{"id":32766,"date":"2019-10-31T21:48:48","date_gmt":"2019-10-31T18:48:48","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1\/"},"modified":"2019-10-31T21:48:48","modified_gmt":"2019-10-31T18:48:48","slug":"kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","title":{"rendered":"Si si oriento Istio, duke p\u00ebrdorur Kubernetes n\u00eb prodhim. Pjesa 1","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c7far\u00eb \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\">Istio<\/a><\/noindex>? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c \u0432\u043d\u0435\u0448\u043d\u0438\u0435 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u043f\u043e\u0445\u043e\u0434\u044b \u0438\u0437 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 \u0432\u043e \u0432\u043d\u0435\u0448\u043d\u044e\u044e \u0441\u0435\u0442\u044c. \u0415\u0441\u0442\u044c \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0437\u0430\u0434\u0430\u0432\u0430\u0442\u044c policy \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0434\u043b\u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u043f\u043e\u0445\u043e\u0434\u043e\u0432 \u043c\u0435\u0436\u0434\u0443 \u0440\u0430\u0437\u043d\u044b\u043c\u0438 \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c\u0438. \u041d\u0430\u043a\u043e\u043d\u0435\u0446, \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0432\u0441\u044e \u043a\u0430\u0440\u0442\u0443 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u043f\u043e \u0441\u0435\u0442\u0438 \u0438 \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0441\u0431\u043e\u0440 \u043c\u0435\u0442\u0440\u0438\u043a \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u0440\u043e\u0437\u0440\u0430\u0447\u043d\u043e \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439.<\/p>\n<p>Mund\u00ebsi p\u00ebr t\u00eb lexuar p\u00ebr mekanizmin e funksionimit n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/concepts\/\">dokumentacionin zyrtar<\/a><\/noindex>. Istio \u00ebsht\u00eb nj\u00eb mjet jasht\u00ebzakonisht i fuqish\u00ebm, i cili lejon zgjidhjen e shum\u00eb problemeve dhe sfidave. N\u00eb k\u00ebt\u00eb artikull, do t\u00eb doja t\u00eb p\u00ebrgjigjem p\u00ebr pyetjet kryesore q\u00eb zakonisht lindin n\u00eb fillim t\u00eb pun\u00ebs me Istio. Kjo do t'ju ndihmoj\u00eb t\u00eb orientoheni m\u00eb shpejt.<\/p>\n<p><img decoding=\"async\" alt=\"Si si oriento Istio, duke p\u00ebrdorur Kubernetes n\u00eb prodhim. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/04\/7ab676ec42cacafc97099d5af9f6332a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>Parimi i funksionimit<\/h3>\n<p>\nIstio p\u00ebrb\u00ebhet nga dy zona kryesore - control plane dhe data plane. Control plane p\u00ebrmban komponent\u00ebt kryesor\u00eb q\u00eb sigurojn\u00eb pun\u00ebn e duhur t\u00eb t\u00eb tjer\u00ebve. N\u00eb versionin aktual (1.0), control plane ka tre komponente kryesore: Pilot, Mixer, Citadel. Citadel nuk do ta shqyrtojm\u00eb, pasi nevojitet p\u00ebr gjenerimin e certifikatave q\u00eb sigurojn\u00eb funksionimin e mutual TLS midis sh\u00ebrbimeve. Le t\u00eb shohim m\u00eb n\u00eb detaje dizajnin dhe q\u00ebllimin e Pilot dhe Mixer.<\/p>\n<p><img decoding=\"async\" alt=\"Si si oriento Istio, duke p\u00ebrdorur Kubernetes n\u00eb prodhim. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/04\/1e2b76b5ec12343dee7728e505321908.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nPilot \u00ebsht\u00eb komponenti kryesor menaxher, i cili shp\u00ebrndan t\u00eb gjitha informacionet n\u00eb lidhje me at\u00eb q\u00eb kemi n\u00eb klaster - sh\u00ebrbimet, endpoint-et e tyre dhe rregullat e routing (p\u00ebr shembull, rregullat p\u00ebr Canary deployment ose rregullat circuit breaker).<\/p>\n<p>Mixer \u00ebsht\u00eb nj\u00eb komponent opsional i control plane, i cili ofron mund\u00ebsin\u00eb e mbledhjes s\u00eb metrikave, log\u00ebve dhe \u00e7do informacioni mbi nd\u00ebrveprimin rrjetor. Po ashtu, ai monitoron p\u00ebrputhshm\u00ebrin\u00eb me politikat dhe respektimin e kufizimeve t\u00eb rate limit.<\/p>\n<p>Data plane realizohet p\u00ebrmes kontejner\u00ebve sidecar-proxy. N\u00eb m\u00ebnyr\u00eb t\u00eb paracaktuar, p\u00ebrdoret nj\u00eb server i fuqish\u00ebm <noindex><a rel=\"nofollow\" href=\"https:\/\/www.envoyproxy.io\/\">proxy-server envoy<\/a><\/noindex>. Ai mund t\u00eb z\u00ebvend\u00ebsohet me nj\u00eb implementim tjet\u00ebr, p\u00ebr shembull nginx (nginmesh).<\/p>\n<p>P\u00ebr t\u00eb siguruar q\u00eb Istio funksionon plot\u00ebsisht n\u00eb m\u00ebnyr\u00eb transparente p\u00ebr aplikacionet, ekziston nj\u00eb sistem automatik injektimi. Implementimi i fundit \u00ebsht\u00eb i p\u00ebrshtatsh\u00ebm p\u00ebr versionet e Kubernetes 1.9+ (mutational admission webhook). P\u00ebr versionet e Kubernetes 1.7, 1.8 ka mund\u00ebsin\u00eb e p\u00ebrdorimit t\u00eb Initializer.<\/p>\n<p>Kontejner\u00ebt sidecar lidhen me Pilot p\u00ebrmes protokollit GRPC, i cili lejon optimizimin e modelit t\u00eb d\u00ebrgimit t\u00eb ndryshimeve q\u00eb ndodhin n\u00eb klaster. GRPC filloi t\u00eb p\u00ebrdoret n\u00eb Envoy q\u00eb nga versioni 1.6, nd\u00ebrsa n\u00eb Istio p\u00ebrdoret q\u00eb nga versioni 0.8 dhe p\u00ebrfaq\u00ebson pilot-agent - nj\u00eb mb\u00ebshtjell\u00ebs n\u00eb golang mbi envoy, i cili konfiguronte parametrat e nisjes.<\/p>\n<p>Pilot dhe Mixer jan\u00eb komponente plot\u00ebsisht stateless, t\u00eb gjitha gjendjet mbahen n\u00eb memory. Konfigurimi p\u00ebr ta caktohet n\u00eb form\u00ebn e Burimeve t\u00eb Personalizuara t\u00eb Kubernetes, t\u00eb cilat ruhen n\u00eb etcd. <br \/>\nIstio-agent merr adres\u00ebn Pilot dhe hap nj\u00eb rrjedh\u00eb GRPC drejt tij. <\/p>\n<p>Si\u00e7 e p\u00ebrmenda, Istio realizon gjith\u00eb funksionalitetin plot\u00ebsisht transparent p\u00ebr aplikacionet. Le t\u00eb shohim se si. Algoritmi \u00ebsht\u00eb i till\u00eb:<\/p>\n<ol>\n<li>Ne e depolojm\u00eb versionin e ri t\u00eb sh\u00ebrbimit.<\/li>\n<li>N\u00eb var\u00ebsi t\u00eb qasjes s\u00eb injektimit, kontenier\u00ebt istio-init dhe istio-agent (envoy) shtohen n\u00eb faz\u00ebn e aplikimit t\u00eb konfiguracionit, ose ata mund t\u00eb jen\u00eb tashm\u00eb t\u00eb vendosur manualisht n\u00eb p\u00ebrshkrimin e entitetit Pod t\u00eb Kubernetes.<\/li>\n<li>Kontrolli istio-init p\u00ebrfaq\u00ebson nj\u00eb skenar q\u00eb aplikon rregulla iptables p\u00ebr podin. Ka dy opsione p\u00ebr konfigurimin e p\u00ebrmbushjes s\u00eb trafikut n\u00eb kontenierin istio-agent: t\u00eb p\u00ebrdorim rregullat redirect t\u00eb iptables ose <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kristrev\/tproxy-example\/blob\/master\/tproxy_example.c\">TPROXY<\/a><\/noindex>. N\u00eb momentin e shkruajtjes s\u00eb k\u00ebtij artikulli, p\u00ebrdoret si me t\u00eb drejt\u00eb qasja me rregulla redirect. N\u00eb istio-init ka mund\u00ebsin\u00eb t\u00eb p\u00ebrcaktoj\u00eb se \u00e7far\u00eb trafik duhet t\u00eb kapet dhe t\u00eb d\u00ebrgohet n\u00eb istio-agent. P\u00ebr shembull, p\u00ebr t\u00eb kapur t\u00eb gjith\u00eb trafikun e ardhsh\u00ebm dhe t\u00eb dal\u00eb, duhet t\u00eb vendosni parametrat <code>-i<\/code> dhe <code>-b<\/code> n\u00eb vler\u00ebn <code>*<\/code>. Mund t\u00eb specifikoni porte specifike q\u00eb duhet t\u00eb kapen. P\u00ebr t\u00eb mos kapur nj\u00eb subnet t\u00eb caktuar, mund ta p\u00ebrcaktoni at\u00eb me ndihm\u00ebn e flags <code>-x<\/code>.<\/li>\n<li>Pas p\u00ebrfundimit t\u00eb konteiner\u00ebve init, nisin ato kryesoret, p\u00ebrfshir\u00eb pilot-agent (envoy). Ai lidhet me Pilot-in e vendosur m\u00eb par\u00eb p\u00ebrmes GRPC dhe merr informacion mbi t\u00eb gjitha sh\u00ebrbimet ekzistuese dhe politikat e routing n\u00eb klaster. Sipas t\u00eb dh\u00ebnave t\u00eb marra, ai konfiguron cluster\u00ebt dhe sh\u00ebnon aty endpoint-et e aplikacioneve tona n\u00eb klasterin Kubernetes. Gjithashtu, \u00ebsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb theksohet nj\u00eb pik\u00eb e r\u00ebnd\u00ebsishme: envoy dinamikisht konfiguron listeners (\u00e7ifte IP, port), t\u00eb cilat fillon t\u00eb d\u00ebgjoj\u00eb. Prandaj, kur k\u00ebrkesat hyjn\u00eb n\u00eb pod, ato redirektohen me ndihm\u00ebn e rregullave t\u00eb iptables n\u00eb sidecar, envoy tashm\u00eb mund t\u00eb p\u00ebrpunoj\u00eb me sukses k\u00ebto lidhje dhe t\u00eb kuptoj\u00eb se ku duhet t\u00eb proxy-t\u00eb trafikun m\u00eb tej. N\u00eb k\u00ebt\u00eb faz\u00eb ndodh gjithashtu d\u00ebrgimi i informacionit n\u00eb Mixer, t\u00eb cilin do ta shqyrtojm\u00eb m\u00eb von\u00eb, dhe d\u00ebrgimi i spaneve t\u00eb gjurmimit.<\/li>\n<\/ol>\n<p>\nSi rezultat, ne marrim nj\u00eb rrjet t\u00eb t\u00ebr\u00eb t\u00eb server\u00ebve proxy envoy, t\u00eb cil\u00ebt mund t'i konfigurojm\u00eb nga nj\u00eb pik\u00eb (Pilot). T\u00eb gjitha k\u00ebrkesat inbound dhe outbound kalojn\u00eb p\u00ebrmes envoy. P\u00ebr m\u00eb tep\u00ebr, vet\u00ebm trafiku TCP kapet. Kjo do t\u00eb thot\u00eb se IP e sh\u00ebrbimit t\u00eb Kubernetes rezolvohet me ndihm\u00ebn e kube-dns p\u00ebrmes UDP pa ndryshime. Pastaj, pas rezolut\u00ebs, ndodh kapja e k\u00ebrkes\u00ebs s\u00eb dal\u00eb dhe p\u00ebrpunimi nga envoy, i cili tashm\u00eb vendos se n\u00eb cilin endpoint duhet d\u00ebrguar k\u00ebrkesa (ose t\u00eb mos d\u00ebrgohet, n\u00eb rastin e politikave t\u00eb aksesit ose aktivizimit t\u00eb algoritmit t\u00eb circuit breaker).<\/p>\n<p>Tani q\u00eb e kuptuam Pilotin, duhet t\u00eb kuptojm\u00eb se si funksionon Mixer dhe p\u00ebrse \u00ebsht\u00eb i nevojsh\u00ebm. Ju mund ta lexoni dokumentacionin zyrtar p\u00ebr t\u00eb. <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/concepts\/policies-and-telemetry\/overview\/\">k\u00ebtu<\/a><\/noindex>.<\/p>\n<p>Mixer n\u00eb form\u00ebn aktuale p\u00ebrb\u00ebhet nga dy komponent\u00eb: istio-telemetry, istio-policy (deri n\u00eb versionin 0.8 ky ishte nj\u00eb komponent istio-mixer). T\u00eb dy p\u00ebrb\u00ebjn\u00eb mixer, secila prej t\u00eb cilave p\u00ebrgjigjet p\u00ebr detyr\u00ebn e saj. Istio telemetry pranon informacion nga kontainer\u00ebt sidecar p\u00ebrmes GRPC, duke raportuar informacionin se kush po shkon ku dhe me cilat parametra. Istio-policy merr k\u00ebrkesa Check p\u00ebr t\u00eb verifikuar p\u00ebrmbushjen e rregullave t\u00eb Politik\u00ebs. Kontrolli i Politik\u00ebs, sigurisht, nuk kryhet p\u00ebr \u00e7do k\u00ebrkes\u00eb, por ruhet n\u00eb klient (n\u00eb sidecar) p\u00ebr nj\u00eb koh\u00eb t\u00eb caktuar. Kontrolluesit e Raportit d\u00ebrgohen me porosi batch. Si t\u00eb konfigurohet dhe cilat parametra t\u00eb d\u00ebrgohen do ta shikojm\u00eb m\u00eb von\u00eb. <\/p>\n<p>Mixer parashikohet si nj\u00eb komponent me disponueshm\u00ebri t\u00eb lart\u00eb, i cili siguron vazhdim\u00ebsin\u00eb e operacioneve p\u00ebr mbledhjen dhe p\u00ebrpunimin e t\u00eb dh\u00ebnave t\u00eb telemetry. Sistemi p\u00ebrfundohet n\u00eb nj\u00eb buffer shum\u00ebnivel\u00ebsh. Fillimisht, t\u00eb dh\u00ebnat bufferizohen n\u00eb an\u00ebn e kontainer\u00ebve sidecar, pastaj n\u00eb an\u00ebn e mixer dhe m\u00eb pas d\u00ebrgohen n\u00eb at\u00eb q\u00eb quhet mixer backend. Si rezultat, n\u00ebse ndonj\u00eb nga komponent\u00ebt e sistemit d\u00ebshton, bufferi rritet dhe pas rikthimit t\u00eb sistemit, ajo zbrazet. Mixer backend p\u00ebrb\u00ebn pika t\u00eb fundit p\u00ebr d\u00ebrgimin e t\u00eb dh\u00ebnave p\u00ebr telemetry: statsd, newrelic etj. Mund t\u00eb shkruani backend tuaj, \u00ebsht\u00eb mjaft e thjesht\u00eb, dhe do ta shqyrtojm\u00eb si ta b\u00ebjm\u00eb.<\/p>\n<p><img decoding=\"async\" alt=\"Si si oriento Istio, duke p\u00ebrdorur Kubernetes n\u00eb prodhim. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/04\/e7dd11d5ee26a692e1cd213578d47700.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nN\u00ebse p\u00ebrmbledhim, skema e pun\u00ebs me istio-telemetry \u00ebsht\u00eb k\u00ebshtu.<\/p>\n<ol>\n<li>Sh\u00ebrbimi 1 d\u00ebrgon nj\u00eb k\u00ebrkes\u00eb n\u00eb sh\u00ebrbimin 2.<\/li>\n<li>Kur del nga sh\u00ebrbimi 1, k\u00ebrkesa paketuar n\u00eb sidecar e tij.<\/li>\n<li>Sidecar envoy monitoron se si kalon k\u00ebrkesa n\u00eb sh\u00ebrbimin 2 dhe p\u00ebrgatit informacionin e nevojsh\u00ebm.<\/li>\n<li>Ajo m\u00eb pas e d\u00ebrgon at\u00eb n\u00eb istio-telemetry p\u00ebrmes nj\u00eb k\u00ebrkese Report.<\/li>\n<li>Istio-telemetry p\u00ebrcakton n\u00ebse duhet t\u00eb d\u00ebrgoj\u00eb k\u00ebt\u00eb Report n\u00eb backend, n\u00eb cilat p\u00ebrkat\u00ebsisht dhe cilat t\u00eb dh\u00ebna duhen d\u00ebrguar.<\/li>\n<li>Istio-telemetry d\u00ebrgon t\u00eb dh\u00ebnat e Report n\u00eb backend n\u00ebse kjo \u00ebsht\u00eb e nevojshme.<\/li>\n<\/ol>\n<p>\nTani le t\u00eb shikojm\u00eb se si t\u00eb instalohet n\u00eb sistemin Istio, q\u00eb p\u00ebrb\u00ebhet vet\u00ebm nga komponent\u00ebt e r\u00ebnd\u00ebsish\u00ebm (Pilot dhe sidecar envoy).<\/p>\n<p>Fillimisht, le t\u00eb shikojm\u00eb konfigurimin kryesor (mesh), q\u00eb Pilot e lexon:<\/p>\n<pre><code class=\"plaintext\">apiVersion: v1\nkind: ConfigMap\nmetadata:\n  name: istio\n  namespace: istio-system\n  labels:\n    app: istio\n    service: istio\ndata:\n  mesh: |-\n\n    # Nd\u00ebrkohe, nuk do t\u00eb aktivizojm\u00eb d\u00ebrgimin e informacionit p\u00ebr tracing (pilot do t\u00eb konfiguroj\u00eb envoy n\u00eb m\u00ebnyr\u00eb q\u00eb d\u00ebrgimi t\u00eb mos ndodh\u00eb)\n    enableTracing: false\n\n    # Nd\u00ebrkohe, nuk do t\u00eb sh\u00ebnojm\u00eb endpoint-et e mixer-it, n\u00eb m\u00ebnyr\u00eb q\u00eb kontejner\u00ebt sidecar t\u00eb mos d\u00ebrgojn\u00eb informacion atje\n    #mixerCheckServer: istio-policy.istio-system:15004\n    #mixerReportServer: istio-telemetry.istio-system:15004\n\n    # Vendosim nj\u00eb interval kohor, me t\u00eb cilin envoy do t\u00eb b\u00ebj\u00eb p\u00ebrshtypje te Pilot (kjo \u00ebsht\u00eb p\u00ebr versionin e vjet\u00ebr t\u00eb proxy-it envoy)\n    rdsRefreshDelay: 5s\n\n    # konfigurimi default p\u00ebr envoy sidecar\n    defaultConfig:\n      # ashtu si rdsRefreshDelay\n      discoveryRefreshDelay: 5s\n\n      # e mbajm\u00eb si\u00e7 \u00ebsht\u00eb (rruga p\u00ebr konfigurimin dhe ekzekutimin e envoy)\n      configPath: \"\/etc\/istio\/proxy\"\n      binaryPath: \"\/usr\/local\/bin\/envoy\"\n\n      # emri default i kontejnerit sidecar t\u00eb nisur (p\u00ebrdoret, p\u00ebr shembull, n\u00eb emrat e sh\u00ebrbimeve gjat\u00eb d\u00ebrgimit t\u00eb tracing span-ve)\n      serviceCluster: istio-proxy\n\n      # koha q\u00eb do t\u00eb pres\u00eb envoy para se t\u00eb mbyll\u00eb t\u00eb gjitha lidhjet e krijuara\n      drainDuration: 45s\n      parentShutdownDuration: 1m0s\n\n      # p\u00ebr default p\u00ebrdoren rregullat REDIRECT t\u00eb iptables. Mund t\u00eb ndryshohet n\u00eb TPROXY.\n      #interceptionMode: REDIRECT\n\n      # Porta, n\u00eb t\u00eb cil\u00ebn do t\u00eb nis\u00eb paneli administrativ i secilit kontejner sidecar (envoy)\n      proxyAdminPort: 15000\n\n      # adresa, n\u00eb t\u00eb cil\u00ebn do t\u00eb d\u00ebrgohen trace-t sipas protokollit zipkin (n\u00eb fillim kemi \u00e7aktivizuar d\u00ebrgimin vet\u00eb, prandaj ky fush\u00eb tani nuk do t\u00eb p\u00ebrdoret)\n      zipkinAddress: tracing-collector.tracing:9411\n\n      # adresa statsd p\u00ebr d\u00ebrgimin e metricave t\u00eb kontejner\u00ebve envoy (\u00e7aktivizojm\u00eb)\n      # statsdUdpAddress: aggregator:8126\n\n      # \u00e7aktivizojm\u00eb mb\u00ebshtetje p\u00ebr opsionin Mutual TLS\n      controlPlaneAuthPolicy: NONE\n\n      # adresa, n\u00eb t\u00eb cil\u00ebn do t\u00eb d\u00ebgjoj\u00eb istio-pilot p\u00ebr t\u00eb raportuar informacion p\u00ebr discovery-in e sh\u00ebrbimeve t\u00eb gjith\u00eb kontejner\u00ebve sidecar\n      discoveryAddress: istio-pilot.istio-system:15007\n<\/code><\/pre>\n<p>\nT\u00eb gjith\u00eb komponent\u00ebt kryesor\u00eb t\u00eb menaxhimit (control plane) do t\u00eb vendosen n\u00eb namespace istio-system n\u00eb Kubernetes.<\/p>\n<p>Minimalisht, na nevojitet t\u00eb nisnim vet\u00ebm Pilot-in. P\u00ebr k\u00ebt\u00eb do t\u00eb p\u00ebrdorim <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/istio\/istio\/blob\/release-1.0\/install\/kubernetes\/helm\/istio\/charts\/pilot\/templates\/deployment.yaml\">k\u00ebt\u00eb konfigurim.<\/a><\/noindex><\/p>\n<p>Dhe do ta konfigurojm\u00eb manualisht injektimin e kontejnerit sidecar.<\/p>\n<p>Kontejneri Init:<\/p>\n<pre><code class=\"plaintext\">initContainers:\n - name: istio-init\n   args:\n   - -p\n   - \"15001\"\n   - -u\n   - \"1337\"\n   - -m\n   - REDIRECT\n   - -i\n   - '*'\n   - -b\n   - '*'\n   - -d\n   - \"\"\n   image: istio\/proxy_init:1.0.0\n   imagePullPolicy: IfNotPresent\n   resources:\n     limits:\n       memory: 128Mi\n   securityContext:\n     capabilities:\n       add:\n       - NET_ADMIN\n<\/code><\/pre>\n<p>\nDhe sidecar:<\/p>\n<pre><code class=\"plaintext\">       emri: istio-proxy\n       args:\n         - \"bash\"\n         - \"-c\"\n         - |\n           exec \/usr\/local\/bin\/pilot-agent proxy sidecar \n           --configPath \n           \/etc\/istio\/proxy \n           --binaryPath \n           \/usr\/local\/bin\/envoy \n           --serviceCluster \n           emri-i-servisit \n           --drainDuration \n           45s \n           --parentShutdownDuration \n           1m0s \n           --discoveryAddress \n           istio-pilot.istio-system:15007 \n           --discoveryRefreshDelay \n           1s \n           --connectTimeout \n           10s \n           --proxyAdminPort \n           \"15000\" \n           --controlPlaneAuthPolicy \n           NONE\n         env:\n         - name: POD_NAME\n           valueFrom:\n             fieldRef:\n               fieldPath: metadata.name\n         - name: POD_NAMESPACE\n           valueFrom:\n             fieldRef:\n               fieldPath: metadata.namespace\n         - name: INSTANCE_IP\n           valueFrom:\n             fieldRef:\n               fieldPath: status.podIP\n         - name: ISTIO_META_POD_NAME\n           valueFrom:\n             fieldRef:\n               fieldPath: metadata.name\n         - name: ISTIO_META_INTERCEPTION_MODE\n           value: REDIRECT\n         image: istio\/proxyv2:1.0.0\n         imagePullPolicy: IfNotPresent\n         resources:\n           requests:\n             cpu: 100m\n             memory: 128Mi\n           limits:\n             memory: 2048Mi\n         securityContext:\n           privileged: false\n           readOnlyRootFilesystem: true\n           runAsUser: 1337\n         volumeMounts:\n         - mountPath: \/etc\/istio\/proxy\n           name: istio-envoy\n<\/code><\/pre>\n<p>\nP\u00ebr t\u00eb siguruar nj\u00eb nisje t\u00eb suksesshme, \u00ebsht\u00eb e nevojshme t\u00eb krijoni nj\u00eb ServiceAccount, ClusterRole, ClusterRoleBinding, CRD p\u00ebr Pilot, p\u00ebrshkrimet e t\u00eb cilave mund t\u00eb gjenden <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/istio\/istio\/tree\/release-1.0\/install\/kubernetes\/helm\/istio\/charts\/pilot\/templates\">k\u00ebtu<\/a><\/noindex>. <\/p>\n<p>Si rezultat, sh\u00ebrbimi n\u00eb t\u00eb cilin ne injektojm\u00eb sidecar me envoy, duhet t\u00eb nis\u00eb me sukses, t\u00eb marr\u00eb t\u00eb gjith\u00eb discovery nga piloti dhe t\u00eb p\u00ebrpunoj\u00eb k\u00ebrkesat.<\/p>\n<p>\u00cbsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb kuptohet se t\u00eb gjith\u00eb komponent\u00ebt e control plane jan\u00eb aplikacione stateless dhe mund t\u00eb shkall\u00ebzohen horizontalisht pa probleme. T\u00eb gjitha t\u00eb dh\u00ebnat ruhen n\u00eb etcd n\u00eb form\u00ebn e p\u00ebrshkrimeve t\u00eb personalizuara t\u00eb burimeve t\u00eb Kubernetes.<\/p>\n<p>Gjithashtu, Istio (deri tani eksperimental) ka mund\u00ebsin\u00eb e nisjes jasht\u00eb klastri dhe mund\u00ebsin\u00eb p\u00ebr t\u00eb par\u00eb dhe ndar\u00eb service discovery midis disa klastrave Kubernetes. M\u00eb shum\u00eb rreth k\u00ebsaj mund t\u00eb lexoni <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/setup\/kubernetes\/multicluster-install\/\">k\u00ebtu<\/a><\/noindex>.<\/p>\n<p>N\u00eb instalimet shum\u00ebklashtore duhet t\u00eb keni parasysh kufizime t\u00eb m\u00ebposhtme:<\/p>\n<ol>\n<li>Pod CIDR dhe Service CIDR duhet t\u00eb jen\u00eb t\u00eb unik\u00eb n\u00eb t\u00eb gjitha klastrat dhe nuk duhet t\u00eb mbivendosen.<\/li>\n<li>T\u00eb gjitha Pod CIDR duhet t\u00eb jen\u00eb t\u00eb aksesueshme nga \u00e7do Pod CIDR midis klastrave.<\/li>\n<li>T\u00eb gjith\u00eb server\u00ebt API t\u00eb Kubernetes duhet t\u00eb jen\u00eb t\u00eb aksesuesh\u00ebm ndaj nj\u00ebri-tjetrit.<\/li>\n<\/ol>\n<p>\nK\u00ebto jan\u00eb informata fillestare q\u00eb do t'ju ndihmojn\u00eb t\u00eb filloni pun\u00ebn me Istio. Megjithat\u00eb, ka ende shum\u00eb pengesa. P\u00ebr shembull, tiparet e routing-ut t\u00eb trafikut t\u00eb jasht\u00ebm (jasht\u00eb klastri), qasjet e debugsimit t\u00eb sidecar-\u00ebve, profilizimi, konfigurimi i mixer dhe krijimi i nj\u00eb backend t\u00eb personalizuar p\u00ebr mixer, konfigurimi i mekanizmit t\u00eb tracing dhe funksionimi i tij me ndihm\u00ebn e envoy.<br \/>\nNe do themi k\u00ebt\u00eb n\u00eb publikimet e tjera. Beni pyetjet tuaja dhe do p\u00ebrpiqem t'i adresoj ato.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/avito\/blog\/419319\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":24545,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-32766","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c Istio, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Kubernetes \u0432 production. \u0427\u0430\u0441\u0442\u044c 1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:48:48+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:48:48+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Si t\u00eb lansoni Istio duke p\u00ebrdorur Kubernetes n\u00eb prodhim. Pjesa 1 | ProHoster","description":"\u00c7far\u00eb \u00ebsht\u00eb Istio? \u00cbsht\u00eb nj\u00eb rrjete sh\u00ebrbimesh, nj\u00eb teknologji q\u00eb shton nj\u00eb nivel abstraksioni mbi rrjetin.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c Istio, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Kubernetes \u0432 production. \u0427\u0430\u0441\u0442\u044c 1 | ProHoster","og:description":"\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:48:48+00:00","article:modified_time":"2019-10-31T18:48:48+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32766","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 12:27:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:53:24","updated":"2026-01-21 12:27:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=32766"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32766\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/24545"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=32766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=32766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=32766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}