DSP Worker Deployment
EKS Cluster Setup
First you need to connect AWS CLI on CMS, for that you must create an IAM user with appropriate permissions. Run “aws configure” to quickly set and view your credentials, Region, and output format.
aws configure
AWS Access Key ID [None]:
AWS Secret Access Key [None]:
Default region name [None]:
Default output format [None]: For more information: https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-files.html
Next you need to create EKS cluster with below command:
eksctl create cluster --name my-cluster --region region-code --version 1.26 --vpc-private-subnets subnet-ExampleID1,subnet-ExampleID2 --without-nodegroupFor more information: https://docs.aws.amazon.com/eks/latest/userguide/create-cluster.html
You can replace “-- version” with any updated versionand you must specify at least two subnet IDs.
Cluster provisioning takes several minutes. While the cluster is being created, several lines of output appear. The last line of output is similar to the following example line.
Lastly for that part, you’ll need to create EC2 Autoscaling Group
eksctl create nodegroup \
--cluster my-cluster \
--region region-code \
--name my-mng \
--node-ami-family ami-family \
--node-type m5.large \
--nodes 3 \
--nodes-min 2 \
--nodes-max 4 \
--ssh-access \
--ssh-public-key my-keyFor more information: https://docs.aws.amazon.com/eks/latest/userguide/create-managed-node-group.html
Loadbalancer Configuration
The AWS Load Balancer Controller manages AWS Elastic Load Balancers for Kubernetes cluster.
Download an IAM policy for the AWS Load Balancer Controller that allows it to make calls to AWS APIs on your behalf:
curl -O https://raw.githubusercontent.com/kubernetes-sigs/aws-load-balancer-controller/v2.4.7/docs/install/iam_policy_us-gov.jsonCreate an IAM policy using the policy downloaded in the previous step:
aws iam create-policy \
--policy-name AWSLoadBalancerControllerIAMPolicy \
--policy-document file://iam_policy_us-gov.jsonCreate an IAM role. Create a Kubernetes service account named aws-load-balancer-controller in the kube-system namespace for the AWS Load Balancer Controller and annotate the Kubernetes service account with the name of the IAM role.
eksctl create iamserviceaccount \
--cluster=my-cluster \
--namespace=kube-system \
--name=aws-load-balancer-controller \
--role-name AmazonEKSLoadBalancerControllerRole \
--attach-policy-arn=arn:aws:iam::111122223333:policy/AWSLoadBalancerControllerIAMPolicy \
--approveInstall the AWS Load Balancer Controller using Helm V3 or later or by applying a Kubernetes manifest. Add the eks-charts repository:
helm repo add eks https://aws.github.io/eks-chartsUpdate your local repo to make sure that you have the most recent charts:
helm repo updateInstall the AWS Load Balancer Controller:
helm install aws-load-balancer-controller eks/aws-load-balancer-controller \
-n kube-system \
--set clusterName=my-cluster \
--set serviceAccount.create=false \
--set serviceAccount.name=aws-load-balancer-controllerVerify that the controller is installed:
kubectl get deployment -n kube-system aws-load-balancer-controllerThe example output is as follows:
Installing DSP with Helm
You need to make sure your IAM policies, VPC settings and security groups are correctly configured on AWS. Now you are ready to install Kron DSP with helm:
Helm repo file (unzip package);
config_values.yaml file;
helm install <podname> <kron helm repo full path> -n <namespace> -f <config values yaml full path> --create-namespace
#Example
helm install krondsppod /kron_helm_repo/vector -n krondspnamespace -f /kron/helmrepo/config_values.yaml --create-namespaceHelm Require Special Firewall Configuration
Outbound traffic
If your firewall restricts outbound network traffic, please open the following for the Helm:
- TCP port 80 (HTTP)
- TCP port 443 (HTTPS)
- UDP port 500 (IPsec IKEv2)
- UDP port 4500 (IPsec NAT traversal)
Inbound traffic
For the Helm files service, network traffic is not routed through the security gateway, but directly to the Helm on TCP port 9443. This requires forwarding of that port from the network's public IP address to the same port on the Helm at its private IP address.
Kubernetes Ctl Require Special Firewall Configuration
When deploying a Kubernetes firewall, you should be aware of the ports and protocols used by the Kubernetes control plane. These must be allowed to enable the cluster to function.
The following TCP ports are used by Kubernetes control plane components:
- Port 6443 –
- Ports 2379-2380 –
- Port 10250 –
- Port 10259 –
- Port 10257 –
The following TCP ports are used by Kubernetes nodes:
- Port 10250 –
- Ports 30000-32767 –
The above are the default ports defined by Kubernetes—if you set custom ports for any of them, the firewall should be enabled for the custom port.
AWS CLI Require Special Firewall Configuration
By default, the AWS CLI sends requests to AWS services by using HTTPS on TCP port 443. To use the AWS CLI successfully, you must be able to make outbound connections on TCP port 443.