Certified Kubernetes Administrator (CKA) with Practice Tests - Sector 2

Albert·2025년 1월 17일

Sector 2

Sector2 에서는 Kubernetes 의 구성요소들에 대해서 간략하게 설명합니다.

ETCD

ETCD는 Kubernetes의 핵심 구성 요소 중 하나로, 분산 키-값 저장소입니다. Kubernetes 클러스터의 상태 데이터를 저장하고 관리하는 역할을 합니다. 이를 통해 클러스터가 안정적으로 동작할 수 있도록 중요한 정보를 제공합니다.

kube-apiserver

Kubernetes 클러스터에서 모든 구성 요소와 사용자 간의 통신 허브로 작동하며, 클러스터의 상태를 관리하고 조작하기 위한 RESTful API를 제공합니다.

kube-apiserver 는 아래와 같은 역할을 담당한다.
1. Authnticate User
2. Validate Request
3. Retrieve data (ETCD cluster)
4. Update ETCD
5. Scheduler
6. Kubelet

만약, "파드를 생성하라" 라는 명령어가 들어온다면
scheduler 는 지속적으로 API 서버를 모니터링 한다.
그리고 나서 새로운 파드가 생겼다는 것을 깨닫는다.
그러면 API 서버에 요청을 보내서 파드를 만드는데,
API 서버는 Worker Node 의 kubelet 에게 해당 명령어를 보낸다.
작업이 완료된 후 kubelet 은 상태값을 API 서버에 반환값으로 응답한다.
그러면 API 서버는 데이터(etcd cluster)를 업데이트한다.

Kube Controller Manager

쿠버네티스의 뇌를 담당하고 있으며, 현재 상태를 원한느 상태로 유지하는 역할을 수행한다. 다양한 컨트롤러들이 존재한다.
1. NodeController
2. Replication Controller
3. Endpoint Controller
4. Service Account & Token Controller
5. Job Controller
6. Resource Quota Controller

Kube Scheduler

새로운 Pod를 적절한 노드에 배치하는 역할을 수행합니다.
Kube Scheduler 는 클러스터의 현재 상태를 분석하고 가장 적합한 노드를 선택하여 Pod를 배치합니다.

Kubelet

배의 선장과 같은 역할을 합니다. 마스터십의 유일한 연결망입니다.

Kube Proxy

Kube proxy 는 모든 각 클러스터에서 실행됩니다.(Kube proxy is a process that runs on each node in the Kubernetes cluster)
kube proxy 는 iptables 룰을 정의하고 정의된 룰을 netfliter 에도 생성되며, 실제로 패킷은 netfilter 에 의해 특정 결로로 전달된다.

https://kodekloud.com/blog/kubernetes-ingress/

What is Kubernetes Ingress?
Kubernetes ingress is a powerful tool for managing external access to your Kubernetes services.
It acts as a layer between your services and the outside world, providing load balancing, SSL termination, and routing based on your defined rules. With Kubernetes ingress, you can easily expose your services to the internet while maintaining granular control over who has access to them.

YAML in kubernetes

top level fields: apiVersion, kind, metadata, spec

apiVersion:
kind:
metadata:
spec:

ReplicaSet

ReplicaSet 과 ReplicaController 는 매우 유사한 동작을 한다.
ReplicaSet 과 ReplicaController 의 한 가지 다른 점은 spec.selector 가 있다는 것이다. 해당 값을 통해서 ReplicaSet 은 기존에 관리되어 있는 Pod 들과 같이 관리할 수 있게 되었다.

  • ReplicaSet -> apiVersion: apps/v1
  • ReplicaController -> apiVersion: v1

Deployment

Deployment 를 생성하면 replicaSet 은 자동으로 생성된다.

Service

Service 도 replicaset, pod 와 같은 object 이다
서비스는 가상환경 서버와 같다

Node Port Service

  • 포트포워딩을 진행
    ClusterIP
  • 클러스터 내부에서만 접근 가능하며, 외부에서는 직접 접근할 수 없다
  • 클러스터 내에서 Pod 통신할 때 사용된다
  • Service 에 고유한 내부 IP 주소를 생성하고 이를 통해 트래픽을 로드밸런싱한다
    - ex. Backend Database 간의 통신
    LoadBalancer
  • 클러스터 외부에서 접근 가능한 IP 주소를 자동으로 프로비저닝한다.
  • 클라우드 환경에서 외부 로드밸런서를 생성하여 트래픽을 Kubernetes Service 로 전달한다
  • 외부 클라이언트가 서비스를 직접 호출 할 수 있다
    - ex. 웹 애플리케이션, API

https://www.udemy.com/course/certified-kubernetes-administrator-with-practice-tests/?couponCode=MT24125BROW
Udemy 강의를 기반으로 합니다.

profile
개발 블로그

0개의 댓글