k8s——pod控制器详解
k8s——pod控制器详解
一、pod控制器介绍
Pod是kubernetes的最小管理单元,在kubernetes中,按照pod的创建方式可以将其分为两类:
-
自主式pod:kubernetes直接创建出来的Pod,这种pod删除后就没有了,也不会重建
-
控制器创建的pod:kubernetes通过控制器创建的pod,这种pod删除了之后还会自动重建
什么是Pod控制器
Pod控制器是管理pod的中间层,使用Pod控制器之后,只需要告诉Pod控制器,想要多少个什么样的Pod就可以了,它会创建出满足条件的Pod并确保每一个Pod资源处于用户期望的目标状态。如果Pod资源在运行中出现故障,它会基于指定策略重新编排Pod。
在kubernetes中,有很多类型的pod控制器,每种都有自己的适合的场景,常见的有下面这些:
ReplicationController:比较原始的pod控制器,已经被废弃,由ReplicaSet替代
ReplicaSet:保证副本数量一直维持在期望值,并支持pod数量扩缩容,镜像版本升级
Deployment:通过控制ReplicaSet来控制Pod,并支持滚动升级、回退版本
Horizontal Pod Autoscaler:可以根据集群负载自动水平调整Pod的数量,实现削峰填谷
DaemonSet:在集群中的指定Node上运行且仅运行一个副本,一般用于守护进程类的任务
Job:它创建出来的pod只要完成任务就立即退出,不需要重启或重建,用于执行一次性任务
Cronjob:它创建的Pod负责周期性任务控制,不需要持续后台运行
StatefulSet:管理有状态应用
二、ReplicaSet(RS)
ReplicaSet的主要作用是保证一定数量的pod正常运行,它会持续监听这些Pod的运行状态,一旦Pod发生故障,就会重启或重建。同时它还支持对pod数量的扩缩容和镜像版本的升降级。

1、ReplicaSet的资源清单文件
apiVersion: apps/v1 # 版本号
kind: ReplicaSet # 类型
metadata: # 元数据name: # rs名称 namespace: # 所属命名空间 labels: #标签controller: rs
spec: # 详情描述replicas: 3 # 副本数量selector: # 选择器,通过它指定该控制器管理哪些podmatchLabels: # Labels匹配规则app: nginx-podmatchExpressions: # Expressions匹配规则- {key: app, operator: In, values: [nginx-pod]}template: # 模板,当副本数量不足时,会根据下面的模板创建pod副本metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1ports:- containerPort: 80
在这里面,需要新了解的配置项就是spec下面几个选项:
replicas:指定副本数量,其实就是当前rs创建出来的pod的数量,默认为1
selector:选择器,它的作用是建立pod控制器和pod之间的关联关系,采用的Label Selector机制
在pod模板上定义label,在控制器上定义选择器,就可以表明当前控制器能管理哪些pod了
template:模板,就是当前控制器创建pod所使用的模板,里面其实就是前一章学过的pod的定义
2、创建ReplicaSet
(1)创建pc-replicaset.yaml文件
[root@master ~]# vim pc-replicaset.yaml
[root@master ~]# cat pc-replicaset.yaml
apiVersion: apps/v1
kind: ReplicaSet
metadata:name: pc-replicasetnamespace: dev
spec:replicas: 3selector: matchLabels:app: nginx-podtemplate:metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1
[root@master ~]# kubectl apply -f pc-replicaset.yaml
replicaset.apps/pc-replicaset created
[root@master ~]# kubectl get rs pc-replicaset -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
pc-replicaset 3 3 3 8s nginx nginx:1.17.1 app=nginx-pod
[root@master ~]# kubectl get pod -n dev --show-labels
NAME READY STATUS RESTARTS AGE LABELS
pc-replicaset-g4crq 1/1 Running 0 75s app=nginx-pod
pc-replicaset-mmsr9 1/1 Running 0 75s app=nginx-pod
pc-replicaset-wgzwg 1/1 Running 0 75s app=nginx-pod
(2)扩缩容
edit编辑
[root@master ~]# kubectl edit rs pc-replicaset -n dev
replicaset.apps/pc-replicaset edited
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-replicaset-g4crq 1/1 Running 0 8m46s
pc-replicaset-mmsr9 1/1 Running 0 8m46s
pc-replicaset-vwnkr 1/1 Running 0 11s
pc-replicaset-wgzwg 1/1 Running 0 8m46s

scale命令,后面–replicas=n直接指定目标数量即可
[root@master ~]# kubectl scale rs pc-replicaset --replicas=2 -n dev
replicaset.apps/pc-replicaset scaled
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-replicaset-g4crq 1/1 Running 0 10m
pc-replicaset-wgzwg 1/1 Running 0 10m
(2)镜像升级(注意只会给后面创建的pod升级版本,已存在的版本保持不变)
# 编辑rs的容器镜像 - image: nginx:1.17.2
[root@master ~]# kubectl edit rs pc-replicaset -n dev
replicaset.apps/pc-replicaset edited
# 再次查看,发现镜像版本已经变更了
[root@master ~]# kubectl get rs -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
pc-replicaset 2 2 2 16m nginx nginx:1.17.2 app=nginx-pod
# 同样的道理,也可以使用命令完成这个工作# kubectl set image rs rs名称 容器=镜像版本 -n namespace
[root@master ~]# kubectl set image rs pc-replicaset nginx=nginx:1.17.1 -n dev
replicaset.apps/pc-replicaset image updated
# 再次查看,发现镜像版本已经变更了
[root@master ~]# kubectl get rs -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
pc-replicaset 2 2 2 17m nginx nginx:1.17.1 app=nginx-pod

(3)删除ReplicaSet
使用kubectl delete命令会删除此RS以及它管理的Pod
在kubernetes删除RS前,会将RS的replicasclear调整为0,等待所有的Pod被删除后,在执行RS对象的删除
[root@master ~]# kubectl delete rs pc-replicaset -n dev
replicaset.apps "pc-replicaset" deleted
[root@master ~]# kubectl get pod -n dev -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
nginx-6c45cbd8c5-7wxt6 1/1 Running 0 16m 172.16.104.25 node2 <none> <none>
nginx-6c45cbd8c5-tz458 1/1 Running 1 (150m ago) 4d 172.16.104.23 node2 <none> <none>
nginx-6c45cbd8c5-vrmdw 1/1 Running 1 (150m ago) 4d 172.16.166.148 node1 <none> <none>
#这里看到的是我之前创建的pod,不是用pc-replicaset.yaml文件创建的pod
# 如果希望仅仅删除RS对象(保留Pod),可以使用kubectl delete命令时添加--cascade=false选项(不推荐)
[root@master ~]# kubectl delete rs pc-replicaset -n dev
replicaset.apps "pc-replicaset" deleted
[root@master ~]# kubectl get pod -n dev -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
nginx-6c45cbd8c5-7wxt6 1/1 Running 0 16m 172.16.104.25 node2 <none> <none>
nginx-6c45cbd8c5-tz458 1/1 Running 1 (150m ago) 4d 172.16.104.23 node2 <none> <none>
nginx-6c45cbd8c5-vrmdw 1/1 Running 1 (150m ago) 4d 172.16.166.148 node1 <none> <none>
[root@master ~]# kubectl apply -f pc-replicaset.yaml
replicaset.apps/pc-replicaset created
[root@master ~]# kubectl delete rs pc-replicaset -n dev --cascade=false
warning: --cascade=false is deprecated (boolean value) and can be replaced with --cascade=orphan.
replicaset.apps "pc-replicaset" deleted
[root@master ~]# kubectl get rs -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
nginx-6c45cbd8c5 3 3 3 4d nginx nginx:latest pod-template-hash=6c45cbd8c5,run=nginx
[root@master ~]# kubectl get pod -n dev -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
pc-replicaset-ql4zv 1/1 Running 0 33s 172.16.104.27 node2 <none> <none>
pc-replicaset-tqr7s 1/1 Running 0 33s 172.16.166.152 node1 <none> <none>
pc-replicaset-xg4c7 1/1 Running 0 33s 172.16.166.153 node1 <none> <none>
# 也可以使用yaml直接删除(推荐)
[root@master ~]# kubectl apply -f pc-replicaset.yaml
replicaset.apps/pc-replicaset created
[root@master ~]# kubectl delete -f pc-replicaset.yaml
replicaset.apps "pc-replicaset" deleted
三、Deployment(Deploy)
为了更好的解决服务编排的问题,kubernetes在V1.2版本开始,引入了Deployment控制器。值得一提的是,这种控制器并不直接管理pod,而是通过管理ReplicaSet来管理Pod,即:Deployment管理ReplicaSet,ReplicaSet管理Pod。所以Deployment比ReplicaSet功能更加强大。

Deployment主要功能有下面几个:
-
支持ReplicaSet的所有功能
-
支持发布的停止、继续
-
支持滚动升级和回滚版本
1、Deployment的资源清单文件
apiVersion: apps/v1 # 版本号
kind: Deployment # 类型
metadata: # 元数据name: # rs名称 namespace: # 所属命名空间 labels: #标签controller: deploy
spec: # 详情描述replicas: 3 # 副本数量revisionHistoryLimit: 3 # 保留历史版本paused: false # 暂停部署,默认是falseprogressDeadlineSeconds: 600 # 部署超时时间(s),默认是600strategy: # 策略type: RollingUpdate # 滚动更新策略rollingUpdate: # 滚动更新maxSurge: 30% # 最大额外可以存在的副本数,可以为百分比,也可以为整数maxUnavailable: 30% # 最大不可用状态的 Pod 的最大值,可以为百分比,也可以为整数selector: # 选择器,通过它指定该控制器管理哪些podmatchLabels: # Labels匹配规则app: nginx-podmatchExpressions: # Expressions匹配规则- {key: app, operator: In, values: [nginx-pod]}template: # 模板,当副本数量不足时,会根据下面的模板创建pod副本metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1ports:- containerPort: 80
2、创建deployment
[root@master ~]# cat pc-deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:name: pc-deploymentnamespace: dev
spec: replicas: 3selector:matchLabels:app: nginx-podtemplate:metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1
[root@master ~]# kubectl apply -f pc-deployment.yaml
deployment.apps/pc-deployment created# 查看deployment# UP-TO-DATE 最新版本的pod的数量# AVAILABLE 当前可用的pod的数量
[root@master ~]# kubectl get deploy pc-deployment -n dev
NAME READY UP-TO-DATE AVAILABLE AGE
pc-deployment 3/3 3 3 10s# 查看rs# 发现rs的名称是在原来deployment的名字后面添加了一个10位数的随机串
[root@master ~]# kubectl get rs -n dev
NAME DESIRED CURRENT READY AGE
pc-deployment-6cb555c765 3 3 3 18s# 查看pod
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-6cb555c765-89gf2 1/1 Running 0 35s
pc-deployment-6cb555c765-kj7vn 1/1 Running 0 35s
pc-deployment-6cb555c765-l5jkf 1/1 Running 0 35s
2、扩缩容
# 变更副本数量为5个
[root@master ~]# kubectl scale deploy pc-deployment --replicas=5 -n dev
deployment.apps/pc-deployment scaled# 查看deployment
[root@master ~]# kubectl get deploy pc-deployment -n dev
NAME READY UP-TO-DATE AVAILABLE AGE
pc-deployment 5/5 5 5 4m26s# 查看pod
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-6cb555c765-7t7fc 1/1 Running 0 16s
pc-deployment-6cb555c765-89gf2 1/1 Running 0 4m34s
pc-deployment-6cb555c765-kj7vn 1/1 Running 0 4m34s
pc-deployment-6cb555c765-l5jkf 1/1 Running 0 4m34s
pc-deployment-6cb555c765-m5hkx 1/1 Running 0 16s# 编辑deployment的副本数量,修改spec:replicas: 2
[root@master ~]# kubectl edit deploy pc-deployment -n dev
deployment.apps/pc-deployment edited
# 查看pod
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-6cb555c765-7t7fc 1/1 Running 0 45s
pc-deployment-6cb555c765-l5jkf 1/1 Running 0 5m3s
3、镜像更新
deployment支持两种更新策略:重建更新和滚动更新,可以通过strategy指定策略类型,支持两个属性
strategy:指定新的Pod替换旧的Pod的策略, 支持两个属性:type:指定策略类型,支持两种策略Recreate:重建更新,在创建出新的Pod之前会先杀掉所有已存在的PodRollingUpdate:滚动更新,就是杀死一部分,就启动一部分,在更新过程中,存在两个版本PodrollingUpdate:当type为RollingUpdate时生效,用于为RollingUpdate设置参数,支持两个属性:maxUnavailable:用来指定在升级过程中不可用Pod的最大数量,默认为25%。maxSurge: 用来指定在升级过程中可以超过期望的Pod的最大数量,默认为25%。
3.1 重建更新
(1)编辑pc-deployment.yaml,在spec节点下添加更新策略
[root@master ~]# kubectl delete -f pc-deployment.yaml
deployment.apps "pc-deployment" deleted
[root@master ~]# vim pc-deployment.yaml
[root@master ~]# cat pc-deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:name: pc-deploymentnamespace: dev
spec:strategy: # 策略type: Recreate # 重建更新replicas: 3selector:matchLabels:app: nginx-podtemplate:metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1
[root@master ~]# vim pc-deployment.yaml
[root@master ~]# kubectl apply -f pc-deployment.yaml
deployment.apps/pc-deployment created
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-6cb555c765-cwkrk 1/1 Running 0 14s
pc-deployment-6cb555c765-dvh26 1/1 Running 0 14s
pc-deployment-6cb555c765-w24nv 1/1 Running 0 14s
(2)创建deploy进行验证
# 变更镜像
[root@master ~]# kubectl set image deployment pc-deployment nginx=nginx:1.17.2 -n dev
deployment.apps/pc-deployment image updated
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-5967bb44bb-8zqgk 1/1 Running 0 40s
pc-deployment-5967bb44bb-hbp5m 1/1 Running 0 40s
pc-deployment-5967bb44bb-jxzqc 1/1 Running 0 40s
(3)观察升级过程(变更之前、变更之后,先删除再创建)

3.2 滚动更新
(1)编辑pc-deployment.yaml,在spec节点下添加更新策略
[root@master ~]kubectl delete -f pc-deployment.yaml
deployment.apps "pc-deployment" deleted
[root@master ~]# cat pc-deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:name: pc-deploymentnamespace: dev
spec:strategy: # 策略type: RollingUpdate # 滚动更新策略rollingUpdate:maxSurge: 25%maxUnavailable: 25% replicas: 8selector:matchLabels:app: nginx-podtemplate:metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1
[root@master ~]# kubectl apply -f pc-deployment.yaml
deployment.apps/pc-deployment created
(2)创建deploy进行验证
# 变更镜像
[root@master ~]# kubectl set image deployment pc-deployment nginx=nginx:1.17.2 -n dev
deployment.apps/pc-deployment image updated
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-5967bb44bb-5rc2v 1/1 Running 0 4s
pc-deployment-5967bb44bb-796jq 1/1 Running 0 4s
pc-deployment-5967bb44bb-8ztmk 1/1 Running 0 4s
pc-deployment-5967bb44bb-gmpqb 0/1 ContainerCreating 0 1s
pc-deployment-5967bb44bb-hngnc 0/1 ContainerCreating 0 1s
pc-deployment-5967bb44bb-srvh2 0/1 ContainerCreating 0 1s
pc-deployment-5967bb44bb-vdbcd 0/1 ContainerCreating 0 2s
pc-deployment-5967bb44bb-w9xcg 1/1 Running 0 4s
pc-deployment-6cb555c765-98b2c 0/1 Terminating 0 26s
pc-deployment-6cb555c765-fm4gs 1/1 Running 0 26s
pc-deployment-6cb555c765-ggk24 0/1 Terminating 0 26s
pc-deployment-6cb555c765-t29vt 1/1 Running 0 26s
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-5967bb44bb-5rc2v 1/1 Running 0 19s
pc-deployment-5967bb44bb-796jq 1/1 Running 0 19s
pc-deployment-5967bb44bb-8ztmk 1/1 Running 0 19s
pc-deployment-5967bb44bb-gmpqb 1/1 Running 0 16s
pc-deployment-5967bb44bb-hngnc 1/1 Running 0 16s
pc-deployment-5967bb44bb-srvh2 1/1 Running 0 16s
pc-deployment-5967bb44bb-vdbcd 1/1 Running 0 17s
pc-deployment-5967bb44bb-w9xcg 1/1 Running 0 19s
(3)观察升级过程
更新镜像之前

更新镜像之后(因为设置的为25%,所以8个pod,一次操作2个pod)
新版本的pod创建完毕,就版本的pod销毁完毕# 中间过程是滚动进行的,也就是边销毁边创建

3.3 滚动更新的过程

镜像更新中rs的变化
# 查看rs,发现原来的rs的依旧存在,只是pod数量变为了0,而后又新产生了一个rs,pod数量为8
[root@master ~]# kubectl get rs -n dev
NAME DESIRED CURRENT READY AGE
pc-deployment-5967bb44bb 8 8 8 7m25s
pc-deployment-6cb555c765 0 0 0 7m47s
[root@master ~]# kubectl get rs -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
pc-deployment-5967bb44bb 8 8 8 8m53s nginx nginx:1.17.2 app=nginx-pod,pod-template-hash=5967bb44bb
pc-deployment-6cb555c765 0 0 0 9m15s nginx nginx:1.17.1 app=nginx-pod,pod-template-hash=6cb555c765
3.4 版本回退
deployment支持版本升级过程中的暂停、继续功能以及版本回退等诸多功能,下面具体来看.
kubectl rollout: 版本升级相关功能,支持下面的选项:
-
status 显示当前升级状态
-
history 显示 升级历史记录
-
pause 暂停版本升级过程
-
resume 继续已经暂停的版本升级过程
-
restart 重启版本升级过程
-
undo 回滚到上一级版本(可以使用–to-revision回滚到指定版本)
# 查看当前升级版本的状态
[root@master ~]# kubectl rollout status deploy pc-deployment -n dev
deployment "pc-deployment" successfully rolled out# 查看升级历史记录
[root@master ~]# kubectl rollout history deploy pc-deployment -n dev
deployment.apps/pc-deployment
REVISION CHANGE-CAUSE
1 <none>
2 <none>
# 可以发现有2次版本记录,说明完成过1次升级# 版本回滚# 这里直接使用--to-revision=1回滚到了1版本, 如果省略这个选项,就是回退到上个版本
[root@master ~]# kubectl rollout undo deploy pc-deployment --to-revision=1 -n dev
deployment.apps/pc-deployment rolled back# 查看发现,通过nginx镜像版本可以发现到了第一版
[root@master ~]# kubectl get deploy -n dev -o wide
NAME READY UP-TO-DATE AVAILABLE AGE CONTAINERS IMAGES SELECTOR
pc-deployment 8/8 8 8 18m nginx nginx:1.17.1 app=nginx-pod# 查看rs,发现第一次(版本一)rs中有8个pod运行
# 其实deployment之所以可是实现版本的回滚,就是通过记录下历史rs来实现的,
# 一旦想回滚到哪个版本,只需要将当前版本pod数量降为0,然后将回滚版本的pod提升为目标数量就可以了
[root@master ~]# kubectl get rs -n dev
NAME DESIRED CURRENT READY AGE
pc-deployment-5967bb44bb 0 0 0 17m
pc-deployment-6cb555c765 8 8 8 18m
3.5 金丝雀发布
Deployment控制器支持控制更新过程中的控制,如“暂停(pause)”或“继续(resume)”更新操作。
比如有一批新的Pod资源创建完成后立即暂停更新过程,此时,仅存在一部分新版本的应用,主体部分还是旧的版本。然后,再筛选一小部分的用户请求路由到新版本的Pod应用,继续观察能否稳定地按期望的方式运行。确定没问题之后再继续完成余下的Pod资源滚动更新,否则立即回滚更新操作。这就是所谓的金丝雀发布
# 更新deployment的版本,并配置暂停deployment
[root@master ~]# kubectl set image deploy pc-deployment nginx=nginx:1.17.4 -n dev && kubectl rollout pause deployment pc-deployment -n dev
deployment.apps/pc-deployment image updated
deployment.apps/pc-deployment paused#观察更新状态
[root@master ~]# kubectl rollout status deploy pc-deployment -n dev
Waiting for deployment "pc-deployment" rollout to finish: 4 out of 8 new replicas have been updated...# 监控更新的过程,可以看到已经新增了一个资源,但是并未按照预期的状态去删除一个旧的资源,就是因为使用了pause暂停命令
[root@master ~]# kubectl get rs -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
pc-deployment-5967bb44bb 0 0 0 33m nginx nginx:1.17.2 app=nginx-pod,pod-template-hash=5967bb44bb
pc-deployment-6cb555c765 6 6 6 33m nginx nginx:1.17.1 app=nginx-pod,pod-template-hash=6cb555c765
pc-deployment-6db6cc7d48 4 4 4 66s nginx nginx:1.17.4 app=nginx-pod,pod-template-hash=6db6cc7d48
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-6cb555c765-cbwjl 1/1 Running 0 16m
pc-deployment-6cb555c765-dpbqd 1/1 Running 0 16m
pc-deployment-6cb555c765-jwf46 1/1 Running 0 16m
pc-deployment-6cb555c765-pgx7w 1/1 Running 0 16m
pc-deployment-6cb555c765-q4cln 1/1 Running 0 16m
pc-deployment-6cb555c765-w4ltm 1/1 Running 0 16m
pc-deployment-6db6cc7d48-c6jvv 1/1 Running 0 92s
pc-deployment-6db6cc7d48-j2rb6 1/1 Running 0 91s
pc-deployment-6db6cc7d48-p97cc 1/1 Running 0 91s
pc-deployment-6db6cc7d48-zsg68 1/1 Running 0 92s# 确保更新的pod没问题了,继续更新
[root@master ~]# kubectl rollout resume deploy pc-deployment -n dev
deployment.apps/pc-deployment resumed# 查看最后的更新情况
[root@master ~]# kubectl get rs -n dev -o wide
NAME DESIRED CURRENT READY AGE CONTAINERS IMAGES SELECTOR
pc-deployment-5967bb44bb 0 0 0 33m nginx nginx:1.17.2 app=nginx-pod,pod-template-hash=5967bb44bb
pc-deployment-6cb555c765 0 0 0 34m nginx nginx:1.17.1 app=nginx-pod,pod-template-hash=6cb555c765
pc-deployment-6db6cc7d48 8 8 8 115s nginx nginx:1.17.4 app=nginx-pod,pod-template-hash=6db6cc7d48
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-deployment-6db6cc7d48-9cr89 1/1 Running 0 24s
pc-deployment-6db6cc7d48-c6jvv 1/1 Running 0 2m10s
pc-deployment-6db6cc7d48-j2rb6 1/1 Running 0 2m9s
pc-deployment-6db6cc7d48-k2dml 1/1 Running 0 24s
pc-deployment-6db6cc7d48-nttxv 1/1 Running 0 24s
pc-deployment-6db6cc7d48-p97cc 1/1 Running 0 2m9s
pc-deployment-6db6cc7d48-xm9pv 1/1 Running 0 24s
pc-deployment-6db6cc7d48-zsg68 1/1 Running 0 2m10s
删除Deployment
[root@master ~]# kubectl delete -f pc-deployment.yaml
deployment.apps "pc-deployment" deleted
[root@master ~]# kubectl get pods -n dev
No resources found in dev namespace.
[root@master ~]# kubectl get rs -n dev
No resources found in dev namespace.
[root@master ~]# kubectl get deployment -n dev
No resources found in dev namespace.
四、Horizontal Pod Autoscaler(HPA)
在前面的课程中,我们已经可以实现通过手工执行kubectl scale命令实现Pod扩容或缩容,但是这显然不符合Kubernetes的定位目标–自动化、智能化。 Kubernetes期望可以实现通过监测Pod的使用情况,实现pod数量的自动调整,于是就产生了Horizontal Pod Autoscaler(HPA)这种控制器。
HPA可以获取每个Pod利用率,然后和HPA中定义的指标进行对比,同时计算出需要伸缩的具体值,最后实现Pod的数量的调整。其实HPA与之前的Deployment一样,也属于一种Kubernetes资源对象,它通过追踪分析RC控制的所有目标Pod的负载变化情况,来确定是否需要针对性地调整目标Pod的副本数,这是HPA的实现原理。

1、安装metrics-server(components.yaml)
[root@master ~]# yum -y install git # 安装git
[root@master ~]# rz -E #有components。yaml文件,直接拖进来了
rz waiting to receive.
[root@master ~]# vim components.yaml # 安装metrics-server
[root@master ~]# kubectl apply -f components.yaml # 查看pod运行情况
[root@master ~]# kubectl get pod -n kube-system
NAME READY STATUS RESTARTS AGE
calico-kube-controllers-9d57d8f49-5zfvc 1/1 Running 4 (7h25m ago) 6d22h
calico-node-nr2ml 1/1 Running 4 (7h24m ago) 6d22h
calico-node-rbpwd 1/1 Running 4 (7h25m ago) 6d22h
calico-node-wfrtx 1/1 Running 4 (7h24m ago) 6d22h
coredns-6554b8b87f-6q2k6 1/1 Running 4 (7h25m ago) 6d23h
coredns-6554b8b87f-8sd7d 1/1 Running 4 (7h25m ago) 6d23h
etcd-master 1/1 Running 4 (7h25m ago) 6d23h
kube-apiserver-master 1/1 Running 4 (7h25m ago) 6d23h
kube-controller-manager-master 1/1 Running 5 (7h25m ago) 6d23h
kube-proxy-7j4jz 1/1 Running 4 (7h25m ago) 6d23h
kube-proxy-95t2g 1/1 Running 4 (7h24m ago) 6d22h
kube-proxy-pcfqn 1/1 Running 4 (7h24m ago) 6d22h
kube-scheduler-master 1/1 Running 4 (7h25m ago) 6d23h
metrics-server-dfb9bd598-x86ls 1/1 Running 0 32s

# 使用kubectl top node 查看资源使用情况
[root@master ~]# kubectl top nodes
NAME CPU(cores) CPU% MEMORY(bytes) MEMORY%
master 301m 7% 2353Mi 62%
node1 116m 2% 1397Mi 36%
node2 123m 3% 1447Mi 38%
[root@master ~]# kubectl top pods -n kube-system
NAME CPU(cores) MEMORY(bytes)
calico-kube-controllers-9d57d8f49-5zfvc 4m 72Mi
calico-node-nr2ml 36m 193Mi
calico-node-rbpwd 57m 192Mi
calico-node-wfrtx 35m 194Mi
coredns-6554b8b87f-6q2k6 2m 24Mi
coredns-6554b8b87f-8sd7d 2m 65Mi
etcd-master 22m 177Mi
kube-apiserver-master 55m 407Mi
kube-controller-manager-master 15m 138Mi
kube-proxy-7j4jz 1m 72Mi
kube-proxy-95t2g 1m 72Mi
kube-proxy-pcfqn 1m 70Mi
kube-scheduler-master 5m 71Mi
metrics-server-dfb9bd598-x86ls 3m 29Mi
# 至此,metrics-server安装完成
2、准备deployment和service
(1)创建pc-hpa-pod.yaml文件
[root@master ~]# cat pc-hpa-pod.yaml
apiVersion: apps/v1
kind: Deployment
metadata:name: nginxnamespace: dev
spec:strategy: # 策略type: RollingUpdate # 滚动更新策略replicas: 1selector:matchLabels:app: nginx-podtemplate:metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1resources: # 资源配额limits: # 限制资源(上限)cpu: "1" # 限制资源(上限)requests: # 请求资源(下限)cpu: "100m" # CPU限制,单位是core数
[root@master ~]# kubectl apply -f pc-hpa-pod.yaml
deployment.apps/nginx created
# 创建service
[root@master ~]# kubectl expose deployment nginx --type=NodePort --port=80 -n dev
service/nginx exposed
# 查看
[root@master ~]# kubectl get deployment,pod,svc -n dev
NAME READY UP-TO-DATE AVAILABLE AGE
deployment.apps/nginx 1/1 1 1 105sNAME READY STATUS RESTARTS AGE
pod/nginx-fcdb96fc4-tx5km 1/1 Running 0 105sNAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
service/nginx NodePort 10.109.175.68 <none> 80:30839/TCP 20s
3、部署HPA
(1)创建pc-hpa.yaml文件
[root@master ~]# cat pc-hpa.yaml
apiVersion: autoscaling/v1
kind: HorizontalPodAutoscaler
metadata:name: pc-hpanamespace: dev
spec:minReplicas: 1maxReplicas: 10targetCPUUtilizationPercentage: 3 scaleTargetRef: apiVersion: apps/v1kind: Deploymentname: nginx
[root@master ~]# kubectl apply -f pc-hpa.yaml
horizontalpodautoscaler.autoscaling/pc-hpa created
[root@master ~]# kubectl get hpa -n dev
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
pc-hpa Deployment/nginx <unknown>/3% 1 10 0 15s
[root@master ~]# kubectl get hpa -n dev
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
pc-hpa Deployment/nginx 0%/3% 1 10 1 22s
4、测试
使用压测工具对service地址进行压测,
while :;do curl http://127.0.0.1:30839;done
[root@node1 ~]# while :;do curl http://127.0.0.1:30839;done
然后通过控制台查看hpa和pod的变化
[root@master ~]# kubectl get hpa -n dev -w
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
pc-hpa Deployment/nginx 15%/3% 1 10 1 80s
pc-hpa Deployment/nginx 23%/3% 1 10 4 90s
^C[root@master ~]# kubectl get deployment -n dev -w
NAME READY UP-TO-DATE AVAILABLE AGE
nginx 7/7 7 7 4m57s
nginx 7/10 7 7 5m9s
nginx 7/10 7 7 5m9s
nginx 7/10 7 7 5m9s
nginx 7/10 10 7 5m9s
nginx 8/10 10 8 5m11s
nginx 9/10 10 9 5m12s
nginx 10/10 10 10 5m12s
取消测压
[root@master ~]# kubectl get deployment -n dev
NAME READY UP-TO-DATE AVAILABLE AGE
nginx 1/1 1 1 12m
[root@master ~]# kubectl get hpa -n dev
NAME REFERENCE TARGETS MINPODS MAXPODS REPLICAS AGE
pc-hpa Deployment/nginx 0%/3% 1 10 1 9m31s
五、DaemonSet(DS)
DaemonSet类型的控制器可以保证在集群中的每一台(或指定)节点上都运行一个副本。一般适用于日志收集、节点监控等场景。也就是说,如果一个Pod提供的功能是节点级别的(每个节点都需要且只需要一个),那么这类Pod就适合使用DaemonSet类型的控制器创建。

DaemonSet控制器的特点:
-
每当向集群中添加一个节点时,指定的 Pod 副本也将添加到该节点上
-
当节点从集群中移除时,Pod 也就被垃圾回收了
1、DaemonSet的资源清单文件
apiVersion: apps/v1 # 版本号
kind: DaemonSet # 类型
metadata: # 元数据name: # rs名称 namespace: # 所属命名空间 labels: #标签controller: daemonset
spec: # 详情描述revisionHistoryLimit: 3 # 保留历史版本updateStrategy: # 更新策略type: RollingUpdate # 滚动更新策略rollingUpdate: # 滚动更新maxUnavailable: 1 # 最大不可用状态的 Pod 的最大值,可以为百分比,也可以为整数selector: # 选择器,通过它指定该控制器管理哪些podmatchLabels: # Labels匹配规则app: nginx-podmatchExpressions: # Expressions匹配规则- {key: app, operator: In, values: [nginx-pod]}template: # 模板,当副本数量不足时,会根据下面的模板创建pod副本metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1ports:- containerPort: 80
2、创建pc-daemonset.yaml
[root@master ~]# cat pc-daemonset.yaml
apiVersion: apps/v1
kind: DaemonSet
metadata:name: pc-daemonsetnamespace: dev
spec: selector:matchLabels:app: nginx-podtemplate:metadata:labels:app: nginx-podspec:containers:- name: nginximage: nginx:1.17.1
[root@master ~]# kubectl apply -f pc-daemonset.yaml
daemonset.apps/pc-daemonset created
[root@master ~]# kubectl get ds -n dev -o wide
NAME DESIRED CURRENT READY UP-TO-DATE AVAILABLE NODE SELECTOR AGE CONTAINERS IMAGES SELECTOR
pc-daemonset 2 2 2 2 2 <none> 14s nginx nginx:1.17.1 app=nginx-pod
[root@master ~]# kubectl get pods -n dev -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
pc-daemonset-h5l5j 1/1 Running 0 39s 172.16.104.55 node2 <none> <none>
pc-daemonset-wsqb4 1/1 Running 0 39s 172.16.166.183 node1 <none> <none>
[root@master ~]# kubectl delete -f pc-daemonset.yaml
daemonset.apps "pc-daemonset" deleted
六、Job
Job,主要用于负责**批量处理(一次要处理指定数量任务)短暂的一次性(每个任务仅运行一次就结束)**任务。Job特点如下:
-
当Job创建的pod执行成功结束时,Job将记录成功结束的pod数量
-
当成功结束的pod达到指定的数量时,Job将完成执行

1、Job的资源清单文件
apiVersion: batch/v1 # 版本号
kind: Job # 类型
metadata: # 元数据name: # rs名称 namespace: # 所属命名空间 labels: #标签controller: job
spec: # 详情描述completions: 1 # 指定job需要成功运行Pods的次数。默认值: 1parallelism: 1 # 指定job在任一时刻应该并发运行Pods的数量。默认值: 1activeDeadlineSeconds: 30 # 指定job可运行的时间期限,超过时间还未结束,系统将会尝试进行终止。backoffLimit: 6 # 指定job失败后进行重试的次数。默认是6manualSelector: true # 是否可以使用selector选择器选择pod,默认是falseselector: # 选择器,通过它指定该控制器管理哪些podmatchLabels: # Labels匹配规则app: counter-podmatchExpressions: # Expressions匹配规则- {key: app, operator: In, values: [counter-pod]}template: # 模板,当副本数量不足时,会根据下面的模板创建pod副本metadata:labels:app: counter-podspec:restartPolicy: Never # 重启策略只能设置为Never或者OnFailurecontainers:- name: counterimage: busybox:1.30command: ["bin/sh","-c","for i in 9 8 7 6 5 4 3 2 1; do echo $i;sleep 2;done"]
关于重启策略设置的说明:如果指定为OnFailure,则job会在pod出现故障时重启容器,而不是创建pod,failed次数不变如果指定为Never,则job会在pod出现故障时创建新的pod,并且故障pod不会消失,也不会重启,failed次数加1如果指定为Always的话,就意味着一直重启,意味着job任务会重复去执行了,当然不对,所以不能设置为Always
2、创建pc-job.yaml
[root@master ~]# cat pc-job.yaml
apiVersion: batch/v1
kind: Job
metadata:name: pc-jobnamespace: dev
spec:manualSelector: trueselector:matchLabels:app: counter-podtemplate:metadata:labels:app: counter-podspec:restartPolicy: Nevercontainers:- name: counterimage: busybox:1.30command: ["bin/sh","-c","for i in 9 8 7 6 5 4 3 2 1; do echo $i;sleep 3;done"]
[root@master ~]# kubectl apply -f pc-job.yaml
job.batch/pc-job created
# 通过观察pod状态可以看到,pod在运行完毕任务后,就会变成Completed状态
[root@master ~]# kubectl get job -n dev -o wide -w
NAME COMPLETIONS DURATION AGE CONTAINERS IMAGES SELECTOR
pc-job 0/1 16s 16s counter busybox:1.30 app=counter-pod
pc-job 0/1 31s 31s counter busybox:1.30 app=counter-pod
pc-job 0/1 32s 32s counter busybox:1.30 app=counter-pod
pc-job 1/1 32s 32s counter busybox:1.30 app=counter-pod
[root@master ~]# kubectl get pods -n dev -w
NAME READY STATUS RESTARTS AGE
pc-job-ds2k4 0/1 Completed 0 45s
3、调整下pod运行的总数量和并行数量 即:在spec下设置下面两个选项
completions: 6 指定job需要成功运行Pods的次数为6
parallelism: 3 指定job并发运行Pods的数量为3
然后重新运行job,观察效果,此时会发现,job会每次运行3个pod,总共执行了6个pod
(1)修改文件
[root@master ~]# cat pc-job.yaml
apiVersion: batch/v1
kind: Job
metadata:name: pc-jobnamespace: dev
spec:completions: 6parallelism: 3manualSelector: trueselector:matchLabels:app: counter-podtemplate:metadata:labels:app: counter-podspec:restartPolicy: Nevercontainers:- name: counterimage: busybox:1.30command: ["bin/sh","-c","for i in 9 8 7 6 5 4 3 2 1; do echo $i;sleep 3;done"]
[root@master ~]# kubectl apply -f pc-job.yaml
job.batch/pc-job created
(2)动态监控(发现,job会每次运行3个pod,总共执行了6个pod)


[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-job-4x5qd 1/1 Running 0 26s
pc-job-9j697 1/1 Running 0 26s
pc-job-v95qh 1/1 Running 0 26s
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-job-4x5qd 0/1 Completed 0 43s
pc-job-5mp2v 1/1 Running 0 9s
pc-job-88mw6 1/1 Running 0 10s
pc-job-9j697 0/1 Completed 0 43s
pc-job-v95qh 0/1 Completed 0 43s
pc-job-zsmnq 1/1 Running 0 10s
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-job-4x5qd 0/1 Completed 0 77s
pc-job-5mp2v 0/1 Completed 0 43s
pc-job-88mw6 0/1 Completed 0 44s
pc-job-9j697 0/1 Completed 0 77s
pc-job-v95qh 0/1 Completed 0 77s
pc-job-zsmnq 0/1 Completed 0 44s
(3)删除Job
[root@master ~]# kubectl delete -f pc-job.yaml
job.batch "pc-job" deleted
七、CronJob(CJ)
CronJob控制器以Job控制器资源为其管控对象,并借助它管理pod资源对象,Job控制器定义的作业任务在其控制器资源创建之后便会立即执行,但CronJob可以以类似于Linux操作系统的周期性任务作业计划的方式控制其运行时间点及重复运行的方式。也就是说,CronJob可以在特定的时间点(反复的)去运行job任务。

1、CronJob的资源清单文件
apiVersion: batch/v1 # 版本号
kind: CronJob # 类型
metadata: # 元数据name: # rs名称 namespace: # 所属命名空间 labels: #标签controller: cronjob
spec: # 详情描述schedule: # cron格式的作业调度运行时间点,用于控制任务在什么时间执行concurrencyPolicy: # 并发执行策略,用于定义前一次作业运行尚未完成时是否以及如何运行后一次的作业failedJobHistoryLimit: # 为失败的任务执行保留的历史记录数,默认为1successfulJobHistoryLimit: # 为成功的任务执行保留的历史记录数,默认为3startingDeadlineSeconds: # 启动作业错误的超时时长jobTemplate: # job控制器模板,用于为cronjob控制器生成job对象;下面其实就是job的定义metadata:spec:completions: 1parallelism: 1activeDeadlineSeconds: 30backoffLimit: 6manualSelector: trueselector:matchLabels:app: counter-podmatchExpressions: 规则- {key: app, operator: In, values: [counter-pod]}template:metadata:labels:app: counter-podspec:restartPolicy: Never containers:- name: counterimage: busybox:1.30command: ["bin/sh","-c","for i in 9 8 7 6 5 4 3 2 1; do echo $i;sleep 20;done"]
需要重点解释的几个选项:
schedule: cron表达式,用于指定任务的执行时间*/1 * * * *<分钟> <小时> <日> <月份> <星期>分钟 值从 0 到 59.小时 值从 0 到 23.日 值从 1 到 31.月 值从 1 到 12.星期 值从 0 到 6, 0 代表星期日多个时间可以用逗号隔开; 范围可以用连字符给出;*可以作为通配符; /表示每...
concurrencyPolicy:Allow: 允许Jobs并发运行(默认)Forbid: 禁止并发运行,如果上一次运行尚未完成,则跳过下一次运行Replace: 替换,取消当前正在运行的作业并用新作业替换它
2、创建pc-cronjob.yaml
[root@master ~]# cat pc-cronjob.yaml
apiVersion: batch/v1
kind: CronJob
metadata:name: pc-cronjobnamespace: devlabels:controller: cronjob
spec:schedule: "*/1 * * * *"jobTemplate:metadata:spec:template:spec:restartPolicy: Nevercontainers:- name: counterimage: busybox:1.30command: ["bin/sh","-c","for i in 9 8 7 6 5 4 3 2 1; do echo $i;sleep 3;done"]
[root@master ~]# kubectl apply -f pc-cronjob.yaml
cronjob.batch/pc-cronjob created
# 查看cronjob
[root@master ~]# kubectl get cronjobs -n dev
NAME SCHEDULE SUSPEND ACTIVE LAST SCHEDULE AGE
pc-cronjob */1 * * * * False 0 40s 99s# 查看job
[root@master ~]# kubectl get jobs -n dev
NAME COMPLETIONS DURATION AGE
pc-cronjob-29370829 1/1 32s 57s
[root@master ~]# kubectl get jobs -n dev
NAME COMPLETIONS DURATION AGE
pc-cronjob-29370829 1/1 32s 66s
pc-cronjob-29370830 0/1 6s 6s
[root@master ~]# kubectl get jobs -n dev
NAME COMPLETIONS DURATION AGE
pc-cronjob-29370829 1/1 32s 2m25s
pc-cronjob-29370830 1/1 32s 85s
pc-cronjob-29370831 0/1 25s 25s# 查看pod(第四个运行成功后会删除第一个pod,保持三个的数量)
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-cronjob-29370829-6p8s2 0/1 Completed 0 84s
pc-cronjob-29370830-xzr95 1/1 Running 0 24s
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-cronjob-29370829-6p8s2 0/1 Completed 0 2m39s
pc-cronjob-29370830-xzr95 0/1 Completed 0 99s
pc-cronjob-29370831-brbll 0/1 Completed 0 39s
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-cronjob-29370829-6p8s2 0/1 Completed 0 3m18s
pc-cronjob-29370830-xzr95 0/1 Completed 0 2m18s
pc-cronjob-29370831-brbll 0/1 Completed 0 78s
pc-cronjob-29370832-w49rk 1/1 Running 0 18s
[root@master ~]# kubectl get pods -n dev
NAME READY STATUS RESTARTS AGE
pc-cronjob-29370830-xzr95 0/1 Completed 0 2m34s
pc-cronjob-29370831-brbll 0/1 Completed 0 94s
pc-cronjob-29370832-w49rk 0/1 Completed 0 34s# 删除cronjob
[root@master ~]# kubectl delete -f pc-cronjob.yaml
cronjob.batch "pc-cronjob" deleted
