如何将K8s服务同步到K8s以外的Consul集群?

时间:2019-05-27 01:44:46

标签: kubernetes kubernetes-helm consul

来自领事k8 document Consul服务器群集可以在Kubernetes群集内运行,也可以在Kubernetes群集内运行。 Consul服务器群集不需要与同步过程在同一台计算机或同一平台上运行。 需要使用Consul群集的地址以及其他访问信息(例如ACL令牌)来配置同步过程。

我要同步的领事集群位于,根据文档,我必须将地址传递给领事集群以进行同步过程。但是,用于安装同步的头盔图进程不包含任何用于配置领事群集ip地址的值。

syncCatalog: 

  # True if you want to enable the catalog sync. "-" for default. 

  enabled: false 

  image: null 

  default: true # true will sync by default, otherwise requires annotation 



  # toConsul and toK8S control whether syncing is enabled to Consul or K8S 

  # as a destination. If both of these are disabled, the sync will do nothing. 

  toConsul: true 

  toK8S: true 



  # k8sPrefix is the service prefix to prepend to services before registering 

  # with Kubernetes. For example "consul-" will register all services 

  # prepended with "consul-". (Consul -> Kubernetes sync) 

  k8sPrefix: null 



  # consulPrefix is the service prefix which preprends itself 

  # to Kubernetes services registered within Consul 

  # For example, "k8s-" will register all services peprended with "k8s-". 

  # (Kubernetes -> Consul sync) 

  consulPrefix: null 



  # k8sTag is an optional tag that is applied to all of the Kubernetes services 

  # that are synced into Consul. If nothing is set, defaults to "k8s". 

  # (Kubernetes -> Consul sync) 

  k8sTag: null 



  # syncClusterIPServices syncs services of the ClusterIP type, which may 

  # or may not be broadly accessible depending on your Kubernetes cluster. 

  # Set this to false to skip syncing ClusterIP services. 

  syncClusterIPServices: true 



  # nodePortSyncType configures the type of syncing that happens for NodePort 

  # services. The valid options are: ExternalOnly, InternalOnly, ExternalFirst. 

  # - ExternalOnly will only use a node's ExternalIP address for the sync 

  # - InternalOnly use's the node's InternalIP address 

  # - ExternalFirst will preferentially use the node's ExternalIP address, but 

  #   if it doesn't exist, it will use the node's InternalIP address instead. 

  nodePortSyncType: ExternalFirst 



  # aclSyncToken refers to a Kubernetes secret that you have created that contains 

  # an ACL token for your Consul cluster which allows the sync process the correct 

  # permissions. This is only needed if ACLs are enabled on the Consul cluster. 

  aclSyncToken: 

    secretName: null 

    secretKey: null 



  # nodeSelector labels for syncCatalog pod assignment, formatted as a muli-line string. 

  # ref: https://kubernetes.io/docs/concepts/configuration/assign-pod-node/#nodeselector 

  # Example: 

  # nodeSelector: | 

  #   beta.kubernetes.io/arch: amd64 

  nodeSelector: null

那么如何设置领事群集IP地址以进行同步处理?

1 个答案:

答案 0 :(得分:1)

它看起来像是k8s主机上的同步服务runs via the consul agent

          env:
            - name: HOST_IP
              valueFrom:
                fieldRef:
                  fieldPath: status.hostIP
          command: 
            - consul-k8s sync-catalog \
                  -http-addr=${HOST_IP}:8500

无法直接配置,但是头盔可以通过client.joinyaml src)配置代理/客户端:

  

如果为null(默认值),则客户端将尝试自动加入Kubernetes中运行的服务器群集。这意味着将server.enabled设置为true时,客户端将自动加入该集群。如果server.enabled不为true,则必须指定一个值,以便客户端可以加入有效的集群。

此值作为--retry-join选项传递给领事代理。

client:
  enabled: true
  join:
  - consul1
  - consul2
  - consul3
syncCatalog:
  enabled: true