Chuyển đến nội dung chính

第 37 課:實作 — HELM、操作員與 GITOPS

模組 8 練習:建立 Helm 4 圖表並發佈到 OCI 註冊表、安裝 cert-manager Operator、設定 ArgoCD GitOps 從 Git 部署應用程式、建立 App of Apps 模式。

🔒 DevSecOps — 第 37 課 第 37 課:實踐-掌舵、操作員和 GITOPS

Kubernetes:從基礎到高級

Module 8: Helm, Operators & GitOps

xdev.asia

🎯 練習課的目的

  • 從頭開始建立 Helm 圖表並安裝
  • 創建 Helm 掛鉤和測試
  • 安裝 cert-manager Operator 並產生 TLS 憑證
  • 部署ArgoCD並創建應用程式
  • 應用程式模式的設定應用程式

實驗 1:建立 Helm 圖表

kubectl create namespace lab8

Tạo chart mới

helm create webapp ls webapp/

Chart.yaml charts/ templates/ values.yaml

Xem chart structure

cat webapp/Chart.yaml cat webapp/values.yaml

Chỉnh sửa values.yaml

cat > webapp/values.yaml <<EOF replicaCount: 2

image: repository: nginx tag: "1.27" pullPolicy: IfNotPresent

service: type: ClusterIP port: 80

ingress: enabled: false

resources: requests: cpu: "100m" memory: "128Mi" limits: cpu: "500m" memory: "256Mi"

livenessProbe: httpGet: path: / port: http

readinessProbe: httpGet: path: / port: http EOF

Lint chart

helm lint webapp/

Dry run

helm install --dry-run --debug webapp-test webapp/ -n lab8

Install

helm install webapp webapp/ -n lab8 helm list -n lab8

Upgrade (thay đổi replicas)

helm upgrade webapp webapp/ -n lab8 --set replicaCount=3

Xem history

helm history webapp -n lab8

Rollback về revision 1

helm rollback webapp 1 -n lab8

實驗室 2:頭盔掛鉤

# Thêm pre-upgrade hook (database migration giả lập)
cat > webapp/templates/migration-job.yaml <<EOF
apiVersion: batch/v1
kind: Job
metadata:
  name: "{{ .Release.Name }}-migration"
  annotations:
    "helm.sh/hook": pre-upgrade,pre-install
    "helm.sh/hook-weight": "-5"
    "helm.sh/hook-delete-policy": hook-succeeded
spec:
  template:
    spec:
      restartPolicy: Never
      containers:
      - name: migration
        image: busybox:1.36
        command: ['sh', '-c', 'echo "Running DB migration..."; sleep 3; echo "Migration complete!"']
EOF

Upgrade với hook

helm upgrade webapp webapp/ -n lab8

Xem migration job

kubectl get jobs -n lab8 kubectl logs -n lab8 job/webapp-migration

實驗室 3:安全帽測試

# Tạo test
mkdir -p webapp/templates/tests
cat > webapp/templates/tests/test-connection.yaml <<EOF
apiVersion: v1
kind: Pod
metadata:
  name: "{{ .Release.Name }}-test-connection"
  annotations:
    "helm.sh/hook": test
spec:
  restartPolicy: Never
  containers:
  - name: test
    image: busybox:1.36
    command:
    - sh
    - -c
    - |
      until wget -qO- http://{{ .Release.Name }}-webapp:{{ .Values.service.port }}; do
        echo "Waiting for service..."
        sleep 2
      done
      echo "Test passed!"
EOF

helm upgrade webapp webapp/ -n lab8 helm test webapp -n lab8

實驗 4:cert-manager 操作員

# Cài cert-manager
helm repo add jetstack https://charts.jetstack.io
helm repo update
helm install cert-manager jetstack/cert-manager \
  --namespace cert-manager \
  --create-namespace \
  --set crds.enabled=true

kubectl get pods -n cert-manager

cert-manager-xxx, cert-manager-cainjector-xxx, cert-manager-webhook-xxx

Tạo self-signed ClusterIssuer

cat <<EOF | kubectl apply -f - apiVersion: cert-manager.io/v1 kind: ClusterIssuer metadata: name: selfsigned-issuer spec: selfSigned: {}

Certificate cho webapp

apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: webapp-tls namespace: lab8 spec: secretName: webapp-tls-secret issuerRef: name: selfsigned-issuer kind: ClusterIssuer dnsNames:

  • webapp.lab8.svc.cluster.local
  • webapp.example.com duration: 2160h # 90 days renewBefore: 360h # renew khi còn 15 days EOF

Xem certificate status

kubectl get certificate -n lab8 kubectl describe certificate webapp-tls -n lab8

Status: Ready

Xem generated secret

kubectl get secret webapp-tls-secret -n lab8 kubectl get secret webapp-tls-secret -n lab8 -o jsonpath='{.data.tls.crt}' | base64 -d | openssl x509 -text -noout

實驗 5:部署 ArgoCD

# Cài ArgoCD
kubectl create namespace argocd
kubectl apply -n argocd -f https://raw.githubusercontent.com/argoproj/argo-cd/stable/manifests/install.yaml

Chờ ArgoCD ready

kubectl wait --for=condition=available deployment/argocd-server -n argocd --timeout=120s

Lấy admin password

ARGOCD_PASSWORD=$(kubectl -n argocd get secret argocd-initial-admin-secret
-o jsonpath="{.data.password}" | base64 -d) echo "ArgoCD password: $ARGOCD_PASSWORD"

Port-forward UI

kubectl port-forward svc/argocd-server -n argocd 8080:443 & echo "ArgoCD UI: https://localhost:8080 (admin/$ARGOCD_PASSWORD)"

Hoặc dùng ArgoCD CLI

argocd login localhost:8080 --username admin --password $ARGOCD_PASSWORD --insecure

實驗 6:創建 ArgoCD 應用程式

# Tạo Application bằng CLI
argocd app create webapp-gitops \
  --repo https://github.com/argoproj/argocd-example-apps \
  --path guestbook \
  --dest-server https://kubernetes.default.svc \
  --dest-namespace lab8 \
  --sync-policy automated \
  --auto-prune \
  --self-heal

Xem status

argocd app list argocd app get webapp-gitops

Sync thủ công

argocd app sync webapp-gitops

Xem trong browser: https://localhost:8080

# Tạo Application bằng YAML
cat <<EOF | kubectl apply -f -
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: guestbook
  namespace: argocd
spec:
  project: default
  source:
    repoURL: https://github.com/argoproj/argocd-example-apps
    targetRevision: HEAD
    path: guestbook
  destination:
    server: https://kubernetes.default.svc
    namespace: lab8
  syncPolicy:
    automated:
      prune: true
      selfHeal: true
    syncOptions:
    - CreateNamespace=true
EOF

實驗室 7:應用中的應用

# Tạo cấu trúc Git repo (simulate locally)
mkdir -p /tmp/gitops-demo/apps-of-apps
mkdir -p /tmp/gitops-demo/apps/{webapp,monitoring}

Root Application file

cat > /tmp/gitops-demo/apps-of-apps/webapp.yaml <<EOF apiVersion: argoproj.io/v1alpha1 kind: Application metadata: name: webapp-child namespace: argocd spec: project: default source: repoURL: https://github.com/argoproj/argocd-example-apps path: helm-guestbook targetRevision: HEAD destination: server: https://kubernetes.default.svc namespace: lab8 syncPolicy: automated: prune: true selfHeal: true EOF

Apply root app

kubectl apply -f /tmp/gitops-demo/apps-of-apps/ -n argocd

ArgoCD sẽ tìm và deploy tất cả Application CRDs trong thư mục

argocd app list

實驗 8:模擬 GitOps 工作流程

# 1. Xem app đang chạy
kubectl get pods -n lab8

2. Simulate: ai đó thay đổi trực tiếp trong cluster (drift)

kubectl scale deployment guestbook-ui -n lab8 --replicas=0

3. ArgoCD detect và tự heal trong vài phút

kubectl get pods -n lab8 -w

4. Xem ArgoCD phục hồi về 2 replicas (self-heal)

argocd app get guestbook

5. Xem sync history

argocd app history guestbook

清理

helm uninstall webapp -n lab8
kubectl delete namespace lab8
kubectl delete application guestbook webapp-gitops webapp-child -n argocd
kubectl delete namespace argocd
helm uninstall cert-manager -n cert-manager
kubectl delete namespace cert-manager

總結

  • ✅ 從頭開始的 Helm 圖表:結構、範本、值
  • ✅ Helm hooks:升級前的遷移作業
  • ✅ Helm 測試:驗證部署
  • ✅ cert-manager:自動 TLS 證書
  • ✅ ArgoCD:應用程式+同步策略自動化
  • ✅ 應用程式中的應用程式:使用 1 個根應用程式管理多個應用程式
  • ✅ GitOps 自我修復:ArgoCD 自我修復漂移