{"id":32766,"date":"2019-10-31T21:48:48","date_gmt":"2019-10-31T18:48:48","guid":{"rendered":"https:\/\/prohoster.info\/blog\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1\/"},"modified":"2019-10-31T21:48:48","modified_gmt":"2019-10-31T18:48:48","slug":"kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","title":{"rendered":"Si t\u00eb aktivizoni Istio duke p\u00ebrdorur Kubernetes n\u00eb produksion. Pjesa 1","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c7far\u00eb \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\">Istio<\/a><\/noindex>? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c \u0432\u043d\u0435\u0448\u043d\u0438\u0435 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0432\u0441\u0435 \u043f\u043e\u0445\u043e\u0434\u044b \u0438\u0437 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 \u0432\u043e \u0432\u043d\u0435\u0448\u043d\u044e\u044e \u0441\u0435\u0442\u044c. \u0415\u0441\u0442\u044c \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0437\u0430\u0434\u0430\u0432\u0430\u0442\u044c policy \u043f\u0440\u0430\u0432\u0438\u043b\u0430 \u0434\u043b\u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u043f\u043e\u0445\u043e\u0434\u043e\u0432 \u043c\u0435\u0436\u0434\u0443 \u0440\u0430\u0437\u043d\u044b\u043c\u0438 \u043c\u0438\u043a\u0440\u043e\u0441\u0435\u0440\u0432\u0438\u0441\u0430\u043c\u0438. \u041d\u0430\u043a\u043e\u043d\u0435\u0446, \u043c\u044b \u043c\u043e\u0436\u0435\u043c \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0432\u0441\u044e \u043a\u0430\u0440\u0442\u0443 \u0432\u0437\u0430\u0438\u043c\u043e\u0434\u0435\u0439\u0441\u0442\u0432\u0438\u044f \u043f\u043e \u0441\u0435\u0442\u0438 \u0438 \u0441\u0434\u0435\u043b\u0430\u0442\u044c \u0443\u043d\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0439 \u0441\u0431\u043e\u0440 \u043c\u0435\u0442\u0440\u0438\u043a \u043f\u043e\u043b\u043d\u043e\u0441\u0442\u044c\u044e \u043f\u0440\u043e\u0437\u0440\u0430\u0447\u043d\u043e \u0434\u043b\u044f \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439.<\/p>\n<p>Mund t\u00eb lexoni p\u00ebr mekanizmin e funksionimit n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/concepts\/\">dokumenti zyrtar<\/a><\/noindex>. Istio \u00ebsht\u00eb nj\u00eb instrument v\u00ebrtet i fuqish\u00ebm q\u00eb lejon zgjidhjen e shum\u00eb problemeve dhe detyrave. N\u00eb k\u00ebt\u00eb artikull do t\u00eb d\u00ebshiroja t\u00eb p\u00ebrgjigjem n\u00eb pyetjet kryesore q\u00eb zakonisht shfaqen n\u00eb fillim t\u00eb pun\u00ebs me Istio. Kjo do t'ju ndihmoj\u00eb t\u00eb kuptoni m\u00eb shpejt.<\/p>\n<p><img decoding=\"async\" alt=\"Si t\u00eb aktivizoni Istio duke p\u00ebrdorur Kubernetes n\u00eb produksion. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/04\/7ab676ec42cacafc97099d5af9f6332a.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>Parimi i funksionimit<\/h3>\n<p>\nIstio p\u00ebrb\u00ebhet nga dy zona kryesore \u2014 control plane dhe data plane. Control plane p\u00ebrmban komponent\u00ebt kryesor\u00eb q\u00eb sigurojn\u00eb funksionimin e drejt\u00eb t\u00eb t\u00eb tjer\u00ebve. N\u00eb versionin aktual (1.0) control plane ka tre komponent\u00eb kryesor\u00eb: Pilot, Mixer, Citadel. Ne nuk do t\u00eb shqyrtojm\u00eb Citadel, pasi ai \u00ebsht\u00eb i nevojsh\u00ebm p\u00ebr t\u00eb krijuar \u00e7ertifikata p\u00ebr t\u00eb siguruar funksionimin e mutual TLS midis sh\u00ebrbimeve. Le t\u00eb shikojm\u00eb m\u00eb n\u00eb detaje struktur\u00ebn dhe q\u00ebllimin e Pilot dhe Mixer.<\/p>\n<p><img decoding=\"async\" alt=\"Si t\u00eb aktivizoni Istio duke p\u00ebrdorur Kubernetes n\u00eb produksion. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/04\/1e2b76b5ec12343dee7728e505321908.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nPilot \u00ebsht\u00eb komponenti kryesor menaxher q\u00eb shp\u00ebrndan t\u00eb gjitha informacionet mbi at\u00eb q\u00eb kemi n\u00eb klaster \u2013 sh\u00ebrbimet, endpoint\u00ebt e tyre dhe rregullat e routing (p\u00ebr shembull, rregullat p\u00ebr Canary deployment ose rregullat e circuit breaker).<\/p>\n<p>Mixer \u00ebsht\u00eb nj\u00eb komponent opsional i control plane, i cili ofron mund\u00ebsin\u00eb p\u00ebr mbledhjen e metrikave, log\u00ebve dhe \u00e7do informacioni mbi nd\u00ebrveprimin n\u00eb rrjet. Ai gjithashtu mbik\u00ebqyr p\u00ebrmbushjen e rregullave t\u00eb Politik\u00ebs dhe respektimin e limiteve t\u00eb normave.<\/p>\n<p>Data plane realizohet p\u00ebrmes kontejner\u00ebve sidecar-proxy. Si parazgjedhje p\u00ebrdoret <noindex><a rel=\"nofollow\" href=\"https:\/\/www.envoyproxy.io\/\">serveri proxy envoy<\/a><\/noindex>. Ai mund t\u00eb z\u00ebvend\u00ebsohet me nj\u00eb implementim tjet\u00ebr, si p\u00ebr shembull nginx (nginmesh).<\/p>\n<p>P\u00ebr t\u00eb siguruar q\u00eb Istio funksionon plot\u00ebsisht n\u00eb m\u00ebnyr\u00eb transparente p\u00ebr aplikacionet, ekziston nj\u00eb sistem automatik injectimi. Implementimi m\u00eb i fundit p\u00ebrshtatet p\u00ebr versionet Kubernetes 1.9+ (mutational admission webhook). P\u00ebr versionet e Kubernetes 1.7, 1.8 ka mund\u00ebsin\u00eb t\u00eb p\u00ebrdorim Initializer.<\/p>\n<p>Kontejner\u00ebt sidecar lidhen me Pilot p\u00ebrmes protokollit GRPC, i cili lejon optimizimin e modelit t\u00eb p\u00ebrdit\u00ebsimit t\u00eb ndryshimeve q\u00eb ndodhin n\u00eb klaster. GRPC filloi t\u00eb p\u00ebrdoret n\u00eb Envoy nga versioni 1.6, n\u00eb Istio p\u00ebrdoret nga versioni 0.8 dhe p\u00ebrb\u00ebn pilot-agent \u2014 nj\u00eb mb\u00ebshtjell\u00ebs mbi golang mbi envoy q\u00eb konfiguron parametrat e ekzekutimit.<\/p>\n<p>Pilot dhe Mixer jan\u00eb plot\u00ebsisht komponent\u00eb stateless, t\u00eb gjitha gjendjet i mbajn\u00eb n\u00eb memorie. Konfigurimi p\u00ebr ta p\u00ebrcaktohet n\u00eb form\u00ebn e Burimeve t\u00eb Personalizuara t\u00eb Kubernetes, t\u00eb cilat ruhen n\u00eb etcd. <br \/>\nIstio-agent merr adres\u00ebn e Pilot dhe hap nj\u00eb stream GRPC p\u00ebr t\u00eb. <\/p>\n<p>Si\u00e7 e thash\u00eb, Istio realizon t\u00eb gjitha funksionalitetet plot\u00ebsisht n\u00eb m\u00ebnyr\u00eb transparente p\u00ebr aplikacionet. Le t\u00eb kuptojm\u00eb se si. Algoritmi \u00ebsht\u00eb i till\u00eb:<\/p>\n<ol>\n<li>Deployojm\u00eb nj\u00eb version t\u00eb ri t\u00eb sh\u00ebrbimit.<\/li>\n<li>N\u00eb p\u00ebrputhje me qasjen e injectimit, kontejner\u00ebt sidecar jan\u00eb t\u00eb shtuar me kontejnerin istio-init dhe kontejnerin istio-agent (envoy) n\u00eb faz\u00ebn e aplikimit t\u00eb konfigurimit, ose ata mund t\u00eb jen\u00eb tashm\u00eb t\u00eb futur manualisht n\u00eb p\u00ebrshkrimin e entitetit Pod t\u00eb Kubernetes.<\/li>\n<li>Kontejneri istio-init p\u00ebrfaq\u00ebson nj\u00eb skript, i cili aplikon rregullat e iptables p\u00ebr podin. Ka dy mund\u00ebsi p\u00ebr konfigurimin e mb\u00ebshtjelljes s\u00eb trafikut n\u00eb kontejnerin istio-agent: p\u00ebrdorimi i rregullave t\u00eb redirect t\u00eb iptables, ose <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kristrev\/tproxy-example\/blob\/master\/tproxy_example.c\">TPROXY<\/a><\/noindex>. N\u00eb momentin kur po shkruaj artikullin, si parazgjedhje p\u00ebrdoret qasja me rregullat e redirect. N\u00eb istio-init ka mund\u00ebsin\u00eb t\u00eb konfigurosh se cili trafikun duhet t\u00eb kapet dhe drejtohet n\u00eb istio-agent. P\u00ebr shembull, p\u00ebr t\u00eb kapur t\u00eb gjith\u00eb trafikun hyr\u00ebs dhe t\u00eb gjith\u00eb trafikun dal\u00ebs, duhet t\u00eb vendosen parametrat <code>-i<\/code> dhe <code>-b<\/code> n\u00eb vler\u00eb <code>*<\/code>. Mund t\u00eb specifikoni porte specifike q\u00eb duhet t\u00eb kapen. P\u00ebr t\u00eb mos kapur nj\u00eb n\u00ebndeg\u00eb t\u00eb caktuar, mund ta specifikoni at\u00eb me an\u00eb t\u00eb flagut <code>-x<\/code>.<\/li>\n<li>Pas ekzekutimit t\u00eb kontejner\u00ebve init, nis\u00ebn ato kryesor\u00eb, dhe p\u00ebrfshir\u00eb pilot-agent (envoy). Ai lidhet me Pilotin e dekretuar p\u00ebrmes GRPC dhe merr informacion mbi t\u00eb gjitha sh\u00ebrbimet ekzistuese dhe politikat e routing n\u00eb klaster. Sipas t\u00eb dh\u00ebnave t\u00eb marra, ai konfiguron klaster\u00ebt dhe shkruan menj\u00ebher\u00eb endpoint\u00ebt e aplikacioneve tona n\u00eb klasterin Kubernetes. Gjithashtu, duhet theksuar nj\u00eb pik\u00eb e r\u00ebnd\u00ebsishme: envoy dinamikisht konfiguron listeners (\u00e7ifte IP, port), q\u00eb fillon t\u00eb d\u00ebgjoj\u00eb. Prandaj, kur k\u00ebrkesat hyjn\u00eb n\u00eb pod, ato redirektohen p\u00ebrmes rregullave t\u00eb iptables n\u00eb sidecar, envoy tani mund t\u00eb p\u00ebrpunoj\u00eb k\u00ebto lidhje dhe t\u00eb kuptoj\u00eb se ku duhet t\u00eb prokurohet trafiku m\u00eb tutje. N\u00eb k\u00ebt\u00eb faz\u00eb ndodh gjithashtu d\u00ebrgimi i informacionit n\u00eb Mixer, t\u00eb cilin do ta shqyrtojm\u00eb m\u00eb von\u00eb, dhe d\u00ebrgimi i span-ev tracing.<\/li>\n<\/ol>\n<p>\nSi rezultat, ne marrim nj\u00eb rrjet t\u00eb t\u00ebr\u00eb server\u00ebsh proxy envoy, t\u00eb cil\u00ebt mund t'i konfigurojm\u00eb nga nj\u00eb pik\u00eb (Pilot). T\u00eb gjitha k\u00ebrkesat hyr\u00ebse dhe dal\u00ebse kalojn\u00eb p\u00ebrmes envoy. N\u00eb fakt, vet\u00ebm trafiku TCP kapet. Kjo do t\u00eb thot\u00eb se IP e sh\u00ebrbimit Kubernetes zgjidhet p\u00ebrmes kube-dns sipas UDP pa ndryshime. M\u00eb pas, pas zgjidhjes ndodh kapja e k\u00ebrkesave dal\u00ebse dhe p\u00ebrpunimi nga envoy, i cili tashm\u00eb vendos se n\u00eb cilin endpoint duhet t\u00eb d\u00ebrgohet k\u00ebrkesa (ose t\u00eb mos d\u00ebrgohet, n\u00eb rastin e politikave t\u00eb aksesit ose n\u00ebse ka ndodhur algoritmi i circuit breaker).<\/p>\n<p>Pas kuptimit t\u00eb Pilot, tani duhet t\u00eb kuptojm\u00eb se si funksionon Mixer dhe p\u00ebrse \u00ebsht\u00eb e nevojshme. Mund t\u00eb lexoni dokumentacionin zyrtar rreth saj. <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/concepts\/policies-and-telemetry\/overview\/\">k\u00ebtu<\/a><\/noindex>.<\/p>\n<p>Mixer n\u00eb form\u00ebn e tanishme p\u00ebrb\u00ebhet nga dy komponente: istio-telemetry dhe istio-policy (para versionit 0.8, ishte nj\u00eb komponent i vet\u00ebm, istio-mixer). T\u00eb dyja p\u00ebrfaq\u00ebsojn\u00eb mixer, secila me detyr\u00ebn e saj. Istio telemetry merr p\u00ebrmes GRPC nga konteiner\u00ebt sidecar informacionin se kush po shkon ku dhe me cilat parametra. Istio-policy merr k\u00ebrkesat Check p\u00ebr t\u00eb verifikuar p\u00ebrmbushjen e rregullave t\u00eb Policy. Kontrollimi i politik\u00ebs nuk b\u00ebhet p\u00ebr \u00e7do k\u00ebrkes\u00eb, por ruhet n\u00eb klient (n\u00eb sidecar) p\u00ebr nj\u00eb koh\u00eb t\u00eb caktuar. Raportet d\u00ebrgohen n\u00eb grupe. Si ta konfigurojm\u00eb dhe cilat parametra t\u00eb ve\u00e7anta duhet t\u00eb d\u00ebrgojm\u00eb do ta shqyrtojm\u00eb m\u00eb von\u00eb. <\/p>\n<p>Mixer parashikohet si nj\u00eb komponent me disponibilitet t\u00eb lart\u00eb, i cili ofron funksionimin pa nd\u00ebrprerje p\u00ebr mbledhjen dhe p\u00ebrpunimin e t\u00eb dh\u00ebnave t\u00eb telemetry. Sistemii p\u00ebrcaktohet si nj\u00eb buffer me shum\u00eb nivele. Fillimisht, t\u00eb dh\u00ebnat ruhen n\u00eb an\u00ebn e konteiner\u00ebve sidecar, pastaj n\u00eb an\u00ebn e mixer dhe m\u00eb pas d\u00ebrgohen n\u00eb at\u00eb q\u00eb quhen mixer backend. N\u00eb p\u00ebrfundim, n\u00ebse ndonj\u00eb nga komponent\u00ebt e sistemit d\u00ebshton, bufferi rritet dhe pas rind\u00ebrtimit t\u00eb sistemit, ai shfryhet. Mixer backend p\u00ebrfaq\u00ebsojn\u00eb piketat finale p\u00ebr d\u00ebrgimin e t\u00eb dh\u00ebnave mbi telemetri: statsd, newrelic dhe t\u00eb tjer\u00eb. Mund t\u00eb shkruani backend tuaj, \u00ebsht\u00eb mjaft e thjesht\u00eb dhe do ta shohim se si ta b\u00ebjm\u00eb k\u00ebt\u00eb.<\/p>\n<p><img decoding=\"async\" alt=\"Si t\u00eb aktivizoni Istio duke p\u00ebrdorur Kubernetes n\u00eb produksion. Pjesa 1\" src=\"\/wp-content\/uploads\/2019\/04\/e7dd11d5ee26a692e1cd213578d47700.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nN\u00ebse p\u00ebrmbledhim, skema e pun\u00ebs me istio-telemetry \u00ebsht\u00eb si m\u00eb posht\u00eb.<\/p>\n<ol>\n<li>Sh\u00ebrbimi 1 d\u00ebrgon nj\u00eb k\u00ebrkes\u00eb n\u00eb sh\u00ebrbimin 2.<\/li>\n<li>Pasi del nga sh\u00ebrbimi 1, k\u00ebrkesa mb\u00ebshtillet n\u00eb sidecar-in e tij.<\/li>\n<li>Sidecar envoy monitoron se si kalon k\u00ebrkesa n\u00eb sh\u00ebrbimin 2 dhe p\u00ebrgatit informacionin e nevojsh\u00ebm.<\/li>\n<li>Pastaj e d\u00ebrgon at\u00eb n\u00eb istio-telemetry p\u00ebrmes k\u00ebrkes\u00ebs Report.<\/li>\n<li>Istio-telemetry p\u00ebrcakton n\u00ebse duhet t\u00eb d\u00ebrgoj\u00eb k\u00ebt\u00eb Report n\u00eb backend, n\u00eb cilat sakt\u00ebsisht dhe \u00e7far\u00eb t\u00eb dh\u00ebnash duhet t\u00eb d\u00ebrgohen.<\/li>\n<li>Istio-telemetry d\u00ebrgon t\u00eb dh\u00ebnat e Report n\u00eb backend n\u00ebse \u00ebsht\u00eb e nevojshme.<\/li>\n<\/ol>\n<p>\nTani le t\u00eb shohim se si t\u00eb implementojm\u00eb n\u00eb sistemin Istio, i p\u00ebrb\u00ebr\u00eb vet\u00ebm nga komponent\u00ebt baz\u00eb (Pilot dhe sidecar envoy).<\/p>\n<p>Fillimisht, le t\u00eb shohim konfigurimin baz\u00eb (mesh) q\u00eb lexon Pilot:<\/p>\n<pre><code class=\"plaintext\">apiVersion: v1\nkind: ConfigMap\nmetadata:\n  name: istio\n  namespace: istio-system\n  labels:\n    app: istio\n    service: istio\ndata:\n  mesh: |-\n\n    # p\u00ebr momentin nuk e aktivizojm\u00eb d\u00ebrgimin e informacionit t\u00eb tracing (pilot do t'i konfiguroj\u00eb envoy-t n\u00eb at\u00eb m\u00ebnyr\u00eb, q\u00eb d\u00ebrgimi t\u00eb mos ndodh)\n    enableTracing: false\n\n    # p\u00ebr momentin nuk tregojm\u00eb endpoint-in e mixer-it, q\u00eb t\u00eb mos d\u00ebrgohen informacionet nga konteiner\u00ebt sidecar atje\n    #mixerCheckServer: istio-policy.istio-system:15004\n    #mixerReportServer: istio-telemetry.istio-system:15004\n\n    # vendosim nj\u00eb interval, me t\u00eb cilin envoy do t\u00eb pyes\u00eb Pilot-in (kjo \u00ebsht\u00eb p\u00ebr versionin e vjet\u00ebr t\u00eb envoy proxy)\n    rdsRefreshDelay: 5s\n\n    # konfigurimi default p\u00ebr envoy sidecar\n    defaultConfig:\n      # ngjash\u00ebm me rdsRefreshDelay\n      discoveryRefreshDelay: 5s\n\n      # l\u00ebm\u00eb t\u00eb gjitha si\u00e7 \u00ebsht\u00eb (rruga drejt konfigurimit dhe binarit t\u00eb envoy)\n      configPath: \"\/etc\/istio\/proxy\"\n      binaryPath: \"\/usr\/local\/bin\/envoy\"\n\n      # emri default i konteinerit sidecar t\u00eb nisur (p\u00ebrdoret, p\u00ebr shembull, n\u00eb emrat e sh\u00ebrbimeve kur d\u00ebrgohen span tracing)\n      serviceCluster: istio-proxy\n\n      # koha q\u00eb do t\u00eb pres\u00eb envoy deri sa t\u00eb p\u00ebrfundoj\u00eb t\u00eb gjitha lidhjet e vendosura\n      drainDuration: 45s\n      parentShutdownDuration: 1m0s\n\n      # sipas default p\u00ebrdoren rregullat REDIRECT t\u00eb iptables. Mund t\u00eb ndryshohet n\u00eb TPROXY.\n      #interceptionMode: REDIRECT\n\n      # Porti, n\u00eb t\u00eb cilin do t\u00eb nis\u00eb paneli administrativ i \u00e7do konteineri sidecar (envoy)\n      proxyAdminPort: 15000\n\n      # adresa, n\u00eb t\u00eb cil\u00ebn do t\u00eb d\u00ebrgohen trace-t sipas protokollit zipkin (n\u00eb fillim e \u00e7aktivizuam d\u00ebrgimin vet\u00eb, k\u00ebshtu q\u00eb kjo fush\u00eb tani nuk do t\u00eb p\u00ebrdoret)\n      zipkinAddress: tracing-collector.tracing:9411\n\n      # adresa statsd p\u00ebr d\u00ebrgimin e metrikave t\u00eb konteiner\u00ebve envoy (e \u00e7aktivizojm\u00eb)\n      # statsdUdpAddress: aggregator:8126\n\n      # \u00e7aktivizojm\u00eb mb\u00ebshtetje p\u00ebr opsionin Mutual TLS\n      controlPlaneAuthPolicy: NONE\n\n      # adresa, n\u00eb t\u00eb cil\u00ebn do t\u00eb d\u00ebgjoj\u00eb istio-pilot p\u00ebr t\u00eb raportuar informacionin mbi zbulimin e sh\u00ebrbimit t\u00eb gjith\u00eb konteiner\u00ebve sidecar\n      discoveryAddress: istio-pilot.istio-system:15007\n<\/code><\/pre>\n<p>\nT\u00eb gjith\u00eb komponent\u00ebt kryesor\u00eb t\u00eb kontrollit (control plane) do t\u2019i vendosim n\u00eb namespace istio-system n\u00eb Kubernetes.<\/p>\n<p>Minimalisht, ne duhet t\u00eb implementojm\u00eb vet\u00ebm Pilot. P\u00ebr k\u00ebt\u00eb do t\u00eb p\u00ebrdorim <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/istio\/istio\/blob\/release-1.0\/install\/kubernetes\/helm\/istio\/charts\/pilot\/templates\/deployment.yaml\">t\u00eb till\u00eb konfigurimi.<\/a><\/noindex><\/p>\n<p>Dhe do ta konfigurojm\u00eb manualisht injektimin e konteinerit sidecar.<\/p>\n<p>Konteineri inicial:<\/p>\n<pre><code class=\"plaintext\">initContainers:\n - name: istio-init\n   args:\n   - -p\n   - \"15001\"\n   - -u\n   - \"1337\"\n   - -m\n   - REDIRECT\n   - -i\n   - '*'\n   - -b\n   - '*'\n   - -d\n   - \"\"\n   image: istio\/proxy_init:1.0.0\n   imagePullPolicy: IfNotPresent\n   resources:\n     limits:\n       memory: 128Mi\n   securityContext:\n     capabilities:\n       add:\n       - NET_ADMIN\n<\/code><\/pre>\n<p>\nDhe sidecar:<\/p>\n<pre><code class=\"plaintext\">       name: istio-proxy\n       args:\n         - \"bash\"\n         - \"-c\"\n         - |\n           exec \/usr\/local\/bin\/pilot-agent proxy sidecar \n           --configPath \n           \/etc\/istio\/proxy \n           --binaryPath \n           \/usr\/local\/bin\/envoy \n           --serviceCluster \n           service-name \n           --drainDuration \n           45s \n           --parentShutdownDuration \n           1m0s \n           --discoveryAddress \n           istio-pilot.istio-system:15007 \n           --discoveryRefreshDelay \n           1s \n           --connectTimeout \n           10s \n           --proxyAdminPort \n           \"15000\" \n           --controlPlaneAuthPolicy \n           NONE\n         env:\n         - name: POD_NAME\n           valueFrom:\n             fieldRef:\n               fieldPath: metadata.name\n         - name: POD_NAMESPACE\n           valueFrom:\n             fieldRef:\n               fieldPath: metadata.namespace\n         - name: INSTANCE_IP\n           valueFrom:\n             fieldRef:\n               fieldPath: status.podIP\n         - name: ISTIO_META_POD_NAME\n           valueFrom:\n             fieldRef:\n               fieldPath: metadata.name\n         - name: ISTIO_META_INTERCEPTION_MODE\n           value: REDIRECT\n         image: istio\/proxyv2:1.0.0\n         imagePullPolicy: IfNotPresent\n         resources:\n           requests:\n             cpu: 100m\n             memory: 128Mi\n           limits:\n             memory: 2048Mi\n         securityContext:\n           privileged: false\n           readOnlyRootFilesystem: true\n           runAsUser: 1337\n         volumeMounts:\n         - mountPath: \/etc\/istio\/proxy\n           name: istio-envoy\n<\/code><\/pre>\n<p>\nP\u00ebr t\u00eb siguruar nj\u00eb fillim t\u00eb suksessh\u00ebm, \u00ebsht\u00eb e nevojshme t\u00eb krijoni nj\u00eb ServiceAccount, ClusterRole, ClusterRoleBinding, dhe CRD p\u00ebr Pilot, p\u00ebr t\u00eb cilat mund t\u00eb gjeni p\u00ebrshkrime <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/istio\/istio\/tree\/release-1.0\/install\/kubernetes\/helm\/istio\/charts\/pilot\/templates\">k\u00ebtu<\/a><\/noindex>. <\/p>\n<p>Si rezultat, sh\u00ebrbimi n\u00eb t\u00eb cilin ne inject'ojm\u00eb sidecar me envoy duhet t\u00eb startup me sukses, t\u00eb marr\u00eb t\u00eb gjith\u00eb zbulimin nga piloti dhe t\u00eb p\u00ebrpunoj\u00eb k\u00ebrkesat.<\/p>\n<p>\u00cbsht\u00eb e r\u00ebnd\u00ebsishme t\u00eb kuptoni se t\u00eb gjitha komponent\u00ebt e planeve t\u00eb kontrollit jan\u00eb aplikacione pa shtet dhe mund t\u00eb p\u00ebrshkall\u00ebzohen horizontalisht pa probleme. T\u00eb gjitha t\u00eb dh\u00ebnat ruhen n\u00eb etcd n\u00eb form\u00ebn e p\u00ebrshkrimeve t\u00eb personalizuara t\u00eb burimeve Kubernetes.<\/p>\n<p>Gjithashtu, Istio (aktualisht eksperimentohet) ka mund\u00ebsin\u00eb e ekzekutimit jasht\u00eb klasterit dhe mund\u00ebsin\u00eb p\u00ebr t\u00eb par\u00eb dhe ndar\u00eb zbulimin e sh\u00ebrbimeve midis disa klaster\u00ebve Kubernetes. M\u00eb shum\u00eb p\u00ebr k\u00ebt\u00eb mund t\u00eb lexoni <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/setup\/kubernetes\/multicluster-install\/\">k\u00ebtu<\/a><\/noindex>.<\/p>\n<p>N\u00eb instalimin me shum\u00eb klaster\u00eb, duhet t\u00eb merret parasysh mir\u00ebk\u00ebto kufizime:<\/p>\n<ol>\n<li>Pod CIDR dhe Service CIDR duhet t\u00eb jen\u00eb unike n\u00eb t\u00eb gjitha klaster\u00ebt dhe nuk duhet t\u00eb p\u00ebrfshijn\u00eb nj\u00ebri-tjetrin.<\/li>\n<li>T\u00eb gjitha Pod CIDR duhet t\u00eb jen\u00eb t\u00eb aksesueshme nga \u00e7do Pod CIDR midis klaster\u00ebve.<\/li>\n<li>T\u00eb gjith\u00eb server\u00ebt API t\u00eb Kubernetes duhet t\u00eb jen\u00eb t\u00eb aksesuesh\u00ebm p\u00ebr nj\u00ebri-tjetrin.<\/li>\n<\/ol>\n<p>\nK\u00ebto jan\u00eb informacionet fillestare q\u00eb do t'ju ndihmojn\u00eb t\u00eb filloni pun\u00ebn me Istio. Megjithat\u00eb, ka akoma shum\u00eb pengesa. P\u00ebr shembull, ve\u00e7orit\u00eb e rrug\u00ebtimit t\u00eb trafikut t\u00eb jasht\u00ebm (jasht\u00eb klasterit), qasjet n\u00eb debug t\u00eb sidecar-\u00ebve, profilizimi, konfigurimi i mixer dhe krijimi i nj\u00eb backend t\u00eb personalizuar t\u00eb mixer, konfigurimi i mekanizmit t\u00eb gjurmimit dhe funksionimi i tij me ndihm\u00ebn e envoy.<br \/>\nT\u00eb gjitha k\u00ebto do t'i shqyrtojm\u00eb n\u00eb publikimet e ardhshme. B\u00ebni pyetjet tuaja, do t\u00eb mundohem t'i sqaroj.<br \/>\n<br \/>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/avito\/blog\/419319\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":24545,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-32766","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c Istio, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Kubernetes \u0432 production. \u0427\u0430\u0441\u0442\u044c 1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:48:48+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:48:48+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Si t\u00eb filloni Istio, duke p\u00ebrdorur Kubernetes n\u00eb prodhim. Pjesa 1 | ProHoster","description":"\u00c7far\u00eb \u00ebsht\u00eb Istio? Ky \u00ebsht\u00eb nj\u00eb tip i ashtuquajtur Service mesh, nj\u00eb teknologji q\u00eb shton nj\u00eb nivel abstraksioni mbi rrjetin. Ne kapim t\u00eb gjith\u00eb ose nj\u00eb pjes\u00eb t\u00eb trafikut n\u00eb klaster dhe kryejm\u00eb nj\u00eb set t\u00eb caktuar operacionesh me t\u00eb. Cilat sakt\u00ebsisht? P\u00ebr shembull, b\u00ebjm\u00eb rrug\u00ebtim t\u00eb zgjuar, ose zbatimi i qasjes circuit breaker, mund t\u00eb organizojm\u00eb \"canary deployment\", duke kaluar pjes\u00ebrisht trafik n\u00eb nj\u00eb version t\u00eb ri t\u00eb sh\u00ebrbimit, ose mund t\u00eb kufizojm\u00eb.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041a\u0430\u043a \u0437\u0430\u043f\u0443\u0441\u0442\u0438\u0442\u044c Istio, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f Kubernetes \u0432 production. \u0427\u0430\u0441\u0442\u044c 1 | ProHoster","og:description":"\u0427\u0442\u043e \u0442\u0430\u043a\u043e\u0435 Istio? \u042d\u0442\u043e \u0442\u0430\u043a \u043d\u0430\u0437\u044b\u0432\u0430\u0435\u043c\u044b\u0439 Service mesh, \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u0438 \u043d\u0430\u0434 \u0441\u0435\u0442\u044c\u044e. \u041c\u044b \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u044b\u0432\u0430\u0435\u043c \u0432\u0435\u0441\u044c \u0438\u043b\u0438 \u0447\u0430\u0441\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0432 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0435 \u0438 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u043c \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439 \u0441 \u043d\u0438\u043c. \u041a\u0430\u043a\u043e\u0439 \u0438\u043c\u0435\u043d\u043d\u043e? \u041d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0434\u0435\u043b\u0430\u0435\u043c \u0443\u043c\u043d\u044b\u0439 \u0440\u043e\u0443\u0442\u0438\u043d\u0433, \u0438\u043b\u0438 \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434 circuit breaker, \u043c\u043e\u0436\u0435\u043c \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u044b\u0432\u0430\u0442\u044c \u00abcanary deployment\u00bb, \u0447\u0430\u0441\u0442\u0438\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u044f \u0442\u0440\u0430\u0444\u0438\u043a \u043d\u0430 \u043d\u043e\u0432\u0443\u044e \u0432\u0435\u0440\u0441\u0438\u044e \u0441\u0435\u0440\u0432\u0438\u0441\u0430, \u0430 \u043c\u043e\u0436\u0435\u043c \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0438\u0432\u0430\u0442\u044c","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/kak-zapustit-istio-ispolzuya-kubernetes-v-production-chast-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:48:48+00:00","article:modified_time":"2019-10-31T18:48:48+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"32766","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 12:27:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:53:24","updated":"2026-01-21 12:27:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=32766"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/32766\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/24545"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=32766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=32766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=32766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}