Úložisko, RBAC a klastrové objekty
Namespace
// Provision an isolated namespace per tenant
$cluster->namespaces()
->setName('tenant-acme')
->setLabels(['example.com/tenant' => 'acme'])
->create();
$tenant = $cluster->namespaces()->withName('tenant-acme')->find();
$tenant->isActive(); // status.phase === 'Active'
$tenant->isTerminating(); // status.phase === 'Terminating'Nody, udalosti a endpointy
Objekty, ktoré prevažne čítate, majú gettery pre polia, ktoré naozaj potrebujete. Udalosti ponúkajú aj getType(), isNormal() a getFirstTimestamp(); endpointy getSubsets() a getSubset($index):
use RoundlyConsulting\KubernetesApi\Resources\Event;
foreach ($cluster->nodes()->get() as $node) {
$node->getName();
$node->getInfo(); // status.nodeInfo
$node->getCapacity(); // status.capacity
$node->getAllocatableInfo(); // status.allocatable
$node->getImages(); // status.images
}
// Warnings about one object, straight from the event log
$warnings = $cluster->events()
->setNamespace('shop')
->whereField('involvedObject.name', 'checkout-5f7c9d8b6-x2kqj')
->get()
->filter(fn (Event $event): bool => $event->isWarning());
foreach ($warnings as $event) {
$event->getReason(); // e.g. 'BackOff'
$event->getMessage();
$event->getCount();
$event->getLastTimestamp(); // ?Carbon
$event->getInvolvedObject(); // kind, name, namespace…
}
// Ready addresses behind a service
$endpoints = $cluster->endpoints()->setNamespace('shop')->withName('checkout')->find();
$endpoints->getReadyAddresses(); // pod IPs
$endpoints->getPorts(); // [8080]Úložisko
Zväzky a claimy zdieľajú setAccessModes(), setStorageClassName() a setCapacity($size, $measure = 'Gi') a k tomu isBound() a isAvailable() podľa status.phase:
// A claim for 10 GiB on a storage class
$cluster->persistentVolumeClaims()
->setNamespace('shop')
->setName('uploads')
->setAccessModes(['ReadWriteOnce'])
->setStorageClassName('fast-ssd')
->setCapacity(10, 'Gi') // spec.resources.requests.storage = 10Gi
->create();
$cluster->persistentVolumeClaims()->setNamespace('shop')->withName('uploads')->find()->isBound();
// A storage class
$cluster->storageClasses()
->setName('fast-ssd')
->setProvisioner('csi.example.com') // magic setter -> provisioner
->setParameters(['type' => 'ssd'])
->setMountOptions(['noatime'])
->create();
// A pre-provisioned NFS volume
$cluster->persistentVolumes()
->setName('shared-media')
->setCapacity(100, 'Gi') // spec.capacity.storage = 100Gi
->setAccessModes(['ReadWriteMany'])
->setStorageClassName('nfs')
->setMountOptions(['nfsvers=4.1'])
->setSpec('nfs', ['server' => 'nfs.example.com', 'path' => '/exports/media'])
->create();RBAC a service accounty
// A service account for your deploy tooling
$cluster->serviceAccounts()
->setNamespace('shop')
->setName('deployer')
->addImagePullSecret('registry-credentials')
->setAutomountServiceAccountToken(false)
->create();
// What it may do in the namespace
$cluster->roles()
->setNamespace('shop')
->setName('deployer')
->addRule(['apps'], ['deployments', 'deployments/scale'], ['get', 'list', 'patch'])
->addRule([''], ['pods', 'pods/log'], ['get', 'list'])
->create();
$cluster->roleBindings()
->setNamespace('shop')
->setName('deployer')
->setRoleRef('deployer') // kind defaults to Role
->addSubject('ServiceAccount', 'deployer', 'shop')
->addSubject('User', '[email protected]')
->create();
// Cluster-wide
$cluster->clusterRoles()
->setName('node-reader')
->addRule([''], ['nodes'], ['get', 'list', 'watch'])
->create();
$cluster->clusterRoleBindings()
->setName('deployer-node-reader')
->setRoleRef('node-reader') // always a ClusterRole
->addSubject('ServiceAccount', 'deployer', 'shop')
->create();addRule($apiGroups, $resources, $verbs) pridá pravidlo. addSubject($kind, $name, $namespace = null) doplní namespace pri subjekte ServiceAccount a API skupinu rbac.authorization.k8s.io pri používateľoch a skupinách. RoleBinding::setRoleRef() prijíma voliteľný kind, takže väzba roly môže odkazovať aj na ClusterRole.
Kvóty a limit ranges
$cluster->resourceQuotas()
->setNamespace('tenant-acme')
->setName('compute')
->setHard(['pods' => '20', 'requests.cpu' => '4', 'requests.memory' => '8Gi'])
->create();
$quota = $cluster->resourceQuotas()->setNamespace('tenant-acme')->withName('compute')->find();
$quota->getHard(); // the limits you set
$quota->getUsed(); // current usage from status.used
$cluster->limitRanges()
->setNamespace('tenant-acme')
->setName('defaults')
->addLimit([
'type' => 'Container',
'default' => ['cpu' => '500m', 'memory' => '512Mi'],
'defaultRequest' => ['cpu' => '100m', 'memory' => '128Mi'],
])
->create();Prejavte lásku k open source
Tento balík je zadarmo pod licenciou MIT. Ak vám šetrí čas, jednorazový príspevok alebo členstvo na Patreone nám pomôže ho ďalej udržiavať, testovať a dokumentovať.
Ďalšie spôsoby podpory vrátane kryptomienOdoslaním daru súhlasíte s našimi podmienkami prijímania darov.
Chcete to zabudovať do svojho produktu?
Naše balíky integrujeme do zákazkových Laravel a AI riešení. Napíšte nám, na čom pracujete, a ozveme sa do 48 hodín.