簡介
在上線之前,系統需要經過生產準備審核。本文提供了微服務和微前端的全面清單。
1. 安全檢查表
1.1 應用程式安全
✅ OWASP Top 10 reviewed:
├── SQL Injection → Parameterized queries
├── XSS → CSP headers, output encoding
├── CSRF → SameSite cookies, CSRF tokens
├── Broken Auth → OAuth2/OIDC, MFA
├── Security Misconfiguration → Hardened defaults
├── Sensitive Data Exposure → Encrypt at rest + transit
├── Broken Access Control → RBAC, resource-level checks
└── Injection → Input validation, allow-lists
1.2 秘密管理
❌ Secrets in code / environment variables:
DB_PASSWORD=mysecretpassword
✅ External secret management:
├── HashiCorp Vault
├── AWS Secrets Manager
├── Kubernetes External Secrets
└── Sealed Secrets (GitOps-friendly)
1.3 網路安全
# Kubernetes Network Policy
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: product-service
spec:
podSelector:
matchLabels:
app: product-service
policyTypes: [Ingress, Egress]
ingress:
- from:
- podSelector:
matchLabels:
app: api-gateway
ports:
- port: 8080
2. 可靠性檢查表
2.1 健康檢查
// Liveness: is the process alive?
app.get('/health/live', (req, res) => {
res.status(200).json({ status: 'alive' });
});
// Readiness: can it serve traffic?
app.get('/health/ready', async (req, res) => {
const dbOk = await checkDB();
const redisOk = await checkRedis();
if (dbOk && redisOk) {
res.status(200).json({ status: 'ready' });
} else {
res.status(503).json({ status: 'not ready', db: dbOk, redis: redisOk });
}
});
2.2 斷路器
Normal: Service A ──► Service B (responding)
Open: Service A ──✕ Service B (down, circuit open)
Half-Open: Service A ──? Service B (testing 1 request)
Closed: Service A ──► Service B (recovered)
Settings:
├── Failure threshold: 5 failures in 30s → OPEN
├── Reset timeout: 30s → try HALF-OPEN
├── Success threshold: 3 successes → CLOSE
└── Fallback: return cached/default data
2.3 正常關機
// Handle SIGTERM gracefully
process.on('SIGTERM', async () => {
console.log('SIGTERM received, shutting down...');
// 1. Stop accepting new requests
server.close();
// 2. Wait for in-flight requests (max 30s)
await waitForInflightRequests(30000);
// 3. Close DB connections
await db.close();
// 4. Close message broker connections
await kafka.disconnect();
console.log('Shutdown complete');
process.exit(0);
});
2.4 資源限制
# K8s resource limits
resources:
requests:
cpu: 100m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi
# HPA (auto-scaling)
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
spec:
minReplicas: 2
maxReplicas: 10
metrics:
- type: Resource
resource:
name: cpu
target:
type: Utilization
averageUtilization: 70
3. 生產準備清單
INFRASTRUCTURE:
☐ Kubernetes cluster with node pools
☐ Auto-scaling (HPA) configured
☐ Resource limits set for all pods
☐ Network policies defined
☐ Ingress/Load balancer configured
☐ SSL/TLS certificates (auto-renew)
SECURITY:
☐ OWASP Top 10 reviewed
☐ Secrets in Vault (not env vars)
☐ RBAC policies configured
☐ Container image scanning
☐ Dependency vulnerability scanning
☐ CSP headers configured
RELIABILITY:
☐ Health checks (liveness + readiness)
☐ Circuit breakers for external calls
☐ Graceful shutdown handlers
☐ Retry policies with backoff
☐ Timeouts configured
☐ PodDisruptionBudget set
OBSERVABILITY:
☐ Structured logging (JSON)
☐ Metrics (RED method)
☐ Distributed tracing
☐ Alerting rules defined
☐ Dashboards created
☐ On-call rotation set
DATA:
☐ Database backups (automated, tested)
☐ Database migration strategy
☐ Data retention policies
☐ GDPR/privacy compliance
☐ Encryption at rest
DEPLOYMENT:
☐ CI/CD pipeline tested
☐ Rollback strategy documented
☐ Canary deployment configured
☐ Feature flags for risky features
☐ Runbook documented
4.災難復原
| 組件 | 復原點目標 | RTO | 戰略 |
|---|---|---|---|
| PostgreSQL | 1 分鐘 | 15 分鐘 | 串流副本 + WAL 檔案 |
| Redis | 5 分鐘 | 5 分鐘 | Redis哨兵+AOF |
| 卡夫卡 | 0 | 5 分鐘 | 多經紀商,複製因子 3 |
| MFE 資產 | 0 | 1 分鐘 | 多區域CDN |
| K8s叢集 | 不適用 | 30 分鐘 | 多可用區、備份 etcd |
總結
- 安全性:OWASP、機密管理、網路策略
- 可靠性:健康檢查、斷路器、正常關閉
- 可觀察性:日誌、指標、追蹤、警報
- 災難復原:備份經過測試,RPO/RTO 已定義
- 清單:每次生產部署前進行檢查
下一篇文章: 第 29 課:案例研究 — 電子商務平台遷移