Identity 관리 모드
Identity 관리 모드 (Identity Management Mode)
Cilium은 Cilium Identity(CID)를 Cilium Agent(기본값) 또는 Cilium Operator가 관리하도록 지원해요. Operator가 identity를 관리하면 중앙 집중화되어 CID 중복을 줄이고 클러스터 확장성을 높일 수 있어요.
본문
Cilium은 Cilium Identity(CID) 관리를 Cilium Agent(기본값) 또는 Cilium Operator가 수행하도록 지원해요.
Operator가 identity를 관리하면 identity 생성이 중앙 집중화돼요. 이는 여러 Agent가 동시에 동일한 라벨 집합에 대해 identity를 생성할 때 발생할 수 있는 CID 중복을 줄이는 등의 이점을 제공해요. 클러스터의 최대 identity 수와 eBPF Policy Map 크기에는 제한이 있으므로 (eBPF Maps 참고), operator가 identity를 관리하면 네트워크 정책의 신뢰성과 클러스터 확장성을 개선할 수 있어요.
Note Identity 관리와 관련된 라벨은 Cilium ConfigMap에서 구성할 수 있어요 (참고: Limiting Identity-Relevant Labels). Cilium Operator가 identity를 관리한다면, 새 라벨 패턴 설정을 적용하려면 Operator와 Agent를 모두 재시작해야 해요.
Cilium Operator에 의한 Identity 관리 활성화 (Beta) (Enable Identity Management by the Cilium Operator (Beta))
Note 이 기능은 베타 단계예요. 문제가 발생하면 피드백을 주고 GitHub issue를 제출해 주세요.
Cilium Agent는 기본적으로 CID를 관리해요. 이 섹션은 Cilium Operator가 CID 관리를 수행하도록 활성화하는 데 필요한 단계를 설명해요.
새 클러스터에서 Operator가 Identity를 관리하도록 활성화 (Enable Operator Managing Identities on a New Cluster)
새 클러스터에서 Cilium Operator가 identity를 관리하도록 하려면 Helm 차트에서 identityManagementMode 값을 operator로 설정하거나 cilium-config configmap에서 identity-management-mode 플래그를 operator로 설정하세요.
Cilium Agent에서 Cilium Operator로 identity 관리 마이그레이션 (How to Migrate from Cilium Agent to Cilium Operator Managing Identities)
연결이나 워크로드 관리의 중단을 최소화하려면 다음 절차를 따라야 해요. 클러스터 중단을 방지하기 위해 Cilium Agent와 Operator가 모두 identity를 관리하는 중간 상태가 있다는 점에 주의하세요. Cilium Agent가 identity를 만드는 동안에는 CID 중복 문제가 발생할 수 있어요. 이 전환 상태는 identity 관리 모드를 마이그레이션하기 위한 목적으로만 임시로 사용하기 위한 것이에요.
-
Helm 차트에서
identityManagementMode값을both로 설정하거나cilium-configconfigmap에서identity-management-mode플래그를both로 설정해 Operator가 identity도 관리하도록 허용하세요. Operator를 재시작하세요. -
operator가 실행 중이면
identityManagementMode값을operator로 설정하거나identity-management-mode플래그를operator로 설정하고 Cilium Agent DaemonSet을 재시작해 Cilium Agent를 업그레이드하세요.
Cilium Operator에서 Cilium Agent로 identity 관리 다운그레이드 (How to Downgrade from Cilium Operator to Cilium Agent Managing Identities)
안전한 다운그레이드를 위해 다음 절차를 따라야 해요.
-
먼저 Helm 차트에서
identityManagementMode값을both로 설정하거나cilium-configconfigmap에서identity-management-mode플래그를both로 설정해 Cilium Agent를 다운그레이드하세요. Cilium Agent DaemonSet을 재시작하세요. -
Cilium Agent가 실행 중이면
identityManagementMode값을agent로 설정하고 Operator를 재시작해 Operator를 다운그레이드하세요.
메트릭 (Metrics)
operator에 의한 identity 관리 메트릭은 메트릭 문서의 Identity Management Mode 섹션에 문서화되어 있어요.