Kubernetes

k0sctl()便IaC
Service Mesh L7 Network Policy
便
L7Pod
Multus使miscord-dev/tetrapod
LoadBalancer Service - PureLB w/ BIRD
PureLB LoadBalancer Service
BIRD
PureLBOSPF
ingress-nginxTLS
ingress-nginx100annotationContourEnvoy
IngressRoute Kubernetes Gateway API HTTPRoute
- External Secrets Operator
GCP Secret Manager ClusterSecretStore 1
GCP Secret Manager IAM ClusterSecretStore
ClusterSecretStore 使 Admission Webhook
OIDC Provider - dex
dex
Auth0 OIDC groups claim
Auth0 OIDC Provider

(MUST) apply
(MUST) Pull-based
apply kubectl
cue GitHub - zoetrope/argocd-cue
Pros
ApplicationSet
Git
Cons
RBAC
CSV
AppProject
Flux CD (v2)
Toolkit Component https://fluxcd.io/flux/components/
Pros
Source (Kustomize, Helm, )
CRD Controller
ServiceAccount
RBAC
Cons
Kubernetes
使
CSI
使
MayaStor使cStorJiva使
MayaStorNVMe-OFcStorJivaiSCSI使
KubernetesLocal Storage
PodPVC
LVM使
LVM
Topo
NASiSCSI
()
(MUST)
(SHOULD)
SecretSecret
Ingress Controller ()
Service Mesh
oauth2-proxy
TLS
TLS
Cipher Suites
TLS
Dashboard
使
ForwardAuth Middleware
oauth2-proxy
TLSOption TLS
p384, p521 使
x448 使
TLS1.2 ciphers
TLS1.3 ciphers
cipher suite
Go
annotation
annotation Ingress
nginx
oauth2-proxy使 /oauth2 Ingress Ingress
IngressIngress
CiliumEnvoyConfig
TLS
Contour Kong ProxyAmbassodor API Gateway Envoy
arm64
HTTPProxy / Kubernetes Gateway API
Envoy
ext_authz gRPC
TLS
TLS1.2 ciphers
ECDSA256 使
Envoy
gRPC-WebgRPC()
Cilium hubble-ui
Service Service ClusterIP Service Endpoint L7
Service L4
Cilium Service Mesh
Cilium Service Mesh Service L4 L7 /Service ClusterIP Endpoint
LoadBalancer Service provider ()
PureLB w/ BIRD()
(MUST)
ECMP
(SHOULD) IPv6使
()L3IX2105BGPIPv6OSPF使
IPv4
FRR Setting
Cilium LoadBalancer
CIliumBGPPeeringPolicyConfigMap
gobgpBGP
BGP使