inject
Kubernetes 매니페스트에 linkerd.io/inject: enabled annotation을 추가해 데이터 플레인 프록시를 주입하는 linkerd inject 명령에 대해 다루는 문서예요.
출처: Linkerd inject
본문
inject 명령은 파일 또는 스트림(-)으로 전달된 Kubernetes 매니페스트를 수정하는 텍스트 변환입니다. 매니페스트에서 해당하는 리소스에 linkerd.io/inject: enabled annotation을 추가합니다. 결과로 만들어진 annotation 달린 매니페스트를 Kubernetes 클러스터에 적용하면, Linkerd의 프록시 자동 주입기(autoinjector)가 해당 파드에 Linkerd 데이터 플레인 프록시를 자동으로 추가합니다.
이 명령을 써야 할 선험적 이유는 없다는 점에 주목하세요. 프로덕션에서는 이런 annotation을 CI/CD 시스템이나 다른 배포 시점 메커니즘이 대신 설정할 수 있습니다.
수동 주입 (Manual injection)
대안으로, 이 명령은 --manual 플래그를 켜면 완전히 클라이언트 측에서 주입 전부를 수행할 수도 있어요. (Linkerd 2.4 이전에는 이것이 기본 동작이었습니다.)
Examples
`# Inject all the deployments in the default namespace.
kubectl get deploy -o yaml | linkerd inject - | kubectl apply -f -
# Injecting a file from a remote URL
linkerd inject https://url.to/yml | kubectl apply -f -
# Inject all the resources inside a folder and its sub-folders.
linkerd inject | kubectl apply -f -`
Flags
| Flag | Usage |
|---|---|
| Flag | Usage |
| --admin-port | Proxy port to serve metrics on |
| --close-wait-timeout | Sets nf_conntrack_tcp_timeout_close_wait |
| --control-port | Proxy port to use for control |
| --default-inbound-policy | Inbound policy to use to control inbound access to the proxy |
| --disable-identity | Disables resources from participating in TLS identity |
| --enable-debug-sidecar | Inject a debug sidecar for data plane debugging |
| --enable-external-profiles | Enable service profiles for non-Kubernetes services |
| --ignore-cluster | Ignore the current Kubernetes cluster when checking for existing cluster configuration (default false) |
| --image-pull-policy | Docker image pull policy |
| --inbound-port | Proxy port to use for inbound traffic |
| --ingress | Enable ingress mode in the linkerd proxy |
| --manual | Include the proxy sidecar container spec in the YAML output (the auto-injector won't pick it up, so config annotations aren't supported) (default false) |
| --native-sidecar | Enable native sidecar |
| --opaque-ports | Set opaque ports on the proxy |
| --outbound-port | Proxy port to use for outbound traffic |
| --output-o | Output format, one of: json|yaml |
| --proxy-cpu | Amount of CPU units that the proxy sidecar requests |
| --proxy-cpu-limit | Maximum amount of CPU units that the proxy sidecar can use |
| --proxy-cpu-request | Amount of CPU units that the proxy sidecar requests |
| --proxy-gid | Run the proxy under this group ID |
| --proxy-image | Linkerd proxy container image name |
| --proxy-log-level | Log level for the proxy |
| --proxy-memory | Amount of Memory that the proxy sidecar requests |
| --proxy-memory-limit | Maximum amount of Memory that the proxy sidecar can use |
| --proxy-memory-request | Amount of Memory that the proxy sidecar requests |
| --proxy-uid | Run the proxy under this user ID |
| --proxy-version-v | Tag to be used for the Linkerd proxy images |
| --registry | Docker registry to pull images from ($LINKERD_DOCKER_REGISTRY) |
| --require-identity-on-inbound-ports | Inbound ports on which the proxy should require identity |
| --skip-inbound-ports | Ports and/or port ranges (inclusive) that should skip the proxy and send directly to the application |
| --skip-outbound-ports | Outbound ports and/or port ranges (inclusive) that should skip the proxy |
| --wait-before-exit-seconds | The period during which the proxy sidecar must stay alive while its pod is terminating. Must be smaller than terminationGracePeriodSeconds for the pod (default 0) |
더 알아보기 (Learn more)
- Linkerd 서비스 추가 가이드에서 주입 방식에 대한 자세한 내용을 확인해 보세요.