1.Kubernetes叢集設計
Cluster
├─ Node Pool: General apps (API, web)
├─ Node Pool: Workers (rendering, queues)
├─ Node Pool: GPU (AI inference)
└─ Node Pool: Data plane add-ons
- 域分隔的命名空間: `core`, `ai`, `ops`, `data`
- 根據 CPU/RAM/佇列深度的 HPA
- 關鍵服務的 PodDisruptionBudget
2. CI/CD + GitOps
Git push
-> CI (test/lint/build/security scan)
-> Build image + SBOM
-> Push registry
-> Update manifest repo
-> ArgoCD sync to cluster
-> Progressive rollout (canary)
// Example deployment strategy
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 25%
maxUnavailable: 0
3. 秘密與 IaC
- 秘密:保險庫/外部秘密操作員
- IaC:用於網路、叢集、DB、CDN 的 Terraform 模組
- 政策即代碼:OPA/Gatekeeper
4. 多區域部署
| 地區 | 角色 |
|---|---|
| 美國 | 原生流量+AI推理 |
| 歐盟 | 數據駐留+低延遲歐盟 |
| 亞太地區 | 區域店面 + 非同步工作人員 |
Routing: Geo DNS + health checks
Data: primary region + read replicas + async replication
Failover: RTO < 30 min, RPO < 5 min
5. 成本優化
- 批次工作人員的 Spot 實例
- 透過間歇性作業將規模縮小到零
- 為穩定工作負載預留容量
- 圖片優化+CDN分流減少出口
六、總結
層次集群 有助於優化效能和成本
Git 操作 增加控制和回滾能力
多區域 是全球擴張時的重要要求
成本最佳化 需要從頭開始設計