【问题标题】:Terraform - How to Create a GKE Cluster and Install Helm Charts?Terraform - 如何创建 GKE 集群并安装 Helm Charts?
【发布时间】:2020-03-28 15:53:11
【问题描述】:

目标

我有一个特定的工作流程来在 Google Cloud 上设置新的 Kubernetes 集群。我想用 Terraform 自动化这个过程。这些是步骤:

  1. 创建集群
    gcloud beta container --project "my-google-project" clusters create "cluster-name" --zone "europe-west3-b"
    
  2. 设置 Helm 存储库
    helm repo add stable https://kubernetes-charts.storage.googleapis.com/
    helm repo add jetstack https://charts.jetstack.io/
    helm repo update
    
  3. 安装 NGINX 入口
    kubectl create clusterrolebinding cluster-admin-binding --clusterrole cluster-admin --user $(gcloud config get-value account)
    helm install nginx-ingress stable/nginx-ingress
    
  4. 安装证书管理器
    kubectl apply --validate=false -f https://raw.githubusercontent.com/jetstack/cert-manager/v0.13.0/deploy/manifests/00-crds.yaml
    kubectl create namespace cert-manager
    helm install cert-manager jetstack/cert-manager --namespace cert-manager
    

想法

第一步可能如下所示:

resource "google_container_cluster" "primary" {
  name               = "cluster-name"
  location           = "europe-west3-b"
  initial_node_count = 3

  master_auth {
    username = ""
    password = ""

    client_certificate_config {
      issue_client_certificate = false
    }
  }

  node_config {
    oauth_scopes = [
      "https://www.googleapis.com/auth/logging.write",
      "https://www.googleapis.com/auth/monitoring",
    ]

    metadata = {
      disable-legacy-endpoints = "true"
    }
  }
}

但我不知道如何处理步骤 2 - 4。

【问题讨论】:

  • 步骤 2-4 是软件配置,应该使用软件配置器来执行。最流行的工具是 Ansible。

标签: terraform google-kubernetes-engine kubernetes-helm kubectl nginx-ingress


【解决方案1】:

虽然 Terraform 对于构建和配置云基础架构以供 Kubernetes 等运行是有意义的,但在部署后用于配置所述基础架构并不一定有意义。我认为大多数基础架构设计都会考虑将部署到已配置集群上的应用程序作为所述集群的配置。这里的语义肯定有点微妙,但我认为像 Ansible 这样的工具更适合在配置后将应用程序部署到您的集群。

所以我的建议是定义一些 Ansible 角色。也许:

create_cluster
deploy_helm
install_nginx_ingress
install_cert_manager

在每个相应的角色中,根据Galaxy schema 定义需要使用的任务和变量。最后,定义一个 Playbook Ansible 用于 include 或 import 这些角色。这将允许您在一个命令中配置您的基础架构并将所有必需的应用程序部署到它:

ansible-playbook playbook.yml

【讨论】:

    猜你喜欢
    • 2021-07-28
    • 2019-12-12
    • 1970-01-01
    • 2020-03-19
    • 2021-09-30
    • 2021-07-07
    • 2019-03-30
    • 2020-12-26
    • 2020-08-20
    相关资源
    最近更新 更多