<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microservices on Virtualthoughts</title><link>http://virtualthoughts.co.uk/categories/microservices/</link><description>Recent content in Microservices on Virtualthoughts</description><generator>Hugo -- gohugo.io</generator><language>en-gb</language><lastBuildDate>Fri, 30 Aug 2024 00:00:00 +0000</lastBuildDate><atom:link href="http://virtualthoughts.co.uk/categories/microservices/index.xml" rel="self" type="application/rss+xml"/><item><title>Kubernetes on RK1 / Turing Pi 2: Automation with Ansible, Cilium and Cert-Manager</title><link>http://virtualthoughts.co.uk/2024/08/30/kubernetes-on-turing-pi-2-automation-with-ansible-cilium-and-cert-manager/</link><pubDate>Fri, 30 Aug 2024 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2024/08/30/kubernetes-on-turing-pi-2-automation-with-ansible-cilium-and-cert-manager/</guid><description>&lt;p&gt;&lt;a href="https://github.com/David-VTUK/turing-pi-ansible"&gt;TLDR: Take me to the Playbook&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Note - This is just a high-level overview, I&amp;rsquo;ll likely follow up with a post dedicated on the CIlium/BGP configuration.&lt;/p&gt;
&lt;p&gt;&lt;img src="images/PXL_20240830_120436916-2048x1152.jpg" alt=""&gt;&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve had my Turing Pi 2 board for a while now, and during that time I&amp;rsquo;ve struggled to decide which automation tooling to use to bootstrap K3s to it. However, I reached a decision to use &lt;a href="https://www.ansible.com/"&gt;Ansible&lt;/a&gt;. It&amp;rsquo;s not something I&amp;rsquo;m overly familiar with, but this would provide a good opportunity to learn by doing.&lt;/p&gt;</description></item><item><title>Replicating my vSphere network configuration in Openshift Virtualisation</title><link>http://virtualthoughts.co.uk/2024/02/05/replicating-my-vsphere-network-configuration-in-openshift-virtualisation/</link><pubDate>Mon, 05 Feb 2024 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2024/02/05/replicating-my-vsphere-network-configuration-in-openshift-virtualisation/</guid><description>&lt;p&gt;&lt;a href="https://www.redhat.com/en/technologies/cloud-computing/openshift/virtualization"&gt;Red Hat Openshift Virtualisation&lt;/a&gt; provides a platform for running and managing Virtual Machines alongside Containers using a consistent API. It also provides a mechanism for migrating VMs from platforms such as vSphere.&lt;/p&gt;
&lt;p&gt;As I have both environments, I wanted to deploy an Openshift Virtualisation setup that mimics my current vSphere setup so I could migrate Virtual Machines to it.&lt;/p&gt;
&lt;h2 id="existing-vsphere-design"&gt;Existing vSphere Design&lt;/h2&gt;
&lt;p&gt;Below is a diagram depicting my current vSphere setup. My ESXi hosts are dual-homed with a separation of management (vmkernel) and virtual machine traffic.&lt;/p&gt;</description></item><item><title>Changing the default apps wildcard certificate in OCP4</title><link>http://virtualthoughts.co.uk/2023/12/30/changing-the-default-apps-wildcard-certificate-in-ocp4/</link><pubDate>Sat, 30 Dec 2023 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2023/12/30/changing-the-default-apps-wildcard-certificate-in-ocp4/</guid><description>&lt;p&gt;In a standard OCP4 installation, several &lt;code&gt;route&lt;/code&gt; objects are created by default and secured with a internally signed wildcard certificate.&lt;/p&gt;
&lt;p&gt;These &lt;code&gt;routes&lt;/code&gt; are configured as &lt;code&gt;&amp;lt;app-name&amp;gt;.apps.&amp;lt;domain&amp;gt;&lt;/code&gt;. In my example, I have a cluster with the assigned domain &lt;code&gt;ocp-acm.virtualthoughts.co.uk&lt;/code&gt;, which results in the &lt;code&gt;routes&lt;/code&gt; below:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;oauth-openshift.apps.ocp-acm.virtualthoughts.co.uk
console-openshift-console.apps.ocp-acm.virtualthoughts.co.uk
grafana-openshift-monitoring.apps.ocp-acm.virtualthoughts.co.uk
thanos-querier-openshift-monitoring.apps.ocp-acm.virtualthoughts.co.uk
prometheus-k8s-openshift-monitoring.apps.ocp-acm.virtualthoughts.co.uk
alertmanager-main-openshift-monitoring.apps.ocp-acm.virtualthoughts.co.uk
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Inspecting &lt;code&gt;console-openshift-console.apps.ocp-acm.virtualthoughts.co.uk&lt;/code&gt; shows us the default wildcard TLS certificate used by the Ingress Operator:&lt;/p&gt;
&lt;p&gt;&lt;img src="images/default-wildcard.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt;Because it&amp;rsquo;s internally signed, it&amp;rsquo;s not trusted by default by external clients. However, this can be changed.&lt;/p&gt;</description></item><item><title>Improving the CI/build process for the community Rancher Exporter</title><link>http://virtualthoughts.co.uk/2023/06/05/improving-the-ci-build-process-for-the-community-rancher-exporter/</link><pubDate>Mon, 05 Jun 2023 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2023/06/05/improving-the-ci-build-process-for-the-community-rancher-exporter/</guid><description>&lt;p&gt;One of my side projects is developing and maintaining an &lt;a href="https://github.com/David-VTUK/prometheus-rancher-exporter"&gt;unofficial Prometheus Exporter for Rancher&lt;/a&gt;. It exposes metrics pertaining to Rancher-specific resources including, but not limited to managed clusters, Kubernetes versions, and more. Below shows an example dashboard based on these metrics.&lt;/p&gt;
&lt;p&gt;&lt;img src="images/overview-dashboard.png" alt="overview-dashboard.png"&gt;&lt;/p&gt;
&lt;p&gt;Incidentally, if you are using Rancher, I&amp;rsquo;d love to hear your thoughts/feedback.&lt;/p&gt;
&lt;h2 id="previous-ci-workflow"&gt;Previous CI workflow&lt;/h2&gt;
&lt;p&gt;The flowchart below outlines the existing process. Whilst automated, pushing directly to &lt;code&gt;latest&lt;/code&gt; is bad practice.&lt;/p&gt;</description></item><item><title>Evaluating Harvester in vSphere</title><link>http://virtualthoughts.co.uk/2021/12/20/evaluating-harvester-in-vsphere/</link><pubDate>Mon, 20 Dec 2021 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2021/12/20/evaluating-harvester-in-vsphere/</guid><description>&lt;p&gt;&lt;strong&gt;Disclaimer - The use of nested virtualisation is not a supported topology&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.harvesterhci.io"&gt;Harvester&lt;/a&gt; is an open-source HCI solution aimed at managing Virtual Machines, similar to vSphere and Nutanix, with key differences including (but not limited to):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fully Open Source&lt;/li&gt;
&lt;li&gt;Leveraging Kubernetes-native technologies&lt;/li&gt;
&lt;li&gt;Integration with Rancher&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Testing/evaluating any hyperconverged solution can be difficult - It usually requires having dedicated hardware as these solutions are designed to work directly on bare metal. However, we can circumvent this by leveraging &lt;strong&gt;&lt;em&gt;nested virtualisation&lt;/em&gt;&lt;/strong&gt; - something which may be familiar with a lot of homelabbers (myself included) - which involves using an existing virtualisation solution provision workloads that also leverage virtualisation technology.&lt;/p&gt;</description></item><item><title>Creating Kubernetes Clusters with Rancher and Pulumi</title><link>http://virtualthoughts.co.uk/2021/05/13/creating-rancher-clusters-with-pulumi/</link><pubDate>Thu, 13 May 2021 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2021/05/13/creating-rancher-clusters-with-pulumi/</guid><description>&lt;p&gt;tldr; &lt;a href="https://github.com/David-VTUK/pulumi-rancher-demos"&gt;Here&lt;/a&gt; is the code repo&lt;/p&gt;
&lt;h2 id="intro"&gt;Intro&lt;/h2&gt;
&lt;p&gt;My Job at Suse (via Rancher) involves hosting a lot of demos, product walk-throughs and various other activities that necessitate spinning up tailored environments on-demand. To facilitate this, I previously leaned towards Terraform, and have since curated a list of individual scripts I have to manage on an individual basis as they address a specific use case.&lt;/p&gt;
&lt;p&gt;This approach reached a point where it became difficult to manage. Ideally, I wanted an IaC environment that catered for:&lt;/p&gt;</description></item><item><title>K3s, Rancher and Pulumi</title><link>http://virtualthoughts.co.uk/2021/04/06/k3s-rancher-and-pulumi/</link><pubDate>Tue, 06 Apr 2021 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2021/04/06/k3s-rancher-and-pulumi/</guid><description>&lt;p&gt;TLDR; Repo can be found &lt;a href="https://github.com/David-VTUK/vSphere-K3s-Rancher-Pulumi"&gt;here&lt;/a&gt; (Be warned, I&amp;rsquo;m at best, a hobbyist programmer and certainly not a software engineer in my day job)&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ve been recently getting acquainted with &lt;a href="https://www.pulumi.com/"&gt;Pulumi&lt;/a&gt; as an alternative to Terraform for managing my infrastructure. I decided to create a repo that would do a number of activities to stand up Rancher in a new K3s cluster, all managed by Pulumi in my vSphere Homelab, consisting of the following activities:&lt;/p&gt;</description></item><item><title>Rancher, vSphere Network Protocol Profiles and static IP addresses for k8s nodes [Updated 2023]</title><link>http://virtualthoughts.co.uk/2020/03/29/rancher-vsphere-network-protocol-profiles-and-static-ip-addresses-for-k8s-nodes/</link><pubDate>Sun, 29 Mar 2020 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2020/03/29/rancher-vsphere-network-protocol-profiles-and-static-ip-addresses-for-k8s-nodes/</guid><description>&lt;p&gt;&lt;strong&gt;Edit:&lt;/strong&gt; This post has been updated to reflect changes in newer versions of Rancher.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; As mentioned by Jonathan in the comments, disabling cloud-init&amp;rsquo;s initial network configuration is recommended. To do this, create a file:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;To contain:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;network: {config: disabled}&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;In your VM template.&lt;/p&gt;
&lt;p&gt;How networking configuration is applied to k8s nodes (or VM&amp;rsquo;s in general) in on-premises environments is usually achieved by one of two ways - DHCP or static. For some, DHCP is not a popular option and static addresses can be time-consuming to manage, particularly when there&amp;rsquo;s no IPAM feature in Rancher. In this blog post I go through how to leverage vSphere Network Protocol Profiles in conjunction with Rancher and Cloud-Init to reliably, and predictably apply static IP addresses to deployed nodes.&lt;/p&gt;</description></item><item><title>K3S and Nvidia Jetson Nano</title><link>http://virtualthoughts.co.uk/2020/03/24/k3s-and-nvidia-jetson-nano/</link><pubDate>Tue, 24 Mar 2020 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2020/03/24/k3s-and-nvidia-jetson-nano/</guid><description>&lt;p&gt;&lt;a href="https://k3s.io/"&gt;K3S&lt;/a&gt; is a lightweight Kubernetes distribution developed by &lt;a href="https://rancher.com/"&gt;Rancher Labs&lt;/a&gt;, perfect for Edge Computing use cases where compute resources may be somewhat limited. It supports x86_64, ARMv7, and ARM64 architectures.&lt;/p&gt;
&lt;h2 id="ok-why-the-nvidia-nano"&gt;Ok, why the Nvidia Nano?&lt;/h2&gt;
&lt;p&gt;Deploying Kubernetes, be it K8s, K3s or otherwise is fairly well documented on devices such as the Raspberry Pi, however, I wanted to have an attempt doing so on a Nano for the GPU capabilities, which might be beneficial with ML/AI workloads.&lt;/p&gt;</description></item><item><title>On-prem K8s clusters with Rancher, Terraform and Ubuntu</title><link>http://virtualthoughts.co.uk/2019/12/27/on-prem-k8s-clusters-with-rancher-terraform-and-ubuntu/</link><pubDate>Fri, 27 Dec 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/12/27/on-prem-k8s-clusters-with-rancher-terraform-and-ubuntu/</guid><description>&lt;p&gt;One of the attractive characteristics of Kubernetes is how it can run pretty much anywhere - in the cloud, in the data center, on the edge, on your local machine and much more. Leveraging existing investments in datacenter resources can be logical when deciding where to place new Kubernetes clusters, and this post goes into automating this with Rancher and Terraform.&lt;/p&gt;
&lt;h2 id="primer"&gt;Primer&lt;/h2&gt;
&lt;p&gt;For this exercise the following is leveraged:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Rancher 2.3&lt;/li&gt;
&lt;li&gt;vSphere 6.7&lt;/li&gt;
&lt;li&gt;Ubuntu 18.04 LTS&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;An Ubuntu VM will be created and configured into a template to spin up Kubernetes nodes.&lt;/p&gt;</description></item><item><title>Pi-Hole and K8s v2 - Now with DNS over HTTPS</title><link>http://virtualthoughts.co.uk/2019/11/07/pi-hole-and-k8s-v2-now-with-dns-over-https/</link><pubDate>Thu, 07 Nov 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/11/07/pi-hole-and-k8s-v2-now-with-dns-over-https/</guid><description>&lt;p&gt;In a previous post, I went through the process of configuring Pi-Hole within a Kubernetes cluster for the purpose of facilitating a network-wide adblocking. Although helpful, I wanted to augment this with DNS over HTTPS.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/David-VTUK/piholev2"&gt;Complete manifests can be found here&lt;/a&gt;. Shout out to &lt;a href="https://github.com/visibilityspots"&gt;visibilityspots&lt;/a&gt; for the &lt;a href="https://hub.docker.com/r/visibilityspots/cloudflared/"&gt;cloudflared image on Dockerhub&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="why"&gt;Why?&lt;/h2&gt;
&lt;p&gt;DNS, as a protocol, is insecure and can be prone to manipulation and man-in-the-middle attacks. DNS over HTTPS helps address this by encrypting the data between the DNS over HTTPS client and the DNS over HTTPS-based DNS resolver. One of which is provided by Cloudflare.&lt;/p&gt;</description></item><item><title>Application security with mutual TLS (mTLS) via Istio</title><link>http://virtualthoughts.co.uk/2019/07/15/application-security-with-mutual-tls-mtls-via-istio/</link><pubDate>Mon, 15 Jul 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/07/15/application-security-with-mutual-tls-mtls-via-istio/</guid><description>&lt;h1 id="tls-overview"&gt;TLS Overview&lt;/h1&gt;
&lt;p&gt;If we take an example of accessing a website such as https://www.virtualthoughts.co.uk/, these are the high-level steps of what occurs:&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;img src="images/https3.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The client initiates a connection to the web server requesting an HTTPS connection.&lt;/li&gt;
&lt;li&gt;The web server responds with its public key. The client validates the key with its list of known Certificate Authorities.&lt;/li&gt;
&lt;li&gt;A session key is generated by the client and encrypted with the web server&amp;rsquo;s public key and is sent back to the web server.&lt;/li&gt;
&lt;li&gt;The web server decrypts the session key with its private key. End to end encryption is established.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;By default, the TLS protocol only proves the identity of the server to the client using X.509 certificate and the authentication of the client to the server is left to the application layer.  For external, public-facing websites, this is an acceptable and well-established implementation of TLS. But what about communication between different microservices?&lt;/p&gt;</description></item><item><title>Container Packet Inspection with NSX-T</title><link>http://virtualthoughts.co.uk/2019/07/10/container-packet-inspection-with-nsx-t/</link><pubDate>Wed, 10 Jul 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/07/10/container-packet-inspection-with-nsx-t/</guid><description>&lt;p&gt;For troubleshooting (or just being a bit nosey) we have a number of tools that allow us to inspect the traffic between two endpoints. When it comes to containers however, our approach has to be adjusted slightly. When using NSX-T as a CNI, we have some of these tools available to us out of the box.&lt;/p&gt;
&lt;h1 id="app-overview"&gt;App Overview&lt;/h1&gt;
&lt;p&gt;&lt;img src="images/app-2.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;For this example, I&amp;rsquo;ve deployed a standard Wordpress deployment consisting of a frontend (web) pod and a backend (DB) pod. The objective is to identify and capture the traffic between these pods.&lt;/p&gt;</description></item><item><title>Step by Step - Istio up and running</title><link>http://virtualthoughts.co.uk/2019/06/23/step-by-step-istio-up-and-running/</link><pubDate>Sun, 23 Jun 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/06/23/step-by-step-istio-up-and-running/</guid><description>&lt;p&gt;Service Mesh is a pretty hot topic in the Kubernetes ecosystem currently, and I wanted to get it up and running in my own lab environment. Istio&amp;rsquo;s documentation has a pre-baked solution to demonstrate some of its capabilities (a book app, if memory serves me correctly), but I wanted to deploy my own app to get more &amp;ldquo;hands-on&amp;rdquo; experience with the tech, even if it&amp;rsquo;s only very basic to start with.&lt;/p&gt;</description></item><item><title>Introducing Velero - Backup and DR for Kubernetes Applications</title><link>http://virtualthoughts.co.uk/2019/06/12/introducing-velero-backup-and-dr-for-kubernetes-applications/</link><pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/06/12/introducing-velero-backup-and-dr-for-kubernetes-applications/</guid><description>&lt;p&gt;&lt;img src="images/1*YsbUiVbFviN34Vh8zop4xQ.png" alt="Image result for velero logo heptio"&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;h1 id="what-is-velero"&gt;What is Velero?&lt;/h1&gt;
&lt;p&gt;Velero (previously known as Heptio ARK) provides a suite of tools to backup Kubernetes resources and applications for two main purposes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Disaster Recovery&lt;/strong&gt; - Recover Kubernetes cluster components and applications.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Migration&lt;/strong&gt; - Migrate your Kubernetes applications to another Kubernetes cluster.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Migrating Kubernetes applications is a compelling use case. One of the significant benefits of using Kubernetes is the predictability of the platform and consequently the portability of applications that reside on it. With the main exception of nuances with persistent storage, the Kubernetes API will fell almost indistinguishable whether it resides on prem, GKE, AKS, EKS and elsewhere. If you have your Kubernetes-based application on one provider and want to migrate it to another or duplicate it to run elsewhere for dev/test, this can easily be achieved. Especially with Velero.&lt;/p&gt;</description></item><item><title>Bootstrapping Prometheus, Grafana and Alertmanager to PKS deployed K8s Clusters</title><link>http://virtualthoughts.co.uk/2019/05/14/bootstrapping-prometheus-grafana-and-alertmanager-to-pks-deployed-k8s-clusters/</link><pubDate>Tue, 14 May 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/05/14/bootstrapping-prometheus-grafana-and-alertmanager-to-pks-deployed-k8s-clusters/</guid><description>&lt;p&gt;PKS is a comprehensive platform for the provisioning and management of Kubernetes clusters, which can be further enhanced by leveraging its extensibility options. In this post, we will modify a plan to deploy a yaml manifest file which provisions Prometheus, Grafana, and Alertmanager backed by NSX-T load balancers.&lt;/p&gt;
&lt;h1 id="why-prometheus-grafana-and-alertmanager"&gt;Why Prometheus, Grafana and Alertmanager?&lt;/h1&gt;
&lt;p&gt;The &lt;a href="https://en.wikipedia.org/wiki/Cloud_Native_Computing_Foundation" title="Cloud Native Computing Foundation"&gt;Cloud Native Computing Foundation&lt;/a&gt; accepted Prometheus as its second incubated project, the first being Kubernetes. Originally developed by SoundCloud. It has quickly become a popular platform for the monitoring of Kubernetes platforms. Built upon a powerful analytics engine, extensive and highly flexible data modeling can be accomplished with relative ease.&lt;/p&gt;</description></item><item><title>CKA Exam Experience (Inc study &amp; lab guide)</title><link>http://virtualthoughts.co.uk/2019/05/07/cka-exam-experience-inc-study-lab-guide/</link><pubDate>Tue, 07 May 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/05/07/cka-exam-experience-inc-study-lab-guide/</guid><description>&lt;h1 id="introduction"&gt;Introduction&lt;/h1&gt;
&lt;p&gt;Over the long bank holiday weekend, I sat and passed the Certified Kubernetes Exam (CKA). This blog post goes over my experience (With respect to the NDA) together with a lab guide I&amp;rsquo;ve made which I&amp;rsquo;ve uploaded hoping it might help others.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;img src="images/339.png" alt=""&gt;&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;h1 id="format"&gt;Format&lt;/h1&gt;
&lt;p&gt;The online exams consist of a set of performance-based items (problems) to be solved on the command line. For the CKA there are 24 questions of varying difficulty. At the time of writing, the only option to sit this exam is through remote proctoring.&lt;/p&gt;</description></item><item><title>Exposing the K8s dashboard via a NSX-T Load balancer</title><link>http://virtualthoughts.co.uk/2019/04/15/exposing-the-k8s-dashboard-via-a-nsx-t-load-balancer/</link><pubDate>Mon, 15 Apr 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/04/15/exposing-the-k8s-dashboard-via-a-nsx-t-load-balancer/</guid><description>&lt;p&gt;For the following to work, your k8s infrastructure needs to leverage some kind of CNI that&amp;rsquo;s able to provision load balancers. For this example I&amp;rsquo;m leveraging PKS which has native integration with NSX-T.&lt;/p&gt;
&lt;p&gt;The default way to access the Kubernetes dashboard is to leverage the kubectl proxy command. However, this is somewhat limiting for a production environment. An alternative way is to expose the dashboard through a load balancer.&lt;/p&gt;
&lt;p&gt;&lt;img src="images/980.png" alt=""&gt;&lt;/p&gt;</description></item><item><title>PKS, Harbor and the importance of container registries</title><link>http://virtualthoughts.co.uk/2019/02/27/pks-harbor-and-the-importance-of-container-registries/</link><pubDate>Wed, 27 Feb 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/02/27/pks-harbor-and-the-importance-of-container-registries/</guid><description>&lt;h1 id="whatare-container-registries-and-why-do-we-need-them"&gt;What are container registries and why do we need them?&lt;/h1&gt;
&lt;p&gt;A lot of the time, particularly when individuals and organisations are evaluating, testing and experimenting with containers they will use &lt;em&gt;public&lt;/em&gt; container registries such as Docker Hub.  These public registries provide an easy-to-use, simple way to access images. As developers, application owners, system admins etc gain familiarity and experience additional operational considerations need to be explored, such as:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Organisation&lt;/strong&gt; - How can we organise container images in a meaningful way? Such as by environment state (Prod/Dev/Test) and application type?&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;RBAC&lt;/strong&gt; - How can we implement role-based access control to a container registry?&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vulnerability Scanning&lt;/strong&gt; - How can we scan container images for known vulnerabilities?&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Efficiency&lt;/strong&gt; - How can we centrally manage all our container images and deploy an application from them?&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security&lt;/strong&gt; - Some images need to kept under lock and key, rather than using an external service like Docker Hub.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id="introducing-vmware-harbor-registry"&gt;Introducing VMware Harbor Registry&lt;/h1&gt;
&lt;p&gt;VMware Harbor Registry has been designed to address these considerations as enterprise-class container registry solution with integration into PKS. In this post, We&amp;rsquo;ll have a quick primer on getting up and running with Harbor in PKS and explore some of its features. To begin, we need to download PKS Harbor from the Pivotal site and import it into ops manager.&lt;/p&gt;</description></item><item><title>Efficiency gains from small(er) containers</title><link>http://virtualthoughts.co.uk/2019/02/11/efficiency-gains-from-smaller-containers/</link><pubDate>Mon, 11 Feb 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/02/11/efficiency-gains-from-smaller-containers/</guid><description>&lt;h1 id="preamble"&gt;Preamble&lt;/h1&gt;
&lt;p&gt;A lot of organisations are looking towards containerising their applications and embracing the world of microservices. There are a number of ways to reach this goal, through a variety of tools and methodologies,  this blog post goes through one way of approaching this task.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://www.virtualthoughts.co.uk/2018/07/13/kubernetes-zero-to-hero-from-single-vm-webserver-to-a-scalable-microservices-infrastructure/"&gt;In a previous blog post&lt;/a&gt; I went through the process of taking a web application and putting it into a container, and whilst it got the job done, there wasn&amp;rsquo;t a lot of attention given to the image used for the container. So let&amp;rsquo;s address that.&lt;/p&gt;</description></item><item><title>vRealize Log Insight + PKS Integration</title><link>http://virtualthoughts.co.uk/2019/02/02/vrealize-log-insight-pks-integration/</link><pubDate>Sat, 02 Feb 2019 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2019/02/02/vrealize-log-insight-pks-integration/</guid><description>&lt;h1&gt;&lt;img src="images/834.png" alt=""&gt;&lt;/h1&gt;
&lt;h1 id="introduction"&gt;Introduction&lt;/h1&gt;
&lt;p&gt;In this blog post, we take a look into the integration between PKS and vRealize Log Insight and how this integration benefits the enterprise. As a bit of a recap:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PKS&lt;/strong&gt; - PKS is a purpose-built enterprise level container solution leveraging the capabilities of Kubernetes, BOSH, VMware NSX-T, Harbour and more to deliver a highly available, highly flexible container runtime that operates on a number of cloud platforms, both private and public, including vSphere, AWS, Azure and GCP.&lt;/p&gt;</description></item><item><title>NSX-T, Kubernetes and Microsegmentation</title><link>http://virtualthoughts.co.uk/2018/08/01/nsx-t-kubernetes-and-microsegmentation/</link><pubDate>Wed, 01 Aug 2018 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2018/08/01/nsx-t-kubernetes-and-microsegmentation/</guid><description>&lt;p&gt;For the uninitiated, VMware NSX comes in two &amp;ldquo;flavours&amp;rdquo;, NSX-V which is heavily integrated with vSphere, and NSX-T which is more IaaS agnostic. NSX-T also has more emphasis on facilitating container-based applications, providing a  number of features into our container ecosystem. In this blog post, we discuss the microsegmentation capabilities provided by NSX-T in combination with container technology.&lt;/p&gt;
&lt;h1 id="what-is-microsegmentation"&gt;What is Microsegmentation?&lt;/h1&gt;
&lt;p&gt;Prior to Software-defined networking, firewall functions were largely centralised, typically manifested as edge devices which were and still are, good for controlling traffic to and from the datacenter, otherwise known as north-south traffic:&lt;/p&gt;</description></item><item><title>Kubernetes zero to hero - from single VM webserver to a scalable microservices infrastructure</title><link>http://virtualthoughts.co.uk/2018/07/13/kubernetes-zero-to-hero-from-single-vm-webserver-to-a-scalable-microservices-infrastructure/</link><pubDate>Fri, 13 Jul 2018 00:00:00 +0000</pubDate><guid>http://virtualthoughts.co.uk/2018/07/13/kubernetes-zero-to-hero-from-single-vm-webserver-to-a-scalable-microservices-infrastructure/</guid><description>&lt;h1 id="preamble"&gt;Preamble&lt;/h1&gt;
&lt;p&gt;Having spent a number of months familiarising myself with container technology I inevitably got &amp;ldquo;stuck in&amp;rdquo; with Kubernetes. Containers are brilliant, but I personally don&amp;rsquo;t see the value of managing individual containers - it&amp;rsquo;s still the pets vs cattle mentality. Orchestrating containers with the likes of Kubernetes, however, makes a &lt;strong&gt;ton&lt;/strong&gt; of sense and reinforces the microservices approach to building and deploying applications.&lt;/p&gt;
&lt;p&gt;To test myself, I decided to document end-to-end the entire journey from taking a web server residing on a standalone virtual machine, containerise it, and deploying it via Kubernetes.&lt;/p&gt;</description></item></channel></rss>