Автоматизация управления ClickHouse-кластерами в Kubernetesнастройки ● ClickHouse settings (profile, server settings) configuration: settings: compression/case/method: zstd ● Zoned deployment, Affinity rules ● AntiAffinity rules ● Service templates0 码力 | 44 页 | 2.24 MB | 1 年前3
绕过conntrack,使用eBPF增强 IPVS优化K8s网络性能Linux distributions • Cons • O(N^2) in control plane / O(N) in data plane • Poor in scheduling algorithm • Iptables rules are difficult to debug IPVS mode • Services are organized in hash table • IPVS time complexity in control/data plane • Stably runs for two decades • Support rich scheduling algorithm • Cons • Performance cost caused by conntrack • Some bugs How to optimize • Guidelines •0 码力 | 24 页 | 1.90 MB | 1 年前3
秘钥管理秘钥Turtles all the way down - Securely managing Kubernetes Secretsencryption: best practices Managing DEKs: ● Generate DEKs locally ● Use a strong cryptographic algorithm ● For easy access, store the DEK near the data that it encrypts ● Ensure DEKs are encrypted at0 码力 | 52 页 | 2.84 MB | 1 年前3
Kubernetes开源书 - 周立请注意,如果某些pod的容器未设置相应的资源请求,则不会定义pod的CPU利⽤率,并且autoscaler不会对该指标 采取任何操作。有关⾃动伸缩算法如何⼯作的更多信息,阅读 autoscaling algorithm design document 。 对于per-pod的⾃定义指标,Controller的功能类似于per-pod的资源指标,除了它适⽤于原始值⽽⾮利⽤率值。 对于对象的指标,获取单个指0 码力 | 135 页 | 21.02 MB | 1 年前3
共 4 条
- 1













