【发布时间】:2021-12-02 05:32:21
【问题描述】:
我有一个应用程序在我的本地机器上运行,它使用 React -> gRPC-Web -> Envoy -> Go 应用程序,一切运行都没有问题。我正在尝试使用 GKE Autopilot 部署它,但我无法正确配置。我是 GCP/GKE 的新手,所以我正在寻求帮助以找出我哪里出错了。
我最初关注的是这个文档,尽管我只有一个 gRPC 服务: https://cloud.google.com/architecture/exposing-grpc-services-on-gke-using-envoy-proxy
根据我的阅读,GKE Autopilot 模式需要使用外部 HTTP(s) 负载平衡,而不是上述解决方案中描述的网络负载平衡,所以我一直在努力让它发挥作用。经过各种尝试,我目前的策略有Ingress、BackendConfig、Service和Deployment。该部署包含三个容器:我的应用程序、一个用于转换 gRPC-Web 请求和响应的 Envoy sidecar,以及一个云 SQL 代理 sidecar。我最终想使用 TLS,但现在我把它省略了,这样事情就不会更复杂了。
当我应用所有配置时,后端服务在一个区域中显示一个后端,并且运行状况检查失败。为端口 8080 和路径 /healthz 设置了运行状况检查,这是我认为我在部署配置中指定的,但我很怀疑,因为当我查看 envoy-sidecar 容器的详细信息时,它显示了就绪探测如:http-get HTTP://:0/healthz headers=x-envoy-livenessprobe:healthz。 “:0”只是表示它正在使用容器的默认地址和端口,还是表示配置问题?
我一直在阅读各种文档,但无法将它们拼凑在一起。有没有一个例子可以说明如何做到这一点?我一直在寻找,但没有找到。
我目前的配置是:
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: grammar-games-ingress
#annotations:
# If the class annotation is not specified it defaults to "gce".
# kubernetes.io/ingress.class: "gce"
# kubernetes.io/ingress.global-static-ip-name: <IP addr>
spec:
defaultBackend:
service:
name: grammar-games-core
port:
number: 80
---
apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
name: grammar-games-bec
annotations:
cloud.google.com/neg: '{"ingress": true}'
spec:
sessionAffinity:
affinityType: "CLIENT_IP"
healthCheck:
checkIntervalSec: 15
port: 8080
type: HTTP
requestPath: /healthz
timeoutSec: 60
---
apiVersion: v1
kind: Service
metadata:
name: grammar-games-core
annotations:
cloud.google.com/neg: '{"ingress": true}'
cloud.google.com/app-protocols: '{"http":"HTTP"}'
cloud.google.com/backend-config: '{"default": "grammar-games-bec"}'
spec:
type: ClusterIP
selector:
app: grammar-games-core
ports:
- name: http
protocol: TCP
port: 80
targetPort: 8080
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: grammar-games-core
spec:
# Two replicas for right now, just so I can see how RPC calls get directed.
# replicas: 2
selector:
matchLabels:
app: grammar-games-core
template:
metadata:
labels:
app: grammar-games-core
spec:
serviceAccountName: grammar-games-core-k8sa
containers:
- name: grammar-games-core
image: gcr.io/grammar-games/grammar-games-core:1.1.2
command:
- "/bin/grammar-games-core"
ports:
- containerPort: 52001
env:
- name: GAMESDB_USER
valueFrom:
secretKeyRef:
name: gamesdb-config
key: username
- name: GAMESDB_PASSWORD
valueFrom:
secretKeyRef:
name: gamesdb-config
key: password
- name: GAMESDB_DB_NAME
valueFrom:
secretKeyRef:
name: gamesdb-config
key: db-name
- name: GRPC_SERVER_PORT
value: '52001'
- name: GAMES_LOG_FILE_PATH
value: ''
- name: GAMESDB_LOG_LEVEL
value: 'debug'
resources:
requests:
# The proxy's memory use scales linearly with the number of active
# connections. Fewer open connections will use less memory. Adjust
# this value based on your application's requirements.
memory: "2Gi"
# The proxy's CPU use scales linearly with the amount of IO between
# the database and the application. Adjust this value based on your
# application's requirements.
cpu: "1"
readinessProbe:
exec:
command: ["/bin/grpc_health_probe", "-addr=:52001"]
initialDelaySeconds: 5
- name: cloud-sql-proxy
# It is recommended to use the latest version of the Cloud SQL proxy
# Make sure to update on a regular schedule!
image: gcr.io/cloudsql-docker/gce-proxy:1.24.0
command:
- "/cloud_sql_proxy"
# If connecting from a VPC-native GKE cluster, you can use the
# following flag to have the proxy connect over private IP
# - "-ip_address_types=PRIVATE"
# Replace DB_PORT with the port the proxy should listen on
# Defaults: MySQL: 3306, Postgres: 5432, SQLServer: 1433
- "-instances=grammar-games:us-east1:grammar-games-db=tcp:3306"
securityContext:
# The default Cloud SQL proxy image runs as the
# "nonroot" user and group (uid: 65532) by default.
runAsNonRoot: true
# Resource configuration depends on an application's requirements. You
# should adjust the following values based on what your application
# needs. For details, see https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources:
requests:
# The proxy's memory use scales linearly with the number of active
# connections. Fewer open connections will use less memory. Adjust
# this value based on your application's requirements.
memory: "2Gi"
# The proxy's CPU use scales linearly with the amount of IO between
# the database and the application. Adjust this value based on your
# application's requirements.
cpu: "1"
- name: envoy-sidecar
image: envoyproxy/envoy:v1.20-latest
ports:
- name: http
containerPort: 8080
resources:
requests:
cpu: 10m
ephemeral-storage: 256Mi
memory: 256Mi
volumeMounts:
- name: config
mountPath: /etc/envoy
readinessProbe:
httpGet:
port: http
httpHeaders:
- name: x-envoy-livenessprobe
value: healthz
path: /healthz
scheme: HTTP
volumes:
- name: config
configMap:
name: envoy-sidecar-conf
---
apiVersion: v1
kind: ConfigMap
metadata:
name: envoy-sidecar-conf
data:
envoy.yaml: |
static_resources:
listeners:
- name: listener_0
address:
socket_address:
address: 0.0.0.0
port_value: 8080
filter_chains:
- filters:
- name: envoy.filters.network.http_connection_manager
typed_config:
"@type": type.googleapis.com/envoy.extensions.filters.network.http_connection_manager.v3.HttpConnectionManager
access_log:
- name: envoy.access_loggers.stdout
typed_config:
"@type": type.googleapis.com/envoy.extensions.access_loggers.stream.v3.StdoutAccessLog
codec_type: AUTO
stat_prefix: ingress_http
route_config:
name: local_route
virtual_hosts:
- name: http
domains:
- "*"
routes:
- match:
prefix: "/grammar_games_protos.GrammarGames/"
route:
cluster: grammar-games-core-grpc
cors:
allow_origin_string_match:
- prefix: "*"
allow_methods: GET, PUT, DELETE, POST, OPTIONS
allow_headers: keep-alive,user-agent,cache-control,content-type,content-transfer-encoding,custom-header-1,x-accept-content-transfer-encoding,x-accept-response-streaming,x-user-agent,x-grpc-web,grpc-timeout
max_age: "1728000"
expose_headers: custom-header-1,grpc-status,grpc-message
http_filters:
- name: envoy.filters.http.health_check
typed_config:
"@type": type.googleapis.com/envoy.extensions.filters.http.health_check.v3.HealthCheck
pass_through_mode: false
headers:
- name: ":path"
exact_match: "/healthz"
- name: "x-envoy-livenessprobe"
exact_match: "healthz"
- name: envoy.filters.http.grpc_web
- name: envoy.filters.http.cors
- name: envoy.filters.http.router
typed_config: {}
clusters:
- name: grammar-games-core-grpc
connect_timeout: 0.5s
type: logical_dns
lb_policy: ROUND_ROBIN
http2_protocol_options: {}
load_assignment:
cluster_name: grammar-games-core-grpc
endpoints:
- lb_endpoints:
- endpoint:
address:
socket_address:
address: 0.0.0.0
port_value: 52001
health_checks:
timeout: 1s
interval: 10s
unhealthy_threshold: 2
healthy_threshold: 2
grpc_health_check: {}
admin:
access_log_path: /dev/stdout
address:
socket_address:
address: 127.0.0.1
port_value: 8090
【问题讨论】:
-
您打算同时公开 gRPC 和 gRPC-Web 侦听器,还是只打算公开 gRPC-Web?
-
我被捆绑了,但会尽我所能尽快看看这个。
-
谢谢@GariSingh。此时只是 gRPC-Web。
-
这个案子有进展吗?我正在尝试像你一样设置 grpc web。
-
我仍在与 Google 支持部门合作,以找出问题所在。一旦我们有了一个可行的解决方案,我会用正确的配置做一个新的帖子。很高兴知道还有其他人对此解决方案感兴趣。
标签: google-kubernetes-engine grpc-web autopilot