Upgrade to Pro — share decks privately, control downloads, hide ads and more …

はじめてのKong Konnect

はじめてのKong Konnect

2021/04/09
HCCJP

Takafumi Ikeda

April 09, 2021
Tweet

More Decks by Takafumi Ikeda

Other Decks in Technology

Transcript

  1. THE CLOUD CONNECTIVITY COMPANY 2 Ϋϥ΢υίωΫςΟϏςΟͷ ͢΂ͯΛΧόʔ: • API Gateway

    • Ingress • Service Mesh • Integration (2021) αʔϏείωΫςΟϏςΟ ϓϥοτϑΥʔϜ
  2. THE CLOUD CONNECTIVITY COMPANY 3 Basic Edge and Cross App

    Plugins Kuma Mesh Basic In-App Policies Kong Gateway Basic Edge and Cross App Plugins Kong Mesh Basic In-App Policies KIC decK Kong Gateway Enterprise RBAC OIDC AuthZ mTLS & JWT sig Advanced Transform Audit Logs Encryption of data at rest Distributed Caching GraphQL and Kafka OPA Hashicorp Vault Multi-Zone AutnZ FIPS-2 compliance Configuration Management UI Runtime Manager Developer Portal ServiceHub Immunity Anomaly Detection Vitals Analytics KIC decK KIC decK Open Source Projects Connectivity Fabric Services Connectivity Runtimes
  3. THE CLOUD CONNECTIVITY COMPANY 5 Central Gateway ෳ਺ϨΠϠʔʹήʔτ΢ΣΠ഑ஔ Ingress
 Controller

    KONG KONG KONG KONG Ingress
 Controller KONG KONG Ingress
 Controller KONG KONG KONG Coarse-grained policies (e.g. global rate- limiting, user & app authentication, IP blacklist, etc.) Fine-grained policies (i.e. upstream TLS, specific microservice cluster rate-limiting)
  4. THE CLOUD CONNECTIVITY COMPANY 6 Central Gateway KONG KONG KONG

    Any Kubernetes
 (EKS, AKS, GKE, OpenShift, etc.) Ingress Controller KONG KONG Service Sidecar Service Sidecar Service Sidecar Service Sidecar Sidecar ήʔτ΢ΣΠͱαʔϏεϝογϡʢk8sʣ
  5. THE CLOUD CONNECTIVITY COMPANY 7 VM Central Gateway KONG KONG

    KONG Any Kubernetes
 (EKS, AKS, GKE, OpenShift, etc.) Ingress Controller KONG Service Sidecar Service Sidecar VM ήʔτ΢ΣΠͱαʔϏεϝογϡʢVMͱk8sࠞ߹ʣ
  6. THE CLOUD CONNECTIVITY COMPANY 8 VM Central Gateway ౷߹͞ΕͨίϯτϩʔϧϓϨʔϯͷఏڙʢ= Konnectʣ

    KONG KONG KONG Any Kubernetes
 (EKS, AKS, GKE, OpenShift, etc.) Ingress Controller KONG Service Service VM
  7. THE CLOUD CONNECTIVITY COMPANY 13 αʔϏε։ൃεϐʔυΞοϓ ϙϦγʔద༻Λૉૣ͘؆୯ʹ • ։ൃͱσϓϩΠͷ଎౓্͕͕Γ·͢ νʔϜͰͷར༻͕؆୯ʹ

    • ։ൃνʔϜ͕ࣗ཯తʹϧʔςΟϯάઃఆՄೳɺRBACʹ ΑͬͯݖݶΛ෼͚Δͷ΋؆୯ʹ αʔϏεσϦόϦʔͷࣗಈԽ͕Մೳ • APIήʔτ΢ΣΠͷઃఆΛCI/CDʹ૊ΈࠐΉͷ͕༰қ 1
  8. THE CLOUD CONNECTIVITY COMPANY 15 αʔϏε։ൃεϐʔυΞοϓ ϙϦγʔద༻Λૉૣ͘؆୯ʹ • ։ൃͱσϓϩΠͷ଎౓্͕͕Γ·͢ νʔϜͰͷར༻͕؆୯ʹ

    • ։ൃνʔϜ͕ࣗ཯తʹϧʔςΟϯάઃఆՄೳɺRBACʹ ΑͬͯݖݶΛ෼͚Δͷ΋؆୯ʹ αʔϏεσϦόϦʔͷࣗಈԽ͕Մೳ • APIήʔτ΢ΣΠͷઃఆΛCI/CDʹ૊ΈࠐΉͷ͕༰қ 1
  9. THE CLOUD CONNECTIVITY COMPANY 17 αʔϏε։ൃεϐʔυΞοϓ ϙϦγʔద༻Λૉૣ͘؆୯ʹ • ։ൃͱσϓϩΠͷ଎౓্͕͕Γ·͢ νʔϜͰͷར༻͕؆୯ʹ

    • ։ൃνʔϜ͕ࣗ཯తʹϧʔςΟϯάઃఆՄೳɺRBACʹ ΑͬͯݖݶΛ෼͚Δͷ΋؆୯ʹ αʔϏεσϦόϦʔͷࣗಈԽ͕Մೳ • APIήʔτ΢ΣΠͷઃఆΛCI/CDʹ૊ΈࠐΉͷ͕༰қ 1
  10. THE CLOUD CONNECTIVITY COMPANY 19 αʔϏε։ൃεϐʔυΞοϓ ϙϦγʔద༻Λૉૣ͘؆୯ʹ • ։ൃͱσϓϩΠͷ଎౓্͕͕Γ·͢ νʔϜͰͷར༻͕؆୯ʹ

    • ։ൃνʔϜ͕ࣗ཯తʹϧʔςΟϯάઃఆՄೳɺRBACʹ ΑͬͯݖݶΛ෼͚Δͷ΋؆୯ʹ αʔϏεσϦόϦʔͷࣗಈԽ͕Մೳ • APIήʔτ΢ΣΠͷઃఆΛCI/CDʹ૊ΈࠐΉͷ͕༰қ 1
  11. THE CLOUD CONNECTIVITY COMPANY 27 εϖοΫυϦϒϯ։ൃͱAPIςετ • Insomnia Kong StudioΛ࢖ͬͨίϥϘϨʔγϣϯ

    αʔϏεͷެ։ɺσϕϩούʔϙʔλϧ • αʔϏεΛσϕϩούʔϙʔλϧʹެ։͠ɺར༻Λଅਐ 3 αʔϏεͷެ։ͱར༻ଅਐ
  12. THE CLOUD CONNECTIVITY COMPANY 29 εϖοΫυϦϒϯ։ൃͱAPIςετ • Insomnia Kong StudioΛ࢖ͬͨίϥϘϨʔγϣϯ

    αʔϏεͷެ։ɺσϕϩούʔϙʔλϧ • αʔϏεΛσϕϩούʔϙʔλϧʹެ։͠ɺར༻Λଅਐ 3 αʔϏεͷެ։ͱར༻ଅਐ
  13. THE CLOUD CONNECTIVITY COMPANY 31 εϖοΫυϦϒϯ։ൃͱAPIςετ • Insomnia Kong StudioΛ࢖ͬͨίϥϘϨʔγϣϯ

    αʔϏεͷެ։ɺσϕϩούʔϙʔλϧ • αʔϏεΛσϕϩούʔϙʔλϧʹެ։͠ɺར༻Λଅਐ 3 αʔϏεͷެ։ͱར༻ଅਐ
  14. THE CLOUD CONNECTIVITY COMPANY 36 Kuma ▪ Kong ͷఏڙ͢Δ৽͍͠ OSS

    ▪ Envoy ্ʹߏங͞ΕͨϢχόʔαϧαʔϏεϝογϡ ▪ ඇৗʹܰྔͳσʔλϓϨʔϯͱίϯτϩʔϧϓϨʔϯ ▪ L4/L7 ͷτϥϑΟοΫͷ؂ࢹɺϧʔςΟϯάɺϩΪϯάɺ mTLSɺαʔϏεؒͷ૬ޓ઀ଓΛίʔυมߋͳ͠ʹ࣮ݱ ▪ k8s ωΠςΟϒͰ͋Δͱಉ࣌ʹඇ k8s ϕʔεʢVMɾϕΞ ϝλϧʣͷαʔϏε্Ͱ΋ಈ࡞͠ɺطଘͷγεςϜͱ͏ ·͘౷߹ ▪ ϚΠΫϩαʔϏεԽɾΫϥ΢υωΠςΟϒԽ΁εϜʔζ ʹҠߦ͢Δ͜ͱ͕Ͱ͖Δ ▪ OPAωΠςΟϒαϙʔτ ▪ Enterprise൛͸Kong Meshͱݺশ
  15. THE CLOUD CONNECTIVITY COMPANY 37 Ϋϥ΢υίωΫςΟϏςΟͷ ͢΂ͯΛΧόʔ: • API Gateway

    • Ingress • Service Mesh • Integration (2021) αʔϏείωΫςΟϏςΟ ϓϥοτϑΥʔϜ