Amazon EKS Windows ื‘-GA ื™ืฉ ื‘ืื’ื™ื, ืื‘ืœ ื”ื•ื ื”ืžื”ื™ืจ ื‘ื™ื•ืชืจ

Amazon EKS Windows ื‘-GA ื™ืฉ ื‘ืื’ื™ื, ืื‘ืœ ื”ื•ื ื”ืžื”ื™ืจ ื‘ื™ื•ืชืจ

ืฆื”ืจื™ื™ื ื˜ื•ื‘ื™ื, ืื ื™ ืจื•ืฆื” ืœื—ืœื•ืง ืื™ืชื›ื ืืช ื”ื ื™ืกื™ื•ืŸ ืฉืœื™ ื‘ื”ื’ื“ืจื” ื•ื”ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืช AWS EKS (Elastic Kubernetes Service) ืขื‘ื•ืจ ืงื•ื ื˜ื™ื™ื ืจื™ื ืฉืœ Windows, ืื• ืœื™ืชืจ ื“ื™ื•ืง ืขืœ ื—ื•ืกืจ ื”ืืคืฉืจื•ืช ืœื”ืฉืชืžืฉ ื‘ื•, ื•ืขืœ ื”ื‘ืื’ ืฉื ืžืฆื ื‘ืงื•ื ื˜ื™ื™ื ืจ ืฉืœ ืžืขืจื›ืช AWS, ืขื‘ื•ืจ ืืœื” ื”ืžืขื•ื ื™ื™ื ื™ื ื‘ืฉื™ืจื•ืช ื–ื” ืขื‘ื•ืจ ืžื™ื›ืœื™ Windows, ืื ื ืชื—ืช cat.

ืื ื™ ื™ื•ื“ืข ืฉืžื™ื›ืœื™ Windows ื”ื ืœื ื ื•ืฉื ืคื•ืคื•ืœืจื™, ื•ืžืขื˜ ืื ืฉื™ื ืžืฉืชืžืฉื™ื ื‘ื”ื, ืื‘ืœ ื‘ื›ืœ ื–ืืช ื”ื—ืœื˜ืชื™ ืœื›ืชื•ื‘ ืืช ื”ืžืืžืจ ื”ื–ื”, ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื• ื›ืžื” ืžืืžืจื™ื ืขืœ Habrรฉ ืขืœ kubernetes ื•-Windows ื•ืขื“ื™ื™ืŸ ื™ืฉ ืื ืฉื™ื ื›ืืœื”.

ื”ื—ืœ

ื”ื›ืœ ื”ืชื—ื™ืœ ื›ืฉื”ื•ื—ืœื˜ ืœื”ืขื‘ื™ืจ ืืช ื”ืฉื™ืจื•ืชื™ื ื‘ื—ื‘ืจื” ืฉืœื ื• ืœ-kubernetes, ืฉื”ื 70% ื•ื•ื™ื ื“ื•ืก ื•-30% ืœื™ื ื•ืงืก. ืœืฆื•ืจืš ื›ืš, ืฉื™ืจื•ืช ื”ืขื ืŸ AWS EKS ื ื—ืฉื‘ ื›ืื—ืช ื”ืืคืฉืจื•ื™ื•ืช ื”ืืคืฉืจื™ื•ืช. ืขื“ ื”-8 ื‘ืื•ืงื˜ื•ื‘ืจ 2019, AWS EKS Windows ื”ื™ื” ื‘-Public Preview, ื”ืชื—ืœืชื™ ืื™ืชื•, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื’ืจืกืช 1.11 ื”ื™ืฉื ื” ืฉืœ kubernetes, ืื‘ืœ ื”ื—ืœื˜ืชื™ ืœื‘ื“ื•ืง ืืช ื–ื” ื‘ื›ืœ ื–ืืช ื•ืœืจืื•ืช ื‘ืื™ื–ื” ืฉืœื‘ ื”ื™ื” ืฉื™ืจื•ืช ื”ืขื ืŸ ื”ื–ื”, ื”ืื ื”ื•ื ืขื•ื‘ื“ ื‘ื›ืœืœ, ื›ืคื™ ืฉื”ืชื‘ืจืจ, ืœื, ื–ื” ื”ื™ื” ื‘ืื’ ืขื ืชื•ืกืคืช ืฉืœ ื”ืกืจืช ืคื•ื“ื™ื, ื‘ืขื•ื“ ื”ื™ืฉื ื™ื ื”ืคืกื™ืงื• ืœื”ื’ื™ื‘ ื“ืจืš ip ืคื ื™ืžื™ ืžืื•ืชื” ืจืฉืช ืžืฉื ื” ื›ืžื• ืฆื•ืžืช ื”ืขื•ื‘ื“ ืฉืœ Windows.

ืœื›ืŸ, ื”ื•ื—ืœื˜ ืœื ื˜ื•ืฉ ืืช ื”ืฉื™ืžื•ืฉ ื‘-AWS EKS ืœื˜ื•ื‘ืช ืืฉื›ื•ืœ ืžืฉืœื ื• ืขืœ kubernetes ื‘ืื•ืชื• EC2, ืจืง ืฉื ืฆื˜ืจืš ืœืชืืจ ืืช ื›ืœ ื”ืื™ื–ื•ืŸ ื•ื”-HA ื‘ืขืฆืžื ื• ื“ืจืš CloudFormation.

ืชืžื™ื›ืช ืืžื–ื•ืŸ EKS Windows Container ื–ืžื™ื ื” ื›ืขืช ื‘ืื•ืคืŸ ื›ืœืœื™

ืžืืช ืžืจื˜ื™ืŸ ื‘ื™ื‘ื™ | ื‘-08 ื‘ืื•ืงื˜ื•ื‘ืจ 2019

ืœืคื ื™ ืฉื”ืกืคืงืชื™ ืœื”ื•ืกื™ืฃ ืชื‘ื ื™ืช ืœ-CloudFormation ืขื‘ื•ืจ ื”ืืฉื›ื•ืœ ืฉืœื™, ืจืื™ืชื™ ืืช ื”ื—ื“ืฉื•ืช ื”ืืœื” ืชืžื™ื›ืช ืืžื–ื•ืŸ EKS Windows Container ื–ืžื™ื ื” ื›ืขืช ื‘ืื•ืคืŸ ื›ืœืœื™

ื›ืžื•ื‘ืŸ, ืฉืžืชื™ ืืช ื›ืœ ื”ืขื‘ื•ื“ื” ืฉืœื™ ื‘ืฆื“ ื•ื”ืชื—ืœืชื™ ืœืœืžื•ื“ ืžื” ื”ื ืขืฉื• ืขื‘ื•ืจ GA, ื•ืื™ืš ื”ื›ืœ ื”ืฉืชื ื” ืขื Public Preview. ื›ืŸ, AWS, ื›ืœ ื”ื›ื‘ื•ื“, ืขื“ื›ื ื” ืืช ื”ืชืžื•ื ื•ืช ืขื‘ื•ืจ Windows worker node ืœื’ืจืกื” 1.14, ื›ืžื• ื’ื ื”ืืฉื›ื•ืœ ืขืฆืžื•, ื’ืจืกื” 1.14 ื‘-EKS, ืชื•ืžืš ื›ืขืช ื‘ืฆืžืชื™ Windows. ืคืจื•ื™ืงื˜ ืžืืช Public Preview ื‘ github ื”ื ื›ื™ืกื• ืืช ื–ื” ื•ืืžืจื• ืขื›ืฉื™ื• ื”ืฉืชืžืฉ ื‘ืชื™ืขื•ื“ ื”ืจืฉืžื™ ื›ืืŸ: ืชืžื™ื›ื” ืฉืœ EKS Windows

ืฉื™ืœื•ื‘ ืฉืœ ืืฉื›ื•ืœ EKS ื‘-VPC ื•ื‘ืจืฉืชื•ืช ื”ืžืฉื ื” ื”ื ื•ื›ื—ื™ื•ืช

ื‘ื›ืœ ื”ืžืงื•ืจื•ืช, ื‘ืงื™ืฉื•ืจ ืฉืœืžืขืœื” ื‘ื”ื•ื“ืขื” ื›ืžื• ื’ื ื‘ืชื™ืขื•ื“, ื”ื•ืฆืข ืœืคืจื•ืก ืืช ื”ืืฉื›ื•ืœ ืื• ื“ืจืš ื›ืœื™ ื”ืฉื™ืจื•ืช ื”ืงื ื™ื™ื ื™ eksctl ืื• ื“ืจืš CloudFormation + kubectl ืœืื—ืจ, ืจืง ื‘ืืžืฆืขื•ืช ืจืฉืชื•ืช ืžืฉื ื” ืฆื™ื‘ื•ืจื™ื•ืช ื‘ืืžื–ื•ืŸ, ื›ืžื• ื’ื ื™ืฆื™ืจืช VPC ื ืคืจื“ ืœืืฉื›ื•ืœ ื—ื“ืฉ.

ืืคืฉืจื•ืช ื–ื• ืื™ื ื” ืžืชืื™ืžื” ืœืจื‘ื™ื; ืจืืฉื™ืช, VPC ื ืคืจื“ ืคื™ืจื•ืฉื• ืขืœื•ื™ื•ืช ื ื•ืกืคื•ืช ืขื‘ื•ืจ ื”ืขืœื•ืช ืฉืœื• + ืชืขื‘ื•ืจืช ื”ืฆืฆื” ืœ-VPC ื”ื ื•ื›ื—ื™ ืฉืœืš. ืžื” ืฆืจื™ืš ืœืขืฉื•ืช ืœืžื™ ืฉื›ื‘ืจ ื™ืฉ ืœื• ืชืฉืชื™ืช ืžื•ื›ื ื” ื‘-AWS ืขื ืžืกืคืจ ื—ืฉื‘ื•ื ื•ืช AWS ืžืฉืœื”ื, VPC, ืจืฉืชื•ืช ืžืฉื ื”, ื˜ื‘ืœืื•ืช ืžืกืœื•ืœื™ื, ืฉืขืจ ืžืขื‘ืจ ื•ื›ื“ื•ืžื”? ื›ืžื•ื‘ืŸ, ืืชื” ืœื ืจื•ืฆื” ืœืฉื‘ื•ืจ ืื• ืœืขืฉื•ืช ืžื—ื“ืฉ ืืช ื›ืœ ื–ื”, ื•ืืชื” ืฆืจื™ืš ืœืฉืœื‘ ืืช ืืฉื›ื•ืœ ื”-EKS ื”ื—ื“ืฉ ื‘ืชืฉืชื™ืช ื”ืจืฉืช ื”ื ื•ื›ื—ื™ืช, ื‘ืืžืฆืขื•ืช ื”-VPC ื”ืงื™ื™ื, ื•ืœืฆื•ืจืš ื”ืคืจื“ื”, ืœื›ืœ ื”ื™ื•ืชืจ ืœื™ืฆื•ืจ ืจืฉืชื•ืช ืžืฉื ื” ื—ื“ืฉื•ืช ืขื‘ื•ืจ ื”ืืฉื›ื•ืœ.

ื‘ืžืงืจื” ืฉืœื™, ื”ื ืชื™ื‘ ื”ื–ื” ื ื‘ื—ืจ, ื”ืฉืชืžืฉืชื™ ื‘-VPC ื”ืงื™ื™ื, ื”ื•ืกืคืชื™ ืจืง 2 ืชืช-ืจืฉืชื•ืช ืฆื™ื‘ื•ืจื™ื•ืช ื•-2 ืชืช-ืจืฉืชื•ืช ืคืจื˜ื™ื•ืช ืœืืฉื›ื•ืœ ื”ื—ื“ืฉ, ื›ืžื•ื‘ืŸ, ื›ืœ ื”ื›ืœืœื™ื ื ืœืงื—ื• ื‘ื—ืฉื‘ื•ืŸ ืœืคื™ ื”ืชื™ืขื•ื“ ืฆื•ืจ VPC ืฉืœ Cluster EKS ืฉืœ Amazon.

ื”ื™ื” ื’ื ืชื ืื™ ืื—ื“: ืื™ืŸ ืฆืžืชื™ ืขื•ื‘ื“ื™ื ื‘ืจืฉืชื•ืช ืžืฉื ื” ืฆื™ื‘ื•ืจื™ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘-EIP.

eksctl ืœืขื•ืžืช CloudFormation

ืื ื™ ืืขืฉื” ื”ืกืชื™ื™ื’ื•ืช ืžื™ื“ ืฉื ื™ืกื™ืชื™ ืืช ืฉืชื™ ื”ืฉื™ื˜ื•ืช ืฉืœ ืคืจื™ืกืช ืืฉื›ื•ืœ, ื‘ืฉื ื™ ื”ืžืงืจื™ื ื”ืชืžื•ื ื” ื”ื™ื™ืชื” ื–ื”ื”.

ืื ื™ ืืจืื” ื“ื•ื’ืžื” ืจืง ื‘ืืžืฆืขื•ืช eksctl ืžื›ื™ื•ื•ืŸ ืฉื”ืงื•ื“ ื›ืืŸ ื™ื”ื™ื” ืงืฆืจ ื™ื•ืชืจ. ื‘ืืžืฆืขื•ืช eksctl, ืคืจื•ืก ืืช ื”ืืฉื›ื•ืœ ื‘-3 ืฉืœื‘ื™ื:

1. ืื ื• ื™ื•ืฆืจื™ื ืืช ื”ืืฉื›ื•ืœ ืขืฆืžื• + ืฆื•ืžืช ื”ืขื‘ื•ื“ื” ืฉืœ Linux, ืฉื™ืืจื— ืžืื•ื—ืจ ื™ื•ืชืจ ืงื•ื ื˜ื™ื™ื ืจื™ื ืฉืœ ืžืขืจื›ืช ื•ืืช ืื•ืชื• ื‘ืงืจ vpc ืื›ื–ืจื™.

eksctl create cluster 
--name yyy 
--region www 
--version 1.14 
--vpc-private-subnets=subnet-xxxxx,subnet-xxxxx 
--vpc-public-subnets=subnet-xxxxx,subnet-xxxxx 
--asg-access 
--nodegroup-name linux-workers 
--node-type t3.small 
--node-volume-size 20 
--ssh-public-key wwwwwwww 
--nodes 1 
--nodes-min 1 
--nodes-max 2 
--node-ami auto 
--node-private-networking

ืขืœ ืžื ืช ืœืคืจื•ืก ืœ-VPC ืงื™ื™ื, ืคืฉื•ื˜ ืฆื™ื™ืŸ ืืช ื”ืžื–ื”ื” ืฉืœ ืจืฉืชื•ืช ื”ืžืฉื ื” ืฉืœืš, ื•-eksctl ื™ืงื‘ืข ืืช ื”-VPC ืขืฆืžื•.

ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉืฆืžืชื™ ื”ืขื‘ื•ื“ื” ืฉืœืš ื™ื™ืคืจืกื• ืจืง ืœืจืฉืช ืžืฉื ื” ืคืจื˜ื™ืช, ืขืœื™ืš ืœืฆื™ื™ืŸ --node-private-networking ืขื‘ื•ืจ ืงื‘ื•ืฆืช ืฆื•ืžืชื™ื.

2. ืื ื• ืžืชืงื™ื ื™ื ืืช vpc-controller ื‘ืืฉื›ื•ืœ ืฉืœื ื•, ืืฉืจ ืœืื—ืจ ืžื›ืŸ ื™ืขื‘ื“ ืืช ืฆืžืชื™ ื”ืขื•ื‘ื“ื™ื ืฉืœื ื•, ืกื•ืคืจ ืืช ืžืกืคืจ ื›ืชื•ื‘ื•ืช ื”-IP ื”ืคื ื•ื™ื•ืช, ื›ืžื• ื’ื ืืช ืžืกืคืจ ื”-ENIs ื‘ืžื•ืคืข, ืžื•ืกื™ืฃ ื•ืžืกื™ืจ ืื•ืชื.

eksctl utils install-vpc-controllers --name yyy --approve

3. ืœืื—ืจ ืฉื”ืžื›ื•ืœื•ืช ืฉืœ ื”ืžืขืจื›ืช ืฉืœืš ื”ื•ืฉืงื• ื‘ื”ืฆืœื—ื” ื‘ืฆื•ืžืช ื”ืขื‘ื•ื“ื” ืฉืœ Linux ืฉืœืš, ื›ื•ืœืœ vpc-controller, ื›ืœ ืฉื ื•ืชืจ ื”ื•ื ืœื™ืฆื•ืจ ืงื‘ื•ืฆืช ืฆื•ืžืช ื ื•ืกืคืช ืขื ืขื•ื‘ื“ื™ Windows.

eksctl create nodegroup 
--region www 
--cluster yyy 
--version 1.14 
--name windows-workers 
--node-type t3.small 
--ssh-public-key wwwwwwwwww 
--nodes 1 
--nodes-min 1 
--nodes-max 2 
--node-ami-family WindowsServer2019CoreContainer 
--node-ami ami-0573336fc96252d05 
--node-private-networking

ืœืื—ืจ ืฉื”ืฆื•ืžืช ืฉืœืš ื”ืชื—ื‘ืจ ื‘ื”ืฆืœื—ื” ืœืืฉื›ื•ืœ ืฉืœืš ื•ื ืจืื” ืฉื”ื›ืœ ื‘ืกื“ืจ, ื”ื•ื ื‘ืžืฆื‘ Ready, ืื‘ืœ ืœื.

ืฉื’ื™ืื” ื‘-vpc-controller

ืื ื ื ืกื” ืœื”ืคืขื™ืœ ืคื•ื“ื™ื ืขืœ ืฆื•ืžืช ืขื‘ื•ื“ื” ืฉืœ Windows, ื ืงื‘ืœ ืืช ื”ืฉื’ื™ืื”:

NetworkPlugin cni failed to teardown pod "windows-server-iis-7dcfc7c79b-4z4v7_default" network: failed to parse Kubernetes args: pod does not have label vpc.amazonaws.com/PrivateIPv4Address]

ืื ื ืกืชื›ืœ ืœืขื•ืžืง, ื ืจืื” ืฉื”ืžื•ืคืข ืฉืœื ื• ื‘-AWS ื ืจืื” ื›ืš:

Amazon EKS Windows ื‘-GA ื™ืฉ ื‘ืื’ื™ื, ืื‘ืœ ื”ื•ื ื”ืžื”ื™ืจ ื‘ื™ื•ืชืจ

ื•ื–ื” ืฆืจื™ืš ืœื”ื™ื•ืช ื›ื›ื”:

Amazon EKS Windows ื‘-GA ื™ืฉ ื‘ืื’ื™ื, ืื‘ืœ ื”ื•ื ื”ืžื”ื™ืจ ื‘ื™ื•ืชืจ

ืžื›ืืŸ ื‘ืจื•ืจ ืฉื”-vpc-controller ืœื ืžื™ืœื ืืช ื—ืœืงื• ืžืฉื•ื ืžื” ื•ืœื ื”ืฆืœื™ื— ืœื”ื•ืกื™ืฃ ื›ืชื•ื‘ื•ืช IP ื—ื“ืฉื•ืช ืœืžื•ืคืข ื›ื“ื™ ืฉื”ืคื•ื“ื™ื ื™ื•ื›ืœื• ืœื”ืฉืชืžืฉ ื‘ื”ืŸ.

ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื”ื™ื•ืžื ื™ื ืฉืœ ื”-vpc-controller pod ื•ื–ื” ืžื” ืฉืื ื—ื ื• ืจื•ืื™ื:

ื™ื•ืžืŸ kubectl -n kube-system

I1011 06:32:03.910140       1 watcher.go:178] Node watcher processing node ip-10-xxx.ap-xxx.compute.internal.
I1011 06:32:03.910162       1 manager.go:109] Node manager adding node ip-10-xxx.ap-xxx.compute.internal with instanceID i-088xxxxx.
I1011 06:32:03.915238       1 watcher.go:238] Node watcher processing update on node ip-10-xxx.ap-xxx.compute.internal.
E1011 06:32:08.200423       1 manager.go:126] Node manager failed to get resource vpc.amazonaws.com/CIDRBlock  pool on node ip-10-xxx.ap-xxx.compute.internal: failed to find the route table for subnet subnet-0xxxx
E1011 06:32:08.201211       1 watcher.go:183] Node watcher failed to add node ip-10-xxx.ap-xxx.compute.internal: failed to find the route table for subnet subnet-0xxx
I1011 06:32:08.201229       1 watcher.go:259] Node watcher adding key ip-10-xxx.ap-xxx.compute.internal (0): failed to find the route table for subnet subnet-0xxxx
I1011 06:32:08.201302       1 manager.go:173] Node manager updating node ip-10-xxx.ap-xxx.compute.internal.
E1011 06:32:08.201313       1 watcher.go:242] Node watcher failed to update node ip-10-xxx.ap-xxx.compute.internal: node manager: failed to find node ip-10-xxx.ap-xxx.compute.internal.

ื—ื™ืคื•ืฉื™ื ื‘ื’ื•ื’ืœ ืœื ื”ื•ื‘ื™ืœื• ืœื›ืœื•ื, ืžื›ื™ื•ื•ืŸ ืฉื›ื›ืœ ื”ื ืจืื” ืืฃ ืื—ื“ ืขื“ื™ื™ืŸ ืœื ืชืคืก ื‘ืื’ ื›ื–ื”, ืื• ืœื ืคืจืกื ื‘ื• ื‘ืขื™ื”, ื”ื™ื™ืชื™ ืฆืจื™ืš ืœื—ืฉื•ื‘ ืขืœ ืืคืฉืจื•ื™ื•ืช ื‘ืขืฆืžื™ ืงื•ื“ื. ื”ื“ื‘ืจ ื”ืจืืฉื•ืŸ ืฉืขืœื” ื‘ืจืืฉ ื”ื•ื ืฉืื•ืœื™ ื”-vpc-controller ืœื ื™ื›ื•ืœ ืœืคืชื•ืจ ืืช ip-10-xxx.ap-xxx.compute.internal ื•ืœื”ื’ื™ืข ืืœื™ื• ื•ืœื›ืŸ ืžืชืจื—ืฉื•ืช ืฉื’ื™ืื•ืช.

ื›ืŸ, ืื›ืŸ, ืื ื• ืžืฉืชืžืฉื™ื ื‘ืฉืจืชื™ DNS ืžื•ืชืืžื™ื ืื™ืฉื™ืช ื‘-VPC ื•ื‘ืื•ืคืŸ ืขืงืจื•ื ื™, ืื™ื ื ื• ืžืฉืชืžืฉื™ื ื‘ืฉืจืชื™ ืืžื–ื•ืŸ, ื›ืš ืฉืืคื™ืœื• ื”ืขื‘ืจื” ืœื ื”ื•ื’ื“ืจื” ืขื‘ื•ืจ ืชื—ื•ื ap-xxx.compute.internal ื–ื”. ื‘ื“ืงืชื™ ืืช ื”ืืคืฉืจื•ืช ื”ื–ื•, ื•ื”ื™ื ืœื ื”ื‘ื™ืื” ืชื•ืฆืื•ืช, ืื•ืœื™ ื”ื‘ื“ื™ืงื” ืœื ื”ื™ื™ืชื” ื ืงื™ื™ื”, ื•ืœื›ืŸ, ื‘ื”ืžืฉืš, ื›ืฉืชืงืฉืจืชื™ ืขื ืชืžื™ื›ื” ื˜ื›ื ื™ืช, ื ื›ื ืขืชื™ ืœืจืขื™ื•ืŸ ืฉืœื”ื.

ืžื›ื™ื•ื•ืŸ ืฉืœื ื”ื™ื• ืžืžืฉ ืจืขื™ื•ื ื•ืช, ื›ืœ ืงื‘ื•ืฆื•ืช ื”ืื‘ื˜ื—ื” ื ื•ืฆืจื• ืขืœ ื™ื“ื™ eksctl ื‘ืขืฆืžื”, ื›ืš ืฉืœื ื”ื™ื” ืกืคืง ืœื’ื‘ื™ ื”ืฉื™ืจื•ืช ืฉืœื”ืŸ, ื’ื ื˜ื‘ืœืื•ืช ื”ืžืกืœื•ืœื™ื ื”ื™ื• ื ื›ื•ื ื•ืช, nat, dns, ื’ื ื’ื™ืฉื” ืœืื™ื ื˜ืจื ื˜ ืขื ืฆืžืชื™ ืขื•ื‘ื“ื™ื ื”ื™ื™ืชื” ืฉื.

ื™ืชืจื” ืžื›ืš, ืื ืืชื” ืคื•ืจืก ืฆื•ืžืช ืขื•ื‘ื“ ืœืจืฉืช ืžืฉื ื” ืฆื™ื‘ื•ืจื™ืช ืžื‘ืœื™ ืœื”ืฉืชืžืฉ ื‘-node-private-networking, ื”ืฆื•ืžืช ื”ื–ื” ืขื•ื“ื›ืŸ ืžื™ื“ ืขืœ ื™ื“ื™ ื”-vpc-controller ื•ื”ื›ืœ ืขื‘ื“ ื›ืžื• ืฉืขื•ืŸ.

ื”ื™ื• ืฉืชื™ ืืคืฉืจื•ื™ื•ืช:

  1. ืชื•ื•ืชืจ ืขืœ ื–ื” ื•ื—ื›ื” ืขื“ ืฉืžื™ืฉื”ื• ื™ืชืืจ ืืช ื”ื‘ืื’ ื”ื–ื” ื‘-AWS ื•ื”ื•ื ื™ืชืงืŸ ืืช ื–ื”, ื•ืื– ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื‘ื˜ื—ื” ื‘-AWS EKS Windows, ืžื›ื™ื•ื•ืŸ ืฉื”ื ืฉื•ื—ืจืจื• ื–ื” ืขืชื” ื‘-GA (ื—ืœืคื• 8 ื™ืžื™ื ื‘ื–ืžืŸ ื›ืชื™ื‘ืช ืžืืžืจ ื–ื”), ืจื‘ื™ื ื›ื ืจืื” ื™ืขืฉื• ื–ืืช ืœืœื›ืช ื‘ืื•ืชื” ื“ืจืš ื›ืžื•ื ื™.
  2. ื›ืชื‘ื• ืœืชืžื™ื›ื” ืฉืœ AWS ื•ืกืคืจื• ืœื”ื ืืช ืžื”ื•ืช ื”ื‘ืขื™ื” ืขื ื—ื‘ื•ืจื” ืฉืœืžื” ืฉืœ ื™ื•ืžื ื™ื ืžื›ืœ ืžืงื•ื ื•ืชื•ื›ื™ื—ื• ืœื”ื ืฉื”ืฉื™ืจื•ืช ืฉืœื”ื ืœื ืขื•ื‘ื“ ื›ืฉืžืฉืชืžืฉื™ื ื‘-VPC ื•ื‘ืจืฉืชื•ืช ื”ืžืฉื ื” ืฉืœื›ื, ืœื ื‘ื›ื“ื™ ื”ื™ื™ืชื” ืœื ื• ืชืžื™ื›ื” ืขืกืงื™ืช, ื›ื“ืื™ ืœื”ืฉืชืžืฉ ื–ื” ืœืคื—ื•ืช ืคืขื ืื—ืช :)

ืชืงืฉื•ืจืช ืขื ืžื”ื ื“ืกื™ AWS

ืœืื—ืจ ืฉื™ืฆืจืชื™ ื›ืจื˜ื™ืก ื‘ืคื•ืจื˜ืœ, ื‘ื—ืจืชื™ ื‘ื˜ืขื•ืช ืœื”ื’ื™ื‘ ืœื™ ื“ืจืš Web - ืžื™ื™ืœ ืื• ืžืจื›ื– ืชืžื™ื›ื”, ื“ืจืš ืืคืฉืจื•ืช ื–ื• ื”ื ื™ื›ื•ืœื™ื ืœืขื ื•ืช ืœืš ืœืื—ืจ ืžืกืคืจ ื™ืžื™ื ื‘ื›ืœืœ, ืœืžืจื•ืช ืฉื”ื›ืจื˜ื™ืก ืฉืœื™ ื”ื™ื” ื‘ืขืœ ื—ื•ืžืจื” - ืžืขืจื›ืช ืœืงื•ื™ื”, ืืฉืจ ื”ืชื›ื•ื•ืŸ ืœืชื’ื•ื‘ื” ืชื•ืš <12 ืฉืขื•ืช, ื•ืžื›ื™ื•ื•ืŸ ืฉืœืชื•ื›ื ื™ืช ื”ืชืžื™ื›ื” ื”ืขืกืงื™ืช ื™ืฉ ืชืžื™ื›ื” 24/7, ืงื™ื•ื•ื™ืชื™ ืœื˜ื•ื‘, ืื‘ืœ ื–ื” ื™ืฆื ื›ืžื• ืชืžื™ื“.

ื”ื›ืจื˜ื™ืก ืฉืœื™ ืœื ื”ื•ืงืฆื” ืžื™ื•ื ืฉื™ืฉื™ ืขื“ ื™ื•ื ืฉื ื™, ื•ืื– ื”ื—ืœื˜ืชื™ ืœื›ืชื•ื‘ ืœื”ื ืฉื•ื‘ ื•ื‘ื—ืจืชื™ ื‘ืืคืฉืจื•ืช ืชื’ื•ื‘ืช ืฆ'ืื˜. ืœืื—ืจ ื”ืžืชื ื” ืงืฆืจื”, ื”ืจืฉ"ื“ ืžื“"ื‘ ืžื•ื ื” ืœืจืื•ืช ืื•ืชื™, ื•ืื– ื–ื” ื”ืชื—ื™ืœ...

ื‘ื™ืฆืขื ื• ืื™ืชื• ื‘ืื’ื™ื ื‘ืื™ื ื˜ืจื ื˜ ื‘ืžืฉืš 3 ืฉืขื•ืช ื‘ืจืฆื™ืคื•ืช, ื”ืขื‘ืจื ื• ื™ื•ืžื ื™ื, ืคืจืกื• ืืช ืื•ืชื• ืืฉื›ื•ืœ ื‘ืžืขื‘ื“ืช ื”-AWS ื›ื“ื™ ืœื—ืงื•ืช ืืช ื”ื‘ืขื™ื”, ื™ืฆืจื ื• ืžื—ื“ืฉ ืืช ื”ืืฉื›ื•ืœ ืžืฆื™ื“ื™ ื•ื›ื•', ื”ื“ื‘ืจ ื”ื™ื—ื™ื“ ืฉื”ื’ืขื ื• ืืœื™ื• ื”ื•ื ืฉืž ื‘ื™ื•ืžื ื™ื ื”ื™ื” ื‘ืจื•ืจ ืฉื”-resol ืœื ืขื•ื‘ื“ ืขื ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ืคื ื™ืžื™ื™ื ืฉืœ AWS, ืขืœื™ื”ื ื›ืชื‘ืชื™ ืœืžืขืœื”, ื•ื”ืจืฉืื“ ืžื“ื”ื‘ ื‘ื™ืงืฉ ืžืžื ื™ ืœื™ืฆื•ืจ ื”ืขื‘ืจื”, ืœื›ืื•ืจื” ืื ื• ืžืฉืชืžืฉื™ื ื‘-DNS ืžื•ืชืื ืื™ืฉื™ืช ื•ื–ื• ืขืœื•ืœื” ืœื”ื™ื•ืช ื‘ืขื™ื”.

ืฉื™ืœื•ื—

ap-xxx.compute.internal  -> 10.x.x.2 (VPC CIDRBlock)
amazonaws.com -> 10.x.x.2 (VPC CIDRBlock)

ื–ื” ืžื” ืฉื ืขืฉื”, ื”ื™ื•ื ื ื’ืžืจ. ื”ืจืฉ"ื“ ืžื“"ื‘ ื›ืชื‘ ื‘ื—ื–ืจื” ืœื‘ื“ื•ืง ืืช ื–ื” ื•ื–ื” ืืžื•ืจ ืœืขื‘ื•ื“, ืื‘ืœ ืœื, ื”ืจื–ื•ืœื•ืฆื™ื” ืœื ืขื–ืจื” ื‘ื›ืœืœ.

ื•ืื– ื”ื™ื™ืชื” ืชืงืฉื•ืจืช ืขื ืขื•ื“ 2 ืžื”ื ื“ืกื™ื, ืื—ื“ ืคืฉื•ื˜ ื ืฉืจ ืžื”ืฆ'ืื˜, ื›ื ืจืื” ืฉื”ื•ื ืคื—ื“ ืžืžืงืจื” ืžื•ืจื›ื‘, ื”ืฉื ื™ ื‘ื™ืœื” ืืช ื”ื™ื•ื ืฉืœื™ ืฉื•ื‘ ื‘ืžื—ื–ื•ืจ ืฉืœื ืฉืœ ืื™ืชื•ืจ ื‘ืื’ื™ื, ืฉืœื™ื—ืช ื™ื•ืžื ื™ื, ื™ืฆื™ืจืช ืืฉื›ื•ืœื•ืช ืžืฉื ื™ ื”ืฆื“ื“ื™ื, ื‘- ืกื•ืฃ ื”ื•ื ืจืง ืืžืจ ื˜ื•ื‘, ื–ื” ืขื•ื‘ื“ ืœื™, ื”ื ื” ืื ื™ ืขื•ืฉื” ื”ื›ืœ ืฆืขื“ ืื—ืจ ืฆืขื“ ื‘ืชื™ืขื•ื“ ื”ืจืฉืžื™ ื•ืืชื” ื•ืืชื” ืชืฆืœื™ื—.

ืืœื™ื• ื‘ื™ืงืฉืชื™ ื‘ื ื™ืžื•ืก ืœืขื–ื•ื‘ ื•ืœื”ืงืฆื•ืช ืžื™ืฉื”ื• ืื—ืจ ืœื›ืจื˜ื™ืก ืฉืœื™ ืื ืืชื” ืœื ื™ื•ื“ืข ืื™ืคื” ืœื—ืคืฉ ืืช ื”ื‘ืขื™ื”.

ืกื•ืคื™

ื‘ื™ื•ื ื”ืฉืœื™ืฉื™ ื”ื•ืฆื‘ ืืฆืœื™ ืžื”ื ื“ืก ื—ื“ืฉ ืืจื•ืŸ ื‘', ื•ืžืจื’ืข ืชื—ื™ืœืช ื”ืชืงืฉื•ืจืช ืขืžื• ื”ื™ื” ื‘ืจื•ืจ ื›ื™ ืœื ืžื“ื•ื‘ืจ ื‘-3 ื”ืžื”ื ื“ืกื™ื ื”ืงื•ื“ืžื™ื. ื”ื•ื ืงืจื ืืช ื›ืœ ื”ื”ื™ืกื˜ื•ืจื™ื” ื•ืžื™ื“ ื‘ื™ืงืฉ ืœืืกื•ืฃ ืืช ื”ื™ื•ืžื ื™ื ื‘ืืžืฆืขื•ืช ื”ืกืงืจื™ืคื˜ ืฉืœื• ื‘-ps1, ืฉื”ื™ื” ื‘-github ืฉืœื•. ืื—ืจื™ ื–ื” ืฉื•ื‘ ื”ื’ื™ืขื• ื›ืœ ื”ืื™ื˜ืจืฆื™ื•ืช ืฉืœ ื™ืฆื™ืจืช ืืฉื›ื•ืœื•ืช, ื”ื•ืฆืืช ืชื•ืฆืื•ืช ืคืงื•ื“ื•ืช, ืื™ืกื•ืฃ ื™ื•ืžื ื™ื, ืื‘ืœ ืืจื•ืŸ ื‘' ื”ืชืงื“ื ื‘ื›ื™ื•ื•ืŸ ื”ื ื›ื•ืŸ ืื ืœืฉืคื•ื˜ ืœืคื™ ื”ืฉืืœื•ืช ืฉื ืฉืืœื• ืื•ืชื™.

ืžืชื™ ื”ื’ืขื ื• ืœื ืงื•ื“ื” ืฉืœ ื”ืคืขืœืช -stderrthreshold=debug ื‘-vpc-controller ืฉืœื”ื, ื•ืžื” ืงืจื” ืื—ืจ ื›ืš? ื›ืžื•ื‘ืŸ ืฉื–ื” ืœื ืขื•ื‘ื“) ื”ืคื•ื“ ืคืฉื•ื˜ ืœื ืžืชื—ื™ืœ ืขื ื”ืืคืฉืจื•ืช ื”ื–ื•, ืจืง -stderrthreshold=info ืขื•ื‘ื“.

ืกื™ื™ืžื ื• ื›ืืŸ ื•ืืจื•ืŸ ื‘' ืืžืจ ืฉื”ื•ื ื™ื ืกื” ืœืฉื—ื–ืจ ืืช ื”ืฆืขื“ื™ื ืฉืœื™ ื›ื“ื™ ืœืงื‘ืœ ืืช ืื•ืชื” ืฉื’ื™ืื”. ืœืžื—ืจืช ืื ื™ ืžืงื‘ืœ ืชืฉื•ื‘ื” ืžืืจื•ืŸ ื‘' ื”ื•ื ืœื ื–ื ื— ืืช ื”ืชื™ืง ื”ื–ื”, ืืœื ืœืงื— ืืช ืงื•ื“ ื”ื‘ื™ืงื•ืจืช ืฉืœ ื”-vpc-controller ืฉืœื”ื ื•ืžืฆื ืืช ื”ืžืงื•ื ืฉื‘ื• ื”ื•ื ื ืžืฆื ื•ืœืžื” ื–ื” ืœื ืขื•ื‘ื“:

Amazon EKS Windows ื‘-GA ื™ืฉ ื‘ืื’ื™ื, ืื‘ืœ ื”ื•ื ื”ืžื”ื™ืจ ื‘ื™ื•ืชืจ

ืœืคื™ื›ืš, ืื ืืชื” ืžืฉืชืžืฉ ื‘ื˜ื‘ืœืช ื”ืžืกืœื•ืœื™ื ื”ืจืืฉื™ืช ื‘-VPC ืฉืœืš, ืื– ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืื™ืŸ ืœื” ืืกื•ืฆื™ืืฆื™ื•ืช ืขื ืจืฉืชื•ืช ื”ืžืฉื ื” ื”ื ื—ื•ืฆื•ืช, ื”ื ื—ื•ืฆื•ืช ื›ืœ ื›ืš ืœ-vpc-controller, ื‘ืžืงืจื” ืฉืœ ืชืช ืจืฉืช ืฆื™ื‘ื•ืจื™ืช, ื™ืฉ ืœื” ื˜ื‘ืœืช ืžืกืœื•ืœ ืžื•ืชืืžืช ืื™ืฉื™ืช ืฉื™ืฉ ืœื• ืืกื•ืฆื™ืืฆื™ื”.

ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืืกื•ืฆื™ืืฆื™ื•ืช ื™ื“ื ื™ืช ืœื˜ื‘ืœืช ื”ืžืกืœื•ืœื™ื ื”ืจืืฉื™ืช ืขื ืจืฉืชื•ืช ื”ืžืฉื ื” ื”ื“ืจื•ืฉื•ืช, ื•ื™ืฆื™ืจื” ืžื—ื“ืฉ ืฉืœ ืงื‘ื•ืฆืช ื”ืฆืžืชื™ื, ื”ื›ืœ ืขื•ื‘ื“ ื‘ืฆื•ืจื” ืžื•ืฉืœืžืช.

ืื ื™ ืžืงื•ื•ื” ืฉืืจื•ืŸ ื‘ื™ ื‘ืืžืช ื™ื“ื•ื•ื— ืขืœ ื”ื‘ืื’ ื”ื–ื” ืœืžืคืชื—ื™ EKS ื•ื ืจืื” ื’ืจืกื” ื—ื“ืฉื” ืฉืœ vpc-controller ืฉื‘ื” ื”ื›ืœ ื™ืขื‘ื•ื“ ืžื”ืงื•ืคืกื”. ื›ืจื’ืข ื”ื’ืจืกื” ื”ืขื“ื›ื ื™ืช ื‘ื™ื•ืชืจ ื”ื™ื: 602401143452.dkr.ecr.ap-southeast-1.amazonaws.com/eks/vpc-resource-controller:0.2.1
ื™ืฉ ืืช ื”ื‘ืขื™ื” ื”ื–ื•.

ืชื•ื“ื” ืœื›ืœ ืžื™ ืฉืงืจื ืขื“ ื”ืกื•ืฃ, ื‘ื“ื•ืง ืืช ื›ืœ ืžื” ืฉืืชื” ื”ื•ืœืš ืœื”ืฉืชืžืฉ ื‘ื™ื™ืฆื•ืจ ืœืคื ื™ ื”ื™ื™ืฉื•ื.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”