Posts

K8s - User and Groups

Image
  In this post, we will see how user and group works. Technically, there is no concept of user and group management in K8s.  But, K8s has something called "Service Account" . When K8s is installed from scratch, every namespace has "default" service account and it has admin access to perform actions. It is not practically possible to use " default " service account for every actions. From security point of view, we need to give fine grained and required access.  K8s has 2 important things in the space of "Access Management". Role and RoleBinding [Namespace Scoped] Role : Create a role with actions allowed actions on the resources. Let's say I want to create a readonly role. Using the role users can only view the resource and cannot perform actions like create, modify, delete. Rolebinding : Attaching the role to a user, group and service account is called "Role Binding". apiVersion : rbac.authorization.k8s.io/v1 kind : Role metadata :...

K8s - Finalizer

Image
  Finalizers  are conditions that must be satisfied before a resource can be deleted. When a delete is ordered on a finalized resource, the resource is locked in changes until the conditions are met. Finalizers are used to signal to the control plane, or to custom controllers like Operators, to clean up for a resource before completely and finally removing it. Some common finalizers you’ve likely encountered are: kubernetes.io/pv-protection kubernetes.io/pvc-protection kubernetes.io/pv-protection, ensures that PVs are not removed while still bound to PVCs. Similarly, the kubernetes.io/pvc-protection finalizer on PVCs blocks the deletion of a PVC that is still in use by a pod. Let's try to implement finalizer on a pod.  Below is my pod YAML: Verifying the finalizer tag on my pod. Let's trigger a delete call on the pod. We can see the pod is in " Terminating " state. What the pod log shows? We see the kubelet has stopped the container, but the pod is in " T...

K8s - Deployment and HPA replicas

Image
  We all know that replica is a critical part of a K8s deployment. Default replica is 1. Setting replicas as 3 will ensure 3 pods of that deployment is running at any given time.  Replica are internally managed by replica set which is in turn controlled by the K8s  ReplicationController   . When a pod is bad or deleted as part of replicaset, replication controller will ensure a new pod is created. Now, coming to HPA (Horizontal Pod Autoscaler) which is a dynamic scaler which works at the pod level based on the metrics configured.  When we configure we must mention min and max values. They should be greater than 1. Let's image I create a HPA with min as 5 and max as 10 under the condition of CPU utilization more than 50%. Initial deployment is set with the replica as 1. On top the deployment, I am attaching a HPA with the mentioned configuration. Under HPA, we are forcing the min replicas to 5. Hence, it autoscales the pod to 5 even though the CPU utilization is ...

K8s - Affinitiy and Anti-Affinity

Image
  Affinity refers to "Establishing a relationship based on similar characteristics". Anti-Affinity refers to "Breaking a relationship based on a similar characteristics". This affinity can be set at node level and pod level. Both node and pod affinity has two parameters: required DuringScheduling IgnoredDuringExecution : Means the scheduler should look for the node matching the  nodeAffinity condition mentioned in the pod configuration file. preferred DuringScheduling IgnoredDuringExecution:  Means the scheduler tries look for the node matching the  nodeAffinity  condition mentioned in the pod configuration file. If no node is available then the scheduler creates pod on any available nodes. What is a node affinity? Node affinity says scheduler to place a pod on a node when one or more condition matches. Node affinity is very similar to "Node Selector", but under node affinity we can mention one or more conditions. I have a node labelled as  datacenter=Chen...

AWS - Route53 Failover Policy

Image
  "Route 53 failover" refers to  a feature within Amazon Route 53, a DNS service, that allows automatic redirection of traffic to a backup server or region if the primary server or region becomes unavailable , essentially ensuring continuous website access even during outages by utilizing health checks to monitor the status of your resources and route users to the healthy endpoint. For this post, I have 2 webservers running web application on port 80. First, I am going to create Route53 Private Hosted Zone.  The zone name is " labexample.com ". I am making this zone as private, so that it can be accessed with AWS VPC. Once we have the zone, we need to create Route53 health check, this is a critical piece to monitor the primary server and enabled route53 to failover if the primary server fails. IP address to monitor is the IP address of the primary server. Here, we are mentioning how often to monitor and failure threshold. Next, we will create DNS record under the p...

SRE/DevOps Syllabus

Image
  DEVOPS/SRE Principles. Git What is Git? Architecture of Git. Working principle of Git. Create and cloning a repo. Version control branching. Version control commit. Version control managing workflows. Git hooks. Git Reflog. Git Stash. Git Cherry Picking. Undoing changes in different states of Git. Git based terraform template management. AWS CI/CD SDLC Automation. Code Commit. Code Build. Code Deployment. Code Pipeline. Elastic Beankstalk. Code Artifact. CodeGuru. Terraform Terraform Basics. Terraform State. Working with Terraform. Terraform with AWS. Remote State. Terraform Provisioners. Terraform Import, Tainting and Debugging. Terraform Modules. Terraform Functions and Conditional Expressions. Automation using Python - AWS AWS lambda. Automating EC2 with Lambda. Automating S3 with Lambda. Automating VPC with Lambda. Cost optimization with Lambda. SNS,SQS and SES with Python. Managing and Automating AWS Security with Python. Kubernetes - CKAD Application Developer. Kubernetes A...

AWS - Code Signer

Image
  AWS Lambda code signing is the practice of digitally signing source code packages for functions and layers. The goal of code signing is to ensure that only trusted code runs in your AWS Lambda functions. AWS Signer is a fully-managed code-signing service that can be used to verify the integrity of your AWS Lambda code. Before your code is deployed, AWS Lambda will perform a series of validation checks which will determine whether to accept or reject the deployment package. The first step in the code signing process is to define Amazon S3 source and destination buckets. AWS Signer retrieves unsigned packages from the S3 source bucket, performs the signing job on the package, then deposits the signed package in the S3 destination bucket. We create a S3 bucket with 2 folders. unsigned code  holds normal zip files. Creating a signing profile: Under profile, we mention the signing platform and validity period. Once the profile is created, "Start signing job". Here, we mention...