{"id":30199,"date":"2019-10-31T21:34:08","date_gmt":"2019-10-31T18:34:08","guid":{"rendered":"https:\/\/prohoster.info\/blog\/vozmozhno-vam-ne-nuzhen-kubernetes\/"},"modified":"2019-10-31T21:34:08","modified_gmt":"2019-10-31T18:34:08","slug":"vozmozhno-vam-ne-nuzhen-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/vozmozhno-vam-ne-nuzhen-kubernetes","title":{"rendered":"You may not need Kubernetes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"You may not need Kubernetes\" src=\"\/wp-content\/uploads\/2019\/03\/4cd1c0ed29bf76731aab81ce67144352.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Girl on a scooter. Illustration <noindex><a rel=\"nofollow\" href=\"https:\/\/www.freepik.com\/free-photos-vectors\/car\">freepik<\/a><\/noindex>, logo of Nomad from <noindex><a rel=\"nofollow\" href=\"https:\/\/www.nomadproject.io\/\">HashiCorp<\/a><\/noindex><\/i><\/p>\n<p>Kubernetes is a 300-kilogram gorilla for orchestrating containers. It operates in some of the largest container systems in the world, but it comes at a high cost.<\/p>\n<p>Especially costly for small teams, which will spend a lot of time on maintenance and face a steep learning curve. For our team of four, this is too much overhead. So, we started looking for alternatives\u2014and fell in love with <noindex><a rel=\"nofollow\" href=\"https:\/\/www.nomadproject.io\/\">Nomad<\/a><\/noindex>.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h1>What we want<\/h1>\n<p>\nOur team supports a number of typical services for monitoring and analyzing performance: API endpoints for metrics written in Go, Prometheus exporter, log parsers like Logstash and <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/trivago\/gollum\">Gollum<\/a><\/noindex>, as well as databases like InfluxDB or Elasticsearch. Each of these services runs in its own container. We need a simple system to keep all this running.<\/p>\n<p>We started with a list of requirements for container orchestration:<\/p>\n<ul>\n<li>Running a set of services on multiple machines.\n<\/li>\n<li>Overview of running services.\n<\/li>\n<li>Connections between services.\n<\/li>\n<li>Automatic restart if a service fails.\n<\/li>\n<li>Maintaining infrastructure with a small team.<\/li>\n<\/ul>\n<p>\nAdditionally, the following features would be nice but not essential:<\/p>\n<ul>\n<li>Tagging machines by their capabilities (for example, tagging machines with fast disks for heavy I\/O services).\n<\/li>\n<li>Ability to run services independent of the orchestrator (for instance, during development).\n<\/li>\n<li>A common place for sharing configurations and secrets.\n<\/li>\n<li>An endpoint for metrics and logs.<\/li>\n<\/ul>\n<p><\/p>\n<h1>Why Kubernetes doesn\u2019t work for us<\/h1>\n<p>\nWhen prototyping with Kubernetes, we noticed that we started adding increasingly complex layers of logic that we unconditionally relied upon.<\/p>\n<p>For example, Kubernetes supports built-in service configurations via <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/tasks\/configure-pod-container\/configure-pod-configmap\/\">ConfigMaps<\/a><\/noindex>. You can quickly get confused, especially when merging multiple configuration files or adding additional services to a pod. Kubernetes (or <noindex><a rel=\"nofollow\" href=\"https:\/\/helm.sh\/\">helm<\/a><\/noindex> In this case, it allows for the dynamic integration of external configurations for dividing interests. However, this leads to a rigid hidden connection between your project and Kubernetes. Nevertheless, Helm and ConfigMaps are additional options, so you are not required to use them. You can simply copy the configuration into the Docker image. Yet, it is tempting to go this route and build unnecessary abstractions, which you might later regret.<\/p>\n<p>Furthermore, the Kubernetes ecosystem is rapidly evolving. It takes a lot of time and energy to stay abreast of best practices and the latest tools. Kubectl, minikube, kubeadm, helm, tiller, kops, oc \u2014 the list goes on and on. In the beginning, you don't need all these tools, but you don't know what will be necessary, so you need to be aware of everything. Because of this, the learning curve is quite steep.<\/p>\n<h1>When to use Kubernetes<\/h1>\n<p>\nMany at our company use Kubernetes and are quite satisfied with it. These instances are managed by Google or Amazon, which have enough resources to support them.<\/p>\n<p>Kubernetes comes with <noindex><a rel=\"nofollow\" href=\"https:\/\/jvns.ca\/blog\/2017\/08\/05\/how-kubernetes-certificates-work\/\">amazing features<\/a><\/noindex>, which make large-scale container orchestration more manageable:<\/p>\n<ul>\n<li>Detailed <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/reference\/access-authn-authz\/authorization\/\">permissions management<\/a><\/noindex>.\n<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/extend-kubernetes\/api-extension\/custom-resources\/#custom-controllers\">Custom controllers<\/a><\/noindex> add logic to the cluster. These are simply programs that communicate with the Kubernetes API.\n<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/tasks\/run-application\/horizontal-pod-autoscale\/\">Autoscaling<\/a><\/noindex>! Kubernetes can scale services on demand, using service metrics and without requiring manual intervention.<\/li>\n<\/ul>\n<p>\nThe question is whether you really need all these features. You cannot just rely on abstractions; <noindex><a rel=\"nofollow\" href=\"https:\/\/jvns.ca\/blog\/2017\/08\/05\/how-kubernetes-certificates-work\/\">you will have to understand what is happening under the hood<\/a><\/noindex>.<\/p>\n<p>Our team provides most services remotely (due to a close tie with the core infrastructure), so we did not want to set up our own Kubernetes cluster. We just wanted to provide services.<\/p>\n<h1>Batteries not included<\/h1>\n<p>\nNomad is 20% orchestration that provides 80% of what you need. All it does is manage deployments. Nomad takes care of deployments, restarts containers in case of errors\u2026 and that\u2019s it.<\/p>\n<p>The whole point of Nomad is what it does <i>at least<\/i>: no detailed permissions management or <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/network-policies\/\">advanced network policies<\/a><\/noindex>, that's by design. These components are provided by external sources or are simply not provided at all.<\/p>\n<p>I believe that Nomad has found the perfect balance between ease of use and usefulness. It is great for small, independent services. If more control is needed, you'll have to set them up yourself or use a different approach. Nomad is <i>simply<\/i> an orchestrator.<\/p>\n<p>The best thing about Nomad is that it is easy to <i>replace<\/i>. Vendor lock-in is virtually nonexistent, as its features easily integrate into any other service management system. It works simply as a regular binary on each machine in the cluster, that\u2019s all!<\/p>\n<h1>The Nomad ecosystem consists of loosely coupled components.<\/h1>\n<p>\nThe real power of Nomad lies in its ecosystem. It integrates very well with other\u2014completely optional\u2014products, such as <noindex><a rel=\"nofollow\" href=\"https:\/\/www.consul.io\/\">Consul<\/a><\/noindex> (key-value store) or <noindex><a rel=\"nofollow\" href=\"https:\/\/www.vaultproject.io\/\">Vault<\/a><\/noindex> (secret management). Within a Nomad file, there are sections for extracting data from these services:<\/p>\n<pre><code class=\"plaintext\">template {\n  data = &lt;&lt;EOH\nLOG_LEVEL=&quot;{{key &quot;service\/geo-api\/log-verbosity&quot;}}&quot;\nAPI_KEY=&quot;{{with secret &quot;secret\/geo-api-key&quot;}}{{.Data.value}}{{end}}&quot;\nEOH\n\n  destination = &quot;secrets\/file.env&quot;\n  env         = true\n}<\/code><\/pre>\n<p>\nHere we read the key <code>service\/geo-api\/log-verbosity<\/code> from Consul and present it as the environment variable <code>LOG_LEVEL<\/code>. We also expose the key <code>secret\/geo-api-key<\/code> from Vault as <code>API_KEY<\/code>. Simple, yet powerful!<\/p>\n<p>Due to its simplicity, Nomad easily extends through other services via API. For example, it supports tags for jobs. We label all services with metrics with the tag <code>trv-metrics<\/code>. Thus, Prometheus easily finds these services through Consul and periodically checks the endpoint <code>\/metrics<\/code> for new data. The same can be done, for instance, for logs, using <noindex><a rel=\"nofollow\" href=\"https:\/\/grafana.com\/loki\">Loki<\/a><\/noindex>.<\/p>\n<p>There are many other examples of extensibility:<\/p>\n<ul>\n<li>Running Jenkins jobs via a hook while Consul tracks the redeployment of Nomad jobs when service configuration changes.\n<\/li>\n<li>Ceph adds distributed file systems to Nomad.\n<\/li>\n<li><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/fabiolb\/fabio\">fabio<\/a><\/noindex> for load balancing.<\/li>\n<\/ul>\n<p>\nAll of this allows for <noindex><a rel=\"nofollow\" href=\"https:\/\/tech.trivago.com\/2019\/01\/25\/nomad-our-experiences-and-best-practices\/\">the organic development of infrastructure<\/a><\/noindex> without significant vendor lock-in.<\/p>\n<h1>Fair warning<\/h1>\n<p>\nNo system is perfect. I wouldn't recommend implementing the latest features into production immediately. Of course, there are bugs and missing features, but the same applies to Kubernetes.<\/p>\n<p>Compared to Kubernetes, the Nomad community is not as large. Kubernetes has around 75,000 commits and 2,000 contributors, while Nomad has about 14,000 commits and 300 contributors. It will be challenging for Nomad to keep pace with Kubernetes in terms of speed, but maybe it doesn't need to! It is a more specialized system, and a smaller community also means your pull request is more likely to be noticed and accepted compared to Kubernetes.<\/p>\n<h1>Summary<\/h1>\n<p>\nConclusion: don't use Kubernetes just because everyone else does. Carefully assess your requirements and see which tool is more advantageous.<\/p>\n<p>If you plan to deploy a large number of uniform services on a large-scale infrastructure, then Kubernetes is a good option. Just keep in mind the added complexity and operational costs. Some expenses can be avoided by using a managed Kubernetes environment, such as <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/kubernetes-engine\/\">Google Kubernetes Engine<\/a><\/noindex> or <noindex><a rel=\"nofollow\" href=\"https:\/\/aws.amazon.com\/eks\/\">Amazon EKS<\/a><\/noindex>.<\/p>\n<p>If you're just looking for a reliable orchestrator that is easy to maintain and scalable, why not give Nomad a try? You might be surprised at how far it takes you.<\/p>\n<p>If Kubernetes is compared to a car, Nomad would be a scooter. Sometimes you need one, and sometimes the other. Both have their place.<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/445030\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u0435\u0432\u0443\u0448\u043a\u0430 \u043d\u0430 \u0441\u043a\u0443\u0442\u0435\u0440\u0435. \u0418\u043b\u043b\u044e\u0441\u0442\u0440\u0430\u0446\u0438\u044f freepik, \u043b\u043e\u0433\u043e\u0442\u0438\u043f Nomad \u043e\u0442 HashiCorp Kubernetes\u00a0\u2014 \u044d\u0442\u043e 300-\u043a\u0438\u043b\u043e\u0433\u0440\u0430\u043c\u043c\u043e\u0432\u0430\u044f \u0433\u043e\u0440\u0438\u043b\u043b\u0430 \u0434\u043b\u044f \u043e\u0440\u043a\u0435\u0441\u0442\u0440\u043e\u0432\u043a\u0438 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432. \u041e\u043d\u0430 \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0430\u043c\u044b\u0445 \u043a\u0440\u0443\u043f\u043d\u044b\u0445 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u0445 \u0432 \u043c\u0438\u0440\u0435, \u043d\u043e \u0434\u043e\u0440\u043e\u0433\u043e \u043e\u0431\u0445\u043e\u0434\u0438\u0442\u0441\u044f. \u041e\u0441\u043e\u0431\u0435\u043d\u043d\u043e \u0434\u043e\u0440\u043e\u0433\u043e \u0434\u043b\u044f \u043d\u0435\u0431\u043e\u043b\u044c\u0448\u0438\u0445 \u043a\u043e\u043c\u0430\u043d\u0434, \u043a\u043e\u0442\u043e\u0440\u044b\u043c \u043f\u0440\u0438\u0434\u0451\u0442\u0441\u044f \u043f\u043e\u0442\u0440\u0430\u0442\u0438\u0442\u044c \u043c\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u043d\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0443 \u0438 \u043a\u0440\u0443\u0442\u0443\u044e \u043a\u0440\u0438\u0432\u0443\u044e \u043e\u0431\u0443\u0447\u0435\u043d\u0438\u044f. \u0414\u043b\u044f \u043d\u0430\u0448\u0435\u0439 \u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0438\u0437 \u0447\u0435\u0442\u044b\u0440\u0451\u0445 \u0447\u0435\u043b\u043e\u0432\u0435\u043a \u044d\u0442\u043e \u0441\u043b\u0438\u0448\u043a\u043e\u043c \u043c\u043d\u043e\u0433\u043e \u043d\u0430\u043a\u043b\u0430\u0434\u043d\u044b\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-30199","post","type-post","status-publish","format-standard","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u0435\u0432\u0443\u0448\u043a\u0430 \u043d\u0430 \u0441\u043a\u0443\u0442\u0435\u0440\u0435.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/vozmozhno-vam-ne-nuzhen-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u0432\u0430\u043c \u043d\u0435 \u043d\u0443\u0436\u0435\u043d Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u0435\u0432\u0443\u0448\u043a\u0430 \u043d\u0430 \u0441\u043a\u0443\u0442\u0435\u0440\u0435.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/vozmozhno-vam-ne-nuzhen-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:34:08+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:34:08+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47You might not need Kubernetes | ProHoster","description":"A girl on a scooter.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/vozmozhno-vam-ne-nuzhen-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u043e\u0437\u043c\u043e\u0436\u043d\u043e, \u0432\u0430\u043c \u043d\u0435 \u043d\u0443\u0436\u0435\u043d Kubernetes | ProHoster","og:description":"\u0414\u0435\u0432\u0443\u0448\u043a\u0430 \u043d\u0430 \u0441\u043a\u0443\u0442\u0435\u0440\u0435.","og:url":"https:\/\/prohoster.info\/en\/blog\/vozmozhno-vam-ne-nuzhen-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:34:08+00:00","article:modified_time":"2019-10-31T18:34:08+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"30199","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 00:06:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:39:24","updated":"2026-01-21 00:06:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/30199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=30199"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/30199\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=30199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=30199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=30199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}