Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Jason Morgan, Flynn

Rating No ratings yet

With the massive increase of microservices, operators and developers face far more complexity in their applications today. Service meshes can help you manage this problem by providing a unified control plane to secure, manage, and monitor your entire network. This practical guide shows you how the Linkerd service mesh enables cloud-native developers--including platform and site reliability engineers--to solve the thorny issue of running distributed applications in Kubernetes. Tech evangelists for Buoyant--the creators of Linkerd--demonstrate how this service mesh can help ensure that your applications are secure, observable, and reliable. Youâ ll understand why Linkerd, the original service mesh, can still claim the lowest time to value of any mesh option available today. Learn how Linkerd works and which tasks it can help you accomplish Install and configure Linkerd in an imperative and declarative manner Secure interservice traffic and set up secure multi-cluster links Launch a zero trust authorization strategy in Kubernetes clusters Organize services in Linkerd to override error codes, set custom retries, and create time-outs Use Linkerd to manage progressive delivery and pair this service mesh with the ingress of your choice

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
# Linkerd Up and Running: A Guide to Operationalizing a Kubernetes-Native Service Mesh ## 【One-Line Pitch】 A practical, hands-on guide for platform engineers and SREs who want to deploy, operate, and troubleshoot Linkerd as their Kubernetes service mesh—covering everything from first install to production hardening, with real CLI examples and configuration patterns throughout. ## 【Book Arc】 - **Opening (~0%–9%)**: Establishes why service meshes matter in the microservices world—where network communication replaces in-process calls and OS-level protections no longer apply—then introduces Linkerd's core architecture: the data plane (sidecar proxies) and control plane, plus the extension ecosystem (Viz, Multicluster, Jaeger, CNI, SMI). - **Early (~9%–25%)**: Walks through deploying Linkerd on a local k3d cluster using both imperative (CLI) and declarative (Helm) methods, covering prerequisites, preflight checks, TLS certificate setup, and the trust hierarchy created during installation. Includes critical warnings about production Prometheus usage. - **Early (~25%–34%)**: Explains how to add workloads to the mesh via the linkerd-proxy-injector admission controller, the annotation system that controls injection, protocol detection mechanics, and common gotchas like server-speaks-first protocols and resource limit overrides. - **Middle (~34%–47%)**: Covers integrating Linkerd with ingress controllers—why you should route to Services rather than Endpoints, how to handle TLS termination at the edge versus mTLS inside the cluster, and concrete examples with Emissary-ingress, NGINX, and Envoy Gateway. - **Middle (~47%–end)**: Dives into operational tooling: the full linkerd CLI command surface, health checking with `linkerd check` (including prechecks and extension-specific checks), debugging data plane and control plane issues, log access, and upgrade procedures via both Helm and CLI paths. ## 【Key Takeaways】 - **Service meshes solve the "network is the new trust boundary" problem** (Early): In microservices, every interaction crosses an unreliable, insecure network—meshes provide the observability, security, and reliability mechanisms that OS-level protections used to offer within a single process. This reframing justifies the entire mesh investment. - **Linkerd's architecture separates data plane from control plane** (Early): The data plane consists of sidecar proxies that mediate all traffic, while the control plane manages them. Extensions like Viz and Multicluster plug into published APIs—meaning anyone can write extensions without special privileges. - **Deployment is a two-track story: CLI or Helm** (Early): Both imperative (`linkerd install`) and declarative (Helm charts) approaches work, but Helm gives you versioned, reproducible installs. Always run `linkerd check --pre` before installing to validate cluster readiness and permissions. - **Never use Linkerd Viz's bundled Prometheus in production** (Early): The internal Prometheus instance lacks persistent storage. For production, configure an external Prometheus—this is a critical operational decision that many teams discover too late. - **Adding workloads to the mesh is annotation-driven, not manual** (Early): The linkerd-proxy-injector watches for Kubernetes annotations to decide which Pods get sidecars. Understanding the full annotation surface (resource limits, ephemeral storage, memory requests) lets you fine-tune proxy behavior per workload. - **Protocol detection is the foundation of mesh value** (Early): Linkerd must identify the protocol in use to provide proper metrics, per-request load balancing, and advanced features. Server-speaks-first protocols are a known gotcha that breaks this detection. - **Ingress integration requires a "two TLS worlds" mental model** (Middle): The ingress controller terminates TLS for external clients, while Linkerd handles mTLS inside the cluster. Use cleartext between ingress and workloads so Linkerd can do per-request routing—not just per-connection proxying. - **Route to Services, not Endpoints** (Middle): A Kubernetes Service has three distinct parts (DNS name, cluster IP, and endpoint Pod IPs). For mesh routing to work correctly, always target the Service, not individual Pod IPs. ## 【Reading Tips】 - **Skim Chapter 1 if you already know microservices pain points**—the call graph and golden metrics discussion is useful context, but the real value starts with the architecture explanation in Chapter 2. - **Deep-read the deployment chapter (Chapter 3) even if you've installed Linkerd before**—the Helm-based approach, trust hierarchy explanation, and production Prometheus warning are easy to miss when following quickstart tutorials. - **Pay special attention to the annotation tables in Chapter 4**—these are reference material you'll return to when tuning proxy resources or debugging injection issues. - **The ingress chapter (Chapter 5) is where most real-world confusion lives**—the "route to Services, not Endpoints" and "cleartext inside, TLS at edge" principles are the two rules that prevent the most common misconfigurations. - **Use the CLI reference and debugging chapters as lookup material**—don't read them cover-to-cover; bookmark them for when you need `linkerd check --proxy` or log-level adjustments in production. ## 【Coverage Limits】 The excerpts cover roughly the first half of the book (through the CLI reference and health checking). Later chapters on mTLS deep-dives, multicluster setup, zero-trust authorization, service profiles, retries/timeouts, progressive delivery, and production metrics collection are not covered in this guide. ##
Excerpt 1
2 Security 4 Reliability ...
View in text
Excerpt 2
king advantage of the Kubernetes concept of sidecars, which allows every application container to be paired with a dedicated proxy that handles all network t...
View in text
Excerpt 3
the beginning and end of a request is crucial to measuring request rate and latency. Reading the status of a request is critical to measuring the success rat...
View in text
Excerpt 4
installed (default "linkerd-cni") --context string Name of the kubeconfig context to use -h, --help help for linker...
View in text
Excerpt 5
ven key, the more valuable it tends to be to break that key. For this reason, certificates are given fixed lifespans, and they must be replaced before they e...
View in text
Excerpt 6
explicit about which accounts are allowed to talk to which workloads—but of course, that requires knowing exactly which communications are truly required by ...
View in text
Excerpt 7
pp spec: parentRefs: - name: books kind: Server group: policy.linkerd.io rules: - matches: - path: value: "/books.jso...
View in text
Excerpt 8
t instability of microservices applications. Load Balancing Load balancing might seem like an odd reliability feature to lead with, since many people think t...
View in text
Tags
AI categories
Cloud NativeBackendDevOps
ISBN: 1098142314
Publisher: O'Reilly Media
Publish Year: 2024
Language: English
Pages: 262
File Format: PDF
File Size: 10.5 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…