Sign inSign up

zemanel/hello-world

By zemanel

•Updated over 6 years ago

Image
0

151

zemanel/hello-world repository overview

⁠About

⁠Kubernetes application

kubernetes/kustomize/helloworld contains Kustomize based Kubernetes manifests to deploy the sample Java application⁠ to K8s.

⁠Local deployment
⁠Requirements
⁠Architecture considerations
  • the sample app Docker image is based on community Tomcat 8 image
  • The docker image is built and hosted on a public Docker Hub Registry for simplicity⁠.
  • Private registry support can be added and authentication to it configured locally with $ minikube addons configure registry-creds
  • the Kubernetes manifests deploy 3 replicas of the application for resilience, with health checks
  • the ingress service⁠ runs on port 8080 in the minikube VM but in a cloud deployment with Loadbalancer support, the app is available on port 8080
⁠Local deployment on Minikube (with Virtualbox backend)

ingress-nginx⁠ is utilized to ingress traffic into K8 applications from outside the cluster.

To deploy the application on a local Minikube cluster, using Make:

# Start the minikube cluster
$ make start-cluster

# Deploy ingress-nginx
$ make deploy-ingress

for opening the running application in the browser, run:

$ minikube service ingress-nginx -n ingress-nginx

⁠Terraform project

The Terraform project on terraform/ deploys a bastion instance and an appserver, from which its possible to $curl http://google.com. The following resources are created:

  • An AWS vpc with Internet Gateway
  • Private subnet with nat gateway for bastion instance
  • Public subnet subnet with nat gateway fo app server
  • Security group for bastion instances that allows ssh ingress from Internet (network whitelist is possible)
  • Security groups for bastion instances, that only allow ssh traffic from bastion hosts through security group (network acl is not implemented)

⁠Requirements

  • Terraform v0.12

⁠Deploy

  • Create local SSH key for access to instances and add to keyring :

      #
      $ ssh-keygen -b 2048 -t rsa -C "bastion" -f ~/.ssh/bastion_rsa
      $ chmod 600 ~/.ssh/bastion_rsa*
      $ ssh-add ~/.ssh/bastion_rsa
    
  • Export AWS credentials for an IAM user with deployment privileges:

    $ export AWS_ACCESS_KEY_ID="< value here>"
    $ export AWS_SECRET_ACCESS_KEY="< value here>"
    
  • In order to use Centos AWS Marketplace product you need to accept terms and subscribe. To do so please visit https://aws.amazon.com/marketplace/pp?sku=67xglex2rdpaymxh17620nfoy⁠

  • Execute Terraform code:

    $ cd terraform/main
    $ terraform init
    $ terraform apply
    

    The bastion and app server dns hostnames will be displayed on output, ex:

    <...>
    Apply complete! Resources: 0 added, 0 changed, 0 destroyed.
    
    Outputs:
    
    appserver_private_ip = ip-10-0-1-118.eu-west-1.compute.internal
    bastion_public_ip = ec2-34-243-99-66.eu-west-1.compute.amazonaws.com
    
  • To SSH to app server instance, in one command:

    $ ssh centos@$(terraform output appserver_private_ip) -o "proxycommand ssh -A -oForwardAgent=yes -W %h:%p centos@$(terraform output bastion_public_ip)" "curl http://www.google.com"
    

Tag summary

Content type

Image

Digest

Size

359.9 MB

Last updated

over 6 years ago

docker pull zemanel/hello-world:master