Book Image

Hands-On Kubernetes on Azure - Second Edition

By : Nills Franssens, Shivakumar Gopalakrishnan, Gunther Lenz
Book Image

Hands-On Kubernetes on Azure - Second Edition

By: Nills Franssens, Shivakumar Gopalakrishnan, Gunther Lenz

Overview of this book

From managing versioning efficiently to improving security and portability, technologies such as Kubernetes and Docker have greatly helped cloud deployments and application development. Starting with an introduction to Docker, Kubernetes, and Azure Kubernetes Service (AKS), this book will guide you through deploying an AKS cluster in different ways. You’ll then explore the Azure portal by deploying a sample guestbook application on AKS and installing complex Kubernetes apps using Helm. With the help of real-world examples, you'll also get to grips with scaling your application and cluster. As you advance, you'll understand how to overcome common challenges in AKS and secure your application with HTTPS and Azure AD (Active Directory). Finally, you’ll explore serverless functions such as HTTP triggered Azure functions and queue triggered functions. By the end of this Kubernetes book, you’ll be well-versed with the fundamentals of Azure Kubernetes Service and be able to deploy containerized workloads on Microsoft Azure with minimal management overhead.
Table of Contents (16 chapters)
1
Section 1: The Basics
4
Section 2: Deploying on AKS
10
Section 3: Leveraging advanced Azure PaaS services
15
Index

The Istio service mesh at your service

We have found a number of ways to secure our Pods, but our network connections are still open. Any Pod in the cluster can talk to any other Pod in the same cluster. As a site reliability engineer, you will want to enforce both ingress and egress rules. Additionally, you also want to introduce traffic monitoring and would like to have better traffic control. As a developer, you don't want to be bothered by all of those requirements as you won't know where your application will be deployed, or what is and isn't allowed. The best solution would be a tool for us to run the applications as is, while still specifying network policies, advanced monitoring, and traffic control.

Enter service mesh. This is defined as the layer that controls service-to-service communication. A service mesh is a network between microservices. A service mesh is implemented as a piece of software that controls and monitors traffic between those different...