Kubernetes คืออะไร
ไอเดียหลักในหนึ่งประโยค
หัวข้อที่มีชื่อว่า “ไอเดียหลักในหนึ่งประโยค”Kubernetes คือ container orchestrator ที่คอยรักษา actual state ของ cluster ให้ตรงกับ state ที่คุณ declare ไว้ โดยทำงานต่อเนื่องอัตโนมัติ
ปัญหา container ไม่ scale ให้เองอัตโนมัติ
หัวข้อที่มีชื่อว่า “ปัญหา container ไม่ scale ให้เองอัตโนมัติ”คำสั่ง docker run เดี่ยว ๆ ทำงานได้ดีบน laptop หรือ server เครื่องเดียว ปัญหาจะเริ่มขึ้นทันทีที่คุณต้องใช้มากกว่าหนึ่งเครื่อง หรือมากกว่าหนึ่ง container หรือต้องการความทนทานใด ๆ เลย ถ้า process ข้างใน container crash จะไม่มีอะไร restart container นั้นให้ นอกจากคุณจะสังเกตเห็นแล้วลงมือทำเอง ถ้าอยากรัน web server 5 ตัวอยู่หลัง address เดียวกัน คุณต้องต่อสายให้เองทั้งหมด ถ้าอยากเปลี่ยน image version ใหม่โดยไม่มี downtime คุณต้องเขียน script ควบคุมลำดับการหยุด container เก่าแล้วเริ่ม container ใหม่ ให้ถูกลำดับ ถูกเครื่อง
docker run -d --name web nginx# if this container's process dies, nothing brings it back automatically —# you have to notice, then run `docker run` again by hand# and there is no built-in way to run five of these behind one addressทั้งหมดนี้ไม่ใช่ข้อบกพร่องของ Docker — หน้าที่ของ container runtime คือรัน container ไม่ใช่ตัดสินใจว่าควรมีกี่ตัว อยู่ที่ไหน หรือทำอะไรเมื่อ container ตาย orchestration เป็นปัญหาคนละชั้น คือเมื่อมีเครื่องหลายเครื่องกับ workload หลายชุด ต้องคอยรักษาจำนวน instance ที่ healthy ให้ถูกต้อง กระจายไปยังเครื่องที่เหมาะสม เรียกหาได้ด้วยชื่อ และอัปเดตได้อย่างปลอดภัย นี่คือปัญหาที่ Kubernetes ถูกสร้างขึ้นมาแก้
Declarative desired state และ reconciliation loop
หัวข้อที่มีชื่อว่า “Declarative desired state และ reconciliation loop”Kubernetes เกิดจากประสบการณ์ภายในของ Google ในการรัน container ที่สเกลใหญ่มาก ด้วยระบบชื่อ Borg และตอนนี้เป็นโครงการระดับ graduated ของ Cloud Native Computing Foundation (CNCF) เป็น open source ไม่ผูกกับ vendor ใดวันหนึ่ง และดูแลโดยชุมชนขนาดใหญ่ ไม่ใช่บริษัทเดียว
ไอเดียหลักที่คุณจะเห็นซ้ำตลอดคอร์สนี้ในทุก module คือ คุณไม่ได้บอก Kubernetes ว่าต้องทำอะไรทีละขั้นตอน แต่คุณ declare desired state — “ฉันอยากได้ replica 3 ตัวของ container image นี้ ฟังที่ port นี้” — แล้ว background process ชุดหนึ่งที่เรียกว่า controller จะคอยเฝ้าดู cluster ต่อเนื่องและลงมือทำทุกอย่างที่จำเป็นเพื่อให้ actual state ตรงกับที่คุณ declare ไว้ นี่คือ reconciliation loop และทำงานตลอดเวลา ไม่ใช่แค่ครั้งเดียวตอนสร้าง ถ้า Pod ตาย controller จะสังเกตเห็นว่า actual state เบี่ยงเบนไปจาก desired state แล้วสร้าง Pod ใหม่มาแทน ถ้าคุณแก้ replica count ที่ต้องการ controller จะเห็นความต่างแล้วสร้างหรือลบ Pod ให้ตรงกัน
เทียบกับเป้าหมายเดียวกัน “รัน nginx รักษา replica 3 ตัวให้ healthy” ที่เขียนแบบ declarative เป็น Kubernetes Deployment
apiVersion: apps/v1kind: Deploymentmetadata: name: webspec: replicas: 3 selector: matchLabels: app: web template: metadata: labels: app: web spec: containers: - name: web image: nginx:1.27 ports: - containerPort: 80คุณส่ง manifest นี้ให้ cluster แค่ครั้งเดียว จากนั้นถ้า replica ตัวไหน crash ถูก evict หรือ node ที่อยู่หายไป controller จะสร้าง Pod ใหม่ขึ้นมาให้จำนวนกลับเป็น 3 โดยคุณไม่ต้องทำอะไรเพิ่ม การ roll out image ใหม่ก็ declarative เหมือนกัน แค่เปลี่ยน image: nginx:1.27 เป็น tag ใหม่แล้ว apply ซ้ำ Deployment controller จะทยอยแทนที่ Pod ให้เองทีละส่วน
Cluster ประกอบด้วย control plane และ node
หัวข้อที่มีชื่อว่า “Cluster ประกอบด้วย control plane และ node”Kubernetes cluster มีเครื่องสองแบบ control plane คือสมองของ cluster เก็บ desired state ตัดสินใจเรื่อง scheduling และรัน controller ที่ขับเคลื่อน reconciliation — บทถัดไปจะลงลึกถึง component ของตัวเอง ส่วน node คือ worker คือเครื่อง (physical หรือ virtual) ที่รัน container ของคุณจริง ๆ โดยห่อหุ้มอยู่ใน unit ที่เล็กที่สุดที่ deploy ได้ของ Kubernetes เรียกว่า Pod
flowchart LR you["You declare desired state (YAML)"] --> api["API server stores it"] api --> ctrl["Controllers watch & reconcile"] ctrl --> actual["Actual cluster state converges"]