본문 바로가기
WIKI 기술 지식 베이스

프록시 구성

원문 보기 위키 갱신

프록시 구성 (Proxy Configuration)

Linkerd는 데이터 플레인 프록시의 구성을 재정의(override) 하는 데 사용할 수 있는 어노테이션 집합을 제공해요. 이는 자동 주입된 프록시의 기본 구성을 재정의할 때 유용해요.

다음은 지원되는 어노테이션 목록이에요:

Annotation Description
Annotation Description
config.alpha.linkerd.io/proxy-enable-native-sidecar Enable KEP-753 native sidecars. Deprecated in favor of config.linkerd.io/proxy-enable-native-sidecar
config.alpha.linkerd.io/proxy-wait-before-exit-seconds Adds a preStop hook to the proxy container to delay receiving SIGTERM signal from Kubernetes but no longer than pod's terminationGracePeriodSeconds. Defaults to 0
config.beta.linkerd.io/proxy-enable-native-sidecar Enable KEP-753 native sidecars. Deprecated in favor of config.linkerd.io/proxy-enable-native-sidecar
config.linkerd.io/access-log Enables HTTP access logging in the proxy. Accepted values are apache, to output the access log in the Appache Common Log Format, and json, to output the access log in JSON.
config.linkerd.io/admin-port Proxy port to serve metrics on
config.linkerd.io/close-wait-timeout Sets nf_conntrack_tcp_timeout_close_wait. Accepts a duration string, e.g. 1m or 3600s
config.linkerd.io/control-port Proxy port to use for control
config.linkerd.io/debug-image Linkerd debug container image name
config.linkerd.io/debug-image-pull-policy Docker image pull policy for debug image
config.linkerd.io/debug-image-version Linkerd debug container image version
config.linkerd.io/default-inbound-policy Proxy's default inbound policy
config.linkerd.io/enable-debug-sidecar Inject a debug sidecar for data plane debugging
config.linkerd.io/enable-external-profiles Enable service profiles for non-Kubernetes services
config.linkerd.io/image-pull-policy Docker image pull policy
config.linkerd.io/inbound-port Proxy port to use for inbound traffic
config.linkerd.io/opaque-ports Ports that skip the proxy's protocol detection mechanism and are proxied opaquely. Comma-separated list of values, where each value can be a port number or a range a-b.
config.linkerd.io/outbound-port Proxy port to use for outbound traffic
config.linkerd.io/pod-inbound-ports Comma-separated list of (non-proxy) container ports exposed by the pod spec. Useful when other mutating webhooks inject sidecar containers after the proxy injector has run
config.linkerd.io/proxy-additional-env Set additional proxy environment variables via a JSON-encoded list of Kubernetes EnvVar objects. Env vars are merged by name across three layers with increasing precedence: Helm proxy.additionalEnv spec:
template:
metadata:
annotations:
config.linkerd.io/proxy-cpu-limit: '1'
config.linkerd.io/proxy-cpu-request: '0.2'
config.linkerd.io/proxy-memory-limit: 2Gi
config.linkerd.io/proxy-memory-request: 128Mi
`

프록시의 리소스 사용량을 조정하는 방법에 대한 자세한 내용은 여기를 참고하세요.

linkerd inject 명령으로 주입된 프록시의 경우 명령줄 플래그로 구성을 재정의할 수 있어요.

출처: Linkerd Proxy Configuration

본문

인그레스 모드 (Ingress Mode)

경고

인그레스를 linkerd.io/inject: ingress로 ingress 모드로 메시에 넣을 때, 인그레스는 클러스터 로컬 및 외부 엔드포인트로의 오픈 릴레이(open relay)가 생기는 것을 피하기 위해 l5d-dst-override 헤더를 제거하도록 반드시 구성해야 해요.

프록시 인그레스 모드는 Linkerd가 특정 인그레스 컨트롤러와 통합되도록 돕기 위해 설계된 동작 모드예요. 인그레스 자체를 Service 포트/IP를 목적지로 사용하도록 구성할 수 없는 경우 인그레스 모드가 필요해요.

개별 Linkerd 프록시가 ingress 모드로 설정되면, 원래 목적지 대신 :authority, Host 또는 l5d-dst-override 헤더를 기준으로 요청을 라우팅해요. 이렇게 하면 Linkerd가 인그레스 컨테이너의 엔드포인트 선택을 재정의하고 자체 엔드포인트 선택을 수행하도록 지시하며, 라우트별 메트릭과 트래픽 분할 같은 기능을 활성화해요.

프록시는 기본 linkerd.io/inject: enabled 어노테이션 대신 linkerd.io/inject: ingress 어노테이션을 사용해서 ingress 모드로 실행하도록 구성할 수 있어요. inject CLI 명령의 --ingress 플래그로도 할 수 있어요:

`kubectl get deployment  -n  -o yaml | linkerd inject --ingress - | kubectl apply -f -
`

더 알아보기 (Learn more)