[Infrastructure as Code (IaC) Pulumi] Use Pulumi kubernetes (K8S) Helm Chart to deploy Istio
Istio
Istio is the simplify observability, traffic management, security, and policy with the leading service mesh
Istio addresses the challenges developers and operators face with a distributed or microservices architecture. Whether you’re building from scratch or migrating existing applications to cloud native, Istio can help.
This article is about how to use Pulumi, kubernetes (K8S) provider, Helm Chart and TypeScript SDK to deploy Istio within Kubernetes (K8S).
Prerequisites
-
Kubernetes (K8s) is an open-source system for automating deployment, scaling, and management of containerized applications.
See Getting started | Kubernetes - https://kubernetes.io/docs/setup/ to leanr more.
-
Pulumi - Modern Infrastructure as Code - https://www.pulumi.com/
Pulumi is a modern infrastructure-as-code platform that allows you to use common programming languages, tools, and frameworks, to provision, update, and manage cloud infrastructure resources.
Install the Pulumi - https://www.pulumi.com/ CLI.
1
2Mac OS X
brew install pulumiSee Download and Install | Pulumi - https://www.pulumi.com/docs/get-started/install/ to learn more about others OS.
-
Node.js - https://nodejs.org/en/
Node.js® is a JavaScript runtime built on Chrome’s V8 JavaScript engine.
Install Node.js - https://nodejs.org/en/ CLI.
1
2Mac OS X
brew install nodeSee Node.js - https://nodejs.org/en/ to learn more about others OS.
Usage
Pulumi New
Create the workspace directory.
1 | mkdir -p col-example-pulumi-typescript-istio |
Pulumi login into local file system.
1 | pulumi login file://. |
Pulumi new a project with kubernetes-typescript SDK.
1 | pulumi new kubernetes-typescript |
The above command will create some files within the current directory.
1 | tree . -L 1 |
Install js-yaml
package to load and parse yaml file.
1 | npm i js-yaml |
Pulumi Configuration
Configure Kubernetes
By default, Pulumi will look for a kubeconfig file in the following locations, just like kubectl:
-
The environment variable:
$KUBECONFIG
, -
Or in current user’s default kubeconfig directory:
~/.kube/config
If the kubeconfig file is not in either of these locations, Pulumi will not find it, and it will fail to authenticate against the cluster. Set one of these locations to a valid kubeconfig file, if you have not done so already.
istio/base
See and modify istio-base/main.ts file.
1 | // istio-base/index.tsmain.ts |
istio/ingress
See and modify istio-ingress/main.ts file.
1 | // istio-ingress/index.tsmain.ts |
values.yaml
Edit istio-ingress/values.yaml and replace content within {{ }}
.
1 | # istio-ingress/values.yaml |
istio/istiod
See and modify istio-istiod/main.ts file.
1 | // istio-istiod/index.tsmain.ts |
Istio Stack
main.ts
Edit ./main.ts
1 | // main.ts |
Check all files.
1 | tree . -L 1 |
Pulumi Up
Run pulumi up to create the namespace and pods.
1 | pulumi up |
See pods about istio.
1 | kubectl get pods -n istio-system |
Assume you have determined that your environment has an external load balancer 192.168.100.120
.
1 | kubectl get svc -n istio-system |
Pulumi Destroy
Destroy all resources created by Pulumi.
1 | pulumi destroy |
References
[1] istio/istio: Connect, secure, control, and observe services. - https://github.com/istio/istio
[2] Istio - https://istio.io/latest/
[3] Istio / Install with Helm - https://istio.io/latest/docs/setup/install/helm/
[4] Istio / Getting Started - https://istio.io/latest/docs/setup/getting-started/
[5] Istio / Install with Istioctl - https://istio.io/latest/docs/setup/install/istioctl/
[6] Kubernetes Getting Started | Pulumi - https://www.pulumi.com/docs/get-started/kubernetes/
[7] Pulumi - Modern Infrastructure as Code - https://www.pulumi.com/
[8] Kubernetes - https://kubernetes.io/
[9] TypeScript: Typed JavaScript at Any Scale. - https://www.typescriptlang.org/