Posts

Showing posts with the label Kubernetes

Kafka Message system on Kubernetes

Image
  Setting up the Kubernetes namespace for kafka apiVersion: v1 kind: Namespace metadata: name: "kafka" labels: name: "kafka" k apply -f kafka-ns.yml Now let's create the ZooKeeper container inside the kafka namespace apiVersion: v1 kind: Service metadata: labels: app: zookeeper-service name: zookeeper-service namespace: kafka spec: type: NodePort ports: - name: zookeeper-port port: 2181 nodePort: 30181 targetPort: 2181 selector: app: zookeeper --- apiVersion: apps/v1 kind: Deployment metadata: labels: app: zookeeper name: zookeeper namespace: kafka spec: replicas: 1 selector: matchLabels: app: zookeeper template: metadata: labels: app: zookeeper spec: containers: - image: wurstmeister/zookeeper imagePullPolicy: IfNotPresent name: zookeeper ports: - containerPort: 2181 image1 - kube-kafka1 From th...

Job & CronJob - Batch Job

Image
What is Job object in Kubernetes? A Job object will be used to create one or more Pods and the Job ensures that a specified number of Pod instances will be created and terminates after completion of the Job. There could be finite jobs which will run within given certain timeout values. Job tracks for 'Successful' completion of the required task. Jobs can be run in two variants they can be parallel and also non-parallel. Kubernetes Job types There are 3 types of jobs non-parallel jobs [single pod jobs - unless it fails. creates replacement pod when pod goes down] parallel jobs with a fixed completion count parallel jobs with task queue  ##Example type 1: hundred-fibonaccis.yml --- apiVersion: batch/v1 kind: Job metadata: name: fibo-100 spec: template: spec: containers: - name: fib-container image: truek8s/hundred-fibonaccis:1.0 restartPolicy: OnFailure backoffLimit: 3 Create the Job: kubectl create -f hundred-fibonaccis.yml Now let's...

Kubernetes Deployment

Image
Hello DevSecOps, SRE or Platform Engineer or DevOps Engineers, In this post I want to discuss, Understanding of Kubernetes deployment it's hierarchy of kube objects. Declaratives and imperative ways to make deployment on kube clusters.  How to deploy an application on  Kubernetes pods, just follow these steps as shown in this post.  Here is new learning, I would like to share with you about Kubernetes deployment hierarchy , which internally calls the replication controller to make desired number of replicas of pod temple specified. Kubernetes Deployment hierarchy Let's go to have a deep understanding about Kubernetes deployment hierarchy. 1. Generating Kubernetes Deployment Manifest file We need to create a YAML file to define the deployment of the 'httpd' Apache Webserver. Here we are going to use the '--dry-run' option with client as value and '-o yaml' to generate the YAML file, to redirect the output we can use the g...

Kubernetes Troubleshooting Guide for DevOps Engineers

Image
Hello DevOps, Platform Engineers, SREs, and Kubernetes Administrators! Modern applications are increasingly built using microservices and deployed on Kubernetes clusters. While Kubernetes provides scalability, resiliency, and automation, troubleshooting failures can sometimes become challenging because issues may originate from multiple layers of the platform. One of the biggest mistakes engineers make during troubleshooting is focusing on a single component without understanding the overall architecture. Effective Kubernetes troubleshooting requires a structured approach that helps quickly identify where the problem exists. Over time, while working on Kubernetes administration, troubleshooting production incidents, and practicing Kubernetes scenarios from KodeKloud labs by Munshi Mohammad, I found it useful to classify Kubernetes issues into three major categories: Application Failures Control Plane (Master Node) Failures Worker Node Failures By identifying the category first, trouble...

50 Kubernetes Admin Commands and Troubleshooting Tricks for Every DevOps Engineer

Image
Hello DevOps Engineers! Over the years, while working with Kubernetes clusters, preparing for certifications, and troubleshooting production incidents, I've collected several command-line shortcuts, administration tricks, and troubleshooting techniques that save significant time. In this article, I share practical Kubernetes commands that I frequently use for: Kubernetes administration Cluster maintenance ETCD backup and recovery Node troubleshooting Cluster upgrades Context and namespace management Network debugging JSONPath queries Productivity improvements Whether you're preparing for the CKA exam , managing production clusters, or simply looking to become faster with Kubernetes, this guide will help. The 'kubectl' command flow architecture This helps beginners understand where each command fits. Come on! let's explore about the API resources which we might be frequently use when we prepare the YAML files for each Kubernetes Obj...

Kubernetes security - Service accounts

Image
In this post we are going to learn more  about what is service accounts in Kubernetes and how that is useful. Prerequisites Kubernetes cluster Up and running Let's take the scenario where we get need to connect with the pods, nodes, deployments and other resources in the Kubernetes cluster. you might be working with the automated build with the CICD pipelines to interconnect with each other resources. Pod  is going to work with the planned application deployments. If  you're working in DevSecOps you need to focus on the regular monthly maintenance OS  patching scheduled in this case Kubernetes node maintenance should be done from a pod.  In the above two scenarios there is a need of service account inside the pod. When Kubernetes cluster is created at the same time service account also created and its name is default . We can also create our own service accounts using the following command Every service account is associated with the secret wh...

Kubernetes Security - ClusterRoles and ClusterRoleBindings: Practical RBAC Guide with Examples

Image
Hello DevOps, DevSecOps Engineers, SREs, and Kubernetes Administrators! As Kubernetes environments grow, managing access becomes an important part of cluster administration. Not every engineer needs full cluster-admin access. In many situations, we need to provide users with access to specific cluster-wide resources such as Nodes, PersistentVolumes, StorageClasses, or other non-namespaced resources . This is where Kubernetes RBAC (Role-Based Access Control) becomes extremely useful. In this article, we will explore ClusterRoles and ClusterRoleBindings with practical examples. We will create permissions for users, bind those permissions to users, validate access, and clean up the configuration. The examples are based on the practical Kubernetes administration scenarios I have worked with and used while practicing Kubernetes RBAC concepts. What We Will Learn In this article, we will cover: What is a ClusterRole? What is a ClusterRoleBinding? ClusterRole vs Role ClusterRoleBinding vs R...

Kubernetes Security - RBAC

My Understanding about RBAC in Kubernetes RBAC stands for Role based access control in our Kubernetes system we have users that needs to access the kubernetes cluster and it's resources. Here role is that categorize their needs. Let's say our project have developers, admins, presale users. We could define role named as "readers" that allows all users, because its common need to all user to read from the system. We could define a role called "writers" and allow certainer users like "developers" who contribute many things to develop in application end, "Admin" user can have this to control it. We could also define a role called "administrators" to admins users. Administrator role users can have full rights such as delete from the system. Role can be used to define "what can be done?" Role will be given to users, application software. If we need to deal with software then we need to use service account. Service accou...

Kubernetes CertificateSigningRequest (CSR) API & Manage User Certificates

Image
Hello everyone! Welcome back to the Kubernetes Security Series . In this article, we'll explore the Kubernetes CertificateSigningRequest (CSR) API , an important security feature that helps Kubernetes administrators securely manage user authentication using certificates. If you're preparing for the CKA (Certified Kubernetes Administrator) exam, working in a DevOps/DevSecOps role, or managing Kubernetes clusters in production, understanding the CSR workflow is essential. What You'll Learn By the end of this blog tutorial, you will be able to: Understand the role of Certificate Authorities (CA) in Kubernetes Generate private and public key pairs Create a Certificate Signing Request (CSR) Submit a CSR to Kubernetes Review, approve, or deny certificate requests Retrieve and decode signed certificates Understand how Kubernetes Controller Manager handles certificate operation User Certificate Approval process What is the Kubernetes Certificate API? Kubernetes uses certificates t...