3๋‹จ๊ณ„: ASM ์„ค์น˜

ASM ์„ค์น˜

Apigee Hybrid๋Š” Anthos Service Mesh(ASM)์™€ ํ•จ๊ป˜ ์ œ๊ณต๋œ Istio ๋ฐฐํฌํŒ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ํด๋Ÿฌ์Šคํ„ฐ์— ASM์„ ์„ค์น˜ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.

์ง€์›๋˜๋Š” ASM ๋ฒ„์ „

  • ์ƒˆ๋กœ์šด ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ๋ฒ„์ „ 1.4.4๋ฅผ ์„ค์น˜ํ•˜๋ ค๋ฉด ASM ๋ฒ„์ „ 1.7.x๋ฅผ ์„ค์น˜ํ•˜์„ธ์š”.
  • ์ด์ „ ๋ฒ„์ „์˜ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ์—์„œ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜๋Š” ๊ฒฝ์šฐ ASM ๋ฒ„์ „ 1.6.x๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

ASM ์„ค์ • ๋ฐ ๊ตฌ์„ฑ ๋‹จ๊ณ„ ์ˆ˜ํ–‰

ASM ์„ค์น˜๋ฅผ ์™„๋ฃŒํ•˜๋ ค๋ฉด ๋จผ์ € ASM ๋ฌธ์„œ์˜ ASM ๊ด€๋ จ ์„ค์ • ๋ฐ ๊ตฌ์„ฑ ๋‹จ๊ณ„๋ฅผ ๋”ฐ๋ผ์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ ํด๋Ÿฌ์Šคํ„ฐ์— ๊ตฌ์„ฑ์„ ์ ์šฉํ•˜๊ธฐ ์ „์— ์—ฌ๊ธฐ๋กœ ๋Œ์•„์™€ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ์ „์šฉ ๊ตฌ์„ฑ์„ ์™„๋ฃŒํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ASM ์„ค์น˜ ๋ฐ ๊ตฌ์„ฑ ์•ˆ๋‚ด๋Š” ํ”Œ๋žซํผ์— ๋”ฐ๋ผ ๋‹ค๋ฆ…๋‹ˆ๋‹ค. ๋‹ค์Œ์—์„œ ํ”Œ๋žซํผ์— ๋งž๋Š” ๋‹จ๊ณ„๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

GKE

  1. ASM ์„ค์ • ๋ฐ ๊ตฌ์„ฑ ๋‹จ๊ณ„๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.
  2. ASM ์„ค์ • ๋ฐ ๊ตฌ์„ฑ ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ–ˆ์œผ๋ฉด ๋‹ค์Œ ์„น์…˜์œผ๋กœ ์ด๋™ํ•˜์—ฌ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ๊ตฌ์„ฑ ๋ฐ ASM ์„ค์น˜ ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•˜์„ธ์š”.

์ตœ์ข… ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ๊ตฌ์„ฑ ์ˆ˜ํ–‰ ๋ฐ ASM ์„ค์น˜

๋งˆ์ง€๋ง‰์œผ๋กœ istio-operator.yaml ํŒŒ์ผ์— ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ์ „์šฉ ๊ตฌ์„ฑ์„ ์ถ”๊ฐ€ํ•˜๊ณ  ASM์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

  1. ASM ์„ค์น˜ ๋ฃจํŠธ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ: 1.7.3-asm.6
  2. ํŽธ์ง‘๊ธฐ์—์„œ istio-operator.yaml ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
    • ASM 1.7.x: ./asm/istio/istio-operator.yaml
    • ASM 1.6.x: ./asm/cluster/istio-operator.yaml
  3. meshConfig: ์„น์…˜ ์•„๋ž˜, values: ๋ฐ”๋กœ ์œ„์— ์žˆ๋Š” istio-operator.yaml ํŒŒ์ผ์˜ spec:components ์Šคํƒ ์ž๋ฅผ ์ถ”๊ฐ€ ๋˜๋Š” ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ reserved_static_ip๋Š” ๋Ÿฐํƒ€์ž„ ์ธ๊ทธ๋ ˆ์Šค ๊ฒŒ์ดํŠธ์›จ์ด๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค. ์˜ˆ์•ฝ๋œ ๊ณ ์ • IP ์ฃผ์†Œ๊ฐ€ ์—†๋‹ค๋ฉด ์ด ๋น ๋ฅธ ์‹œ์ž‘์—์„œ LoadBalancerIP ์†์„ฑ์„ ์ œ์™ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    ๋ณต์‚ฌํ•  ํ…์ŠคํŠธ

      components:
        ingressGateways:
        - name: istio-ingressgateway
          enabled: true
          k8s:
            service:
              type: LoadBalancer
              loadBalancerIP: static_ip # If you do not have a reserved static IP, leave this out.
              ports:
              - name: status-port
                port: 15021 # for ASM 1.7.x and above, else 15020
                targetPort: 15021 # for ASM 1.7.x and above, else 15020
              - name: http2
                port: 80
                targetPort: 8080
              - name: https
                port: 443
                targetPort: 8443
    

    ๋ฐฐ์น˜ ์˜ˆ์‹œ

    ๊ฐ€๋…์„ฑ์„ ์œ„ํ•ด ์ค„ ๋ฐ”๊ฟˆ์ด ์‚ฝ์ž…๋จ

    apiVersion: install.istio.io/v1alpha1
    kind: IstioOperator
    metadata:
      clusterName: "hybrid-example/us-central1/example-cluster" # {"$ref":"#/definitions/io.k8s.cli.substitutions.cluster-name"}
    spec:
      profile: asm
      hub: gcr.io/gke-release/asm # {"$ref":"#/definitions/io.k8s.cli.setters.anthos.servicemesh.hub"}
      tag: 1.5.7-asm.0 # {"$ref":"#/definitions/io.k8s.cli.setters.anthos.servicemesh.tag"}
      meshConfig:
        defaultConfig:
          proxyMetadata:
            GCP_METADATA: "hybrid-example|123456789123|example-cluster|us-central1" #
              {"$ref":"#/definitions/io.k8s.cli.substitutions.gke-metadata"}
    
      components:
        pilot:
          k8s:
            hpaSpec:
              maxReplicas: 2
        ingressGateways:
        - name: istio-ingressgateway
          enabled: true
          k8s:
            service:
              type: LoadBalancer
              loadBalancerIP: 123.234.56.78
              ports:
              - name: status-port
                port: 15021 # for ASM 1.7.x and above, else 15020
                targetPort: 15021 # for ASM 1.7.x and above, else 15020
              - name: http2
                port: 80
                targetPort: 8080
              - name: https
                port: 443
                targetPort: 8443
            hpaSpec:
              maxReplicas: 2
      values:
        .
        .
        .
  4. ์ด์ „์— ์‚ฌ์šฉํ•œ ASM ๋ฌธ์„œ๋กœ ๋Œ์•„๊ฐ€์„œ ASM ์„ค์น˜๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค(ํด๋Ÿฌ์Šคํ„ฐ์— istio-operator.yaml ํŒŒ์ผ์„ ์„ค์น˜ํ•˜๊ฑฐ๋‚˜ ์ ์šฉ). ASM 1.6์„ ์‚ฌ์šฉ ์ค‘์ด๊ณ  ์„ ํƒ๊ถŒ์ด ์žˆ๋Š” ๊ฒฝ์šฐ PERMISSIVE mTLS๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

GKE On-Prem

ASM ์„ค์ • ๋ฐ ๋‹ค์šด๋กœ๋“œ

ASM ๋ฌธ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ™˜๊ฒฝ์„ ์„ค์ •ํ•˜๊ณ  ASM์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

  1. ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์ž์„ธํžˆ ์ฝ์–ด๋ณด์„ธ์š”. ASM ๋ฌธ์„œ์— ๋‚˜์—ด๋œ ๋ช‡ ๊ฐ€์ง€ ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„ ์—ฌ๊ธฐ๋กœ ๋Œ์•„์™€์„œ ์„ค์น˜๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.
  2. ์˜จํ”„๋ ˆ๋ฏธ์Šค์— Anthos Service Mesh ์„ค์น˜๋กœ ์ด๋™ํ•˜์—ฌ istio-system ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๋งŒ๋“ค๊ธฐ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋“  ASM ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„ ๋‹ค์Œ ์„น์…˜์ธ ์•„๋ž˜์˜ ๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ

ASM ์„ค์น˜ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ’€์—ˆ์œผ๋ฉด, ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๊ณ„์†ํ•ฉ๋‹ˆ๋‹ค.

  1. ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ‘ผ Istio ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. 1.7.3-asm.6).
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ your_static_ip๋Š” Istio ์ธ๊ทธ๋ ˆ์Šค ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ณ ์ • IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค. ๊ณ ์ • IP ์ฃผ์†Œ๊ฐ€ ์˜ˆ์•ฝ๋˜์ง€ ์•Š์•˜์œผ๋ฉด --set values.gateways.istio-ingressgateway.loadBalancerIP ์ค„์„ ๊ทธ๋Œ€๋กœ ๋‘ก๋‹ˆ๋‹ค.
    ./bin/istioctl install --set profile=asm-multicloud \
     --set values.gateways.istio-ingressgateway.loadBalancerIP=your_static_IP
  3. ๋งˆ์ง€๋ง‰์œผ๋กœ ASM ๋ฌธ์„œ๋กœ ๋Œ์•„๊ฐ€ ์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ํ™•์ธํ•˜์—ฌ ์„ค์น˜๋ฅผ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

ASM ์„ค์น˜ ๋งž์ถค์„ค์ •

์ง€๊ธˆ ์ˆ˜ํ–‰ํ•œ ASM ์„ค์น˜๋Š” ์ตœ์†Œ ์„ค์น˜์ด๋ฉฐ, ๊ธฐ๋ณธ ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ์œ„ํ•ด Apigee Hybrid๋ฅผ ํ…Œ์ŠคํŠธํ•˜๊ณ  ์‚ฌ์šฉํ•˜๋Š” ๋ฐ์—๋Š” ์ถฉ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ๋ถ€ํ•˜ ๋ถ„์‚ฐ๊ธฐ ํฌํŠธ ๋ฒˆํ˜ธ ์ถ”๊ฐ€, ์‚ญ์ œ ๋˜๋Š” ์ˆ˜์ •๊ณผ ๊ฐ™์€ ๊ณ ๊ธ‰ ์‚ฌ์šฉ ์‚ฌ๋ก€ ํ•ด๊ฒฐ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์„ ํƒ ๊ธฐ๋Šฅ ์‚ฌ์šฉ ์„ค์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์š”์•ฝ

cert-manager์™€ ASM์ด ์„ค์น˜๋˜์—ˆ์œผ๋ฉฐ ์ด์ œ Apigee Hybrid ๋ช…๋ น์ค„ ๋„๊ตฌ๋ฅผ ๋กœ์ปฌ ๋จธ์‹ ์— ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

AKS

ASM ์„ค์ • ๋ฐ ๋‹ค์šด๋กœ๋“œ

ASM ๋ฌธ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ™˜๊ฒฝ์„ ์„ค์ •ํ•˜๊ณ  ASM์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

  1. ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์ž์„ธํžˆ ์ฝ์–ด๋ณด์„ธ์š”. ASM ๋ฌธ์„œ์— ๋‚˜์—ด๋œ ๋ช‡ ๊ฐ€์ง€ ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„ ์—ฌ๊ธฐ๋กœ ๋Œ์•„์™€์„œ ์„ค์น˜๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.
  2. ์—ฐ๊ฒฐ๋œ ํด๋Ÿฌ์Šคํ„ฐ์— Anthos Service Mesh ์„ค์น˜๋กœ ์ด๋™ํ•˜์—ฌ istio-system ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๋งŒ๋“ค๊ธฐ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋“  ASM ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„, ์ž‘์—…์„ ๋ฉˆ์ถ”๊ณ  ๋‹ค์Œ ์„น์…˜์ธ ์•„๋ž˜์˜ ๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ

ASM ์„ค์น˜ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ’€์—ˆ์œผ๋ฉด, ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๊ณ„์†ํ•ฉ๋‹ˆ๋‹ค.

  1. ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ‘ผ Istio ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. 1.7.3-asm.6).
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ your_static_ip๋Š” Istio ์ธ๊ทธ๋ ˆ์Šค ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ณ ์ • IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค. ๊ณ ์ • IP ์ฃผ์†Œ๊ฐ€ ์˜ˆ์•ฝ๋˜์ง€ ์•Š์•˜์œผ๋ฉด --set values.gateways.istio-ingressgateway.loadBalancerIP ์ค„์„ ๊ทธ๋Œ€๋กœ ๋‘ก๋‹ˆ๋‹ค.
    ./bin/istioctl install --set profile=asm-multicloud \
     --set values.gateways.istio-ingressgateway.loadBalancerIP=your_static_IP
  3. ๋งˆ์ง€๋ง‰์œผ๋กœ ASM ๋ฌธ์„œ๋กœ ๋Œ์•„๊ฐ€ ์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ํ™•์ธํ•˜์—ฌ ์„ค์น˜๋ฅผ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

ASM ์„ค์น˜ ๋งž์ถค์„ค์ •

์ง€๊ธˆ ์ˆ˜ํ–‰ํ•œ ASM ์„ค์น˜๋Š” ์ตœ์†Œ ์„ค์น˜์ด๋ฉฐ, ๊ธฐ๋ณธ ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ์œ„ํ•ด Apigee Hybrid๋ฅผ ํ…Œ์ŠคํŠธํ•˜๊ณ  ์‚ฌ์šฉํ•˜๋Š” ๋ฐ์—๋Š” ์ถฉ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ๋ถ€ํ•˜ ๋ถ„์‚ฐ๊ธฐ ํฌํŠธ ๋ฒˆํ˜ธ ์ถ”๊ฐ€, ์‚ญ์ œ ๋˜๋Š” ์ˆ˜์ •๊ณผ ๊ฐ™์€ ๊ณ ๊ธ‰ ์‚ฌ์šฉ ์‚ฌ๋ก€ ํ•ด๊ฒฐ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์„ ํƒ ๊ธฐ๋Šฅ ์‚ฌ์šฉ ์„ค์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์š”์•ฝ

cert-manager์™€ ASM์ด ์„ค์น˜๋˜์—ˆ์œผ๋ฉฐ ์ด์ œ Apigee Hybrid ๋ช…๋ น์ค„ ๋„๊ตฌ๋ฅผ ๋กœ์ปฌ ๋จธ์‹ ์— ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

GKE on AWS

ASM ์„ค์ • ๋ฐ ๋‹ค์šด๋กœ๋“œ

ASM ๋ฌธ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ™˜๊ฒฝ์„ ์„ค์ •ํ•˜๊ณ  ASM์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

  1. ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์ž์„ธํžˆ ์ฝ์–ด๋ณด์„ธ์š”. ASM ๋ฌธ์„œ์— ๋‚˜์—ด๋œ ๋ช‡ ๊ฐ€์ง€ ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„ ์—ฌ๊ธฐ๋กœ ๋Œ์•„์™€์„œ ์„ค์น˜๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.
  2. GKE on AWS์— Anthos Service Mesh ์„ค์น˜๋กœ ์ด๋™ํ•˜์—ฌ ์„ค์น˜ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ๋ฅผ ํฌํ•จํ•˜์—ฌ ๋ชจ๋“  ASM ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„ ์ค‘์ง€ํ•˜๊ณ  ๋‹ค์Œ ์„น์…˜์ธ ์•„๋ž˜์˜ ๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ

ASM ์„ค์น˜ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ’€์—ˆ์œผ๋ฉด, ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๊ณ„์†ํ•ฉ๋‹ˆ๋‹ค.

  1. ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ‘ผ Istio ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. 1.7.3-asm.6).
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ your_static_ip๋Š” Istio ์ธ๊ทธ๋ ˆ์Šค ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ณ ์ • IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค. ๊ณ ์ • IP ์ฃผ์†Œ๊ฐ€ ์˜ˆ์•ฝ๋˜์ง€ ์•Š์•˜์œผ๋ฉด --set values.gateways.istio-ingressgateway.loadBalancerIP ์ค„์„ ๊ทธ๋Œ€๋กœ ๋‘ก๋‹ˆ๋‹ค.
    ./bin/istioctl install --set profile=asm-multicloud \
     --set values.gateways.istio-ingressgateway.loadBalancerIP=your_static_IP
  3. ๋งˆ์ง€๋ง‰์œผ๋กœ ASM ๋ฌธ์„œ๋กœ ๋Œ์•„๊ฐ€ ์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ํ™•์ธํ•˜์—ฌ ์„ค์น˜๋ฅผ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

ASM ์„ค์น˜ ๋งž์ถค์„ค์ •

์ง€๊ธˆ ์ˆ˜ํ–‰ํ•œ ASM ์„ค์น˜๋Š” ์ตœ์†Œ ์„ค์น˜์ด๋ฉฐ, ๊ธฐ๋ณธ ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ์œ„ํ•ด Apigee Hybrid๋ฅผ ํ…Œ์ŠคํŠธํ•˜๊ณ  ์‚ฌ์šฉํ•˜๋Š” ๋ฐ์—๋Š” ์ถฉ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ๋ถ€ํ•˜ ๋ถ„์‚ฐ๊ธฐ ํฌํŠธ ๋ฒˆํ˜ธ ์ถ”๊ฐ€, ์‚ญ์ œ ๋˜๋Š” ์ˆ˜์ •๊ณผ ๊ฐ™์€ ๊ณ ๊ธ‰ ์‚ฌ์šฉ ์‚ฌ๋ก€ ํ•ด๊ฒฐ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์„ ํƒ ๊ธฐ๋Šฅ ์‚ฌ์šฉ ์„ค์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์š”์•ฝ

cert-manager์™€ ASM์ด ์„ค์น˜๋˜์—ˆ์œผ๋ฉฐ ์ด์ œ Apigee Hybrid ๋ช…๋ น์ค„ ๋„๊ตฌ๋ฅผ ๋กœ์ปฌ ๋จธ์‹ ์— ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

EKS

ASM ์„ค์ • ๋ฐ ๋‹ค์šด๋กœ๋“œ

ASM ๋ฌธ์„œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ™˜๊ฒฝ์„ ์„ค์ •ํ•˜๊ณ  ASM์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

  1. ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์ž์„ธํžˆ ์ฝ์–ด๋ณด์„ธ์š”. ASM ๋ฌธ์„œ์— ๋‚˜์—ด๋œ ๋ช‡ ๊ฐ€์ง€ ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„ ์—ฌ๊ธฐ๋กœ ๋Œ์•„์™€์„œ ์„ค์น˜๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.
  2. ์—ฐ๊ฒฐ๋œ ํด๋Ÿฌ์Šคํ„ฐ์— Anthos Service Mesh ์„ค์น˜๋กœ ์ด๋™ํ•˜์—ฌ istio-system ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๋งŒ๋“ค๊ธฐ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋“  ASM ๋‹จ๊ณ„๋ฅผ ์ˆ˜ํ–‰ํ•œ ํ›„, ์ž‘์—…์„ ๋ฉˆ์ถ”๊ณ  ๋‹ค์Œ ์„น์…˜์ธ ์•„๋ž˜์˜ ๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

๋งค๋‹ˆํŽ˜์ŠคํŠธ ์ ์šฉ

ASM ์„ค์น˜ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ’€์—ˆ์œผ๋ฉด, ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๊ณ„์†ํ•ฉ๋‹ˆ๋‹ค.

  1. ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์••์ถ•์„ ํ‘ผ Istio ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. 1.7.3-asm.6).
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ your_static_ip๋Š” Istio ์ธ๊ทธ๋ ˆ์Šค ๊ตฌ์„ฑ์š”์†Œ๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ณ ์ • IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค. ๊ณ ์ • IP ์ฃผ์†Œ๊ฐ€ ์˜ˆ์•ฝ๋˜์ง€ ์•Š์•˜์œผ๋ฉด --set values.gateways.istio-ingressgateway.loadBalancerIP ์ค„์„ ๊ทธ๋Œ€๋กœ ๋‘ก๋‹ˆ๋‹ค.
    ./bin/istioctl install --set profile=asm-multicloud \
     --set values.gateways.istio-ingressgateway.loadBalancerIP=your_static_IP
  3. ๋งˆ์ง€๋ง‰์œผ๋กœ ASM ๋ฌธ์„œ๋กœ ๋Œ์•„๊ฐ€ ์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ํ™•์ธํ•˜์—ฌ ์„ค์น˜๋ฅผ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.

ASM ์„ค์น˜ ๋งž์ถค์„ค์ •

์ง€๊ธˆ ์ˆ˜ํ–‰ํ•œ ASM ์„ค์น˜๋Š” ์ตœ์†Œ ์„ค์น˜์ด๋ฉฐ, ๊ธฐ๋ณธ ์‚ฌ์šฉ ์‚ฌ๋ก€๋ฅผ ์œ„ํ•ด Apigee Hybrid๋ฅผ ํ…Œ์ŠคํŠธํ•˜๊ณ  ์‚ฌ์šฉํ•˜๋Š” ๋ฐ์—๋Š” ์ถฉ๋ถ„ํ•ฉ๋‹ˆ๋‹ค. ๋ถ€ํ•˜ ๋ถ„์‚ฐ๊ธฐ ํฌํŠธ ๋ฒˆํ˜ธ ์ถ”๊ฐ€, ์‚ญ์ œ ๋˜๋Š” ์ˆ˜์ •๊ณผ ๊ฐ™์€ ๊ณ ๊ธ‰ ์‚ฌ์šฉ ์‚ฌ๋ก€ ํ•ด๊ฒฐ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์„ ํƒ ๊ธฐ๋Šฅ ์‚ฌ์šฉ ์„ค์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์š”์•ฝ

cert-manager์™€ ASM์ด ์„ค์น˜๋˜์—ˆ์œผ๋ฉฐ ์ด์ œ Apigee Hybrid ๋ช…๋ น์ค„ ๋„๊ตฌ๋ฅผ ๋กœ์ปฌ ๋จธ์‹ ์— ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์š”์•ฝ

cert-manager์™€ ASM์ด ์„ค์น˜๋˜์—ˆ์œผ๋ฉฐ ์ด์ œ Apigee Hybrid ๋ช…๋ น์ค„ ๋„๊ตฌ๋ฅผ ๋กœ์ปฌ ๋จธ์‹ ์— ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

1 2 3 (๋‹ค์Œ) 4๋‹จ๊ณ„: apigeectl ์„ค์น˜ 5 6 7