[k8s]kube-proxy浅析

参考:

https://xuxinkun.github.io/2016/07/22/kubernetes-proxy/

https://kubernetes.io/docs/concepts/services-networking/service/
http://blog.csdn.net/WaltonWang/article/details/55236300

顺便画了一幅图:


1,创建mysql-rc

apiVersion: v1  
kind: ReplicationController  
metadata:  
  name: mysql 
spec:  
  replicas: 2  
  template:  
    metadata:  
      name: mysql
      labels:  
        mysql-service: "true"
    spec:  
      containers:  
      - name: mysql
        image: mysql  
        imagePullPolicy: IfNotPresent  
        ports:  
        - containerPort: 3306
        env: 
        - name: MYSQL_ROOT_PASSWORD
          value: "123456"
#podip分别是10.233.103.25 10.233.109.154


2.创建mysql-svc
apiVersion: v1
kind: Service
metadata:
  labels:
    name: mysql
    role: service
  name: mysql-service
spec:
  ports:
    - port: 3306
      targetPort: 3306
      nodePort: 30964
  type: NodePort
  selector:
    mysql-service: "true"
#使得1对2的模式

#查看master的iptables,发现其他节点也一样
iptables -S -t nat|grep mysql-service
#1.通过node问
#1.1 先匹配到以下这条
-A KUBE-NODEPORTS -p tcp -m comment --comment "default/mysql-service:" -m tcp --dport 30964 -j KUBE-MARK-MASQ
-A KUBE-NODEPORTS -p tcp -m comment --comment "default/mysql-service:" -m tcp --dport 30964 -j KUBE-SVC-67RL4FN6JRUPOJYM


#抛给svc 因为2个pod 所以每个50% ;利用了iptables的–probability的特性
-A KUBE-SVC-67RL4FN6JRUPOJYM -m comment --comment "default/mysql-service:" -m statistic --mode random --probability 0.50000000000 -j KUBE-SEP-WFO43VXQL6LOB7I7
-A KUBE-SVC-67RL4FN6JRUPOJYM -m comment --comment "default/mysql-service:" -j KUBE-SEP-3EHQVVHCPL2BJNYW

# 2.1DNAT
-A KUBE-SEP-3EHQVVHCPL2BJNYW -s 10.233.109.154/32 -m comment --comment "default/mysql-service:" -j KUBE-MARK-MASQ
-A KUBE-SEP-3EHQVVHCPL2BJNYW -p tcp -m comment --comment "default/mysql-service:" -m tcp -j DNAT --to-destination 10.233.109.154:3306



# 2.2DNAT
-A KUBE-SEP-WFO43VXQL6LOB7I7 -s 10.233.103.25/32 -m comment --comment "default/mysql-service:" -j KUBE-MARK-MASQ
-A KUBE-SEP-WFO43VXQL6LOB7I7 -p tcp -m comment --comment "default/mysql-service:" -m tcp -j DNAT --to-destination 10.233.103.25:3306

#通过clusterip访问直接给转发1.1
-A KUBE-SERVICES ! -s 10.233.64.0/18 -d 10.233.59.234/32 -p tcp -m comment --comment "default/mysql-service: cluster IP" -m tcp --dport 3306 -j KUBE-MARK-MASQ
-A KUBE-SERVICES -d 10.233.59.234/32 -p tcp -m comment --comment "default/mysql-service: cluster IP" -m tcp --dport 3306 -j KUBE-SVC-67RL4FN6JRUPOJYM



http://lustlost.blog.51cto.com/2600869/943110









评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值