hard across multiple services

It works on my machine problem still applies

Production problems still apply: Redundancy, resilience, upgrades/downgrades, scaling up/down

@meteatamel

Page 11: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Simple Microservice

@meteatamel

Page 12: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Containers

@meteatamel

Page 13: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

What is a container?

LightweightHermetically sealedIsolated

Easily deployableIntrospectableComposable

Linux (or Windows) processes

DockerA lightweight way to virtualize applications

@meteatamel

Page 14: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

✕ No isolation✕ Common libs✕ Highly coupled Apps

& OS

Why containers?

app

libs

kernel

libs

app app

kernel

app

libs

libs

kernel

kernel

libs

app

kernel

libs

app

libs

app

libs

app

✓ Isolation✓ No Common Libs✕ Expensive and

Inefficient✕ Hard to manage

✓ Isolation✓ No Common Libs✓ Less overhead✕ Less Dependency on

Host OS

kernellibs

app

app app

app

Shared Machines VMs/Bare Metal Containers

@meteatamel

Page 15: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Google has been developing and using containers to manage our applications for over 12 years.

Images by Connie Zhou

@meteatamel

Page 16: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Everything at Google runs in containers

Gmail, Web Search, Maps, ...MapReduce, batch, ...GFS, Colossus, ...Even Google’s Cloud Platform: our VMs run in containers!

We launch over 2 billion containers per week

@meteatamel

Page 17: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Containerised Microservice

@meteatamel

Page 18: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Containers not enough @meteatamel

Containers help to create a lightweight and consistent environment for apps

But you still need to manage your app in production

● Resiliency● Scaling up and down● Deploying a new version of your app reliably● Rolling back a version● Health checks● Graceful shutdown● Etc.

Page 19: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Kubernetes

@meteatamel

Page 20: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Greek for “Helmsman”; also the root of the words “governor” and “cybernetic”

• Manages container clusters

• Inspired and informed by Google’s experiences and internal systems (borg)

• Supports multiple cloud and bare-metal environments

• Supports multiple container runtimes

• 100% Open source, written in Go

Manage applications, not machines

Kubernetes @meteatamel

Page 21: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

kubelet

UI

kubelet CLI

API

users master nodes

etcd

kubelet

scheduler

controllers

apiserver

The 10000 foot view @meteatamel

Page 22: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

UI

APIContainer

Cluster

All you really care about @meteatamel

Page 23: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

1. Setting up the cluster• Choose a cloud: GCE, AWS, Azure, Rackspace, on-premises, ...• Choose a node OS: CoreOS, Atomic, RHEL, Debian, CentOS, Ubuntu, ...• Provision machines: Boot VMs, install and run kube components, ...• Configure networking: IP ranges for Pods, Services, SDN, ...• Start cluster services: DNS, logging, monitoring, ...• Manage nodes: kernel upgrades, OS updates, hardware failures...

Not the easy or fun part, but unavoidable

This is where things like Google Container Engine (GKE) really help

Container clusters: A story in two parts @meteatamel

Page 24: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Kubernetes cluster on GKE @meteatamel

Page 25: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Create Kubernetes cluster

@meteatamel

Page 26: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

2. Using the cluster• Run Pods & Containers• Replica Sets• Services• Volumes

This is the fun part!

A distinct set of problems from cluster setup and management

Don’t make developers deal with cluster administration!

Accelerate development by focusing on the applications, not the cluster

Container clusters: A story in two parts @meteatamel

Page 27: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Kubernetes Building Blocks

@meteatamel

Page 28: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Container cluster

Service

Pods

Each pod containers one or more containers

Nodes

Role: frontend

Role: frontend Role: frontend Role: frontend

Replication controllerReplicas: 3

Env: prod

microservice

labels

Service communication channel

Blueprint“pod template”

Env: prod Env: prod Env: prod registry

containers

@meteatamel

Page 29: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Deployments

@meteatamel

Page 30: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

A Deployment provides declarative updates for Pods and Replica Sets

Describe the desired state and the Deployment controller will change the actual state to the desired state at a controlled rate for you.

Deployment manages replica changes for you• stable object name• updates are configurable, done server-side• kubectl edit or kubectl apply ...

Deployments @meteatamel

Page 31: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Create Deployment

@meteatamel

Page 32: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Pods and Volumes

@meteatamel

Page 33: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Small group of containers & volumes

Tightly coupled

The atom of scheduling & placement

Shared namespace• share IP address & localhost• share IPC, etc.

Managed lifecycle• bound to a node, restart in place• can die, cannot be reborn with same ID

Example: data puller & web server

ConsumersContent Manager

File Puller

Web Server

Volume

Pod

Pods @meteatamel

Page 34: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Pod-scoped storage

Support many types of volume plugins• Empty dir (and tmpfs)• Host path• Git repository• GCE Persistent Disk• AWS Elastic Block Store• Azure File Storage• iSCSI• Flocker• NFS

• vSphere• GlusterFS• Ceph File and RBD• Cinder• FibreChannel• Secret, ConfigMap,

DownwardAPI• Flex (exec a binary)• ...

Volumes @meteatamel

Page 35: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Labels & Selectors

@meteatamel

Page 36: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Arbitrary metadata

Attached to any API object

Generally represent identity

Queryable by selectors• think SQL ‘select ... where ...’

The only grouping mechanism• pods under a ReplicationController• pods in a Service• capabilities of a node (constraints)

Labels @meteatamel

Page 37: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

App: MyApp

Phase: prod

Role: FE

App: MyApp

Phase: test

Role: FE

App: MyApp

Phase: prod

Role: BE

App: MyApp

Phase: test

Role: BE

Selectors @meteatamel

Page 38: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

App: MyApp

Phase: prod

Role: FE

App: MyApp

Phase: test

Role: FE

App: MyApp

Phase: prod

Role: BE

App: MyApp

Phase: test

Role: BE

App = MyApp

Selectors @meteatamel

Page 39: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

App: MyApp

Phase: prod

Role: FE

App: MyApp

Phase: test

Role: FE

App: MyApp

Phase: prod

Role: BE

App: MyApp

Phase: test

Role: BE

App = MyApp, Role = FE

Selectors @meteatamel

Page 40: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

App: MyApp

Phase: prod

Role: FE

App: MyApp

Phase: test

Role: FE

App: MyApp

Phase: prod

Role: BE

App: MyApp

Phase: test

Role: BE

App = MyApp, Role = BE

Selectors @meteatamel

Page 41: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

App: MyApp

Phase: prod

Role: FE

App: MyApp

Phase: test

Role: FE

App: MyApp

Phase: prod

Role: BE

App: MyApp

Phase: test

Role: BE

App = MyApp, Phase = prod

Selectors @meteatamel

Page 42: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

App: MyApp

Phase: prod

Role: FE

App: MyApp

Phase: test

Role: FE

App: MyApp

Phase: prod

Role: BE

App: MyApp

Phase: test

Role: BE

App = MyApp, Phase = test

Selectors @meteatamel

Page 43: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Replication

@meteatamel

Page 44: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

A simple control loop

Runs out-of-process wrt API server

One job: ensure N copies of a pod• grouped by a selector• too few? start some• too many? kill some

Layered on top of the public Pod API

Replicated pods are fungible• No implied order or identity

* The evolution of ReplicationControllers

ReplicaSet- name = “my-rc”- selector = {“App”: “MyApp”}- template = { ... }- replicas = 4

API Server

How many?

3

Start 1 more

OK

How many?

4

ReplicaSets* @meteatamel

Page 45: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSets

Replication Controller Pod

frontend

Pod

frontendapp = demo app = demo app = demo

ReplicaSet

#pods = 3app = democolor in (blue,grey)

show: version = v2

color = blue color = blue color = grey

Behavior Benefits

● Keeps Pods running● Gives direct control of Pod #s● Grouped by Label Selector

➔ Recreates Pods, maintains desired state➔ Fine-grained control for scaling ➔ Standard grouping semantics

Pod Pod Pod

@meteatamel

Page 46: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Replication

@meteatamel

Page 47: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Services

@meteatamel

Page 48: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Services

Client

Pod

Container

Pod

Container

Pod

Container

A logical grouping of pods that perform the same function (the Service’s endpoints)

• grouped by label selector

Load balances incoming requests across constituent pods

Choice of pod is random but supports session affinity (ClientIP)

Gets a stable virtual IP and port• also a DNS nametype =

Service

Label selector: type = FE

VIP

type = FE type = FE type = FE

@meteatamel

Page 49: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Services

@meteatamel

Page 50: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Scaling

@meteatamel

Page 51: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Scaling @meteatamel

Service

Label selectors: version = 1.0 type = Frontend

Servicename = frontend

Label selector: type = BE

Replication Controller Pod

frontend

Pod

version= v1 version = v1

ReplicaSet

version = v1#pods = 1

show: version = v2 type = FE type = FE

Pod

frontend

Pod

version = v1type = FE

ReplicaSet

version = v1#pods = 2

show: version = v2

Pod

ReplicaSetversion = v1type = FE#pods = 3

show: version = v2

Page 52: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Scaling @meteatamel

Service

Label selectors: version = 1.0 type = Frontend

Servicename = frontend

Label selector: type = BE

Replication Controller Pod

frontend

Pod

version= v1 version = v1

ReplicaSet

version = v1#pods = 1

show: version = v2 type = FE type = FE

Pod

frontend

Pod

version = v1type = FE

ReplicaSet

version = v1#pods = 2

show: version = v2

Pod Pod

ReplicaSetversion = v1type = FE#pods = 4

show: version = v2

version = v1type = FE

Page 53: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Scaling

@meteatamel

Page 54: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Rolling Update

@meteatamel

Page 55: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 3- selector:

- app: MyApp- version: v1

Service- app: MyApp

Rolling Update @meteatamel

Page 56: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 3- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 0- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 57: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 3- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 1- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 58: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 2- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 1- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 59: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 2- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 2- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 60: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 1- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 2- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 61: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 1- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 3- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 62: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v1- replicas: 0- selector:

- app: MyApp- version: v1

ReplicaSet- name: my-app-v2- replicas: 3- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 63: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ReplicaSet- name: my-app-v2- replicas: 3- selector:

- app: MyApp- version: v2

Service- app: MyApp

Rolling Update @meteatamel

Page 64: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Demo: Rolling Update

@meteatamel

Page 65: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Canary Deployments

Replication ControllerReplicaSetversion = v2type = BE#pods = 1

show: version = v2

Pod

frontend

Pod

version = v2type = BE

@meteatamel

Pod

frontend

Service

Label selectors: version = 1.0 type = Frontend

Servicename = backend

Label selector: type = BE

Replication Controller

Pod

version= v1

ReplicaSetversion = v1type = BE#pods = 2

show: version = v2 type = BE type = BE

Pod

version = v1

Page 66: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Autoscaling

Replication Controller Pod

frontend

Pod

name=locust name=locust

ReplicaSetname=locustrole=worker#pods = 1

show: version = v2

Pod

frontend

Pod

name=locust

ReplicaSetname=locustrole=worker#pods = 2

show: version = v2

Pod Pod

name=locust

role=worker role=worker role=worker role=worker

ReplicaSetname=locustrole=worker#pods = 4

Heapster

70% CPU 40% CPU

ScaleCPU Target% = 50

> 50% CPU

@meteatamel

Page 67: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

DaemonSets

@meteatamel

Page 68: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Problem: how to run a Pod on every node?• or a subset of nodes

Similar to ReplicaSet• principle: do one thing, don’t overload

“Which nodes?” is a selector

Use familiar tools and patterns

Pod

DaemonSets @meteatamel

Page 69: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Jobs

@meteatamel

Page 70: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Run-to-completion, as opposed to run-forever• Express parallelism vs. required completions• Workflow: restart on failure• Build/test: don’t restart on failure

Aggregates success/failure counts

Built for batch and big-data work

...

Jobs @meteatamel

Page 71: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

StatefulSets

@meteatamel

Page 72: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Goal: enable clustered software on Kubernetes• mysql, redis, zookeeper, ...

Clustered apps need “identity” and sequencing guarantees

• stable hostname, available in DNS• an ordinal index• stable storage: linked to the ordinal & hostname• discovery of peers for quorum• startup/teardown ordering

StatefulSets @meteatamel

Page 73: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

ConfigMaps

@meteatamel

Page 74: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Goal: manage app configuration• ...without making overly-brittle container images

12-factor says config comes from the environment

• Kubernetes is the environment

Manage config via the Kubernetes API

Inject config as a virtual volume into your Pods• late-binding, live-updated (atomic)• also available as env vars

node

API

Pod ConfigMap

ConfigMaps @meteatamel

Page 75: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Secrets

@meteatamel

Page 76: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Google Cloud Platform

Goal: grant a pod access to a secured something• don’t put secrets in the container image!

12-factor says config comes from the environment

• Kubernetes is the environment

Manage secrets via the Kubernetes API

Inject secrets as virtual volumes into your Pods• late-binding, tmpfs - never touches disk• also available as env vars

node

API

Pod Secret

Secrets @meteatamel

Page 77: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Confidential & ProprietaryGoogle Cloud Platform 77

There is more!

@meteatamel

Page 78: Resilient microservices with Kubernetes - Mete Atamel - Codemotion Rome 2017

Confidential & ProprietaryGoogle Cloud Platform 78

kubernetes.iocloud.google.com/container-engine

Mete Atamel@meteatamel

[email protected]

Thank You

@meteatamel

Send talk feedback bit.ly/atamel