KubeCon2020/腾讯会议大规模使用Kubernetes的技术实践������������������� StatefulSetPlus Operator Ø Keep share memory during Pod upgrade Ø Upgrade jitter (a few ms) for keep-alive services Flexible and dynamic resource management Dynamic Scheduler is0 码力 | 19 页 | 10.94 MB | 1 年前3
Putting an Invisible Shield on Kubernetes SecretsUse envelope encryption scheme • DEK & KEK Motivation: K8s Secrets Protection • Performance & latency • Network • Security • DEK in the clear in memory • Secret in the clear in memory • kubeconfig • Encrypted memory • SW/HW attacks prevented TEE-based KMS Plugin [1] • Address performance & latency concerns • Reduce / minimize remote KMS interactions w/o compromising security • Address security force update • Liveness probe • Monitoring • Integration w/ Prometheus • Metrics including • latency of en/decryption • failure times of en/decryption • KMS health check • Ops tooling • kms-plugin-tools0 码力 | 33 页 | 20.81 MB | 1 年前3
Kubernetes & YARN: a hybrid container cloud
Online service Batch jobs Category Online shopping web apps, payment service MR, spark, flink Latency Sensitive Insensitive Priority high low Traffic pattern Peak at day time Peak at night time Fault0 码力 | 42 页 | 25.48 MB | 1 年前3
Chaos Mesh让应用与混沌在 Kubernetes 上共舞-杨可奥强大的工具箱 ● PodChaos: kill / fail / ... ● NetworkChaos: delay / lose / dup / partition / … ● IOChaos: latency / fault / … ● TimeChaos: clock skew ● KernelChaos: kernel fault injection ● StressChaos: burn0 码力 | 30 页 | 1.49 MB | 9 月前3
绕过conntrack,使用eBPF增强 IPVS优化K8s网络性能measurement Test topology Test result Service type Short connection cps Short connection P99 latency Long connection pps ClusterIP +40% -31% not available NodePort +64% -47% +22% Test result •0 码力 | 24 页 | 1.90 MB | 1 年前3
在大规模Kubernetes集群上实现高SLO的方法function and process — to provide the best opportunity for service recipient success. — Gartner Latency SLI Availability QPS Correctness SLO …… Punishment SLA SLI defines an indicator, which can0 码力 | 11 页 | 4.01 MB | 1 年前3
共 6 条
- 1













