kubernetes 的 ingress 配置部署

kubernetes 的 ingress 配置部署

標籤(空格分隔): kubernetes系列


  • 一:kubernetes 的 ingress

一:kubernetes 的 nginx ingress

1.1 ingress-nginx的部署

Ingress-Nginx github 地址:https://github.com/kubernetes/ingress-nginx
Ingress-Nginx 官方網站:https://kubernetes.github.io/ingress-nginx/

image_1e2qgqi6g1hoi1s7345s1moe1u4t9.png-364.6kB

image_1e2qgr12u9gabc11nf4naucnm.png-220.1kB

部署:

wget https://raw.githubusercontent.com/kubernetes/ingress-nginx/nginx-0.30.0/deploy/static/mandatory.yaml

wget https://raw.githubusercontent.com/kubernetes/ingress-nginx/nginx-0.30.0/deploy/static/provider/baremetal/service-nodeport.yaml

kubectl apply -f mandatory.yaml

kubectl apply -f service-nodeport.yaml

----

所有節點上傳ingress-contro.tar 文件

所有節點加載鏡像
docker load -i ingree.contro.tar

docker images 

kubectl apply -f mandatory.yaml

kubectl get deploy -n ingress-nginx
kubectl get pod -n ingress-nginx 

image_1e2qi3l331ev61urt1dul105lh6716.png-200.2kB

image_1e2qi4iq7noa3bjksgisj1gh61j.png-143.9kB

image_1e2qkh2fe15o117rqkj5ca6plu9.png-103.9kB

image_1e2qo4pse13ah24dobmrbs3go1g.png-204.4kB


如何使用國外機器打包鏡像已經下載

先部署docker 

yum install -y yum-utils device-mapper-persistent-data lvm2

yum-config-manager --add-repo http://mirrors.aliyun.com/docker-ce/linux/centos/docker-ce.repo

yum install docker-ce-18.09.9 docker-ce-cli-18.09.9 containerd.io -y

service docker start

----

docker pull quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.30.0

docker save -o ingrss.contro.tar quay.io/kubernetes-ingress-controller/nginx-ingress-controller:0.30.0 

tar -zcvf ingrss.contro.tar.gz ingrss.contro.tar

然後 下載 ingrss.contro.tar.gz 即可

部署ingress-nginx的 svc

wget https://raw.githubusercontent.com/kubernetes/ingress-nginx/nginx-0.30.0/deploy/static/provider/baremetal/service-nodeport.yaml

kubectl apply -f service-nodeport.yaml

kubectl get svc -n ingress-nignx

image_1e2qofkpgomcsdoi1u7fd1fdl1t.png-228.4kB


1.2:Ingress HTTP 代理訪問

deployment、Service、Ingress Yaml 文件

---

vim svc-deploy.yaml

---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: nginx-dm
spec:
  replicas: 2
  template:
    metadata:
      labels:
        name: nginx
    spec:
      containers:
        - name: nginx
          image: wangyanglinux/myapp:v1
          imagePullPolicy: IfNotPresent
          ports:
            - containerPort: 80
---

apiVersion: v1
kind: Service
metadata:
  name: nginx-svc
spec:
  ports:
   - port: 80
     targetPort: 80
     protocol: TCP
  selector:
    name: nginx

---

image_1e2qps2gt133vp826c31p0jvss9.png-163.7kB

image_1e2qq04pv1qi1lrl1mlmfv88esm.png-142kB

使用ingress 發佈

vim nginx-ingress.yaml
----

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: nginx-test
spec:
  rules:
    - host: node01.flyfish
      http:
        paths:
        - path: /
          backend:
            serviceName: nginx-svc
            servicePort: 80
---

kubectl apply -f nginx-ingress.yaml

kubectl get svc -n ingress-nginx

image_1e2qqfajh1a2j10afm201lc06tl1g.png-61.8kB

image_1e2qqc24f1cg882f1sqruvt1dt813.png-92.1kB


實現一個虛擬主機

image_1e2rv86aogi8le21tsn2n77b0m.png-158.4kB


定義deploy1 與svc1 

vim deployment1.yaml

---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: deployment1
spec:
  replicas: 2
  template:
    metadata:
      labels:
        name: nginx1
    spec:
      containers:
        - name: nginx1
          image: wangyanglinux/myapp:v1
          imagePullPolicy: IfNotPresent
          ports:
            - containerPort: 80
---
apiVersion: v1
kind: Service
metadata:
  name: svc-1
spec:
  ports:
   - port: 80
     targetPort: 80
     protocol: TCP
  selector:
    name: nginx1
---
kubectl apply -f deployment1.yaml

image_1e2rvceuna8nhpd1rl3tgcgme13.png-31.5kB


定義deploy2 與svc2 

vim deployment2.yaml

---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: deployment2
spec:
  replicas: 2
  template:
    metadata:
      labels:
        name: nginx2
    spec:
      containers:
        - name: nginx2
          image: wangyanglinux/myapp:v2
          imagePullPolicy: IfNotPresent
          ports:
            - containerPort: 80
---
apiVersion: v1
kind: Service
metadata:
  name: svc-2
spec:
  ports:
   - port: 80
     targetPort: 80
     protocol: TCP
  selector:
    name: nginx2
---
kubectl apply -f deployment2.yaml

image_1e2rvf3gscqm1c5i19kqa9m19oa1j.png-38.7kB

定義ingress的nginx 對外連接

vim ingress.yaml
---

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: ingress1
spec:
  rules:
    - host: www1.flyfish.com
      http:
        paths:
        - path: /
          backend:
            serviceName: svc-1
            servicePort: 80
---
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: ingress2
spec:
  rules:
    - host: www2.flyfish.com
      http:
        paths:
        - path: /
          backend:
            serviceName: svc-2
            servicePort: 80
---

kubectl apply -f ingress.yaml

image_1e2rvkbo71gbg86n6sq9l2iu20.png-44.1kB

測試: 

kubectl get svc 

kubectl get svc -n ingress-nginx

image_1e2rvmmif11p1bagvcd138dj0v2t.png-136.5kB

image_1e2rvnngu1hk51rtjrfl***62f3d.png-61.1kB

image_1e2rvognc1vcg1ic31bgbi4o1s9h3q.png-71.1kB

image_1e2rvotpt1sfg1o8h1p2a1m14f5k47.png-83.4kB


1.3 Ingress HTTPS 代理訪問

創建證書,以及 cert 存儲方式

openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 -keyout tls.key -out tls.crt -subj "/CN=nginxsvc/O=nginxsvc"

kubectl create secret tls tls-secret --key tls.key --cert tls.crt

image_1e2s1e65h1q9r1f2k9221l1bf715u.png-98.4kB

image_1e2s1f9i6m351rne78312o5q4e6u.png-39.2kB

image_1e2s1frca10khg691s2913ctjvu7b.png-52.5kB


deployment、Service、Ingress Yaml 文件

vim deployment3.yaml

---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: deployment1
spec:
  replicas: 2
  template:
    metadata:
      labels:
        name: nginx3
    spec:
      containers:
        - name: nginx3
          image: wangyanglinux/myapp:v3
          imagePullPolicy: IfNotPresent
          ports:
            - containerPort: 80
---
apiVersion: v1
kind: Service
metadata:
  name: svc-3
spec:
  ports:
   - port: 80
     targetPort: 80
     protocol: TCP
  selector:
    name: nginx3
---

vim ingress.yaml

---
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: https
spec:
  tls:
    - hosts:
      - www3.flyfish.com
      secretName: tls-secret
  rules:
    - host: www3.flyfish.com
      http:
        paths:
        - path: /
          backend:
            serviceName: svc-3
            servicePort: 80
---

kubectl apply -f deployment3.yaml
kubectl apply -f ingress.yaml

image_1e2s1km34nom1ursluu1ekj1eu485.png-37.4kB

image_1e2s1k978gfr75b9d1e8hdd87o.png-39.9kB

image_1e2s1m97kq2l8bj1rgt13gm16b48i.png-101.5kB

image_1e2s1c0ru1u6vkmesr91aijhuo4k.png-305.5kB

image_1e2s1cft53fmpri18mi1h8vmgt51.png-52kB


1.4 Nginx 進行 BasicAuth

yum -y install httpd
htpasswd -c auth foo
kubectl create secret generic basic-auth --from-file=auth

kubectl get secret 

image_1e2s325i9e4u18t3e0bgtvpbt9p.png-44.6kB

image_1e2s3344u1f4f10pob2u1q3tpina6.png-150.9kB


vim deployment4.yaml
---
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  name: deployment4
spec:
  replicas: 2
  template:
    metadata:
      labels:
        name: nginx4
    spec:
      containers:
        - name: nginx4
          image: wangyanglinux/myapp:v4
          imagePullPolicy: IfNotPresent
          ports:
            - containerPort: 80
---
apiVersion: v1
kind: Service
metadata:
  name: svc-4
spec:
  ports:
   - port: 80
     targetPort: 80
     protocol: TCP
  selector:
    name: nginx4
---

vim  basicauth.yaml
---
apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: ingress-with-auth
  annotations:
    nginx.ingress.kubernetes.io/auth-type: basic
    nginx.ingress.kubernetes.io/auth-secret: basic-auth
    nginx.ingress.kubernetes.io/auth-realm: 'Authentication Required - foo'
spec:
  rules:
  - host: auth.flyfish.com
    http:
      paths:
      - path: /
        backend:
          serviceName: svc-4
          servicePort: 80
---
kubectl apply -f deployment4.yaml
kubectl apply -f basicauth.yaml
kubectl get svc -n ingress-nginx

image_1e2s369a21lml1n9n16991277rejb0.png-51.7kB

image_1e2s35m2qona1mbclgcv7p1o59aj.png-128.6kB

image_1e2s2ih5919i0jrd74j13o414sk8v.png-124.6kB

image_1e2s2u71e1sb414k81bq61omh4jk9c.png-76.7kB


##1.5 Nginx 進行重寫

image_1e2s4cj9l1m58rir125lmh2b1nbj.png-149.4kB

image_1e2sa96vjo6u14mg4061bnnnocd.png-144.5kB

vim ingress-re.yaml
---

apiVersion: extensions/v1beta1
kind: Ingress
metadata:
  name: nginx-re
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: https://www3.flyfish.com:32500/hostname.html
spec:
  rules:
  - host: re.flyfish.com
    http:
     paths:
     - path: /
       backend:
         serviceName: svc-2
         servicePort: 80
---

kubectl apply -f ingress-re.yaml

kubectl get svc -n ingress-nginx 

image_1e2sab7hq1o4q29q45nepcuc1cq.png-37.6kB

image_1e2sadkek1ado19ph1chc2qljcbd7.png-149.2kB

image_1e2safgomq4j143g4qj9r77cje1.png-63.2kB

image_1e2sae37g1qru1ves1gtv16v91qfndk.png-108.4kB

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章