此项目采用单实例部署,切勿在生产环境使用! |
1. 说明
此项目需要镜像 redis:7
。部署完成后,集群内部地址为:
1
svc-redis.core-middle.svc.cluster.local:6379
2. 创建持久化磁盘
Redis 需要将内存中存储的键值对数据缓存到本地磁盘
1
2
3
4
5
6
7
8
9
10
11
12
13
14
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: pvc-redis-data
namespace: core-middle
labels:
app: redis
spec:
storageClassName: 'sc-nfs-share'
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 20Gi
3. 创建配置
3.1. Redis 管理配置
使用此配置文件映射 Redis 管理员密码
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
apiVersion: v1
kind: Secret
metadata:
name: secret-redis
namespace: core-middle
labels:
app: redis
annotations:
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "kube-system,default,core-system,core-middleware,core-app,share-app,monitor-app,dev-ops"
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "kube-system,default,core-system,core-middleware,core-app,share-app,monitor-app,dev-ops"
type: Opaque
stringData:
password: 'redis-password' (1)
其中
1 | 请将其设置为复杂的密码 |
3.2. Redis 配置
Redis 带有大量参数需要配置,使用 ConfigMap 创建 Redis 相关的配置。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
apiVersion: v1
kind: ConfigMap
metadata:
name: conf-redis
namespace: core-middle
labels:
app: redis
data:
redis.conf: |
protected-mode yes
bind * -::*
timeout 0
tcp-keepalive 300
daemonize no
pidfile /var/run/redis.pid
loglevel warning
databases 64
always-show-logo no
set-proc-title no
save 60 1
stop-writes-on-bgsave-error yes
rdbcompression yes
rdbchecksum yes
dbfilename dump.rdb
dir ./
replica-serve-stale-data yes
replica-read-only yes
repl-diskless-sync no
repl-diskless-load disabled
repl-disable-tcp-nodelay no
replica-priority 100
acllog-max-len 128
lazyfree-lazy-eviction no
lazyfree-lazy-expire no
lazyfree-lazy-server-del no
replica-lazy-flush no
lazyfree-lazy-user-del no
lazyfree-lazy-user-flush no
oom-score-adj no
oom-score-adj-values 0 200 800
disable-thp yes
appendonly no
appendfilename "appendonly.aof"
appendfsync everysec
no-appendfsync-on-rewrite no
auto-aof-rewrite-percentage 100
auto-aof-rewrite-min-size 64mb
aof-load-truncated yes
aof-use-rdb-preamble yes
lua-time-limit 5000
slowlog-log-slower-than 10000
slowlog-max-len 128
latency-monitor-threshold 0
hash-max-ziplist-entries 512
hash-max-ziplist-value 64
list-max-ziplist-size -2
list-compress-depth 0
set-max-intset-entries 512
zset-max-ziplist-entries 128
hll-sparse-max-bytes 3000
zset-max-ziplist-value 64
stream-node-max-bytes 4096
stream-node-max-entries 100
activerehashing yes
client-output-buffer-limit normal 0 0 0
client-output-buffer-limit replica 256mb 64mb 60
client-output-buffer-limit pubsub 32mb 8mb 60
hz 10
dynamic-hz yes
aof-rewrite-incremental-fsync yes
rdb-save-incremental-fsync yes
jemalloc-bg-thread yes
4. 部署 Redis
现在可以部署 Redis Server了。
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: sts-redis
namespace: core-middle
labels:
app: redis
spec:
serviceName: svc-redis
selector:
matchLabels:
app: redis
replicas: 1
template:
metadata:
labels:
app: redis
spec:
containers:
- name: redis
image: redis:7
command:
- redis-server
- /usr/local/etc/redis/redis.conf
- '--port 6379'
- "--requirepass $(REDIS_PASSWORD)"
volumeMounts:
- name: redis-data
mountPath: /data
- name: redis-conf
mountPath: /usr/local/etc/redis
env:
- name: REDIS_PASSWORD
valueFrom:
secretKeyRef:
name: secret-redis
key: password
volumes:
- name: redis-data
persistentVolumeClaim:
claimName: pvc-redis-data
- name: redis-conf
configMap:
name: conf-redis
5. 创建 Service
部署完成后,需为 Redis Server 创建 Service 关联。
1
2
3
4
5
6
7
8
9
10
11
12
13
apiVersion: v1
kind: Service
metadata:
labels:
app: redis
name: svc-redis
namespace: core-middle
spec:
ports:
- port: 6379
name: redis
selector:
app: redis
6. 测试
当所有机器部署完成后,使用以下目录查看部署结果:
1
kubectl get pvc,secrets,configmaps,pods,service -n core-middle -l app=redis
如果一切无误,可使用以下命令测试,正常情况下将会显示 OK 然后退出。
1
2
REDIS_PASSWD=$(kubectl get secrets -n core-middle secret-redis -o jsonpath='{.data.password}' | base64 -d)
kubectl exec -it -n core-middle pods/sts-redis-0 -- redis-cli -h svc-redis.core-middle.svc.cluster.local AUTH $REDIS_PASSWD