본문 바로가기
WIKI 기술 지식 베이스

Linkerd viz

원문 보기 위키 갱신

viz는 Linkerd 서비스 메시의 linkerd-viz 확장을 관리해요.

출처: Linkerd viz

본문

Flags

Flag Usage
--api-addr Override kubeconfig and communicate directly with the control plane at host:port (mostly for testing)
--as Username to impersonate for Kubernetes operations
--as-group Group to impersonate for Kubernetes operations
--context Name of the kubeconfig context to use
--kubeconfig Path to the kubeconfig file to use for CLI requests
--linkerd-namespace-L Namespace in which Linkerd is installed
--verbose Turn on debug logging
--viz-namespace Name of the linkerd-viz namespace. If not set, it's automatically detected

하위 명령어 (Subcommands)

Subcommand Description
allow-scrapes Output Kubernetes resources to authorize Prometheus scrapes
authz Display stats for authorizations for a resource
check Check the Linkerd Viz extension for potential problems
dashboard Open the Linkerd dashboard in a web browser
edges Display connections between resources, and Linkerd proxy identities
install Output Kubernetes resources to install linkerd-viz extension
list Lists which pods can be tapped
profile Output service profile config for Kubernetes based off tap data
prune Output extraneous Kubernetes resources in the linkerd-viz extension
routes Display route stats
stat Display traffic stats about one or many resources
stat-inbound Display inbound traffic stats about a resource
stat-outbound Display outbound traffic stats about a resource
tap Listen to a traffic stream
top Display sorted information about live traffic
uninstall Output Kubernetes resources to uninstall the linkerd-viz extension

allow-scrapes

config.linkerd.io/default-inbound-policy: deny가 설정된 네임스페이스 또는 클러스터에서 Prometheus 스크레이프를 허가하는 Kubernetes 리소스를 출력해요.

Examples

# Allow scrapes in the 'emojivoto' namespace
linkerd viz allow-scrapes --namespace emojivoto | kubectl apply -f -

Flags

Flag Usage
--namespace-n The namespace in which to authorize Prometheus scrapes.
--output-o Output format. One of: json|yaml

authz

리소스에 대한 인가(authorization) 통계를 표시해요.

Flags

Flag Usage
--namespace-n Namespace of the specified resource
--output-o Output format; one of: "table" or "json" or "wide"
--selector-l Selector (label query) to filter on, supports '=', '==', and '!='
--time-window-t Stat window (for example: "15s", "1m", "10m", "1h"). Needs to be at least 15s.

check

Linkerd Viz 확장의 잠재적 문제를 확인해요.

check 명령어는 Linkerd Viz 확장이 올바르게 구성됐는지 검증하는 일련의 검사를 수행해요. 검사가 실패하면 실패에 대한 추가 정보를 출력하고 0이 아닌 종료 코드로 종료돼요.

Examples

# Check that the viz extension is up and running
linkerd viz check

Flags

Flag Usage
--namespace-n Namespace to use for --proxy checks (default: all namespaces)
--output-o Output format. One of: table, json, short
--proxy Also run data-plane checks, to determine if the data plane is healthy
--wait Maximum allowed time for all tests to pass

dashboard

웹 브라우저에서 Linkerd 대시보드를 엽니다. 이 명령어가 무엇을 하는지에 대한 더 자세한 설명은 아키텍처 문서를 확인하세요.

Flags

Flag Usage
--address The address at which to serve requests
--port-p The local port on which to serve requests (when set to 0, a random port will be used)
--show Open a dashboard in a browser or show URLs in the CLI (one of: linkerd, grafana, url)
--wait Wait for dashboard to become available if it's not available when the command is run

(*) 이 값으로 대시보드의 enforced-host 파라미터를 조정해야 해요. 자세한 내용은 DNS-rebinding 보호 문서를 참고하세요.

edges

리소스 간 연결과 Linkerd 프록시 아이덴티티를 표시해요.

RESOURCETYPE 인자는 edges를 표시할 리소스의 유형을 지정해요.

Examples:

  • cronjob
  • deploy
  • ds
  • job
  • po
  • rc
  • rs
  • sts

유효한 리소스 유형:

  • cronjobs
  • daemonsets
  • deployments
  • jobs
  • pods
  • replicasets
  • replicationcontrollers
  • statefulsets

Examples

# Get all edges between pods that either originate from or terminate in the test namespace.
linkerd viz edges po -n test

# Get all edges between pods that either originate from or terminate in the default namespace.
linkerd viz edges po

# Get all edges between pods in all namespaces.
linkerd viz edges po --all-namespaces

Flags

Flag Usage
--all-namespaces-A If present, returns edges across all namespaces, ignoring the "--namespace" flag
--namespace-n Namespace of the specified resource
--output-o Output format; one of: "table" or "json" or "wide"

install

linkerd-viz 확장을 설치하는 데 필요한 Kubernetes 리소스를 출력해요.

Examples

# Default install.
linkerd viz install | kubectl apply -f -

The installation can be configured by using the --set, --values, --set-string and --set-file flags.
A full list of configurable values can be found at https://www.github.com/linkerd/linkerd2/tree/main/viz/charts/linkerd-viz/README.md

Flags

Flag Usage
--ha Install Viz Extension in High Availability mode.
--ignore-cluster Ignore the current Kubernetes cluster when checking for existing cluster configuration (default false)
--output-o Output format. One of: json|yaml
--set set values on the command line (can specify multiple or separate values with commas: key1=val1,key2=val2)
--set-file set values from respective files specified via the command line (can specify multiple or separate values with commas: key1=path1,key2=path2)
--set-string set STRING values on the command line (can specify multiple or separate values with commas: key1=val1,key2=val2)
--skip-checks Skip checks for linkerd core control-plane existence
--values-f specify values in a YAML file or a URL (can specify multiple)
--wait Wait for core control-plane components to be available

list

tap 할 수 있는 파드를 나열해요.

Flags

Flag Usage
--all-namespaces-A If present, list pods across all namespaces
--namespace-n The namespace to list pods in

profile

tap 데이터를 기반으로 Kubernetes용 서비스 프로파일 구성을 출력해요.

Examples

# Generate a profile by watching live traffic.
linkerd viz profile -n emojivoto web-svc --tap deploy/web --tap-duration 10s --tap-route-limit 5

Flags

Flag Usage
--namespace-n Namespace of the service
--output-o Output format. One of: yaml, json
--tap Output a service profile based on tap data for the given target resource
--tap-duration Duration over which tap data is collected (for example: "10s", "1m", "10m")
--tap-route-limit Max number of routes to add to the profile

routes

routes 명령어는 라우트별 서비스 메트릭을 표시해요. 이 정보를 활용하려면 요청을 받는 서비스에 서비스 프로파일이 정의되어 있어야 해요. 서비스 프로파일 만드는 방법은 service profiles와 profile 명령어 참조를 확인하세요.

인바운드 메트릭 (Inbound Metrics)

기본적으로 routes는 대상에 대한 인바운드 메트릭을 표시해요. 즉 대상으로 보내진 요청과 대상이 반환한 응답에 관한 정보를 보여줘요. 예를 들어 다음 명령어는:

linkerd viz routes deploy/webapp

webapp 디플로이먼트에 대한 요청의 요청량, 성공률, 지연 시간을 표시해요. 이 메트릭은 webapp 디플로이먼트의 관점에서 나온 것이에요. 따라서 예를 들어 이 지연 시간에는 클라이언트와 webapp 디플로이먼트 사이의 네트워크 지연이 포함되지 않아요.

아웃바운드 메트릭 (Outbound Metrics)

--to 플래그를 지정하면 linkerd viz routes는 대상 리소스에서 --to 플래그의 리소스로의 아웃바운드 메트릭을 표시해요. 인바운드 메트릭과 달리 이 메트릭은 송신자 관점에서 나온 것이에요. 즉 이 지연 시간에는 클라이언트와 서버 사이의 네트워크 지연이 포함돼요. 예를 들어 다음 명령어는:

linkerd viz routes deploy/traffic --to deploy/webapp

traffic 디플로이먼트 관점에서 traffic에서 webapp으로의 요청의 요청량, 성공률, 지연 시간을 표시해요.

유효(effective) 메트릭과 실제(actual) 메트릭

아웃바운드 메트릭을 볼 때(--to 플래그 지정) -o wide 플래그를 사용해서 effective 메트릭과 actual 메트릭을 구분할 수 있어요.

effective 요청은 어떤 클라이언트가 Linkerd 프록시로 보낸 요청이에요. actual 요청은 Linkerd 프록시가 어떤 서버로 보내는 요청이에요. Linkerd 프록시가 재시도를 수행하면 하나의 effective 요청이 하나 이상의 actual 요청으로 번역될 수 있어요. 프록시가 재시도를 수행하지 않으면 effective 요청과 actual 요청은 항상 같아요. 재시도를 활성화하면 actual 요청 비율이 증가하고 effective 성공률이 증가하는 것을 볼 수 있어요. 자세한 내용은 retries and timeouts 섹션을 참고하세요.

재시도는 아웃바운드(클라이언트) 쪽에서만 수행되므로, -o wide 플래그는 --to 플래그를 지정했을 때만 사용할 수 있어요.

Examples

# Routes for the webapp service in the test namespace.
linkerd viz routes service/webapp -n test

# Routes for calls from the traffic deployment to the webapp service in the test namespace.
linkerd viz routes deploy/traffic -n test --to svc/webapp

Flags

Flag Usage
--namespace-n Namespace of the specified resource
--output-o Output format; one of: "table", "wide", or "json"
--selector-l Selector (label query) to filter on, supports '=', '==', and '!='
--time-window-t Stat window (for example: "10s", "1m", "10m", "1h")
--to If present, shows outbound stats to the specified resource
--to-namespace Sets the namespace used to lookup the "--to" resource; by default the current "--namespace" is used

stat

하나 또는 여러 리소스에 대한 트래픽 통계를 표시해요.

RESOURCES 인자는 통계를 집계할 대상 리소스를 지정해요: (TYPE [NAME] | TYPE/NAME) 또는 (TYPE [NAME1] [NAME2]...) 또는 (TYPE1/NAME1 TYPE2/NAME2...)

Examples:

  • cronjob/my-cronjob
  • deploy
  • deploy/my-deploy
  • deploy/ po/
  • ds/my-daemonset
  • job/my-job
  • ns/my-ns
  • po/mypod1 rc/my-replication-controller
  • po mypod1 mypod2
  • rc/my-replication-controller
  • rs
  • rs/my-replicaset
  • sts/my-statefulset
  • ts/my-split
  • authority
  • au/my-authority
  • httproute/my-route
  • route/my-route
  • all

유효한 리소스 유형:

  • cronjobs
  • daemonsets
  • deployments
  • namespaces
  • jobs
  • pods
  • replicasets
  • replicationcontrollers
  • statefulsets
  • authorities (not supported in --from)
  • authorizationpolicies (not supported in --from)
  • httproutes (not supported in --from)
  • services (not supported in --from)
  • servers (not supported in --from)
  • serverauthorizations (not supported in --from)
  • all (all resource types, not supported in --from or --to)

이 명령어는 완료된 리소스(예: Succeeded 또는 Failed 단계의 파드)는 숨겨요. 리소스 이름을 지정하지 않으면 지정된 RESOURCETYPE의 모든 리소스에 대한 통계를 표시해요.

Examples

# Get all deployments in the test namespace.
linkerd viz stat deployments -n test

# Get the hello1 replication controller in the test namespace.
linkerd viz stat replicationcontrollers hello1 -n test

# Get all namespaces.
linkerd viz stat namespaces

# Get all inbound stats to the web deployment.
linkerd viz stat deploy/web

# Get all inbound stats to the pod1 and pod2 pods
linkerd viz stat po pod1 pod2

# Get all inbound stats to the pod1 pod and the web deployment
linkerd viz stat po/pod1 deploy/web

# Get all pods in all namespaces that call the hello1 deployment in the test namespace.
linkerd viz stat pods --to deploy/hello1 --to-namespace test --all-namespaces

# Get all pods in all namespaces that call the hello1 service in the test namespace.
linkerd viz stat pods --to svc/hello1 --to-namespace test --all-namespaces

# Get the web service. With Services, metrics are generated from the outbound metrics
# of clients, and thus will not include unmeshed client request metrics.
linkerd viz stat svc/web

# Get the web services and metrics for any traffic coming to the service from the hello1 deployment
# in the test namespace.
linkerd viz stat svc/web --from deploy/hello1 --from-namespace test

# Get the web services and metrics for all the traffic that reaches the web-pod1 pod
# in the test namespace exclusively.
linkerd viz stat svc/web --to pod/web-pod1 --to-namespace test

# Get all services in all namespaces that receive calls from hello1 deployment in the test namespace.
linkerd viz stat services --from deploy/hello1 --from-namespace test --all-namespaces

# Get all namespaces that receive traffic from the default namespace.
linkerd viz stat namespaces --from ns/default

# Get all inbound stats to the test namespace.
linkerd viz stat ns/test

# Get all inbound stats to the emoji-grpc server
linkerd viz stat server/emoji-grpc

# Get all inbound stats to the web-public server authorization resource
linkerd viz stat serverauthorization/web-public

# Get all inbound stats to the web-get and web-delete HTTP route resources
linkerd viz stat route/web-get route/web-delete

# Get all inbound stats to the web-authz authorization policy resource
linkerd viz stat authorizationpolicy/web-authz

Flags

Flag Usage
--all-namespaces-A If present, returns stats across all namespaces, ignoring the "--namespace" flag
--from If present, restricts outbound stats from the specified resource name
--from-namespace Sets the namespace used from lookup the "--from" resource; by default the current "--namespace" is used
--namespace-n Namespace of the specified resource
--output-o Output format; one of: "table" or "json" or "wide"
--selector-l Selector (label query) to filter on, supports '=', '==', and '!='
--time-window-t Stat window (for example: "15s", "1m", "10m", "1h"). Needs to be at least 15s.
--to If present, restricts outbound stats to the specified resource name
--to-namespace Sets the namespace used to lookup the "--to" resource; by default the current "--namespace" is used
--unmeshed If present, include unmeshed resources in the output

tap

트래픽 스트림을 수신(listen)해요.

RESOURCE 인자는 tap 할 대상 리소스를 지정해요: (TYPE [NAME] | TYPE/NAME)

Examples:

  • cronjob/my-cronjob
  • deploy
  • deploy/my-deploy
  • deploy my-deploy
  • ds/my-daemonset
  • job/my-job
  • ns/my-ns
  • rs
  • rs/my-replicaset
  • sts
  • sts/my-statefulset

유효한 리소스 유형:

  • cronjobs
  • daemonsets
  • deployments
  • jobs
  • namespaces
  • pods
  • replicasets
  • replicationcontrollers
  • statefulsets
  • services (only supported as a --to resource)

참고

파드가 config.linkerd.io/skip-inbound-ports 또는 config.linkerd.io/skip-outbound-ports 어노테이션으로 구성된 경우, 해당 포트의 트래픽은 Linkerd 프록시를 우회해요. linkerd tap은 프록시를 통한 트래픽을 관찰하므로 건너뛴 포트의 트래픽은 tap 할 수 없어요.

Examples

# tap the web deployment in the default namespace
linkerd viz tap deploy/web

# tap the web-dlbvj pod in the default namespace
linkerd viz tap pod/web-dlbvj

# tap the test namespace, filter by request to prod namespace
linkerd viz tap ns/test --to ns/prod

Flags

Flag Usage
--authority Display requests with this :authority
--max-rps Maximum requests per second to tap.
--method Display requests with this HTTP method
--namespace-n Namespace of the specified resource
--output-o Output format. One of: "wide", "json", "jsonpath"
--path Display requests with paths that start with this prefix
--scheme Display requests with this scheme
--selector-l Selector (label query) to filter on, supports '=', '==', and '!='
--to Display requests to this resource
--to-namespace Sets the namespace used to lookup the "--to" resource; by default the current "--namespace" is used

top

라이브 트래픽에 대한 정렬된 정보를 표시해요.

RESOURCE 인자는 트래픽을 볼 대상 리소스를 지정해요: (TYPE [NAME] | TYPE/NAME)

Examples:

  • cronjob/my-cronjob
  • deploy
  • deploy/my-deploy
  • deploy my-deploy
  • ds/my-daemonset
  • job/my-job
  • ns/my-ns
  • rs
  • rs/my-replicaset
  • sts
  • sts/my-statefulset

유효한 리소스 유형:

  • cronjobs
  • daemonsets
  • deployments
  • jobs
  • namespaces
  • pods
  • replicasets
  • replicationcontrollers
  • statefulsets
  • services (only supported as a --to resource)

Examples

# display traffic for the web deployment in the default namespace
linkerd viz top deploy/web

# display traffic for the web-dlbvj pod in the default namespace
linkerd viz top pod/web-dlbvj

Flags

Flag Usage
--authority Display requests with this :authority
--hide-sources Hide the source column
--max-rps Maximum requests per second to tap.
--method Display requests with this HTTP method
--namespace-n Namespace of the specified resource
--path Display requests with paths that start with this prefix
--routes Display data per route instead of per path
--scheme Display requests with this scheme
--selector-l Selector (label query) to filter on, supports '=', '==', and '!='
--to Display requests to this resource
--to-namespace Sets the namespace used to lookup the "--to" resource; by default the current "--namespace" is used

uninstall

linkerd-viz 확장을 제거하는 데 필요한 Kubernetes 리소스를 출력해요.

이 명령어는 Linkerd-viz 확장을 제거하는 데 필요한 모든 Kubernetes 네임스페이스 범위 및 클러스터 범위 리소스(예: services, deployments, RBACs 등)를 제공해요.

Examples

linkerd viz uninstall | kubectl delete -f -

Flags

Flag Usage
--output-o Output format. One of: json|yaml

더 알아보기 (Learn more)