About Plesk's Visit to KubeCon

This year, Plesk decided to send a few people to KubeCon — the main event for Kubernetes in the world. There are no specialized conferences on this topic in Russia. Of course, K8s is discussed, and everyone wants it, but no other place gathers so many practicing companies at once. I was one of the attendees as I work on a platform based on Kubernetes.

About Plesk's Visit to KubeCon

About the Organization

The scale of the conference is impressive: 7,000 attendees and a huge exhibition center. It took 5-7 minutes to move from one hall to another. Simultaneously, there were about 30 presentations on various topics. A large number of companies had their stands, with many offering decent and some fantastic prizes, as well as distributing various items like T-shirts, pens, and other nice things. All communication was in English, but I didn't experience any difficulties. If this is the only factor preventing you from attending international conferences, go for it. English in IT is easier than regular English due to the abundance of familiar words that you use and read every day in code and documentation. There were also no problems understanding the presentations. My mind was overloaded with information. By evening, I felt like a server suffering from a buffer overflow, with data being poured straight into my subconscious.

About the Presentations

I want to briefly discuss the presentations that I enjoyed the most and would recommend watching.

Intro to CNAB: Packaging Cloud Native Applications with Multiple Toolchains — Chris Crone, Docker

This presentation made a strong impression on me because it addressed significant pain points. We have many disparate services, supported and developed by different people in the team. We follow infrastructure as code approaches, but there are some unresolved issues. There is a repository with Ansible code, but the current state and inventory are stored on the machine of the developer running the script, along with credentials. Some information can be found in Confluence, but it is not always obvious where. There is no place where you can just press a button and everything will work well. It is suggested to create documentation and store not only the code but also deployment tools in the repository. Describe where to get the state and credentials, run make Install, and enjoy the results. I would like more order in the services; I will keep an eye on CNAB releases, use them myself, implement them, and convince others. A good template for creating a Readme in the repo.

Keep the Space Shuttle Flying: Writing Robust Operators — Illya Chekrygin, Upbound

There is a lot of information about the pitfalls when writing operators. I consider this presentation a must-watch for anyone planning to write their own operator for Kubernetes. It covers all aspects like statuses, garbage collection, concurrency, and much more. Very informative. I particularly liked the quote from the code of Kubernetes persistent volumes:
About Plesk's Visit to KubeCon

The Kubernetes Control Plane for Busy People Who Like Pictures — Daniel Smith, Google

K8s prioritizes integration complexity in favor of implementation simplicity.

This presentation details one of the core architectural elements of a cluster — the control plane, specifically the set of controllers. It describes their role and architecture, as well as the basic principles for creating your own controller using existing examples.

One of the most original points is the recommendation not to mask abnormal situations with the correct behavior of the controller, but to change its behavior in some way to signal the system about the emergence of problems.

Running eBay’s High-Performance Workloads with Kubernetes — Xin Ma, eBay

Very interesting experience, with a lot of information and recipes about what to consider when you have truly high loads. They have integrated well into Kubernetes, supporting 50 clusters. They discussed all aspects of maximizing performance. I recommend watching this presentation before making any technical decisions regarding clusters.

Grafana Loki: Like Prometheus, But for logs. — Tom Wilkie, Grafana Labs

The report after which I realized that Loki must be tried for logging in a cluster and, most likely, to stick with it. The essence: Elasticsearch is heavy. Grafana wanted to develop a lightweight scalable solution suitable for debugging issues. The solution turned out to be elegant: Loki selects metadata from Kubernetes (labels like Prometheus) and arranges the logs by them. Thus, one can choose log segments by service, find a specific pod, select a specific time, and filter by error code. These filters operate without full-text search. So, by gradually narrowing down the search, one can reach a specific needed error. In the end, searching is still involved, but since the search space is narrowed, speed is sufficient without indexing. By clicking on it, context is loaded — a couple of lines before and a couple of lines of log after. Thus, it appears like searching a log file and grepping through it, but a bit more convenient and in the same interface where the metrics are. It can count the number of occurrences of the search query. The search queries themselves resemble Prometheus language and look simple. The presenter drew our attention to the fact that this solution isn't very suitable for analytics. I highly recommend this to everyone who needs logs; it's a very easy presentation.

How Intuit Does Canary and Blue Green Deployments with a K8s Controller — Daniel Thomson

The processes of canary and blue-green deployment are clearly illustrated. I recommend watching this report to those who have not yet embraced it. The presenters present the solution as an extension for the promising CI-CD system ARGO. The English speech of the presenter from Russia is easier to listen to than that of the other presenters.

Smarter Kubernetes Access Control: A Simpler Approach to Auth — Rob Scott, ReactiveOps

One of the most challenging aspects of cluster management remains security configuration, particularly resource access rights. Built-in K8s primitives allow authorization to be configured in any way. How to maintain them painlessly in an up-to-date state? How to figure out what's happening with access rights and debug created roles? This report presents not only an overview of several authorization debugging tools in K8s but also provides general recommendations for building simple and effective policies.

Other reports

I won't make a recommendation. Some were captain-level, while others were overly complex. I advise checking out this playlist and watching everything labeled as keynote. This will give a broad overview of the industry around Cloud Native Apps, and then you can press ctrl+f to search for specific keywords, companies, products, and approaches that interest you.

Here is a link to the playlist of talks; pay attention to it.

YouTube Playlist

About the company booths

At the Haproxy booth, I received a T-shirt for my son. I doubt I'll replace Nginx with Haproxy in production because of this, but they left a strong impression on me. Who knows what the new owners will do with Nginx.

About Plesk's Visit to KubeCon
At the IBM booth, short talks were held all three days, and they attracted people by raffling off an Oculus Go, Beats headphones, and a drone. You had to stay at the booth for half an hour. I tried my luck twice over three days — no luck. There were also short talks from VMWare and Microsoft.

At the Ubuntu booth, I did what seems everyone did — took a photo with Shuttleworth. He's a friendly guy; I was glad to tell him I've been using it since 8.04 and that my server has run for 10 years without a dist upgrade without a single interruption (though without Internet access).

About Plesk's Visit to KubeCon
Ubuntu is developing its MicroK8s — Fast, Light, Upstream Developer Kubernetes. microk8s.io

I couldn't pass by a tired Dmitry Stolyarov and talked to him about the challenging daily lives of engineers supporting Kubernetes. He will delegate reading the talks to his colleagues but is preparing some new format for presenting the material. He urged everyone to subscribe to the Flant channel on YouTube.

About Plesk's Visit to KubeCon
IBM, Cisco, Microsoft, and VMWare invested a lot in their booths. The booths of the open-source friends were more modest. I chatted with representatives from Grafana, and they convinced me — I need to try Loki. It seems that full-text search in the logging system is only necessary for analytics, while for troubleshooting, a system like Loki is sufficient. I spoke with the developers of Prometheus. They do not plan to create long-term metric storage and data downsampling. They recommend looking at Cortex and Thanos for solutions. There were so many booths; I needed a whole day to visit them all. A dozen monitoring solutions as a service. Five security services. Five performance services. A dozen UIs for Kubernetes. Many who provide k8s as a service. Everyone wants their piece of the market.

Amazon and Google rented rooftop patios with artificial grass, setting up deck chairs there. Amazon handed out cups and served lemonade while showcasing innovations in working with spot instances. Google distributed cookies with Kubernetes logos and created a great photo area, while their booth featured a fishing theme aimed at catching large enterprise clients.

About Barcelona

In love with Barcelona. I was there for the second time, the first being in 2012 for a sightseeing tour. It's amazing how many facts resurfaced in my memory, allowing me to share a lot with my colleagues as a mini-guide. The fresh sea air instantly cured my allergies. Delicious seafood, paella, sangria. Very warm, sunny architecture. Low-rise buildings with plenty of greenery. Over these three days, we walked about 50 kilometers; it's a city you want to explore again and again. All this happened after the presentations in the evenings.

About Plesk's Visit to KubeCon
About Plesk's Visit to KubeCon
About Plesk's Visit to KubeCon

What I understood the most

I am very glad to have the opportunity to attend this conference. It clarified many things that were previously vague. It inspired me and made several aspects obvious.

A common thread throughout was: Kubernetes is not the final destination, but a tool. A platform for creating platforms.

And the main goal of this movement is: to build and run scalable applications

The main areas the community is working on have crystallized. Just as the twelve-factor apps emerged in their time, a list has been created outlining what to do for infrastructure as a whole. If you want, you could call this trends:

  • Dynamic environments
  • Public, hybrid, and private clouds
  • Containers
  • Service mesh
  • Microservices
  • Immutable infrastructure
  • Declarative API

These techniques allow for building systems with the following characteristics:

  • Protected against data loss
  • Elastic (adapting to load)
  • Maintained
  • Observable (the three pillars: monitoring, logging, tracing)
  • Capable of rolling out significant changes frequently and predictably and safely.

CNCF selects the best projects (a short list) and advocates for such things:

  • Sound automation
  • Open source
  • Freedom to choose a service provider

Kubernetes is complex. It is simple conceptually and in parts, but complicated overall. No one has demonstrated an all-in-one solution. The market for k8s as a service, as well as the rest of the market, resembles the Wild West: support is offered for both $50 and $1000 a month. Everyone delves into some aspect and digs into it. Some focus on monitoring and dashboards, some on performance, others on security.

K8S, it's just the beginning!

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster