프록시 구성
프록시 구성 (Proxy Configuration)
Linkerd는 데이터 플레인 프록시의 구성을 재정의(override) 하는 데 사용할 수 있는 어노테이션 집합을 제공해요. 이는 자동 주입된 프록시의 기본 구성을 재정의할 때 유용해요.
다음은 지원되는 어노테이션 목록이에요:
| Annotation | Description |
|---|---|
| Annotation | Description |
| config.alpha.linkerd.io/proxy-enable-native-sidecar | Enable KEP-753 native sidecars. Deprecated in favor of config.linkerd.io/proxy-enable-native-sidecar |
| config.alpha.linkerd.io/proxy-wait-before-exit-seconds | Adds a preStop hook to the proxy container to delay receiving SIGTERM signal from Kubernetes but no longer than pod's terminationGracePeriodSeconds. Defaults to 0 |
| config.beta.linkerd.io/proxy-enable-native-sidecar | Enable KEP-753 native sidecars. Deprecated in favor of config.linkerd.io/proxy-enable-native-sidecar |
| config.linkerd.io/access-log | Enables HTTP access logging in the proxy. Accepted values are apache, to output the access log in the Appache Common Log Format, and json, to output the access log in JSON. |
| config.linkerd.io/admin-port | Proxy port to serve metrics on |
| config.linkerd.io/close-wait-timeout | Sets nf_conntrack_tcp_timeout_close_wait. Accepts a duration string, e.g. 1m or 3600s |
| config.linkerd.io/control-port | Proxy port to use for control |
| config.linkerd.io/debug-image | Linkerd debug container image name |
| config.linkerd.io/debug-image-pull-policy | Docker image pull policy for debug image |
| config.linkerd.io/debug-image-version | Linkerd debug container image version |
| config.linkerd.io/default-inbound-policy | Proxy's default inbound policy |
| config.linkerd.io/enable-debug-sidecar | Inject a debug sidecar for data plane debugging |
| config.linkerd.io/enable-external-profiles | Enable service profiles for non-Kubernetes services |
| config.linkerd.io/image-pull-policy | Docker image pull policy |
| config.linkerd.io/inbound-port | Proxy port to use for inbound traffic |
| config.linkerd.io/opaque-ports | Ports that skip the proxy's protocol detection mechanism and are proxied opaquely. Comma-separated list of values, where each value can be a port number or a range a-b. |
| config.linkerd.io/outbound-port | Proxy port to use for outbound traffic |
| config.linkerd.io/pod-inbound-ports | Comma-separated list of (non-proxy) container ports exposed by the pod spec. Useful when other mutating webhooks inject sidecar containers after the proxy injector has run |
| config.linkerd.io/proxy-additional-env | Set additional proxy environment variables via a JSON-encoded list of Kubernetes EnvVar objects. Env vars are merged by name across three layers with increasing precedence: Helm proxy.additionalEnv spec: |
| template: | |
| metadata: | |
| annotations: | |
| config.linkerd.io/proxy-cpu-limit: '1' | |
| config.linkerd.io/proxy-cpu-request: '0.2' | |
| config.linkerd.io/proxy-memory-limit: 2Gi | |
| config.linkerd.io/proxy-memory-request: 128Mi | |
| ` |
프록시의 리소스 사용량을 조정하는 방법에 대한 자세한 내용은 여기를 참고하세요.
linkerd inject 명령으로 주입된 프록시의 경우 명령줄 플래그로 구성을 재정의할 수 있어요.
본문
인그레스 모드 (Ingress Mode)
경고
인그레스를 linkerd.io/inject: ingress로 ingress 모드로 메시에 넣을 때, 인그레스는 클러스터 로컬 및 외부 엔드포인트로의 오픈 릴레이(open relay)가 생기는 것을 피하기 위해 l5d-dst-override 헤더를 제거하도록 반드시 구성해야 해요.
프록시 인그레스 모드는 Linkerd가 특정 인그레스 컨트롤러와 통합되도록 돕기 위해 설계된 동작 모드예요. 인그레스 자체를 Service 포트/IP를 목적지로 사용하도록 구성할 수 없는 경우 인그레스 모드가 필요해요.
개별 Linkerd 프록시가 ingress 모드로 설정되면, 원래 목적지 대신 :authority, Host 또는 l5d-dst-override 헤더를 기준으로 요청을 라우팅해요. 이렇게 하면 Linkerd가 인그레스 컨테이너의 엔드포인트 선택을 재정의하고 자체 엔드포인트 선택을 수행하도록 지시하며, 라우트별 메트릭과 트래픽 분할 같은 기능을 활성화해요.
프록시는 기본 linkerd.io/inject: enabled 어노테이션 대신 linkerd.io/inject: ingress 어노테이션을 사용해서 ingress 모드로 실행하도록 구성할 수 있어요. inject CLI 명령의 --ingress 플래그로도 할 수 있어요:
`kubectl get deployment -n -o yaml | linkerd inject --ingress - | kubectl apply -f -
`