GiangITLearn Today · Build Tomorrow
Linux

Linux Professional

LPIC-1, Enterprise Linux

★ 4.8 (210 đánh giá) · 1 học viên
IMG
11.jpg · 114 KB
IMG
22.jpg · 100 KB
IMG
33.jpg · 72 KB

Bạn sẽ học được gì

  • Tự triển khai được Linux Professional trong môi trường lab
  • Hiểu cấu hình và xử lý lỗi thường gặp
  • Áp dụng best practice bảo mật và vận hành
  • Có tài liệu lệnh mẫu để dùng lại khi đi làm
Khóa học Linux Professional: LPIC-1, Enterprise Linux. Học theo từng bước, có lệnh mẫu và bài thực hành trên máy của bạn. Phù hợp cho kỹ sư muốn vận hành hệ thống doanh nghiệp một cách bài bản.
Giảng viênGiảng viên nội bộ
Thời lượng38 giờ
Cấp độCơ bản
Nội dung11 bài · 3 chương

Yêu cầu

  • Máy tính RAM tối thiểu 8GB để chạy lab ảo hóa
  • Kiến thức mạng cơ bản (IP, subnet, DNS)

Argo CD là một công cụ Continuous Delivery (CD) mã nguồn mở dành cho Kubernetes, hoạt động theo mô hình GitOps.

Hiểu đơn giản là Argo CD giúp triển khai và đồng bộ ứng dụng trên Kubernetes trực tiếp từ Git repository.

 Argo CD sẽ tự động đảm bảo cluster luôn giống với cấu hình trong Git

Argo CD làm gì?

·         Theo dõi repo Git (chứa YAML, Helm chart, Kustomize…)

·         So sánh trạng thái Git với Kubernetes Cluster

·         Tự động:

o    Deploy ứng dụng

o    Sync khi có thay đổi

o    Rollback khi cần

 

Setup ArgoCD + HTTPS với certbot (Let's Encrypt qua cert-manager) đúng theo hạ tầng bạn mô tả:

👉 Bạn có:

·        Ingress external IP: 10.128.48.209 (đã NAT ra public)

·        Domain: argocd.giangit.com → trỏ về public IP

·        Khai báo dns server, domain: argocd.giangit.com → trỏ về IP external load balancer

👉 expose ArgoCD UI qua HTTPS:

---------------------

#Label worker node

giang@admin:/$ kubectl label node worker1 node-type=worker

giang@admin:/$ kubectl label node worker2 node-type=worker

giang@admin:/$ kubectl label node worker3 node-type=worker

 

#Cài cert-manager  (công cụ quản lý, tự động tạo, renew ssl)

giang@admin:/$ helm repo add jetstack https://charts.jetstack.io

giang@admin:/$ helm repo update

giang@admin:/$ helm install cert-manager jetstack/cert-manager \

--namespace cert-manager \

--create-namespace \

--set installCRDs=true

#ClusterIssuer (cấu hình nguồn cấp ssl, cụ thể là Let's Encrypt)

Tạo file clusterissuer.yaml

--------------------

apiVersion: cert-manager.io/v1

kind: ClusterIssuer

metadata:

 name: letsencrypt

spec:

acme:

email: admin@giangit.com

server: https://acme-v02.api.letsencrypt.org/directory

privateKeySecretRef:

name: letsencrypt-key

solvers:

- http01:

ingress:

class: nginx

--------------------

giang@admin:/$ kubectl apply -f clusterissuer.yaml

#Cài ArgoCD bằng Helm

             Tạo values.yaml

--------------------

 

global:

nodeSelector:

node-type: worker

 

server:

replicas: 2

extraArgs:

- --insecure

 

service:

type: ClusterIP

 

resources:

requests:

cpu: 100m

memory: 128Mi

 

repoServer:

replicas: 1

 

controller:

replicas: 1

 

redis:

enabled: true

--------------------

          giang@admin:/$ kubectl create namespace argocd

giang@admin:/$ helm repo add argo https://argoproj.github.io/argo-helm

giang@admin:/$ helm repo update

giang@admin:/$ helm install argocd argo/argo-cd \

-n argocd \

-f values.yaml \

--timeout 10m

giang@admin:/$ kubectl get pods -n argocd

#Tạo Ingress

Tạo file argocd-ingress.yaml

--------------------

apiVersion: networking.k8s.io/v1

kind: Ingress

metadata:

name: argocd

namespace: argocd

annotations:

cert-manager.io/cluster-issuer: letsencrypt

#nginx.ingress.kubernetes.io/ssl-redirect: "false"

#nginx.ingress.kubernetes.io/force-ssl-redirect: "false"

#nginx.ingress.kubernetes.io/backend-protocol: "HTTP"

spec:

ingressClassName: nginx

 

tls:

- hosts:

- argocd.giangit.com

secretName: argocd-tls

 

rules:

- host: argocd.giangit.com

http:

paths:

- path: /

pathType: Prefix

backend:

service:

name: argocd-server

port:

number: 80

--------------------

giang@admin:/$ kubectl apply -f argocd-ingress.yaml

#Kiểm tra certificate

giang@admin:/$ kubectl describe certificate -n argocd

giang@admin:/$ kubectl get certificate -n argocd -w

READY: True ✅

#Lấy password

giang@admin:/$ kubectl -n argocd get secret argocd-initial-admin-secret \

-o jsonpath="{.data.password}" | base64 -d

Truy cập thử argocd: https://argocd.giangit.com