Skip to content
Beside the Wheel
Search
Ctrl
K
Cancel
Email
GitHub
Select theme
Dark
Light
Auto
공부
(5)
spot 인스턴스에서 서버 가용성 개선하기
eBPF로 서버 성능 Profiling하는 법: Pyroscope의 구현 살펴보기
정수론부터 RSA까지
strace로 shaka-packager 버그 추적
Kubernetes The Hard Way
TIL
(956)
AI
(43)
DevOps
(230)
Network
(61)
OS
(155)
개발
(113)
데이터베이스
(64)
서버
(72)
수학
(20)
알고리즘
(24)
암호학
(32)
언어
(113)
컴퓨터구조
(5)
코드
(24)
독후감
(43)
과학
(1)
사회
(2)
산문
(3)
소설
(12)
인문
(11)
자기계발
(7)
철학
(7)
생각
(6)
고민
변화에 대하여
의식의 영역에 대하여
본질을 보려면
짧은 생각들
소유냐 존재냐
회고
(14)
2022.03-04 대덕소마고 입학소감/다짐
2022.05-08 프로젝트와 인간관계
2022.09-2023.02 불안과 판단
2023.03-07 DMS 리더 회고
2023.08-11 나는 누구인가?
2023.12 더 많은 걸 배우기 위한 경험
2024.01-02 회사 인턴 회고
2024.03-04 고3 근황
2024.05-07 고등학교 마무리
2024.08-12 첫 회사
2025.01-03 입출력
2025.03-08 효능감이란 무엇일까
2025.09-12 연말회고
2026.01-08 담론
Email
GitHub
Select theme
Dark
Light
Auto
태그: service-mesh
총 12개의 글이 있습니다.
Linkerd와 Istio 비교
service-mesh
2025. 11. 28.
Service Mesh는 마이크로서비스 간의 통신을 관리하는 인프라 계층이다. Kubernetes 환경에서 가장 많이 사용되는 Service Mesh인 Linkerd와 Istio의 구조와 특징을 비교해보자. Service Mesh가 필요한 이유 마이크로서비스 아키텍처에서는 수십, 수백 개의 서비스가 서로 통신한다. 이때 몇 가지 문제가 발생한다. 서비스 간 통신은 기본적으로 암호화되지 않는다. 어떤 서비스가 어떤 서비스와 통신하는지 파악하기 어렵다. 특정 서비스에 장애가 발생하면 연쇄적으로 다른 서비스에 영향을 미친다. 트래픽을 세밀하게 제어하기 어렵다. 이런 문제를 해결하기 위해 각 서비스에 프록시를 붙여서 모든 트래픽을 가로채고 관리하는 방식이 등장했다. 이것이 Service Mesh다. 그
linkerd
linkerd
2025. 5. 14.
Control Plane Control plane은 Kubernetes의 전용 네임스페이스 (`linkerd`)에서 Linkerd 전체 제어를 위해 실행되는 서비스 집합이다. Destination Service 프록시가 서비스 디스커버리 정보를 가져오는 역할 서비스가 어디에 있는지, 어떤 TLS 인증서가 필요한지 등의 정보를 gRPC API로 제공 정책 정보와 service profile(재시도, 타임아웃, per-route metrics에 사용)을 프록시에 전달 Identity Service mTLS를 위한 인증서 발급 기능을 수행 프록시가 부트스트랩 시 CSR(Certificate Signing Request)을 보내면, CA 역할을 하여 서명된 인증서를 반환 프록시 간 통신
service mesh
service-mesh
2025. 4. 29.
Dry run
istio
2024. 3. 13.
A dry run (or practice run) is a software testing process used to make sure that a system works correctly and will not result in severe failure. Istio has a experimental annotation `istio.io/dry-run` to dry-run the policy without actually enforcing it. The dry-run annotation allows you to better understand the effect of an authorization policy before applying it to the production traffic. This h
gateway log debug 하는 법
istio
2024. 3. 13.
Debugging Istio Envoy filters can be challenging but there are several techniques and tools that can help you troubleshoot issues. Here's a step-by-step guide to debug Istio Envoy filters: 1. Enable Debug Logs: By default, Istio's Envoy sidecar logs only contain essential information. To get more detailed logs, you can enable debug logging by changing the log level. To do this, you'll need to mo
Istio Arcitecture
istio
2024. 3. 13.
An Istio service mesh is logically split into a data plane and a control plane. The data plane is composed of a set of intelligent proxies (Envoy) deployed as sidecars. These proxies mediate and control all network communication between microservices. They also collect and report telemetry on all mesh traffic. The control plane manages and configures the proxies to route traffic. The following
Istio authorization
istio
2024. 3. 13.
Istio는 `ClusterRbacConfig`를 통해 ServiceRole에 권한 Rule을 정의한 후 ServiceRoleBinding을 통해 특정 대상에 해당 ServiceRole에 지정하여 접근 제어를 수행한다. mesh, namespace, workload 범위에서의 access control을 적용할 수 있다. Istio authorization을 사용했을 때 얻을 수 있는 이점은 아래와 같다. 간단한 API: AuthorizationPolicy CRD를 통해 쉬운 접근 제어가 가능하다. 유연한 설정: CUSTOM, DENY 및 ALLOW 등 Istio 특성에 대한 사용자 지정 조건을 자유롭게 정의할 수 있다. 고성능: Envoy native를 사용하기에 성능이 우수하다. 높은 호환성: gRP
Istio Configuration Profiles
istio
2024. 3. 13.
default: enables components according to the default settings of the IstioOperator API. This profile is recommended for production deployments and for primary clusters in a multicluster mesh. You can display the default settings by running the istioctl profile dump command. demo: configuration designed to showcase Istio functionality with modest resource requirements. It is suitable to ru
Istio RBAC
istio
2024. 3. 13.
Istio RBAC를 통해 네임스페이스, 서비스, HTTP 메소드 수준의 권한 제어를 실습 해보자. 준비작업 1. k8s, helm 설치 2. Istio 초기화 (namespace, CRDs) bash $ wget $ tar -vxzf istio-1.8.2-osx.tar.gz $ cd istio-1.8.2 $ kubectl create namespace istio-system $ helm template install/kubernetes/helm/istio-init --name istio-init --namespace istio-system | kube
Istioctl
istio
2024. 3. 13.
bash istioctl proxy-status NAME CLUSTER CDS LDS EDS RDS ECDS ISTIOD VERSION argocd-application-controller-0.argocd Kubernetes SYNCED SYNCED SYNCED SYNCED NOT SENT istiod-977466b69-2kms7 1.18.2 argocd-applicationset-controlle
Resource Annotations & Labels
istio
2024. 3. 13.
The various resource annotations that Istio supports to control its behavior. |Annotation|Name|Resource Types|Description| |-|-|-|-| |`galley.istio.io/analyze-suppres`s|[Any]|A comma separated list of configuration analysis message codes to suppress when Istio analyzers are run. For example, to suppress reporting of IST0103 |(PodMissingP
ServiceEntry
istio
2024. 3. 13.
Since not all services live in the sevice mesh, we need a way for services inside the mesh to communicate with those outdise the mesh. Those could be existing HTTP services or, more likely, infrastructure services like databases or caches. We can still implement sophisticated routing for services that reside outside Istio, but first we have to introduce the concept of a `ServiceEntry`. Istio