{"id":39016,"date":"2019-10-31T22:27:21","date_gmt":"2019-10-31T19:27:21","guid":{"rendered":"https:\/\/prohoster.info\/blog\/7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google\/"},"modified":"2019-10-31T22:27:21","modified_gmt":"2019-10-31T19:27:21","slug":"7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google","title":{"rendered":"7 best practices for container operations according to Google","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><i><b>Sh\u00ebn. p\u00ebrkth.<\/b>: Autori i artikullit origjinal \u00ebsht\u00eb Th\u00e9o Chamley, arkitekt i zgjidhjeve t\u00eb cloud nga Google. N\u00eb k\u00ebt\u00eb publikim p\u00ebr blogun e Google Cloud, ai paraqet nj\u00eb p\u00ebrmbledhje t\u00eb shkurt\u00ebr nga nj\u00eb udh\u00ebzues m\u00eb i detajuar i kompanis\u00eb s\u00eb tij, t\u00eb quajtur \"<noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/solutions\/best-practices-for-operating-containers\">Praktikat m\u00eb t\u00eb mira p\u00ebr operimin e kontejner\u00ebve<\/a><\/noindex>\u201c. N\u00eb t\u00eb, ekspert\u00ebt e Google kan\u00eb mbledhur praktikat m\u00eb t\u00eb mira p\u00ebr menaxhimin e kontejner\u00ebve n\u00eb kontekstin e p\u00ebrdorimit t\u00eb Google Kubernetes Engine dhe m\u00eb shum\u00eb, duke p\u00ebrfshir\u00eb nj\u00eb gam\u00eb t\u00eb gjer\u00eb temash: nga siguria deri te monitorimi dhe regjistrimi. Pra, cilat jan\u00eb praktikat m\u00eb t\u00eb r\u00ebnd\u00ebsishme n\u00eb pun\u00ebn me kontejner\u00ebt sipas mendimit t\u00eb Google?<\/i><\/p>\n<p><img decoding=\"async\" alt=\"7 best practices for container operations according to Google\" src=\"\/wp-content\/uploads\/2019\/10\/43aaa13a0fae1564ffc7f0a1fe0020b7.jpg\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/kubernetes-engine\/\">Kubernetes Engine<\/a><\/noindex> <i>(nj\u00eb sh\u00ebrbim i bazuar n\u00eb Kubernetes p\u00ebr t\u00eb drejtuar aplikacione t\u00eb kontejnerizuara n\u00eb Google Cloud \u2014 <b>sh\u00ebnim i p\u00ebrkthyesit.<\/b>)<\/i> \u2014 \u00ebsht\u00eb nj\u00eb nga m\u00ebnyrat m\u00eb t\u00eb mira p\u00ebr t\u00eb drejtuar ngarkesa pune q\u00eb kan\u00eb nevoj\u00eb p\u00ebr shkall\u00ebzim. <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/kubernetes\/\">Kubernetes<\/a><\/noindex> do t\u00eb siguroj\u00eb funksionimin pa probleme t\u00eb shumic\u00ebs s\u00eb aplikacioneve, n\u00ebse jan\u00eb t\u00eb kontejnerizuara. Por n\u00ebse d\u00ebshironi q\u00eb aplikacioni t\u00eb jet\u00eb i leht\u00eb p\u00ebr t'u menaxhuar dhe d\u00ebshironi t\u00eb shfryt\u00ebzoni t\u00eb gjitha avantazhet e Kubernetes, \u00ebsht\u00eb e nevojshme t\u00eb ndiqni praktikat m\u00eb t\u00eb mira. Ato do ta thjeshtojn\u00eb operimin e aplikacionit, monitorimin dhe pastrimin e tij, si dhe do t\u00eb rrisin sigurin\u00eb.<\/p>\n<p>N\u00eb k\u00ebt\u00eb artikull do t\u00eb kalojm\u00eb n\u00ebp\u00ebr nj\u00eb list\u00eb t\u00eb asaj q\u00eb duhet t\u00eb dini dhe t\u00eb b\u00ebni p\u00ebr funksionimin efektiv t\u00eb kontejner\u00ebve n\u00eb Kubernetes. Ata q\u00eb d\u00ebshirojn\u00eb t\u00eb thellohen n\u00eb detaje duhet t\u00eb lexojn\u00eb materialin <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/solutions\/best-practices-for-operating-containers\">Praktikat m\u00eb t\u00eb mira p\u00ebr operimin e kontejner\u00ebve<\/a><\/noindex>, si dhe t\u00eb ken\u00eb parasysh postimin ton\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/blog\/products\/gcp\/7-best-practices-for-building-containers\">m\u00eb t\u00eb hersh\u00ebm<\/a><\/noindex> p\u00ebr nd\u00ebrtimin e kontejner\u00ebve.<\/p>\n<h2>1. P\u00ebrdorni mekanizmat natyror\u00eb t\u00eb kontejner\u00ebve p\u00ebr regjistrimin<\/h2>\n<p>\nN\u00ebse aplikacioni \u00ebsht\u00eb i drejtuar n\u00eb nj\u00eb grup Kubernetes, p\u00ebr regjistrimin nuk nevojitet shum\u00eb. Nj\u00eb sistem i centralizuar i regjistrimit, p\u00ebr t\u00eb cilin ndoshta tashm\u00eb \u00ebsht\u00eb i integruar n\u00eb grupe, p\u00ebrgjigjet p\u00ebr k\u00ebt\u00eb n\u00eb rastin e p\u00ebrdorimit t\u00eb Kubernetes Engine <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/logging\/\">Stackdriver Logging<\/a><\/noindex>. <i>(<b>Sh\u00ebn. p\u00ebrkth.<\/b>: Nd\u00ebrsa p\u00ebr nj\u00eb instalim t\u00eb vet\u00eb-kontrolluar Kubernetes, rekomandojm\u00eb t\u00eb shikoni zgjidhjen ton\u00eb me burim t\u00eb hapur \u2014 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/flant\/loghouse\">loghouse<\/a><\/noindex>.)<\/i> Mos e kompliko jet\u00ebn dhe p\u00ebrdor mekanizmat natyror\u00eb t\u00eb regjistrimit t\u00eb kontejner\u00ebve. Shkruani regjistrat n\u00eb stdout dhe stderr \u2014 ato do t\u00eb merren automatikisht, ruhen, dhe indeksohen.<\/p>\n<p>N\u00ebse d\u00ebshironi, mund t\u00eb shkruani gjithashtu regjistrat n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/logging\/docs\/structured-logging\">formatin JSON<\/a><\/noindex>. Ky qasje do t\u00eb lejoj\u00eb q\u00eb t\u00eb shtoni leht\u00ebsisht metadatat. Dhe s\u00eb bashku me to, n\u00eb Stackdriver Logging do t\u00eb ket\u00eb mund\u00ebsi k\u00ebrkimi n\u00eb regjistrat duke p\u00ebrdorur k\u00ebto metadata.<\/p>\n<h2>2. Sigurohuni q\u00eb kontejner\u00ebt jan\u00eb stateless dhe t\u00eb pandryshuesh\u00ebm<\/h2>\n<p>\nP\u00ebr funksionimin e sakt\u00eb t\u00eb konteiner\u00ebve n\u00eb klasterin Kubernetes, ato duhet t\u00eb jen\u00eb stateless dhe immutable. Kur k\u00ebto kushte plot\u00ebsohen, Kubernetes do t\u00eb jet\u00eb n\u00eb gjendje t\u00eb kryej\u00eb pun\u00ebn e tij, duke krijuar dhe shkat\u00ebrruar entitete t\u00eb aplikacionit kur dhe ku nevojitet.<\/p>\n<p><i>Stateless<\/i> do t\u00eb thot\u00eb se \u00e7do gjendje (t\u00eb dh\u00ebna t\u00eb q\u00ebndrueshme t\u00eb \u00e7do lloji) ruhen jasht\u00eb konteinerit. P\u00ebr k\u00ebt\u00eb, n\u00eb var\u00ebsi t\u00eb nevojave, mund t\u00eb angazhohen lloje t\u00eb ndryshme t\u00eb ruajtjeve t\u00eb jashtme: <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/storage\/docs\">Ruajtja n\u00eb Re<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/kubernetes-engine\/docs\/how-to\/stateful-apps\">Disku i Q\u00ebndruesh\u00ebm<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/memorystore\/docs\/redis\/\">Redis<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/sql\/docs\/\">Cloud SQL<\/a><\/noindex> apo baza t\u00eb tjera t\u00eb dh\u00ebnash t\u00eb menaxhuara. <i>(<b>Sh\u00ebn. p\u00ebrkth.<\/b>: M\u00eb shum\u00eb rreth k\u00ebsaj mund t\u00eb lexoni gjithashtu n\u00eb artikullin ton\u00eb \"<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/326414\/\">Operator\u00ebt p\u00ebr Kubernetes: si t\u00eb ekzekutoni aplikacione stateful<\/a><\/noindex>\u00bb.)<\/i><\/p>\n<p><i>Immutable<\/i> do t\u00eb thot\u00eb se konteineri nuk do t\u00eb modifikohet gjat\u00eb jet\u00ebs s\u00eb tij: nuk ka p\u00ebrdit\u00ebsime, patches, ndryshime n\u00eb konfiguracion. N\u00ebse ju nevojitet t\u00eb p\u00ebrdit\u00ebsoni kodin e aplikacionit ose t\u00eb aplikoni nj\u00eb patch, krijoni nj\u00eb imazh t\u00eb ri dhe depozitoni at\u00eb. Rekomandohet t\u00eb nxirreni konfiguracionin e konteinerit (porta p\u00ebr d\u00ebgjim, opsionet e mjedisit ekzekutiv etj.) jasht\u00eb \u2014 n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/configuration\/secret\/\">Sekretet<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/tasks\/configure-pod-container\/configure-pod-configmap\/\">ConfigMaps<\/a><\/noindex>. Ato mund t\u00eb p\u00ebrdit\u00ebsohen pa pasur nevoj\u00eb t\u00eb krijoni nj\u00eb imazh t\u00eb ri t\u00eb konteinerit. P\u00ebr krijimin e thjesht\u00eb t\u00eb pipeline-ve p\u00ebr nd\u00ebrtimin e imazheve mund t\u00eb p\u00ebrdorni <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/cloud-build\/\">Cloud Build<\/a><\/noindex>. <i>(<b>Sh\u00ebn. p\u00ebrkth.<\/b>: Ne p\u00ebr k\u00ebto q\u00ebllime p\u00ebrdorim mjetin Open Source <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/flant\/dapp\">dapp<\/a><\/noindex>.)<\/i><\/p>\n<p><img decoding=\"async\" alt=\"7 best practices for container operations according to Google\" src=\"\/wp-content\/uploads\/2019\/10\/f13a83d22e7b8d7c1e8ac6a63c35646c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Shembulli i p\u00ebrdit\u00ebsimit t\u00eb konfiguracionit t\u00eb Deployment n\u00eb Kubernetes duke p\u00ebrdorur ConfigMap, t\u00eb montuar n\u00eb pod p\u00ebr si nj\u00eb konfigurim<\/i><\/p>\n<h2>3. Shmangni konteiner\u00ebt me privilegje<\/h2>\n<p>\nNuk e \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u045a\u0438 aplikacione n\u00ebn root n\u00eb server\u00ebt tuaj, apo jo? N\u00ebse nj\u00eb k\u00ebrc\u00ebnues arrin t\u00eb dep\u00ebrtoj\u00eb n\u00eb aplikacion, ai do t\u00eb ket\u00eb akses me t\u00eb drejtat root. T\u00eb nj\u00ebjtat argumente jan\u00eb t\u00eb vlefshme edhe p\u00ebr t\u00eb mos drejtuar kontejner\u00eb me privilegje. N\u00ebse \u00ebsht\u00eb e nevojshme t\u00eb ndryshoni konfigurimet n\u00eb host, mund t'i jepni kontejnerit specifike. <i>capabilities<\/i> p\u00ebrmes opsionit <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/tasks\/configure-pod-container\/security-context\/#set-capabilities-for-a-container\"><code>securityContext<\/code><\/a><\/noindex> n\u00eb Kubernetes. N\u00ebse nevojitet t\u00eb ndryshoni <i>sysctls<\/i>, Kubernetes ka <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/tasks\/administer-cluster\/sysctl-cluster\/\">nj\u00eb annotim t\u00eb ve\u00e7ant\u00eb<\/a><\/noindex> p\u00ebr k\u00ebt\u00eb. N\u00eb p\u00ebrgjith\u00ebsi, p\u00ebrpiquni t\u00eb p\u00ebrdorni sa m\u00eb shum\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/workloads\/pods\/init-containers\/\">init-<\/a><\/noindex> dhe konteiner\u00eb sidecar p\u00ebr kryerjen e operacioneve t\u00eb tilla me privilegje. Ata nuk kan\u00eb nevoj\u00eb p\u00ebr aksesim p\u00ebr asnj\u00eb trafik t\u00eb brendsh\u00ebm apo t\u00eb jasht\u00ebm.<\/p>\n<p>N\u00ebse ju menaxhoni klasterin, mund t\u00eb p\u00ebrdorni <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/policy\/pod-security-policy\/#privileged\">Pod Security Policy<\/a><\/noindex> p\u00ebr kufizimet n\u00eb p\u00ebrdorimin e konteiner\u00ebve me privilegje.<\/p>\n<h2>4. Shmangni ekzekutimin n\u00ebn root<\/h2>\n<p>\nU p\u00ebrmend\u00ebn tashm\u00eb kontejner\u00ebt me privilegje, por do t\u00eb ishte edhe m\u00eb mir\u00eb, n\u00ebse p\u00ebrve\u00e7 k\u00ebsaj, nuk do t\u00eb drejtoni aplikacione n\u00ebn root brenda kontejnerit. N\u00ebse nj\u00eb k\u00ebrc\u00ebnues gjen nj\u00eb vulnerabilitet t\u00eb larg\u00ebt n\u00eb aplikacionin me t\u00eb drejta root q\u00eb mund\u00ebson ekzekutimin e kodit, ai mund t\u00eb dal\u00eb nga kufijt\u00eb e kontejnerit p\u00ebrmes nj\u00eb vulnerabiliteti ende t\u00eb panjohur dhe t\u00eb fitoj\u00eb root-in n\u00eb host.<\/p>\n<p>M\u00ebnyra m\u00eb e mir\u00eb p\u00ebr t\u00eb shmangur k\u00ebt\u00eb \u00ebsht\u00eb, mbi t\u00eb gjitha, t\u00eb mos drejtoni asgj\u00eb n\u00ebn root. P\u00ebr k\u00ebt\u00eb, mund t\u00eb p\u00ebrdorni direktiv\u00ebn <code>USER<\/code> n\u00eb <code>Dockerfile<\/code> ose <code>runAsUser<\/code> n\u00eb Kubernetes. Administratori i klasterit gjithashtu mund ta konfiguroj\u00eb nj\u00eb sjellje t\u00eb detyrueshme duke p\u00ebrdorur <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/kubernetes-engine\/docs\/how-to\/pod-security-policies\">Pod Security Policy<\/a><\/noindex>.<\/p>\n<h2>5. B\u00ebni aplikacionin t\u00eb leht\u00eb p\u00ebr monitorim<\/h2>\n<p>\nSi\u00e7 \u00ebsht\u00eb regjistrimi, monitorimi \u00ebsht\u00eb nj\u00eb pjes\u00eb e pandashme e menaxhimit t\u00eb aplikacionit. Nj\u00eb zgjidhje e njohur p\u00ebr monitorimin n\u00eb komunitetin Kubernetes \u00ebsht\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/prometheus.io\/\">Prometheus<\/a><\/noindex> \u2014 nj\u00eb sistem q\u00eb zbulon automatikisht pod-\u00ebt dhe sh\u00ebrbimet q\u00eb k\u00ebrkojn\u00eb monitorim. <i>(<b>Sh\u00ebn. p\u00ebrkth.<\/b>: Shih gjithashtu raportin ton\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/412901\/\">t\u00eb detajuar<\/a><\/noindex> n\u00eb lidhje me monitorimin p\u00ebrmes Prometheus dhe Kubernetes.)<\/i> <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/monitoring\/kubernetes-engine\/\">Stackdriver<\/a><\/noindex> \u00ebsht\u00eb n\u00eb gjendje t\u00eb monitoroj\u00eb klasteret Kubernetes dhe p\u00ebrfshin versionin e tij t\u00eb Prometheus p\u00ebr monitorimin e aplikacioneve.<\/p>\n<p><img decoding=\"async\" alt=\"7 best practices for container operations according to Google\" src=\"\/wp-content\/uploads\/2019\/10\/642b9ccc4b7a789018a4aeeb62e7cae7.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Paneli i monitorimit Kubernetes n\u00eb Stackdriver<\/i><\/p>\n<p>Prometheus pret q\u00eb aplikacioni t\u00eb jap\u00eb metrikat n\u00eb nj\u00eb HTTP endpoint. P\u00ebr k\u00ebt\u00eb, jan\u00eb t\u00eb disponueshme <noindex><a rel=\"nofollow\" href=\"https:\/\/prometheus.io\/docs\/instrumenting\/clientlibs\/\">bibliotekat klient t\u00eb Prometheus<\/a><\/noindex>. I nj\u00ebjti format po ashtu p\u00ebrdoret nga mjete t\u00eb tjera si <noindex><a rel=\"nofollow\" href=\"http:\/\/opencensus.io\/\">OpenCensus<\/a><\/noindex> dhe <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/\">Istio<\/a><\/noindex>.<\/p>\n<h2>6. B\u00ebni t\u00eb disponuesh\u00ebm gjendjen sh\u00ebndet\u00ebsore t\u00eb aplikacionit<\/h2>\n<p>\nMenaxhimi i aplikacionit n\u00eb prodhim ndihmohet nga aft\u00ebsia e tij p\u00ebr t\u00eb raportuar gjendjen e tij t\u00ebr\u00eb sistemit. A \u00ebsht\u00eb aplikacioni i nisur? A \u00ebsht\u00eb ai n\u00eb rregull? A \u00ebsht\u00eb i gatsh\u00ebm p\u00ebr t\u00eb pranuar trafik? Si po sillet? M\u00ebnyra m\u00eb e zakonshme p\u00ebr t\u00eb zgjidhur k\u00ebt\u00eb problem \u00ebsht\u00eb t\u00eb implementoni kontrollet e sh\u00ebndetit <i>(health checks)<\/i>. Kubernetes ka dy lloje t\u00eb tyre: <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/tasks\/configure-pod-container\/configure-liveness-readiness-probes\/\">liveness dhe readiness probes<\/a><\/noindex>.<\/p>\n<p>P\u00ebr liveness probe <i>(kontrolli i jetes\u00ebs)<\/i> aplikacioni duhet t\u00eb ket\u00eb nj\u00eb HTTP endpoint q\u00eb kthen nj\u00eb p\u00ebrgjigje \"200 OK\" n\u00ebse ai funksionon dhe var\u00ebsit\u00eb e tij kryesore jan\u00eb t\u00eb k\u00ebnaqura. P\u00ebr readiness probe <i>(kontrolli i gatishm\u00ebris\u00eb p\u00ebr sh\u00ebrbim)<\/i> aplikacioni duhet t\u00eb ket\u00eb nj\u00eb endpoint tjet\u00ebr HTTP q\u00eb kthen p\u00ebrgjigjen \"200 OK\", n\u00ebse aplikacioni \u00ebsht\u00eb n\u00eb nj\u00eb gjendje t\u00eb sh\u00ebndetshme, hapat e inicializimit jan\u00eb kryer dhe \u00e7do k\u00ebrkes\u00eb korrekte nuk shkakton nj\u00eb gabim. Kubernetes do t\u00eb drejtoj\u00eb trafikun n\u00eb kontejner vet\u00ebm kur aplikacioni \u00ebsht\u00eb i gatsh\u00ebm sipas k\u00ebtyre kontrollimeve. Dy endpoint mund t\u00eb bashkohen, n\u00ebse nuk ka ndryshim midis gjendjeve t\u00eb jetueshm\u00ebris\u00eb (liveness) dhe gatishm\u00ebris\u00eb (readiness).<\/p>\n<p>M\u00eb shum\u00eb rreth k\u00ebsaj mund t\u00eb lexoni n\u00eb artikullin p\u00ebrkat\u00ebs nga Sandeep Dinesh, Avokat i Zhvillimit n\u00eb Google: \"<noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/blog\/products\/gcp\/kubernetes-best-practices-setting-up-health-checks-with-readiness-and-liveness-probes\">Praktikat m\u00eb t\u00eb mira t\u00eb Kubernetes: Cil\u00ebsimi i kontrolleve t\u00eb sh\u00ebndetit me kontrollet e gatishm\u00ebris\u00eb dhe jet\u00ebsis\u00eb<\/a><\/noindex>\u00bb.<\/p>\n<h2>7. Zgjidhni kujdes me versionin e imazhit<\/h2>\n<p>\nShumica e imazheve publike dhe private p\u00ebrdorin nj\u00eb sistem etiketimi, t\u00eb ngjash\u00ebm me at\u00eb t\u00eb p\u00ebrshkruar n\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/solutions\/best-practices-for-building-containers#properly_tag_your_images\">Praktikat m\u00eb t\u00eb Mira p\u00ebr Nd\u00ebrtime t\u00eb Kontejner\u00ebve<\/a><\/noindex>. N\u00ebse imazhi aplikon nj\u00eb sistem q\u00eb \u00ebsht\u00eb i af\u00ebrt me <noindex><a rel=\"nofollow\" href=\"https:\/\/semver.org\/lang\/ru\/\">versionimin semantik<\/a><\/noindex>, \u00ebsht\u00eb e nevojshme t\u00eb merret parasysh specifikimi i etiketimit. P\u00ebr shembull, etiketa <code>latest<\/code> mund t\u00eb l\u00ebviz\u00eb shpesh nga nj\u00eb imazh n\u00eb nj\u00eb tjet\u00ebr \u2014 nuk mund t\u00eb mb\u00ebshteteni n\u00eb t\u00eb, n\u00ebse ju nevojiten nd\u00ebrtime dhe instalime t\u00eb parashikueshme dhe t\u00eb riprodhueshme.<\/p>\n<p>Mund t\u00eb p\u00ebrdorni etiket\u00ebn <code>X.Y.Z<\/code> ((ato pothuajse gjithmon\u00eb mbeten t\u00eb pandryshuara), megjithat\u00eb n\u00eb k\u00ebt\u00eb rast mbani n\u00ebn kontroll t\u00eb gjitha patch-\u00ebt dhe p\u00ebrdit\u00ebsimet p\u00ebr imazhin. N\u00ebse imazhi q\u00eb po p\u00ebrdorni ka etiket\u00ebn <code>X.Y<\/code>, kjo \u00ebsht\u00eb nj\u00eb mund\u00ebsi e mir\u00eb e nj\u00eb mesatare t\u00eb arsyeshme. Duke e zgjedhur at\u00eb, automatikisht merrni patch-et dhe, nj\u00ebkoh\u00ebsisht, mb\u00ebshteteni n\u00eb nj\u00eb version stabil t\u00eb aplikacionit.<\/p>\n<h2>P.S. nga p\u00ebrkthyesi<\/h2>\n<p>\nLexoni gjithashtu n\u00eb blogun ton\u00eb:<\/p>\n<ul>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/422949\/\">Statistikat e reja t\u00eb CNCF p\u00ebr kontejner\u00ebt, cloud native dhe Kubernetes<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/353272\/\">7 principles of application design based on containers<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/417905\/\">11 m\u00ebnyra p\u00ebr t\u00eb (nuk) r\u00ebn\u00eb pre e hakerimit n\u00eb Kubernetes<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/331188\/\">P\u00ebrvoja jon\u00eb me Kubernetes n\u00eb projekte t\u00eb vogla<\/a><\/noindex>\u00bb <i>(p\u00ebrmbledhje dhe video e prezantimit)<\/i>;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/412901\/\">Monitorimi dhe Kubernetes<\/a><\/noindex>\u00bb <i>(p\u00ebrmbledhje dhe video e prezantimit)<\/i>;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/324274\/\">Krijojm\u00eb imazhe Docker p\u00ebr CI\/CD shpejt dhe leht\u00eb me dapp<\/a><\/noindex>\u00bb <i>(p\u00ebrmbledhje dhe video e prezantimit)<\/i>;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/322686\/\">Praktikat e ShDeliveries me Docker<\/a><\/noindex>\u00bb <i>(p\u00ebrmbledhje dhe video e prezantimit)<\/i>;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/company\/flant\/blog\/347518\/\">Vdekja e \u00e7menduris\u00eb s\u00eb mikrosh\u00ebrbimeve n\u00eb vitin 2018<\/a><\/noindex>\u00bb.<\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/425085\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0410\u0432\u0442\u043e\u0440 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Th\u00e9o Chamley, \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u043e\u0440 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0440\u0435\u0448\u0435\u043d\u0438\u0439 Google. \u0412 \u044d\u0442\u043e\u0439 \u043f\u0443\u0431\u043b\u0438\u043a\u0430\u0446\u0438\u0438 \u0434\u043b\u044f \u0431\u043b\u043e\u0433\u0430 Google Cloud \u043e\u043d \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u0438\u043b \u043a\u0440\u0430\u0442\u043a\u0443\u044e \u0432\u044b\u0436\u0438\u043c\u043a\u0443 \u0438\u0437 \u0431\u043e\u043b\u0435\u0435 \u0434\u0435\u0442\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0440\u0443\u043a\u043e\u0432\u043e\u0434\u0441\u0442\u0432\u0430 \u0435\u0433\u043e \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438, \u043d\u0430\u0437\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u00abBest Practices for Operating Containers\u00bb. \u0412 \u043d\u0451\u043c \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u0438\u0441\u0442\u044b Google \u0441\u043e\u0431\u0440\u0430\u043b\u0438 \u043b\u0443\u0447\u0448\u0438\u0435 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0438 \u043f\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 \u0432 \u043a\u043e\u043d\u0442\u0435\u043a\u0441\u0442\u0435 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f Google Kubernetes Engine \u0438 \u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e, \u0437\u0430\u0442\u0440\u043e\u043d\u0443\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":29273,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-39016","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0410\u0432\u0442\u043e\u0440 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Th\u00e9o Chamley, \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u043e\u0440 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0440\u0435\u0448\u0435\u043d\u0438\u0439 Google.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd477 \u043b\u0443\u0447\u0448\u0438\u0445 \u043f\u0440\u0430\u043a\u0442\u0438\u043a \u043f\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 \u043f\u043e \u0432\u0435\u0440\u0441\u0438\u0438 Google | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0410\u0432\u0442\u043e\u0440 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Th\u00e9o Chamley, \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u043e\u0440 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0440\u0435\u0448\u0435\u043d\u0438\u0439 Google.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:27:21+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:27:21+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd477 praktikat m\u00eb t\u00eb mira p\u00ebr operimin e kontejner\u00ebve sipas Google | ProHoster","description":"Sh\u00ebn. p\u00ebrkth: Autori i artikelit origjinal \u00ebsht\u00eb Th\u00e9o Chamley, arkitekt i zgjidhjeve n\u00eb re n\u00eb Google.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd477 \u043b\u0443\u0447\u0448\u0438\u0445 \u043f\u0440\u0430\u043a\u0442\u0438\u043a \u043f\u043e \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043e\u0432 \u043f\u043e \u0432\u0435\u0440\u0441\u0438\u0438 Google | ProHoster","og:description":"\u041f\u0440\u0438\u043c. \u043f\u0435\u0440\u0435\u0432.: \u0410\u0432\u0442\u043e\u0440 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0438 \u2014 Th\u00e9o Chamley, \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u043e\u0440 \u043e\u0431\u043b\u0430\u0447\u043d\u044b\u0445 \u0440\u0435\u0448\u0435\u043d\u0438\u0439 Google.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/7-luchshih-praktik-po-ekspluatatsii-kontejnerov-po-versii-google","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:27:21+00:00","article:modified_time":"2019-10-31T19:27:21+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39016","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 00:24:24","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:58:39","updated":"2026-01-24 00:24:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/39016","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=39016"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/39016\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/29273"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=39016"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=39016"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=39016"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}