← Back to list

ใช้ Istio จัดการ K8s apps โดยไม่ต้องแตะ Code (ตอนที่ 2 เจ็บปวดกับการติดตั้ง)

หลังจากที่เราทำความเข้าใจคร่าวๆ เกี่ยวกับ Scenarios ทั้ง Single Cloud และ Multicloud ไปแล้ว จากตอนที่แล้ว

Nutta · 2019-09-24 08:23 · 5 claps · 5.1 min read
#ibm-cloud-thailand #ibm-cloud-istio #การใช้-istio #สอน-istio #ตัวอย่าง-istio
Open on Medium ↗
Wiki topics: ☁️ · DevOps & Cloud

ใช้ Istio จัดการ K8s apps โดยไม่ต้องแตะ Code (ตอนที่ 2 เจ็บปวดกับการติดตั้ง)

หลังจากที่เราทำความเข้าใจคร่าวๆ เกี่ยวกับ Scenarios ทั้ง Single Cloud และ Multicloud ไปแล้ว จากตอนที่แล้ว

[embed]ใช้ Istio จัดการ K8s apps โดยไม่ต้องแตะ Code ต่อจากบทความที่แล้วเกี่ยวกับ Istio นะครับ (ถ้าใครยังไม่ทราบว่า Istio คืออะไร…medium.com

พร้อมทั้งการติดตั้ง เตรียมพร้อม ก่อนที่จะเริ่มลงมือทำ ดังนั้น Click ที่บทความด้านบนได้นะครับ ถ้าใครยังไม่ได้อ่านตอนแรก

ใส่ความปลอดภัยให้ Frontend

จาก App ตัวอย่างที่เกริ่นไว้ก่อนหน้านี้ซึ่งสามารถ Clone ได้จาก Github ตาม Command ด้านล่างนี้ ซึ่ง /isitio-sample-app/ คือ App ตัวอย่างที่เราจะใช้สำหรับ Frontend

git clone https://github.com/ibm-cloud-security/appid-sample-code-snippets
cd appid-sample-code-snippets
cd isitio-sample-app
npm install
node app.js

เมื่อเราทำตาม Steps ด้านบนแล้ว Console ก็จะแสดงว่าเราทำการรัน Node.Js App ได้แล้วที่ port number 8000 ซึ่ง http://localhost:8000/web/home/ คือ URL สำหรับ App ตัวอย่าง Frontend นั่นเอง

เมื่อเราทำตาม Steps ด้านบนแล้ว Console ก็จะแสดงว่าเราทำการรัน Node.Js App ได้แล้วที่ port number 8000 ซึ่ง http://localhost:8000/web/home/ คือ URL สำหรับ App ตัวอย่าง Frontend นั่นเอง

App ตัวอย่างเรารันได้เรียบร้อยแล้ว เราจะเห็นว่า Access Token มันว่างเปล่า ซึ่งเราจะเพิ่มความปลอดภัยเข้าไปโดยการใช้ OIDC Authorization Flow + App ID ต่อไป

App ตัวอย่างเรารันได้เรียบร้อยแล้ว เราจะเห็นว่า Access Token มันว่างเปล่า ซึ่งเราจะเพิ่มความปลอดภัยเข้าไปโดยการใช้ OIDC Authorization Flow + App ID ต่อไป

เอาละ ตอนนี้ก็พอคร่าวๆ กันได้แล้ว ว่าหน้าตาของ Frontend เป็นอย่างไร ง่ายๆ ด้วย Node.js นั่นเอง Step ต่อไป เราก็ต้อง Spin up Kubernetes Cluster แบบ Free บน IBM Cloud (เชื่อว่า ผู้อ่าน อ่านมาถึงจุดนี้แล้วก็ยังไม่ได้ Provision K8s Cluster แบบ Free บน IBM Cloud ถึงแม้ว่า เกริ่นในบทความที่แล้ว เรื่องการติดตั้ง App Identity/Access Adapter แต่ไม่เป็นไรครับ เราก็สอนให้หมด ง่ายๆ ทีละ Step ก็ทำตามกันได้เลย)

้าใครยังไม่ได้ Sign up IBM Cloud ก็ทำตาม Step ด้านล่างนี้ได้เลยครับ

[embed]Create IBM Cloud Account Step by Step and Other useful CLI tools + How to get free 1,200 USD Credits for IBM Cloud and Watson AI Services including IBM Managed Kubernetes Cluster ibm.biz

หลังจากนั้นแล้ว จะ Upgrade Account เป็น Pay-As-You-Go ก่อน เพราะว่า Istio บน IBM Cloud นั้น ต้องการ Machine Type ที่มี Spec อย่างน้อยคือ

4 CPUs 16 GB RAM

(หรือ ท่านใดสนใตทดลองใช้งาน IBM Cloud และ อยากได้ Promo Code ที่หาได้จาก บทความด้านล่างนี้ก็ได้นะครับ)

[embed]แจกฟรี 1,200 USD Credit ทดลองใช้งาน IBM Cloud สวัสดีครับ หลังจากที่ผมได้เขียน 2 Blogs เกี่ยวกับmedium.com

Provision Kubernetes Cluster (b3c.4x16–4CPUs 16 GB RAM)

สำคัญ Cluster กับ Machine Type นี้ไม่ Free นะครับ แต่สามารถใช้ 200$ Credit ที่ได้มาฟรีๆ จากการ upgrade account เป็น Pay-As-You-Go จากการใส่บัตรเครดิตนะครับ

เมื่อเรา login ผ่าน https://cloud.ibm.com แล้ว เราก็จะเห็น Kubernetes Cluster Service ที่นี่ https://cloud.ibm.com/kubernetes/catalog/cluster

เลือก Standard Cluster แล้วหลังจากนั้น เราจะไปเลือก Machine Type อีกที

เลือก Standard Cluster แล้วหลังจากนั้น เราจะไปเลือก Machine Type อีกที

Location เลือกเองใกล้ที่เราอยู่นะครับ หรือ จะใช้ Single Zone ก็ได้ะครับ

Location เลือกเองใกล้ที่เราอยู่นะครับ หรือ จะใช้ Single Zone ก็ได้ะครับ

แล้วเราก็เลือก 4 CPUs และ 16 GB RAM นะครับ คือ Requirement พื้นฐานของ Istio

แล้วเราก็เลือก 4 CPUs และ 16 GB RAM นะครับ คือ Requirement พื้นฐานของ Istio

เมื่อเราสั่ง Provision Kubernetes Cluster แบบ Free ขึ้นมาแล้ว ฝั่ง IBM Cloud ก็จะใช้เวลานิดนึง

ระหว่างรอ เราสามารถดูได้ที่ Tab Access นะครับ จะมีชุดคำสั่งว่าเราจะเชื่อมต่อจาก Computer ของเรา ไปที่ Kubernetes บน IBM Cloud อย่างไร ง่ายๆ เราก็เพียง Copy และ แปะ ใน Terminal/Command Prompt ของเราได้เลย แต่ก่อนอื่น ต้อง Login IBM Cloud เข้าไปก่อนนะครับ ผ่านทาง CLI (ถ้าใคร ยังไม่ได้ติดตั้ง IBM Cloud CLI tool ย้อนกลับไปด้านบน ที่ Guide การสร้าง IBM Cloud Account นะครับ)

เมื่อทุกอย่างพร้อม K8s Cluster ก็พร้อมแล้ว เราก็ลุยด้วยชุดคำสั่ง login ตามด้านล่าง

C:\ibmcloud loging
email >
password >

หลังจาก login ibmcloud ผ่าน CLI แล้ว เราก็จะเห็น console แสดง API endpoint, region แบบข้างบน

หลังจาก login ibmcloud ผ่าน CLI แล้ว เราก็จะเห็น console แสดง API endpoint, region แบบข้างบน

เมื่อ login ได้แล้ว หลังจากนั้น เราก็ย้อนกลับไปที่ https://cloud.ibm.com เลือก Kubernetes Cluster Service ที่ Tab — Access เราก็ใส่ ชุดคำสั่งเชื่อมต่อจาก Computer ของเราเองไปที่ Kubenetes บน IBM Cloud

ที่ Access Tab ชุดคำสั่งมาเป็นขั้นตอน นะครับ หลังจาก login แล้ว เราก็ข้ามไปที่ Step ที่ 2 ได้เลย

ส่วน Step ที่ 3 สำคัญมาก ซึ่งเปรียบได้ว่าเราต้อง set ค่า ผ่าน terminal/command prompt เหมือนกับการ set path นั่นเอง ซึ่ง จาก Step ที่ 2 CLI tool จะส่งค่ามาให้สองค่านะครับ ค่าแรกสำหรับ unix command ส่วนค่าที่สองเป็น cmd command เลือกใช้กันได้ไม่ว่าจะเป็น unix หรือ cmd บน Windows ขึ้นกับว่า Computer ของเราเป็นรุ่นไหน

ส่วน Step ที่ 4 ก็เป็นการทดสอบว่าเราเชื่อมต่อ Kubernetes cluster เรียบร้อยแล้ว

ติดตั้ง helm

สามารถ download ได้จาก

[embed]helm/helm You can't perform that action at this time. You signed in with another tab or window. You signed out in another tab or…github.com

ซึ่ง ณ วันที่เขียนบทความนี้ผมใช้ v2.14.3 นะครับ หลังจากทำการติดตั้งแล้ว เราก็ไปที่ command line กันเลย

C:\>helm init
Creating C:\Users\userA\.helm
Creating C:\Users\userA\.helm\repository
Creating C:\Users\userA\.helm\repository\cache
Creating C:\Users\userA\.helm\repository\local
Creating C:\Users\userA\.helm\plugins
Creating C:\Users\userA\.helm\starters
Creating C:\Users\userA\.helm\cache\archive
Creating C:\Users\userA\.helm\repository\repositories.yaml
Adding stable repo with URL: https://kubernetes-charts.storage.googleapis.com
Adding local repo with URL: http://127.0.0.1:8879/charts
$HELM_HOME has been configured at C:\Users\userA\.helm.
Tiller (the Helm server-side component) has been installed into your Kubernetes Cluster.
Please note: by default, Tiller is deployed with an insecure ‘allow unauthenticated users’ policy.
To prevent this, run `helm init` with the — tiller-tls-verify flag.
For more information on securing your installation see: https://docs.helm.sh/using_helm/#securing-your-helm-installation

ติดตั้ง Istio

คู่มือติดตั้ง Istio สำหรับ Mac OS/Linux สามารถดูได้จาก Official Istio ด้านล่าง

[embed]Setup สInstructions for installing the Istio control plane on Kubernetes and adding virtual machines into the mesh. Visit our…istio.io

ส่วนถ้าใครใช้ Windows และใช้ Powershell ถึงแม้จะทำตามคู่มือด้านบนแล้ว เราก็ยัง install Istio ไม่ได้อยู๋ดี ไม่ต้องห่วงครับ เราแนะได้อีกว่าติดตั้ง Istio บน Windows ยังงัย ตามนี้เลย

  1. Download file — getLatestIstio.ps1 จาก Github
  2. เปิด Powershell แล้ว execute file getLatestIstio.ps1 ที่เพิ่งโหลดมา
  3. script จะ download Istio ซึ่งมาเป็น compressed file และจะแตก files ออกมาให้ด้วย เราก็ได้จะได้ Istio ทั้ง folder เลย
  4. ย้าย Istio folder ที่เราเพิ่งได้มา ไว้ที่ต้องการ และทำการ Set ISTIO_HOME และ ใส่ %ISTIO_HOME%\bin เข้าไปที่ PATH ใน Environment settings
  5. หลังจากนั้นแล้ว เราก็จะเริ่มติดตั้ง Istio ไปยัง K8s Cluster ของเราก่อน (ณ ตอนนี้ เราใช้ Managed Kubernetes บน IBM Cloud)
# Steps ย่อย ในการติดตั้ง Istio อย่างถูกวิธิ ทำตามขั้นตอน นะครับ ณ ตอนนี้ให้เรา cd dir ไปที่ Istio home ที่เรา set เอาไว้นะครับ
1. สร้าง Service Account ด้วยคำสั่ง 
kubectl apply -f install/kubernetes/helm/helm-service-account.yaml
2. Initialize Helm บน Cluster ของเรา 
helm init --service-account tiller
3. Bootstrap Istio file CRD's ด้วย istio-init chart 
helm install install/kubernetes/helm/istio-init --name istio-init --namespace istio-system
4. ทดสอบให้แน่ใจว่า ตั้งตั้ง file ถูกต้องด้วยการ check จำนวณ CRD files 
#linux 
kubectl get crds | grep 'istio.io\|certmanager.k8s.io' | wc -l'
#CMD - Windows
kubectl get crds | findstr "istio.io" | find /c /v ""
5. ติดตั้ง Istio บน Cluster ของเรา และ Enable Policy Checks
helm install install/kubernetes/helm/istio --name istio --namespace istio-system --set global.disablePolicyChecks=false
6. ทดสอบว่า Services สร้างได้เรียบร้อยแล้วไหม 
kubectl get svc -n istio-system
7. ทดสอบว่า pods บน Cluster ของเรายังทำงานอยู่
kubectl get pods -n istio-system
8. [Optional] ตั้ง auto-injection ให้กับ namespace ด้วย 
kubectl label namespace default istio-injection=enabled
9. ทดสอบด้วยการดูค่า Istio Ingress IP address 
kubectl -n istio-system get service istio-ingressgateway -o jsonpath='{.status.loadBalancer.ingress[0].ip}'
10. ลอง get ค่า Istio Port ด้วย
kubectl -n istio-system get service istio-ingressgateway -o jsonpath='{.spec.ports[?(@.name=="http2")].port}

ติดตั้ง App Identity / Access Adapter ผ่าน Helm

ด้วย 3 Commands เท่านั้น

C:\>helm init
C:\>helm repo add appidentityandaccessadapter https://raw.githubusercontent.com/ibm-cloud-security/app-identity-and-access-adapter/master/helm/appidentityandaccessadapter
“appidentityandaccessadapter” has been added to your repositories
C:\>helm install — name appidentityandaccessadapter appidentityandaccessadapter/appidentityandaccessadapter
NAME: appidentityandaccessadapter
LAST DEPLOYED: Tue Sep 24 15:16:09 2019
NAMESPACE: default
STATUS: DEPLOYED
RESOURCES:
==> v1/ClusterRoleBinding
NAME AGE
cluster-role-binding-appidentityandaccessadapter 1s
==> v1/Pod(related)
NAME READY STATUS RESTARTS AGE
dpl-appidentityandaccessadapter-6c98bdc98c-d6mzk 0/1 ContainerCreating 0 1s
==> v1/Service
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
svc-appidentityandaccessadapter ClusterIP 172.21.78.124 <none> 47304/TCP 1s
==> v1alpha2/adapter
NAME AGE
appidentityandaccessadapter 1s
==> v1alpha2/handler
NAME AGE
handler-appidentityandaccessadapter 1s
==> v1alpha2/instance
NAME AGE
instance-appidentityandaccessadapter 1s
==> v1alpha2/rule
NAME AGE
rule-appidentityandaccessadapter 1s
==> v1alpha2/template
NAME AGE
authnz 1s
==> v1beta1/CustomResourceDefinition
NAME AGE
jwtconfigs.security.cloud.ibm.com 1s
oidcconfigs.security.cloud.ibm.com 1s
policies.security.cloud.ibm.com 1s
==> v1beta1/Deployment
NAME READY UP-TO-DATE AVAILABLE AGE
dpl-appidentityandaccessadapter 0/1 1 0 1s
NOTES:
App Identity and Access Adapter installed successfully!

ท้ายที่สุดแล้ว มาตรวจสอบกันว่า App Identity / Access Adapter ติดตั้งสมบูรณ์บน Cluster ของเรา

C:\>kubectl get pods -A

และ เราก็จะเห็น appidentity/access adapter บน istio-namespace นั่นเอง

และ เราก็จะเห็น appidentity/access adapter บน istio-namespace นั่นเอง

เป็นอย่างไรครับ ค่อนข้างวุ่นวายนิดนึง เรื่องการติดตั้ง Istio ผ่าน Helm และ ตอนต่อไป ก็จะเริ่มลงมือ Secure App กันอย่างจริงจังนะครับ ติดตามตอนต่อไปได้ที่ link ด้านล่างเลยนะครับ

[embed]ใช้ Istio จัดการ K8s apps โดยไม่ต้องแตะ Code (ตอนจบ) ความเดิมตอนที่แล้วmedium.com

ท้ายที่สุดแล้ว แนะนำกลุ่ม IBM Cloud Thailand นะครับ สามารถเข้ามาพูดคุย แลกเปลี่ยนประสบการ์ณกันได้ครับ

*ibm.biz/IBMCloudThailandFacebookGroup*


메타데이터
post_id
d6156ad982cd
slug
ใช้-istio-จัดการ-k8s-apps-โดยไม่ต้องแตะ-code-ตอนที่-2-เจ็บปวดกับการติดตั้ง-d6156ad982cd
url
https://medium.com/@nutta/%E0%B9%83%E0%B8%8A%E0%B9%89-istio-%E0%B8%88%E0%B8%B1%E0%B8%94%E0%B8%81%E0%B8%B2%E0%B8%A3-k8s-apps-%E0%B9%82%E0%B8%94%E0%B8%A2%E0%B9%84%E0%B8%A1%E0%B9%88%E0%B8%95%E0%B9%89%E0%B8%AD%E0%B8%87%E0%B9%81%E0%B8%95%E0%B8%B0-code-%E0%B8%95%E0%B8%AD%E0%B8%99%E0%B8%97%E0%B8%B5%E0%B9%88-2-%E0%B9%80%E0%B8%88%E0%B9%87%E0%B8%9A%E0%B8%9B%E0%B8%A7%E0%B8%94%E0%B8%81%E0%B8%B1%E0%B8%9A%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%95%E0%B8%B4%E0%B8%94%E0%B8%95%E0%B8%B1%E0%B9%89%E0%B8%87-d6156ad982cd
canonical_url
https://medium.com/@nutta/%E0%B9%83%E0%B8%8A%E0%B9%89-istio-%E0%B8%88%E0%B8%B1%E0%B8%94%E0%B8%81%E0%B8%B2%E0%B8%A3-k8s-apps-%E0%B9%82%E0%B8%94%E0%B8%A2%E0%B9%84%E0%B8%A1%E0%B9%88%E0%B8%95%E0%B9%89%E0%B8%AD%E0%B8%87%E0%B9%81%E0%B8%95%E0%B8%B0-code-%E0%B8%95%E0%B8%AD%E0%B8%99%E0%B8%97%E0%B8%B5%E0%B9%88-2-%E0%B9%80%E0%B8%88%E0%B9%87%E0%B8%9A%E0%B8%9B%E0%B8%A7%E0%B8%94%E0%B8%81%E0%B8%B1%E0%B8%9A%E0%B8%81%E0%B8%B2%E0%B8%A3%E0%B8%95%E0%B8%B4%E0%B8%94%E0%B8%95%E0%B8%B1%E0%B9%89%E0%B8%87-d6156ad982cd
author_url
https://medium.com/@nutta
status
ok
fetched_at
2026-08-10 08:44:23