More than 5 years have passed since last update.

KubeWeekly #158

Last updated at Posted at 2019-01-16


KubeWeeklyは毎週Kubernetesに関する興味深いニュースを提供しています。(http://bit.ly/kubeweekly )この記事は 2019/01/09に発行された Kube Weekly #158 ( https://mailchi.mp/cncf/kubeweekly-158 ) を読んで、感じたことをメモ的にまとめたものです。

The Headline

Early in 2018 our engineering team embarked on a journey to revamp our infrastructure and tooling. In essence our developer experience was…


In a best-practice Kubernetes cluster every request to the Kubernetes APIServer is authenticated and authorized. Authorization is usually…

例えば kube-system以外のnamespaceにはフルアクセスを許可したい、PSPでrootで動くコンテナを抑制したり、hostPathの使用を不許可にしたい など。
その後OPAを使ってMutatingWebhookとして実装するようにした。実装にあたっては GitHub - open-policy-agent/kubernetes-policy-controller: kubernetes-policy-controller を利用している。

Originally published here by Sean Porter, CTO of Sensu Our industry has long been relying on microservice-based architecture to deliver software faster and safer. The advent and ubiquity of microservices naturally...


  • ホストのメトリクス node-exporter
  • kubernetesのコントローラとkubeletのメトリクス
  • cAdvisorのメトリクス
  • kube-state-metrics

当然アプリケーションのメトリクスも取る必要があるが、それは次回以降のテーマ らしい

The Technical

This Tutorial demonstrates how to get started with Knative Serving a platform to build, deploy and mangage modern serverless workloads


Bringing cloud native to the enterprise, simplifying the transition to microservices on Kubernetes


Authors: Irfan Ur Rehman (Huawei), Paul Morie (RedHat) and Shashidhara T D (Huawei) Deploying applications to a kubernetes cluster is well defined and can in some cases be as simple as kubectl create -f app.yaml. The user’s story to deploy apps across multiple clusters has not been that simple. How should an app workload be distributed? Should the app resources be replicated into all clusters, or replicated into selected clusters or partitioned into clusters?

Federation v2の紹介。

The default metrics sent by Istio are useful to get an idea on how the traffic flows in your cluster. However, to understand how your…


Telepresence can speed up developing microservices running on Kubernetes cluster. And save you a lot of time and money.


In the last paper, I explored how to create custom metrics of the application and present the result in the Grafana dashboard. In this…

GitHub - DirectXMan12/k8s-prometheus-adapter: An implementation of the custom.metrics.k8s.io API using Prometheus を使っている。

It has been more than a year since we moved part of our workloads to Kubernetes and in this particular post I’m going to share some…

Gatling Load and Performance testing - Open-source load and performance testing というツールを使ってKubernetes上でWebアプリケーションの負荷テストを行う方法の紹介。

Simplify your Kubernetes deployments

GitHub - hypnoglow/helm-s3: Helm plugin that allows to use AWS S3 as a [private] chart repository. をつかう。

Tooling Soptlight


A tool to scan Kubernetes cluster for risky permissions - cyberark/KubiScan


Securing Kubernetes Clusters by Eliminating Risky Permissions - CyberArk


Local Kubernetes development with no stress. Contribute to windmilleng/tilt development by creating an account on GitHub.

CUIだがグラフィカルなUIが良い。GitHub - GoogleContainerTools/skaffold: Easy and Repeatable Kubernetes Developmentっぽい?

The Editorial

CNCFのExecutive DirectorによるCNCFについてのインタビュー(PodCast)

During 2018, Bitnami has been changing how we approach and utilize infrastructure to deliver our services, moving from a "single server per project" approach to one where we use Kubernetes. Doing so not only makes management easier, but also allows us to respond more quickly to infrastructure vulnerabilities...


Enterprise Kubernetes: 5 insights from >200 practitioners from KubeCon 2017 on use cases, challenges and plans for use of Kubernetes and containers.

KubeCon + CloudNativeCon 2018でPlatform9が実施したサーベイの結果

  • どういう立場の人がKubernetesに関心を持っているか?
  • ユースケースは何か?
  • どのクラウドプロバイダで動かしているか?
  • どのようなクラウドネイティブ技術を使っているか?
  • Kubernetesやクラウドネイティブ導入の上での懸念は何か?

Solar panels are getting cheaper, and are becoming an economically viable source of renewable energy in many parts of the world. For solar panels to operate efficiently, they need to be kept clean and pointed at an optimal angle to the sun that balances power generation and prevents overheating. An embedded computer is in charge of monitoring metrics and driving the actuators. But when you have thousands of solar panels and embedded computers how do you orchestrate software updates, monitor uptime and secure communications?


Last year I wrote a post entitled A Trip From the Past to the Future of Kubernetes. In it, I talked about the KVM and AWS versions of our stack and the imminent availability of our Azure release. I also...
  • 大企業がKubernetesを使い始める
  • セキュリティやアップデートなどDay2オペレーションにフォーカスするようになる
  • Kubernetes上でビッグデータを扱う事例が増える
  • ClusterAPIなどのコントロールプレーン技術が盛り上がる
  • KubernetesAPIの拡張が進む
    • Operatorで自社製品をうまくKubernetes上にデプロイできるようにする
    • Kubernetesの仕組みを使って何か他のものを制御する ML/AI PlatformやPaaSやCI/CDなど

At KubeCon + CloudNativeCon NA 2018, an Epic Games engineer explains why the world's most popular game is now running on Kubernetes.

Epic GamesのKubernetes事例 EKSを使っているらしい。

CTO and CDO Yasir Anwar has led successful pilots of Kubernetes and AI and ML-based tools at the company. Looking ahead to 2019, even more innovation is on his agenda. 


Last year, Kubernetes took center stage in the telecommunications industry as the primary means for managing containers, but there's still work to do. The use of containers is already underway by telcos such as AT&T and BT, and there's no doubt more service providers will use them going forward.


We predict new enterprise application development will pass a tipping point in 2019 and shift away from legacy virtual machines (VMs) and strongly toward


Since the inception of Docker and OCI(Open Container Initiative), the landscape for Operating-system-level virtualization has changed. So…



