ื’ื•ื’ืœ ืžื•ืกื™ืคื” ืชืžื™ื›ืช Kubernetes ืœืžื—ืฉื•ื‘ ืกื•ื“ื™

TL; DR: ื›ืขืช ืชื•ื›ืœ ืœื”ืคืขื™ืœ ืืช Kubernetes ืขืœ ืžื›ืฉื™ืจื™ VM ื—ืกื•ื™ื™ื ืžื’ื•ื’ืœ.

ื’ื•ื’ืœ ืžื•ืกื™ืคื” ืชืžื™ื›ืช Kubernetes ืœืžื—ืฉื•ื‘ ืกื•ื“ื™

ื’ื•ื’ืœ ื”ื™ื•ื (08.09.2020/XNUMX/XNUMX, ืžืฉื•ืขืจ. ืžึฐืชื•ึผืจื’ึฐืžึธืŸ) ื‘ืื™ืจื•ืข Cloud Next OnAir ื”ื•ื“ื™ืขื” ืขืœ ื”ืจื—ื‘ืช ืงื• ื”ืžื•ืฆืจื™ื ืฉืœื” ืขื ื”ืฉืงืช ืฉื™ืจื•ืช ื—ื“ืฉ.

ืฆืžืชื™ GKE ื—ืกื•ื™ื™ื ืžื•ืกื™ืคื™ื ื™ื•ืชืจ ืคืจื˜ื™ื•ืช ืœืขื•ืžืกื™ ืขื‘ื•ื“ื” ื”ืคื•ืขืœื™ื ื‘-Kubernetes. ื‘ื™ื•ืœื™ ื”ื•ืฉืง ื”ืžื•ืฆืจ ื”ืจืืฉื•ืŸ ืฉื ืงืจื ืžื›ืฉื™ืจื™ VM ื—ืกื•ื™ื™ื, ื•ื›ื™ื•ื ื”ืžื›ื•ื ื•ืช ื”ื•ื™ืจื˜ื•ืืœื™ื•ืช ื”ืœืœื• ื›ื‘ืจ ื–ืžื™ื ื•ืช ืœื›ื•ืœื.

ืžื—ืฉื•ื‘ ืกื•ื“ื™ ื”ื•ื ืžื•ืฆืจ ื—ื“ืฉ ื”ื›ื•ืœืœ ืื—ืกื•ืŸ ื ืชื•ื ื™ื ื‘ืฆื•ืจื” ืžื•ืฆืคื ืช ื‘ื–ืžืŸ ืฉื”ื ืžืขื•ื‘ื“ื™ื. ื–ื•ื”ื™ ื”ื—ื•ืœื™ื” ื”ืื—ืจื•ื ื” ื‘ืฉืจืฉืจืช ื”ืฆืคื ืช ื”ื ืชื•ื ื™ื, ืžื›ื™ื•ื•ืŸ ืฉืกืคืงื™ ืฉื™ืจื•ืชื™ ืขื ืŸ ื›ื‘ืจ ืžืฆืคื™ื ื™ื ื ืชื•ื ื™ื ืคื ื™ืžื” ื•ื”ื—ื•ืฆื”. ืขื“ ืœืื—ืจื•ื ื” ื”ื™ื” ืฆื•ืจืš ืœืคืขื ื— ื ืชื•ื ื™ื ืชื•ืš ื›ื“ื™ ืขื™ื‘ื•ื“ื, ื•ืžื•ืžื—ื™ื ืจื‘ื™ื ืจื•ืื™ื ื‘ื›ืš ื—ื•ืจ ื‘ื•ืœื˜ ื‘ืชื—ื•ื ื”ืฆืคื ืช ื”ื ืชื•ื ื™ื.

ื™ื•ื–ืžืช ื”ืžื—ืฉื•ื‘ ื”ืกื•ื“ื™ ืฉืœ ื’ื•ื’ืœ ืžื‘ื•ืกืกืช ืขืœ ืฉื™ืชื•ืฃ ืคืขื•ืœื” ืขื Confidential Computing Consortium, ืงื‘ื•ืฆื” ื‘ืชืขืฉื™ื™ื” ืœืงื™ื“ื•ื ื”ืจืขื™ื•ืŸ ืฉืœ ืกื‘ื™ื‘ื•ืช ื‘ื™ืฆื•ืข ืžื”ื™ืžื ื•ืช (TEEs). TEE ื”ื•ื ื—ืœืง ืžืื•ื‘ื˜ื— ืฉืœ ื”ืžืขื‘ื“ ืฉื‘ื• ื”ื ืชื•ื ื™ื ื•ื”ืงื•ื“ ื”ื˜ืขื•ื ื™ื ืžื•ืฆืคื ื™ื, ืžื” ืฉืื•ืžืจ ืฉืœื ื ื™ืชืŸ ืœื’ืฉืช ืœืžื™ื“ืข ื–ื” ืขืœ ื™ื“ื™ ื—ืœืงื™ื ืื—ืจื™ื ืฉืœ ืื•ืชื• ืžืขื‘ื“.

ื”-VMs Confidential ืฉืœ ื’ื•ื’ืœ ืคื•ืขืœื™ื ืขืœ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช N2D ื”ืคื•ืขืœื•ืช ืขืœ ืžืขื‘ื“ื™ EPYC ืžื”ื“ื•ืจ ื”ืฉื ื™ ืฉืœ AMD, ื”ืžืฉืชืžืฉื™ื ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช Secure Encrypted Virtualization ื›ื“ื™ ืœื‘ื•ื“ื“ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืžื”ืžื—ืฉื‘ ืฉืขืœื™ื• ื”ืŸ ืคื•ืขืœื•ืช. ื™ืฉื ื” ืขืจื•ื‘ื” ืฉื”ื ืชื•ื ื™ื ื ืฉืืจื™ื ืžื•ืฆืคื ื™ื ืœืœื ืงืฉืจ ืœืฉื™ืžื•ืฉ ื‘ื•: ืขื•ืžืกื™ ืขื‘ื•ื“ื”, ื ื™ืชื•ื—ื™ื, ื‘ืงืฉื•ืช ืœืžื•ื“ืœื™ื ืœื”ื“ืจื›ื” ืœื‘ื™ื ื” ืžืœืื›ื•ืชื™ืช. ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืืœื• ื ื•ืขื“ื• ืœืขื ื•ืช ืขืœ ื”ืฆืจื›ื™ื ืฉืœ ื›ืœ ื—ื‘ืจื” ื”ืžื˜ืคืœืช ื‘ื ืชื•ื ื™ื ืจื’ื™ืฉื™ื ื‘ืชื—ื•ืžื™ื ืžื•ืกื“ืจื™ื ื›ืžื• ืชืขืฉื™ื™ืช ื”ื‘ื ืงืื•ืช.

ืื•ืœื™ ื“ื—ื•ืคื” ื™ื•ืชืจ ื”ื™ื ื”ื”ื›ืจื–ื” ืขืœ ื‘ื“ื™ืงืช ื”ื‘ื˜ื ื”ืงืจื•ื‘ื” ืฉืœ ืฆืžืชื™ GKE ืกื•ื“ื™ื™ื, ืฉืœื“ื‘ืจื™ ื’ื•ื’ืœ ื™ื•ืฆื’ื• ื‘ืžื”ื“ื•ืจื” ื”ืงืจื•ื‘ื” ืฉืœ 1.18 ืžื ื•ืข Google Kubernetes (GKE). GKE ื”ื™ื ืกื‘ื™ื‘ื” ืžื ื•ื”ืœืช ื•ืžื•ื›ื ื” ืœื™ื™ืฆื•ืจ ืœื”ืคืขืœืช ืงื•ื ื˜ื™ื™ื ืจื™ื ื”ืžืืจื—ื™ื ื—ืœืงื™ื ืฉืœ ื™ื™ืฉื•ืžื™ื ืžื•ื“ืจื ื™ื™ื ืฉื ื™ืชืŸ ืœื”ืคืขื™ืœ ืขืœ ืคื ื™ ืžืกืคืจ ืกื‘ื™ื‘ื•ืช ืžื—ืฉื•ื‘. Kubernetes ื”ื•ื ื›ืœื™ ืชื–ืžื•ืจ ื‘ืงื•ื“ ืคืชื•ื— ื”ืžืฉืžืฉ ืœื ื™ื”ื•ืœ ื”ืงื•ื ื˜ื™ื™ื ืจื™ื ื”ืœืœื•.

ื”ื•ืกืคืช ืฆืžืชื™ GKE ื—ืกื•ื™ื™ื ืžืกืคืงืช ืคืจื˜ื™ื•ืช ืจื‘ื” ื™ื•ืชืจ ื‘ืขืช ื”ืคืขืœืช ืืฉื›ื•ืœื•ืช GKE. ื›ืืฉืจ ื”ื•ืกืคื ื• ืžื•ืฆืจ ื—ื“ืฉ ืœืงื• ื”ืžื—ืฉื•ื‘ ื”ืกื•ื“ื™, ืจืฆื™ื ื• ืœืกืคืง ืจืžื” ื—ื“ืฉื” ืฉืœ
ืคืจื˜ื™ื•ืช ื•ื ื™ื™ื“ื•ืช ืขื‘ื•ืจ ืขื•ืžืกื™ ืขื‘ื•ื“ื” ื‘ืžื›ื•ืœื•ืช. ืฆืžืชื™ ื”-GKE ื”ืกื•ื“ื™ื™ื ืฉืœ ื’ื•ื’ืœ ื‘ื ื•ื™ื™ื ืขืœ ืื•ืชื” ื˜ื›ื ื•ืœื•ื’ื™ื” ื›ืžื• ื”-VMs Confidential, ื”ืžืืคืฉืจื•ืช ืœืš ืœื”ืฆืคื™ืŸ ื ืชื•ื ื™ื ื‘ื–ื™ื›ืจื•ืŸ ื‘ืืžืฆืขื•ืช ืžืคืชื— ื”ืฆืคื ื” ืกืคืฆื™ืคื™ ืœืฆื•ืžืช ืฉื ื•ืฆืจ ื•ืžื ื•ื”ืœ ืขืœ ื™ื“ื™ ืžืขื‘ื“ AMD EPYC. ืฆืžืชื™ื ืืœื” ื™ืฉืชืžืฉื• ื‘ื”ืฆืคื ืช RAM ืžื‘ื•ืกืกืช ื—ื•ืžืจื” ื”ืžื‘ื•ืกืกืช ืขืœ ืชื›ื•ื ืช SEV ืฉืœ AMD, ืžื” ืฉืื•ืžืจ ืฉืขื•ืžืกื™ ื”ืขื‘ื•ื“ื” ืฉืœืš ื”ืคื•ืขืœื™ื ืขืœ ื”ืฆืžืชื™ื ื”ืœืœื• ื™ื•ืฆืคื ื• ื‘ื–ืžืŸ ืฉื”ื ืคื•ืขืœื™ื.

ืกื•ื ื™ืœ ืคื•ื˜ื™ ื•ืื™ื™ืœ ืžื ื•ืจ, ืžื”ื ื“ืกื™ ืขื ืŸ, ื’ื•ื’ืœ

ื‘ืฆืžืชื™ GKE ื—ืกื•ื™ื™ื, ืœืงื•ื—ื•ืช ื™ื›ื•ืœื™ื ืœื”ื’ื“ื™ืจ ืืฉื›ื•ืœื•ืช GKE ื›ืš ืฉืžืื’ืจื™ ืฆืžืชื™ื ื™ืคืขืœื• ื‘-VMs ืกื•ื“ื™ื™ื. ื‘ืžื™ืœื™ื ืคืฉื•ื˜ื•ืช, ื›ืœ ืขื•ืžืกื™ ื”ืขื‘ื•ื“ื” ื”ืคื•ืขืœื™ื ื‘ืฆืžืชื™ื ืืœื” ื™ื•ืฆืคื ื• ื‘ื–ืžืŸ ืขื™ื‘ื•ื“ ื”ื ืชื•ื ื™ื.

ืืจื’ื•ื ื™ื ืจื‘ื™ื ื“ื•ืจืฉื™ื ืืคื™ืœื• ื™ื•ืชืจ ืคืจื˜ื™ื•ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืชื™ ืขื ืŸ ืฆื™ื‘ื•ืจื™ื™ื ืžืืฉืจ ืขื‘ื•ืจ ืขื•ืžืกื™ ืขื‘ื•ื“ื” ืžืงื•ืžื™ื™ื ื”ืคื•ืขืœื™ื ื‘ืžืงื•ื ื›ื“ื™ ืœื”ื’ืŸ ืžืคื ื™ ืชื•ืงืคื™ื. ื”ื”ืจื—ื‘ื” ืฉืœ Google Cloud ืฉืœ ืงื• ื”ืžื—ืฉื•ื‘ ื”ืกื•ื“ื™ ืฉืœื” ืžืขืœื” ืืช ื”ืจืฃ ื”ื–ื” ื‘ื›ืš ืฉื”ื™ื ืžืกืคืงืช ืœืžืฉืชืžืฉื™ื ืืช ื”ื™ื›ื•ืœืช ืœืกืคืง ืกื•ื“ื™ื•ืช ืขื‘ื•ืจ ืืฉื›ื•ืœื•ืช GKE. ื•ื‘ื”ืชื—ืฉื‘ ื‘ืคื•ืคื•ืœืจื™ื•ืช ืฉืœื•, Kubernetes ื”ื•ื ืฆืขื“ ืžืคืชื— ืงื“ื™ืžื” ืขื‘ื•ืจ ื”ืชืขืฉื™ื™ื”, ื•ืžืขื ื™ืง ืœื—ื‘ืจื•ืช ืืคืฉืจื•ื™ื•ืช ื ื•ืกืคื•ืช ืœืืจื— ื‘ืฆื•ืจื” ืžืื•ื‘ื˜ื—ืช ื™ื™ืฉื•ืžื™ ื”ื“ื•ืจ ื”ื‘ื ื‘ืขื ืŸ ื”ืฆื™ื‘ื•ืจื™.

ื”ื•ืœื’ืจ ืžื•ืœืจ, ืื ืœื™ืกื˜ ื‘-Constellation Research.

ื .ื‘. ื—ื‘ืจืชื ื• ื™ื•ืฆืืช ื‘ืงื•ืจืก ืื™ื ื˜ื ืกื™ื‘ื™ ืžืขื•ื“ื›ืŸ ื‘ืชืืจื™ื›ื™ื 28-30 ื‘ืกืคื˜ืžื‘ืจ ื‘ืกื™ืก Kubernetes ืœืžื™ ืฉืขื“ื™ื™ืŸ ืœื ืžื›ื™ืจ ืืช Kubernetes, ืื‘ืœ ืจื•ืฆื” ืœื”ื›ื™ืจ ื•ืœื”ืชื—ื™ืœ ืœืขื‘ื•ื“. ื•ืื—ืจื™ ื”ืื™ืจื•ืข ื”ื–ื” ื‘-14-16 ื‘ืื•ืงื˜ื•ื‘ืจ, ืื ื—ื ื• ืžืฉื™ืงื™ื ืขื“ื›ื•ืŸ Kubernetes Mega ืœืžืฉืชืžืฉื™ Kubernetes ืžื ื•ืกื™ื ืฉื—ืฉื•ื‘ ืœื”ื ืœื”ื›ื™ืจ ืืช ื›ืœ ื”ืคืชืจื•ื ื•ืช ื”ืžืขืฉื™ื™ื ื”ืขื“ื›ื ื™ื™ื ื‘ื™ื•ืชืจ ื‘ืขื‘ื•ื“ื” ืขื ื”ื’ืจืกืื•ืช ื”ืขื“ื›ื ื™ื•ืช ื‘ื™ื•ืชืจ ืฉืœ Kubernetes ื•"ื’ืจืคื”" ืืคืฉืจื™ืช. ืขึทืœ Kubernetes Mega ื ื ืชื— ื‘ืชื™ืื•ืจื™ื” ื•ื‘ืคื•ืขืœ ืืช ื”ืžื•ืจื›ื‘ื•ื™ื•ืช ืฉืœ ื”ืชืงื ื” ื•ื”ื’ื“ืจืช ืืฉื›ื•ืœ ืžื•ื›ืŸ ืœื™ื™ืฆื•ืจ ("ื”ื“ืจืš-ืœื ื›ืœ ื›ืš ืงืœื”"), ืžื ื’ื ื•ื ื™ื ืœื”ื‘ื˜ื—ืช ืื‘ื˜ื—ื” ื•ืกื•ื‘ืœื ื•ืช ืชืงืœื•ืช ืฉืœ ื™ื™ืฉื•ืžื™ื.

ื‘ื™ืŸ ื”ื™ืชืจ, ื’ื•ื’ืœ ืืžืจื” ื›ื™ ื”-VMs ื”ืกื•ื“ื™ื™ื ืฉืœื” ื™ืงื‘ืœื• ื›ืžื” ืชื›ื•ื ื•ืช ื—ื“ืฉื•ืช ื›ืฉื”ืŸ ื™ื”ื™ื• ื–ืžื™ื ื•ืช ื‘ืื•ืคืŸ ื›ืœืœื™ ื”ื—ืœ ืžื”ื™ื•ื. ืœื“ื•ื’ืžื”, ื”ื•ืคื™ืขื• ื“ื•ื—ื•ืช ื‘ื™ืงื•ืจืช ื”ืžื›ื™ืœื™ื ื™ื•ืžื ื™ื ืžืคื•ืจื˜ื™ื ืฉืœ ื‘ื“ื™ืงืช ืชืงื™ื ื•ืช ื”ืงื•ืฉื—ื” ืฉืœ AMD Secure Processor ื”ืžืฉืžืฉืช ืœื™ืฆื™ืจืช ืžืคืชื—ื•ืช ืขื‘ื•ืจ ื›ืœ ืžื•ืคืข ืฉืœ VMs ืกื•ื“ื™ื™ื.

ื™ืฉ ื’ื ืคืงื“ื™ื ื ื•ืกืคื™ื ืœื”ื’ื“ืจืช ื–ื›ื•ื™ื•ืช ื’ื™ืฉื” ืกืคืฆื™ืคื™ื•ืช, ื•ื’ื•ื’ืœ ื”ื•ืกื™ืคื” ื’ื ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉื‘ื™ืช ื›ืœ ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ืœื ืžืกื•ื•ื’ืช ื‘ืคืจื•ื™ืงื˜ ื ืชื•ืŸ. ื’ื•ื’ืœ ื’ื ืžื—ื‘ืจืช ืžื›ืฉื™ืจื™ VM ืกื•ื“ื™ื™ื ืขื ืžื ื’ื ื•ื ื™ ืคืจื˜ื™ื•ืช ืื—ืจื™ื ื›ื“ื™ ืœืกืคืง ืื‘ื˜ื—ื”.

ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืฉื™ืœื•ื‘ ืฉืœ VPCs ืžืฉื•ืชืคื™ื ืขื ื›ืœืœื™ ื—ื•ืžืช ืืฉ ื•ื”ื’ื‘ืœื•ืช ืžื“ื™ื ื™ื•ืช ืืจื’ื•ื ื™ื•ืช ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉ-VMs ืกื•ื“ื™ื™ื ื™ื›ื•ืœื™ื ืœืชืงืฉืจ ืขื VMs ืกื•ื“ื™ื™ื ืื—ืจื™ื, ื’ื ืื ื”ื ืคื•ืขืœื™ื ื‘ืคืจื•ื™ืงื˜ื™ื ืฉื•ื ื™ื. ื‘ื ื•ืกืฃ, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘-VPC Service Controls ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ื™ืงืฃ ื”ืžืฉืื‘ื™ื ืฉืœ GCP ืขื‘ื•ืจ ื”-VMs ื”ืกื•ื“ื™ื™ื ืฉืœืš.

ืกื•ื ื™ืœ ืคื•ื˜ื™ ื•ืื™ื™ืœ ืžื ื•ืจ

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”