安装参考
CLI 命令行安装
| |
Helm 安装 Cilium
安装 Helm:
| |
添加 Helm 仓库:
| |
安装 Cilium: 参数配置及格式同 CLI 模式。
| |
内网离线安装镜像处理
目前cilium的CLI工具没有提供统一的离线安装参数,但是可以在安装时指定组件镜像 默认镜像源:quay.io,目前在国内可以正常下载,无需梯子
CRI 镜像仓库代理
在CRI(containerd/docker)替换镜像仓库代理:quay.io/cilium ==》 harbor.my.cn/devops(替换为自己的内网镜像仓库地址)
containerd,参考文档:https://github.com/containerd/containerd/blob/main/docs/hosts.md#cri
查看版本:ctr -v
- 如果是1.x版本可以使用方式一配置较简单,但是会有waring报警
- 方式二是官方建议配置方式,稍微麻烦一点
方式一,适用1.x版本:
配置文件 /etc/containerd/config.toml 添加,
1 2 3 4 5 6[plugins."io.containerd.grpc.v1.cri".registry.mirrors] [plugins."io.containerd.grpc.v1.cri".registry.mirrors."'quay.io/cilium'"] # 代理仓库配置 endpoint = ["'https://harbor.my.cn/devops'"] [plugins."io.containerd.grpc.v1.cri".registry.configs] # 可选:关闭tls校验,可以使用http,便于本地测试 [plugins."io.containerd.grpc.v1.cri".registry.configs."'harbor.my.cn/devops'".tls] insecure_skip_verify = true方式二,适用2.x版本:
/etc/containerd/config.toml 添加
1 2[plugins."io.containerd.cri.v1.images".registry] config_path = "/etc/containerd/certs.d"config_path内具体路径,registry_host_name为代理的repo地址:域名或端口号,hosts为具体配置内容
/etc/containerd/certs.d/[registry_host_name|IP address][:port]/hosts.tomlhosts.toml配置
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19# server指定此 Registry Host 命名空间的默认服务器。 #指定 (s) 后,将按列出的顺序首先尝试主机。 如果 (s) 都已尝试,则 将用作回退。hosthostserver #如果未指定,则将自动使用映像的注册表主机命名空间。server server = "https://registry-1.docker.io" [host."https://mirror.registry"] # 是用于指定主机操作的可选设置 能够执行。仅包含适用的值。 capabilities = ["pull", "resolve", "push"] # ca(证书颁发机构认证)可以设置为路径或 paths 每个路径都指向一个 CA 文件,用于对 Registry 进行身份验证 Namespace。 ca = "/etc/certs/mirror.pem" # skip_verify跳过对注册表证书链的验证,并且 host name (设置为 .这应该仅用于测试或 与其他验证连接的方法结合使用。(默认为true) skip_verify = false [host."https://mirror.registry".header] x-custom-2 = ["value1", "value2"] [host."https://non-compliant-mirror.registry/v2/upstream"] capabilities = ["pull"] # override_path用于指示已定义主机的 API 根端点 在 URL 路径中,而不是按 API 规范。这可以与 缺少前缀的不合规 OCI 注册表。 (默认为/false) override_path = true
通过 Helm 指定组件镜像
helm/cilium 创建时通过参数指定组件的镜像,参考文档
基本使用镜像 注意修改镜像版本信息,可以直接helm拉chart下来,然后自己看value.yaml
operator.image: quay.io/cilium/operator-generic:v1.16.4@sha256:c55a7cbe19fe0b6b28903a085334edb586a3201add9db56d2122c8485f7a51c5
hubble.relay.image: quay.io/cilium/hubble-relay:v1.16.4@sha256:fb2c7d127a1c809f6ba23c05973f3dd00f6b6a48e4aee2da95db925a4f0351d2
hubble.ui.frontend.image: quay.io/cilium/hubble-ui-backend:v0.13.1@sha256:0e0eed917653441fded4e7cdb096b7be6a3bddded5a2dd10812a27b1fc6ed95b
镜像参数参考列表
helm/cilium 安装设计镜像参数参考列表:
image | Agent container image. | object |
|
imagePullSecrets | Configure image pull secrets for pulling container images | list |
|
preflight.image | Cilium pre-flight image. | object |
|
certgen | Configure certificate generation for Hubble integration. If hubble.tls.auto.method=cronJob, these values are used for the Kubernetes CronJob which will be scheduled regularly to (re)generate any certificates not provided manually. | object |
|
clustermesh.apiserver.image | Clustermesh API server image. | object |
|
envoy.image | Envoy container image. | object |
|
hubble.relay.image | Hubble-relay container image. | object |
|
hubble.ui.backend.image | Hubble-ui backend image. | object |
|
hubble.ui.frontend.image | Hubble-ui frontend image. | object |
|
nodeinit.image | node-init image. | object |
|
operator.image | cilium-operator image. | object |
|
preflight.image | Cilium pre-flight image. | object |
|
Cilium 与 Kata 配合使用
暂未详细调研。
参考文档:https://docs.cilium.io/en/stable/network/kubernetes/kata/#kata-containers-with-cilium
使用外部 etcd 存储 Cilium 元数据
指定外部 etcd 端点
helm install cilium cilium/cilium --version 1.14.4 --namespace kube-system --set etcd.enabled=true --set “etcd.endpoints[0]=http://etcd-endpoint1:2379” --set “etcd.endpoints[1]=http://etcd-endpoint2:2379” --set “etcd.endpoints[2]=http://etcd-endpoint3:2379” --set identityAllocationMode=kvstore
创建 TLS 证书 Secret
使用根证书权限、客户端密钥和 etcd 证书创建一个secret
kubectl create secret generic -n kube-system cilium-etcd-secrets --from-file=etcd-client-ca.crt=ca.crt --from-file=etcd-client.key=client.key --from-file=etcd-client.crt=client.crt
启用 SSL
为 etcd 启用 SSL, etcd 端点 URL 修改为 https
helm install cilium cilium/cilium --version 1.14.4 --namespace kube-system --set etcd.enabled=true --set etcd.ssl=true --set “etcd.endpoints[0]=https://etcd-endpoint1:2379” --set “etcd.endpoints[1]=https://etcd-endpoint2:2379” --set “etcd.endpoints[2]=https://etcd-endpoint3:2379”
与 Istio 共同使用
Cilium 适配配置
istio会将POD的流量通过iptable代理到边车容器或者节点代理cilium在开启kubeProxyReplacement时,可能会中断相关代理流量
| |
Istio 相关配置
- Sidecar: 通过在 Istio 的 PeerAuthentication 下配置 mTLS.mode = DISABLE,为希望用 Cilium L7 策略管理的工作负载禁用 Istio mTLS,Istio PeerAuthentication.
- Ambient: 通过从名称空间中移除 Istio.io/dataplane-mode 标签,或者在你希望用 Cilium l7 管理的 pods 上标注 “禁用”,从而从 Istio 环境中移除你希望用 Cilium l7 管理的工作负载 ambient.Istio.io/redirection
替换 kube-proxy
安装与状态检查
安装cilium 开启替换kube-proxy特性:
| |
查看cilium状态 KubeProxyReplacement: Strict:
| |
状态详情:
| |
查看转发规则
idtable查看是否有kube-proxy转发的service:
| |
bpf转发的service 列表:
| |
Cilium Ingress
前置条件:需开启kube-proxy替换
Helm 安装参数
| |
升级与配置
cilium upgrade 会覆盖之前的参数 注意保存之前的安装命令
cilium upgrade --version 1.14.17 \ --set kubeProxyReplacement=true \ --set ingressController.enabled=true \ --set ingressController.loadbalancerMode=dedicated
通过 kube-system / cilium-config(configmap),配置ingressclass的Name,tls开启等
故障排查
注意看agent启动日志,可以看到agent的所有参数
无法识别路由设备
| |
在 kube-system / cilium-config (configmap)指定主网卡
| |
其他参考文档
内核情况整理
CentOS 内核升级
主要考虑centos内核升级
kernel-ml 中的ml是英文【 mainline stable 】的缩写,是最新的稳定主线版本。
- 目前较新的版本:5.4.278
kernel-lt 中的lt是英文【 long term support 】的缩写,是长期支持版本。
- 6.1.12
- 6.6.9
Cilium 功能对应内核版本
| 功能 | 说明 | 建议内核版本 | |
| cilium | 基础ebpf功能 | 4.15 | |
| replace kube-proxy | 替换kube-proxy | v4.19.57 v5.1.16 v5.2.0 以上版本 --- v5.3 v5.8 以上性能更好 | Kubernetes Without kube-proxy |
| ingress | 需开启kube-proxy替换 | - | Kubernetes Ingress Support |
| Gateway API | 需开启kube-proxy替换 | - | Gateway API Support |
| 7层流量处理 | 需开启kube-proxy替换 | - | 熔断 |
| IP透传 | - | ||
| node-ipam | - | ||
| 整合istio | - | Integration with Istio |
讨论