kubernetes-ops

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Kubernetes Operations

Kubernetes 运维操作

Deploy and manage containerized applications on Kubernetes clusters.
在Kubernetes集群上部署和管理容器化应用。

When to Use This Skill

何时使用此技能

Use this skill when:
  • Deploying applications to Kubernetes
  • Managing pods, deployments, and services
  • Configuring resource limits and scaling
  • Troubleshooting Kubernetes workloads
  • Setting up networking and ingress
在以下场景使用此技能:
  • 将应用部署到Kubernetes
  • 管理Pod、Deployment和Service
  • 配置资源限制与扩缩容
  • 排查Kubernetes工作负载问题
  • 配置网络与Ingress

Prerequisites

前置条件

  • kubectl installed and configured
  • Access to a Kubernetes cluster
  • Basic understanding of containers
  • 已安装并配置kubectl
  • 拥有Kubernetes集群的访问权限
  • 具备容器的基础知识

Core Resources

核心资源

Deployment

Deployment

yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: myapp
  labels:
    app: myapp
spec:
  replicas: 3
  selector:
    matchLabels:
      app: myapp
  template:
    metadata:
      labels:
        app: myapp
    spec:
      containers:
      - name: myapp
        image: myapp:1.0.0
        ports:
        - containerPort: 8080
        resources:
          requests:
            memory: "128Mi"
            cpu: "100m"
          limits:
            memory: "256Mi"
            cpu: "500m"
        livenessProbe:
          httpGet:
            path: /health
            port: 8080
          initialDelaySeconds: 10
          periodSeconds: 10
        readinessProbe:
          httpGet:
            path: /ready
            port: 8080
          initialDelaySeconds: 5
          periodSeconds: 5
        env:
        - name: DATABASE_URL
          valueFrom:
            secretKeyRef:
              name: myapp-secrets
              key: database-url
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: myapp
  labels:
    app: myapp
spec:
  replicas: 3
  selector:
    matchLabels:
      app: myapp
  template:
    metadata:
      labels:
        app: myapp
    spec:
      containers:
      - name: myapp
        image: myapp:1.0.0
        ports:
        - containerPort: 8080
        resources:
          requests:
            memory: "128Mi"
            cpu: "100m"
          limits:
            memory: "256Mi"
            cpu: "500m"
        livenessProbe:
          httpGet:
            path: /health
            port: 8080
          initialDelaySeconds: 10
          periodSeconds: 10
        readinessProbe:
          httpGet:
            path: /ready
            port: 8080
          initialDelaySeconds: 5
          periodSeconds: 5
        env:
        - name: DATABASE_URL
          valueFrom:
            secretKeyRef:
              name: myapp-secrets
              key: database-url

Service

Service

yaml
apiVersion: v1
kind: Service
metadata:
  name: myapp
spec:
  selector:
    app: myapp
  ports:
  - port: 80
    targetPort: 8080
  type: ClusterIP
---
yaml
apiVersion: v1
kind: Service
metadata:
  name: myapp
spec:
  selector:
    app: myapp
  ports:
  - port: 80
    targetPort: 8080
  type: ClusterIP
---

LoadBalancer for external access

LoadBalancer for external access

apiVersion: v1 kind: Service metadata: name: myapp-external spec: selector: app: myapp ports:
  • port: 80 targetPort: 8080 type: LoadBalancer
undefined
apiVersion: v1 kind: Service metadata: name: myapp-external spec: selector: app: myapp ports:
  • port: 80 targetPort: 8080 type: LoadBalancer
undefined

Ingress

Ingress

yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: myapp
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  ingressClassName: nginx
  tls:
  - hosts:
    - myapp.example.com
    secretName: myapp-tls
  rules:
  - host: myapp.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: myapp
            port:
              number: 80
yaml
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: myapp
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  ingressClassName: nginx
  tls:
  - hosts:
    - myapp.example.com
    secretName: myapp-tls
  rules:
  - host: myapp.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: myapp
            port:
              number: 80

Configuration Management

配置管理

ConfigMap

ConfigMap

yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: myapp-config
data:
  config.yaml: |
    server:
      port: 8080
    logging:
      level: info
  APP_ENV: production
yaml
undefined
yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: myapp-config
data:
  config.yaml: |
    server:
      port: 8080
    logging:
      level: info
  APP_ENV: production
yaml
undefined

Using ConfigMap

Using ConfigMap

containers:
  • name: myapp envFrom:
    • configMapRef: name: myapp-config volumeMounts:
    • name: config mountPath: /etc/config volumes:
  • name: config configMap: name: myapp-config
undefined
containers:
  • name: myapp envFrom:
    • configMapRef: name: myapp-config volumeMounts:
    • name: config mountPath: /etc/config volumes:
  • name: config configMap: name: myapp-config
undefined

Secret

Secret

yaml
apiVersion: v1
kind: Secret
metadata:
  name: myapp-secrets
type: Opaque
stringData:
  database-url: postgres://user:pass@host:5432/db
  api-key: secret-key-value
bash
undefined
yaml
apiVersion: v1
kind: Secret
metadata:
  name: myapp-secrets
type: Opaque
stringData:
  database-url: postgres://user:pass@host:5432/db
  api-key: secret-key-value
bash
undefined

Create secret from command line

Create secret from command line

kubectl create secret generic myapp-secrets
--from-literal=database-url='postgres://...'
--from-file=tls.crt=cert.pem
undefined
kubectl create secret generic myapp-secrets
--from-literal=database-url='postgres://...'
--from-file=tls.crt=cert.pem
undefined

kubectl Commands

kubectl 命令

Resource Management

资源管理

bash
undefined
bash
undefined

Apply configuration

Apply configuration

kubectl apply -f deployment.yaml
kubectl apply -f deployment.yaml

Get resources

Get resources

kubectl get pods kubectl get deployments kubectl get services kubectl get all -n myapp
kubectl get pods kubectl get deployments kubectl get services kubectl get all -n myapp

Describe resource

Describe resource

kubectl describe pod myapp-xxx
kubectl describe pod myapp-xxx

Delete resource

Delete resource

kubectl delete -f deployment.yaml kubectl delete pod myapp-xxx
kubectl delete -f deployment.yaml kubectl delete pod myapp-xxx

Edit resource

Edit resource

kubectl edit deployment myapp
undefined
kubectl edit deployment myapp
undefined

Debugging

调试

bash
undefined
bash
undefined

View logs

View logs

kubectl logs myapp-xxx kubectl logs -f myapp-xxx --tail=100 kubectl logs myapp-xxx -c sidecar # specific container
kubectl logs myapp-xxx kubectl logs -f myapp-xxx --tail=100 kubectl logs myapp-xxx -c sidecar # specific container

Execute command

Execute command

kubectl exec -it myapp-xxx -- /bin/sh
kubectl exec -it myapp-xxx -- /bin/sh

Port forward

Port forward

kubectl port-forward svc/myapp 8080:80 kubectl port-forward pod/myapp-xxx 8080:8080
kubectl port-forward svc/myapp 8080:80 kubectl port-forward pod/myapp-xxx 8080:8080

View events

View events

kubectl get events --sort-by='.lastTimestamp'
kubectl get events --sort-by='.lastTimestamp'

Debug pod

Debug pod

kubectl debug myapp-xxx -it --image=busybox
undefined
kubectl debug myapp-xxx -it --image=busybox
undefined

Scaling

扩缩容

bash
undefined
bash
undefined

Manual scaling

Manual scaling

kubectl scale deployment myapp --replicas=5
kubectl scale deployment myapp --replicas=5

Autoscaling

Autoscaling

kubectl autoscale deployment myapp
--min=2 --max=10
--cpu-percent=80
undefined
kubectl autoscale deployment myapp
--min=2 --max=10
--cpu-percent=80
undefined

Horizontal Pod Autoscaler

Horizontal Pod Autoscaler

yaml
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
  name: myapp
spec:
  scaleTargetRef:
    apiVersion: apps/v1
    kind: Deployment
    name: myapp
  minReplicas: 2
  maxReplicas: 10
  metrics:
  - type: Resource
    resource:
      name: cpu
      target:
        type: Utilization
        averageUtilization: 80
  - type: Resource
    resource:
      name: memory
      target:
        type: Utilization
        averageUtilization: 80
yaml
apiVersion: autoscaling/v2
kind: HorizontalPodAutoscaler
metadata:
  name: myapp
spec:
  scaleTargetRef:
    apiVersion: apps/v1
    kind: Deployment
    name: myapp
  minReplicas: 2
  maxReplicas: 10
  metrics:
  - type: Resource
    resource:
      name: cpu
      target:
        type: Utilization
        averageUtilization: 80
  - type: Resource
    resource:
      name: memory
      target:
        type: Utilization
        averageUtilization: 80

Persistent Storage

持久化存储

PersistentVolumeClaim

PersistentVolumeClaim

yaml
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: myapp-data
spec:
  accessModes:
    - ReadWriteOnce
  storageClassName: standard
  resources:
    requests:
      storage: 10Gi
---
yaml
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: myapp-data
spec:
  accessModes:
    - ReadWriteOnce
  storageClassName: standard
  resources:
    requests:
      storage: 10Gi
---

Using PVC

Using PVC

containers:
  • name: myapp volumeMounts:
    • name: data mountPath: /data volumes:
  • name: data persistentVolumeClaim: claimName: myapp-data
undefined
containers:
  • name: myapp volumeMounts:
    • name: data mountPath: /data volumes:
  • name: data persistentVolumeClaim: claimName: myapp-data
undefined

StatefulSet

StatefulSet

yaml
apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: postgres
spec:
  serviceName: postgres
  replicas: 3
  selector:
    matchLabels:
      app: postgres
  template:
    metadata:
      labels:
        app: postgres
    spec:
      containers:
      - name: postgres
        image: postgres:15
        ports:
        - containerPort: 5432
        volumeMounts:
        - name: data
          mountPath: /var/lib/postgresql/data
  volumeClaimTemplates:
  - metadata:
      name: data
    spec:
      accessModes: ["ReadWriteOnce"]
      resources:
        requests:
          storage: 10Gi
yaml
apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: postgres
spec:
  serviceName: postgres
  replicas: 3
  selector:
    matchLabels:
      app: postgres
  template:
    metadata:
      labels:
        app: postgres
    spec:
      containers:
      - name: postgres
        image: postgres:15
        ports:
        - containerPort: 5432
        volumeMounts:
        - name: data
          mountPath: /var/lib/postgresql/data
  volumeClaimTemplates:
  - metadata:
      name: data
    spec:
      accessModes: ["ReadWriteOnce"]
      resources:
        requests:
          storage: 10Gi

Jobs and CronJobs

Job与CronJob

Job

Job

yaml
apiVersion: batch/v1
kind: Job
metadata:
  name: migration
spec:
  template:
    spec:
      containers:
      - name: migrate
        image: myapp:1.0.0
        command: ["./migrate.sh"]
      restartPolicy: Never
  backoffLimit: 3
yaml
apiVersion: batch/v1
kind: Job
metadata:
  name: migration
spec:
  template:
    spec:
      containers:
      - name: migrate
        image: myapp:1.0.0
        command: ["./migrate.sh"]
      restartPolicy: Never
  backoffLimit: 3

CronJob

CronJob

yaml
apiVersion: batch/v1
kind: CronJob
metadata:
  name: backup
spec:
  schedule: "0 2 * * *"
  jobTemplate:
    spec:
      template:
        spec:
          containers:
          - name: backup
            image: backup-tool:latest
            command: ["./backup.sh"]
          restartPolicy: OnFailure
yaml
apiVersion: batch/v1
kind: CronJob
metadata:
  name: backup
spec:
  schedule: "0 2 * * *"
  jobTemplate:
    spec:
      template:
        spec:
          containers:
          - name: backup
            image: backup-tool:latest
            command: ["./backup.sh"]
          restartPolicy: OnFailure

Network Policies

网络策略

yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: myapp-network-policy
spec:
  podSelector:
    matchLabels:
      app: myapp
  policyTypes:
  - Ingress
  - Egress
  ingress:
  - from:
    - podSelector:
        matchLabels:
          app: frontend
    ports:
    - protocol: TCP
      port: 8080
  egress:
  - to:
    - podSelector:
        matchLabels:
          app: database
    ports:
    - protocol: TCP
      port: 5432
yaml
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: myapp-network-policy
spec:
  podSelector:
    matchLabels:
      app: myapp
  policyTypes:
  - Ingress
  - Egress
  ingress:
  - from:
    - podSelector:
        matchLabels:
          app: frontend
    ports:
    - protocol: TCP
      port: 8080
  egress:
  - to:
    - podSelector:
        matchLabels:
          app: database
    ports:
    - protocol: TCP
      port: 5432

Resource Quotas

资源配额

yaml
apiVersion: v1
kind: ResourceQuota
metadata:
  name: myapp-quota
  namespace: myapp
spec:
  hard:
    requests.cpu: "10"
    requests.memory: 20Gi
    limits.cpu: "20"
    limits.memory: 40Gi
    pods: "20"
yaml
apiVersion: v1
kind: ResourceQuota
metadata:
  name: myapp-quota
  namespace: myapp
spec:
  hard:
    requests.cpu: "10"
    requests.memory: 20Gi
    limits.cpu: "20"
    limits.memory: 40Gi
    pods: "20"

Rolling Updates

滚动更新

yaml
spec:
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxSurge: 1
      maxUnavailable: 0
bash
undefined
yaml
spec:
  strategy:
    type: RollingUpdate
    rollingUpdate:
      maxSurge: 1
      maxUnavailable: 0
bash
undefined

Update image

Update image

kubectl set image deployment/myapp myapp=myapp:2.0.0
kubectl set image deployment/myapp myapp=myapp:2.0.0

Check rollout status

Check rollout status

kubectl rollout status deployment/myapp
kubectl rollout status deployment/myapp

View history

View history

kubectl rollout history deployment/myapp
kubectl rollout history deployment/myapp

Rollback

Rollback

kubectl rollout undo deployment/myapp kubectl rollout undo deployment/myapp --to-revision=2
undefined
kubectl rollout undo deployment/myapp kubectl rollout undo deployment/myapp --to-revision=2
undefined

Common Issues

常见问题

Issue: Pod Stuck in Pending

问题:Pod卡在Pending状态

Problem: Pod won't start Solution: Check resource availability, node selector, PVC binding
bash
kubectl describe pod myapp-xxx
kubectl get events
问题描述:Pod无法启动 解决方案:检查资源可用性、节点选择器、PVC绑定情况
bash
kubectl describe pod myapp-xxx
kubectl get events

Issue: CrashLoopBackOff

问题:CrashLoopBackOff

Problem: Container keeps restarting Solution: Check logs, verify entrypoint, check probes
bash
kubectl logs myapp-xxx --previous
kubectl describe pod myapp-xxx
问题描述:容器持续重启 解决方案:查看日志、验证入口点、检查探针配置
bash
kubectl logs myapp-xxx --previous
kubectl describe pod myapp-xxx

Issue: Service Not Accessible

问题:Service无法访问

Problem: Cannot connect to service Solution: Check selector labels, verify endpoints exist
bash
kubectl get endpoints myapp
kubectl describe svc myapp
问题描述:无法连接到Service 解决方案:检查选择器标签、验证端点是否存在
bash
kubectl get endpoints myapp
kubectl describe svc myapp

Issue: Image Pull Error

问题:镜像拉取失败

Problem: ImagePullBackOff Solution: Check image name, verify registry credentials
bash
kubectl create secret docker-registry regcred \
  --docker-server=registry.example.com \
  --docker-username=user \
  --docker-password=pass
问题描述:ImagePullBackOff 解决方案:检查镜像名称、验证镜像仓库凭证
bash
kubectl create secret docker-registry regcred \
  --docker-server=registry.example.com \
  --docker-username=user \
  --docker-password=pass

Best Practices

最佳实践

  • Always set resource requests and limits
  • Implement liveness and readiness probes
  • Use namespaces for isolation
  • Apply network policies for security
  • Use ConfigMaps and Secrets for configuration
  • Implement pod disruption budgets for availability
  • Use labels consistently for organization
  • Enable RBAC for access control
  • 始终设置资源请求与限制
  • 实现存活探针与就绪探针
  • 使用命名空间进行隔离
  • 应用网络策略保障安全
  • 使用ConfigMap和Secret管理配置
  • 实现Pod中断预算保障可用性
  • 保持标签一致性以便管理
  • 启用RBAC进行访问控制

Related Skills

相关技能

  • helm-charts - Package management
  • argocd-gitops - GitOps deployments
  • kubernetes-hardening - Security
  • helm-charts - 包管理
  • argocd-gitops - GitOps部署
  • kubernetes-hardening - 安全加固