7 minute read

WIP

Kubernetes

It’s orchestration engine and gives basic primitives to orchestrate application deployments on a low level -such as pods, jobs, deployments, services, ingress, persisten volumes, volume claims, secrets, configmaps, daemon, and statefulsets etc..

k8s

Basics

If you like cars, before diving into engine specs and horsepower, you first need to know how to drive. In this blog is no different—so before we get under the hood with intermediate concepts, let’s briefly touch on the basics to make sure we’re all on the same page. Promise we’ll keep it quick!

Setup

Verify

kubectl config view  # tells which cluster it talks to
kubectl config view --raw # 
kubectl config get-contexts $(kubectl config current-context)  # details
kubectl config use-context # 

kubectl api-resources --api-group=apps --namespaced=false
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJkekNDQVIyZ0F3SUJBZ0lCQURBS0JnZ3Foa2pPUFFRREFqQWpNU0V3SHdZRFZRUUREQmhyTTNNdGMyVnkKZG1WeUxXTmhRREUzT0RRNE16Y3dNalV3SGhjTk1qWXdOekl6TWpBd016UTFXaGNOTXpZd056SXdNakF3TXpRMQpXakFqTVNFd0h3WURWUVFEREJock0zTXRjMlZ5ZG1WeUxXTmhRREUzT0RRNE16Y3dNalV3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFRZGxhNnpjaFljbklkVHN3M2U2NmNocG1kL2dEdWdJMkx5UEY3L1BTOXcKWDNsUVRyWnNmaCtsNDZ0eHdiekxyQmVyR3pLL3lDak5tS05PWXFQMlhHK1FvMEl3UURBT0JnTlZIUThCQWY4RQpCQU1DQXFRd0R3WURWUjBUQVFIL0JBVXdBd0VCL3pBZEJnTlZIUTRFRmdRVUo3LzlwZmE1NStkS1ZxZXZTdjRaCm9GaURyZmt3Q2dZSUtvWkl6ajBFQXdJRFNBQXdSUUloQUpjWkRzUzJuUzdOcG9XWHNPUkN0RGdUSER6YS9FdkEKVm1vTG5HSlA0MjhkQWlBcVlNajUyNXhiUFlNVE90WmlsVnZrd1U4bUI4OUtJVkF2VSthZUhBSERlUT09Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
    server: https://127.0.0.1:6443
  name: default
contexts:
- context:
    cluster: default
    user: default
  name: default
current-context: default
kind: Config
users:
- name: default
  user:
    client-certificate-data: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJrVENDQVRlZ0F3SUJBZ0lJSGs0NGVNd2lGU013Q2dZSUtvWkl6ajBFQXdJd0l6RWhNQjhHQTFVRUF3d1kKYXpOekxXTnNhV1Z1ZEMxallVQXhOemcwT0RNM01ESTFNQjRYRFRJMk1EY3lNekl3TURNME5Wb1hEVEkzTURjeQpNekl3TURNME5Wb3dNREVYTUJVR0ExVUVDaE1PYzNsemRHVnRPbTFoYzNSbGNuTXhGVEFUQmdOVkJBTVRESE41CmMzUmxiVHBoWkcxcGJqQlpNQk1HQnlxR1NNNDlBZ0VHQ0NxR1NNNDlBd0VIQTBJQUJFRHZzNVFOL0cwTHRVVGIKc3p4WW43aXYyeTZSY1drakdmc3lVSjdzaVYrYlVBcXpLNXNKa3RIWWNpcUJDMGRndU5UekwxeDYvNjNsTWVUWQpwYk5pclB1alNEQkdNQTRHQTFVZER3RUIvd1FFQXdJRm9EQVRCZ05WSFNVRUREQUtCZ2dyQmdFRkJRY0RBakFmCkJnTlZIU01FR0RBV2dCU2NhOTk3MWVkMmhBUHJNOUlTMnRsbmtkc1dxVEFLQmdncWhrak9QUVFEQWdOSUFEQkYKQWlCZXBXT2hHSmtvdWk1RVdvbzMxZWFpSDF1MGROYzlrQkdIZmI1ejQ3czlId0loQUtLUTZsM3JWVFhLK1hTdQpuWkUzbUJ6U2Vvd1R1bENQdDBUd0lvY1lmODJnCi0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0KLS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUJlRENDQVIyZ0F3SUJBZ0lCQURBS0JnZ3Foa2pPUFFRREFqQWpNU0V3SHdZRFZRUUREQmhyTTNNdFkyeHAKWlc1MExXTmhRREUzT0RRNE16Y3dNalV3SGhjTk1qWXdOekl6TWpBd016UTFXaGNOTXpZd056SXdNakF3TXpRMQpXakFqTVNFd0h3WURWUVFEREJock0zTXRZMnhwWlc1MExXTmhRREUzT0RRNE16Y3dNalV3V1RBVEJnY3Foa2pPClBRSUJCZ2dxaGtqT1BRTUJCd05DQUFUQnlFd2pKVDF6bVN0OVBuR1MranZGNkN0NklTVkdnTTg0bkNVWGxRZUIKNHVGT3FlZUxheDA4eENRTGozZXpBKzJCNloxaWp2dXpGSkl3QXpoeEJVTm5vMEl3UURBT0JnTlZIUThCQWY4RQpCQU1DQXFRd0R3WURWUjBUQVFIL0JBVXdBd0VCL3pBZEJnTlZIUTRFRmdRVW5HdmZlOVhuZG9RRDZ6UFNFdHJaClo1SGJGcWt3Q2dZSUtvWkl6ajBFQXdJRFNRQXdSZ0loQUxvbnhMeWVpWVYzbXd4M2JoY25mVFZnd0RQbkhxOXkKY2pHaU9PVEpTQ3JpQWlFQTduZ0NGNC9CZ3JJQzhTaDJGaEgvd0V2ZHFSTXZ5czdRd3RWQjFCWWdOUFU9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K
    client-key-data: LS0tLS1CRUdJTiBFQyBQUklWQVRFIEtFWS0tLS0tCk1IY0NBUUVFSUlJcWJXd2FiemFwWGxYRVBwMGswa21RditqWjNpYkxVOGNvd09jaTBHUVJvQW9HQ0NxR1NNNDkKQXdFSG9VUURRZ0FFUU8remxBMzhiUXUxUk51elBGaWZ1Sy9iTHBGeGFTTVorekpRbnV5Slg1dFFDck1ybXdtUwowZGh5S29FTFIyQzQxUE12WEhyL3JlVXg1TmlsczJLcyt3PT0KLS0tLS1FTkQgRUMgUFJJVkFURSBLRVktLS0tLQo=
kubectl api-resources

  NAME                                SHORTNAMES   APIVERSION                          NAMESPACED   KIND
  bindings                                         v1                                  true         Binding
  componentstatuses                   cs           v1                                  false        ComponentStatus
  configmaps                          cm           v1                                  true         ConfigMap
  endpoints                           ep           v1                                  true         Endpoints
  events                              ev           v1                                  true         Event
  limitranges                         limits       v1                                  true         LimitRange
  namespaces                          ns           v1                                  false        Namespace
  nodes                               no           v1                                  false        Node
  persistentvolumeclaims              pvc          v1                                  true         PersistentVolumeClaim
  persistentvolumes                   pv           v1                                  false        PersistentVolume
  pods                                po           v1                                  true         Pod
  podtemplates                                     v1                                  true         PodTemplate
  replicationcontrollers              rc           v1                                  true         ReplicationController
  resourcequotas                      quota        v1                                  true         ResourceQuota
  secrets                                          v1                                  true         Secret
  serviceaccounts                     sa           v1                                  true         ServiceAccount
  services                            svc          v1                                  true         Service
  mutatingwebhookconfigurations                    admissionregistration.k8s.io/v1     false        MutatingWebhookConfiguration
  validatingadmissionpolicies                      admissionregistration.k8s.io/v1     false        ValidatingAdmissionPolicy
  validatingadmissionpolicybindings                admissionregistration.k8s.io/v1     false        ValidatingAdmissionPolicyBinding
  validatingwebhookconfigurations                  admissionregistration.k8s.io/v1     false        ValidatingWebhookConfiguration
  customresourcedefinitions           crd,crds     apiextensions.k8s.io/v1             false        CustomResourceDefinition
  apiservices                                      apiregistration.k8s.io/v1           false        APIService
  controllerrevisions                              apps/v1                             true         ControllerRevision
  daemonsets                          ds           apps/v1                             true         DaemonSet
  deployments                         deploy       apps/v1                             true         Deployment
  replicasets                         rs           apps/v1                             true         ReplicaSet
  statefulsets                        sts          apps/v1                             true         StatefulSet
  selfsubjectreviews                               authentication.k8s.io/v1            false        SelfSubjectReview
  tokenreviews                                     authentication.k8s.io/v1            false        TokenReview
  localsubjectaccessreviews                        authorization.k8s.io/v1             true         LocalSubjectAccessReview
  selfsubjectaccessreviews                         authorization.k8s.io/v1             false        SelfSubjectAccessReview
  selfsubjectrulesreviews                          authorization.k8s.io/v1             false        SelfSubjectRulesReview
  subjectaccessreviews                             authorization.k8s.io/v1             false        SubjectAccessReview
  horizontalpodautoscalers            hpa          autoscaling/v2                      true         HorizontalPodAutoscaler
  cronjobs                            cj           batch/v1                            true         CronJob
  jobs                                             batch/v1                            true         Job
  certificatesigningrequests          csr          certificates.k8s.io/v1              false        CertificateSigningRequest
  leases                                           coordination.k8s.io/v1              true         Lease
  endpointslices                                   discovery.k8s.io/v1                 true         EndpointSlice
  events                              ev           events.k8s.io/v1                    true         Event
  flowschemas                                      flowcontrol.apiserver.k8s.io/v1     false        FlowSchema
  prioritylevelconfigurations                      flowcontrol.apiserver.k8s.io/v1     false        PriorityLevelConfiguration
  gatewayclasses                      gc           gateway.networking.k8s.io/v1        false        GatewayClass
  gateways                            gtw          gateway.networking.k8s.io/v1        true         Gateway
  grpcroutes                                       gateway.networking.k8s.io/v1        true         GRPCRoute
  httproutes                                       gateway.networking.k8s.io/v1        true         HTTPRoute
  referencegrants                     refgrant     gateway.networking.k8s.io/v1beta1   true         ReferenceGrant
  helmchartconfigs                                 helm.cattle.io/v1                   true         HelmChartConfig
  helmcharts                                       helm.cattle.io/v1                   true         HelmChart
  accesscontrolpolicies                            hub.traefik.io/v1alpha1             false        AccessControlPolicy
  aiservices                                       hub.traefik.io/v1alpha1             true         AIService
  apiaccesses                                      hub.traefik.io/v1alpha1             true         APIAccess
  apibundles                                       hub.traefik.io/v1alpha1             true         APIBundle
  apicatalogitems                                  hub.traefik.io/v1alpha1             true         APICatalogItem
  apiplans                                         hub.traefik.io/v1alpha1             true         APIPlan
  apiportals                                       hub.traefik.io/v1alpha1             true         APIPortal
  apiratelimits                                    hub.traefik.io/v1alpha1             true         APIRateLimit
  apis                                             hub.traefik.io/v1alpha1             true         API
  apiversions                                      hub.traefik.io/v1alpha1             true         APIVersion
  managedsubscriptions                             hub.traefik.io/v1alpha1             true         ManagedSubscription
  addons                                           k3s.cattle.io/v1                    true         Addon
  etcdsnapshotfiles                                k3s.cattle.io/v1                    false        ETCDSnapshotFile
  nodes                                            metrics.k8s.io/v1beta1              false        NodeMetrics
  pods                                             metrics.k8s.io/v1beta1              true         PodMetrics
  ingressclasses                                   networking.k8s.io/v1                false        IngressClass
  ingresses                           ing          networking.k8s.io/v1                true         Ingress
  ipaddresses                         ip           networking.k8s.io/v1                false        IPAddress
  networkpolicies                     netpol       networking.k8s.io/v1                true         NetworkPolicy
  servicecidrs                                     networking.k8s.io/v1                false        ServiceCIDR
  runtimeclasses                                   node.k8s.io/v1                      false        RuntimeClass
  poddisruptionbudgets                pdb          policy/v1                           true         PodDisruptionBudget
  clusterrolebindings                              rbac.authorization.k8s.io/v1        false        ClusterRoleBinding
  clusterroles                                     rbac.authorization.k8s.io/v1        false        ClusterRole
  rolebindings                                     rbac.authorization.k8s.io/v1        true         RoleBinding
  roles                                            rbac.authorization.k8s.io/v1        true         Role
  deviceclasses                                    resource.k8s.io/v1                  false        DeviceClass
  resourceclaims                                   resource.k8s.io/v1                  true         ResourceClaim
  resourceclaimtemplates                           resource.k8s.io/v1                  true         ResourceClaimTemplate
  resourceslices                                   resource.k8s.io/v1                  false        ResourceSlice
  priorityclasses                     pc           scheduling.k8s.io/v1                false        PriorityClass
  csidrivers                                       storage.k8s.io/v1                   false        CSIDriver
  csinodes                                         storage.k8s.io/v1                   false        CSINode
  csistoragecapacities                             storage.k8s.io/v1                   true         CSIStorageCapacity
  storageclasses                      sc           storage.k8s.io/v1                   false        StorageClass
  volumeattachments                                storage.k8s.io/v1                   false        VolumeAttachment
  volumeattributesclasses             vac          storage.k8s.io/v1                   false        VolumeAttributesClass
  ingressroutes                                    traefik.io/v1alpha1                 true         IngressRoute
  ingressroutetcps                                 traefik.io/v1alpha1                 true         IngressRouteTCP
  ingressrouteudps                                 traefik.io/v1alpha1                 true         IngressRouteUDP
  middlewares                                      traefik.io/v1alpha1                 true         Middleware
  middlewaretcps                                   traefik.io/v1alpha1                 true         MiddlewareTCP
  serverstransports                                traefik.io/v1alpha1                 true         ServersTransport
  serverstransporttcps                             traefik.io/v1alpha1                 true         ServersTransportTCP
  tlsoptions                                       traefik.io/v1alpha1                 true         TLSOption
  tlsstores                                        traefik.io/v1alpha1                 true         TLSStore
  traefikservices                                  traefik.io/v1alpha1                 true         TraefikService

K8S 101

alt text

- Container

A sealed application package (Docker)

- Pod

The smallest and simplest Kubernetes object. It represents a single instance of a running process in your cluster. pods are one or more containers

kubectl run web-pod --image=gcr.io/google-samples/kubernetes-bootcamp:v1 --dry-run=client -o yml > pod.yml
  • Qos: Settings requests and limits influence the kubelet to make decision as to which pod to evicit first in the event of resource starvation requests:: min amount of resource that pod needs. limits:: define the max amount of resources that you need to supply for a given pod.
    • Guaranteed:: Every container must have both CPU and memory limits and requests defined. requests == limits
    • Burstable:: At least one container has a CPU or memory request that does not equal its limit. requests defined
    • Best Effort:: No containers have any CPU or memory requests or limits defined. 1st one get killed if resource starvation
  • Pod Priority and preemption: Now, what happens if high priority comes when there are no nodes with respective pods? The scheduler will remove low-priority pods
apiVersion: scheduling.k8s.io/v1
kind: PriorityClass
metadata:
  name: high-priority-apps
value: 1000000
# preemptionPolicy: Never  # Non-preempting PriorityClass
globalDefault: false
description: "This priority class is reserved for mission-critical core applications."
---
apiVersion: v1
kind: Pod
metadata:
  name: critical-api-pod
  labels:
    app: api-service
spec:
  priorityClassName: high-priority-apps # Linking the pod-priority
  containers:
  - name: web-app
    image: nginx:latest
    # defining resource and limits
    resources:
      requests:
        memory: "256Mi"
        cpu: "500m"
      limits:
        memory: "512Mi"
        cpu: "1000m"

sharabled-non-sharable-resources

  • Sharable Resources that can be shared among different consumers limited when required. CPU is sharable resources, it pod wants more than limit, it will not get terminated. Kubelet throttles the container, leads to negative performance.
  • Non sharable resources that cannot be shared by nature, Memory. when container exceeds it will get killed OOMKilled

  • Health Checks: Liveness Probe, Readiness Probe and Startup Probe
        Application Running
                │
                ▼
        Liveness Probe
                │
          Healthy?
            /    \
        Yes      No
        │         │
        │     Restart Container
        ▼
        Continue Running
        
          Application Starting
                  │
                  ▼
          Readiness Probe
                  │
            Ready?
            /    \
          Yes     No
          │        │
          │     Don't send traffic
          ▼
          Receive traffic
          
- Labels

Identify metadata attached to objects. use to determin which objects to apply an operation to primitive objects

apiVersion: v1
kind: Pod
metadata:
  name: dev-fe
  labels:
    app: nify
    phase: dev
    role: fe
spec:
  containers:
  - name: nginx
    image: nginx:alpine
---
apiVersion: v1
kind: Pod
metadata:
  name: dev-be
  labels:
    app: nify
    phase: dev
    role: be
spec:
  containers:
  - name: python
    image: python:3.12-alpine
    command: ["python", "-m", "http.server", "8000"]
---
apiVersion: v1
kind: Pod
metadata:
  name: test-fe
  labels:
    app: nify
    phase: test
    role: fe
spec:
  containers:
  - name: httpd
    image: httpd:alpine
---
apiVersion: v1
kind: Pod
metadata:
  name: test-be
  labels:
    app: nify
    phase: test
    role: be
spec:
  containers:
  - name: golang
    image: golang:1.24-alpine
    command:
      - sh
      - -c
      - |
        cat <<'EOF' > /tmp/server.go
        package main

        import (
          "fmt"
          "net/http"
        )

        func main() {
          http.HandleFunc("/", func(w http.ResponseWriter, r *http.Request) {
            fmt.Fprintln(w, "Hello from Go!")
          })
          http.ListenAndServe(":8080", nil)
        }
        EOF
        go run /tmp/server.go

alt text

- Selector

Query against labels, producing a set result

apiVersion: v1
kind: Service
metadata:
  name: nify-service
spec:
  selector:
    app: nify
  ports:
  - port: 80
    targetPort: 80
  type: ClusterIP
  • Query App=Nifty alt text
apiVersion: v1
kind: Service
metadata:
  name: nify-fe-service
spec:
  selector:
    app: nify
    role: fe
  ports:
  - port: 80
    targetPort: 80
  type: ClusterIP
  • Query App=Nifty and Role=FE alt text
apiVersion: v1
kind: Service
metadata:
  name: nify-dev-service
spec:
  selector:
    app: nify
    phase: dev
  ports:
  - port: 80
    targetPort: 80
  type: ClusterIP
  • Query App=Nifty and Phase=Dev alt text

To test the connection

kubectl port-forward service/SERVICE_NAME 8080:80
- Controller

A reconcilation loop that drives current state towards desired state

while(true) {
    desired = API Server
    actual  = Cluster

    if desired != actual {
        reconcile()
    }
}
- Replica Set
- Deployment

Grp of pods of the same type together to achieve load balancing. Greate for stateless workload, where exact copies of app runs and destory, maintain desired number of apps.

- Rollout
- Service

A set of pods that work together in deployment and Service helps expose your deployment. This exposure can be to other deployments and/or to the outside world. alt text

  • Types of Services types
    • ClusterIP
    • NodePort
    • LoadBalancer
- ConfigMap
- Secrets
- Namespace

It provide a mechanism for isolating groups of resources within a single cluster. ns

kubectl create ns NAMESPACE
kubectl config set-context --current --namespace=NAMESPACE
- StatefulSets

Similar to deployments but used for applications where copies of same application must coordianate with each other to maintain state. It manage the lifecycle of unique copies of pods. make sure networking & storage are reused if unhealthy pod need to be replaced.

- Volumes

alt text


Kubernets Components

k8s

  • API Server: responsible for communication with kubelet on the worker nodes. Authentication , Authorization of the requestor
  • Etcd: key-value store of the critical state of system. Distributed Core Logic snapsotting the status of the k8s cluster
  • Kube Controller Manager: responsible for monitoring the shared state of cluster through apiserver and making it to desired state
  • Kube Scheduler: responsbile for select the worker node for a POD, and provision on target node according to resource specification.

Kube Scheduler