getting started with pivotal container server pks

Getting started with Pivotal Container Service (PKS)

November 12, 2019

Pivotal Container Service (PKS) is a managed Kubernetes service for developers to operate and manage enterprise-grade Kubernetes clusters using BOSH and Pivotal Ops Manager. PKS uses the On-Demand Broker to deploy Cloud Foundry Container Runtime, a BOSH release that offers a uniform way to instantiate, deploy, and manage highly available Kubernetes clusters on a cloud platform using BOSH. After operators install the PKS tile on the Ops Manager Installation Dashboard, developers can provision Kubernetes clusters using the PKS Command Line Interface (PKS CLI), and run container-based workloads on the clusters with the Kubernetes CLI, kubectl.

Architecture

This section describes how Pivotal Container Service (PKS) manages the deployment on Kubernetes clusters. Developers interact with PKS and PKS-deployed Kubernetes in two ways:

The following architectural diagram shows how components interact:

PKS Control Plane

The PKS control plane manages the lifecycle of Kubernetes clusters deployed using PKS CLI. The control plan allows users to create, scale and manage cluster using BOSH. The PKS API LoadBalancer is used for interaction with PKS control plane.

UAA

PKS CLI communicates with UAA to authenticate log in and log out of PKS API through PKS API.

PKS API

With PKS CLI, users instruct the PKS API server to deploy, scale up, and delete Kubernetes clusters as well as show cluster details and plans.

PKS Broker

When the PKS API receives a request to modify a Kubernetes cluster, it instructs the PKS Broker to make the requested change. The PKS Broker generates a BOSH manifest and instructs the BOSH Director to deploy or delete the Kubernetes cluster.

Overview

This guide is designed to help you to get started with Pivotal Container Service (PKS). You can install PKS on Amazon Web Services (AWS), Google Cloud Platform (GCP), or vSphere. We will be using Amazon Web Services for setting up the control plane. This guide will walk through the steps to :

Deploying Ops Manager

This guide describes the preparation steps required to deploy Ops Manager on Amazon Web Services (AWS) using Terraform templates.

Prerequisites

Before you deploy Ops Manager on AWS, ensure you have the following:

Download Templates and Edit Variables File

Before you can run Terraform commands to provision infrastructure resources, you must download the AWS Terraform templates and create a Terraform template variables file as described below:

cd ~/workspace/pivotal-cf-terraforming-aws
env_name = "YOUR-ENVIRONMENT-NAME"
access_key = "YOUR-ACCESS-KEY"
secret_key = "YOUR-SECRET-KEY"
region = "YOUR-AWS-REGION"
availability_zones = ["YOUR-AZ-1", "YOUR-AZ-2", "YOUR-AZ-3"]
ops_manager_ami = "YOUR-OPS-MAN-IMAGE-AMI"
dns_suffix = "YOUR-DNS-SUFFIX"
ssl_cert = <-----BEGIN EXAMPLE RSA PRIVATE KEY-----
YOUR-PRIVATE-KEY-----END EXAMPLE RSA PRIVATE KEY-----
SSL_KEY

Create AWS Resources with Terraform

Follow these steps to use the Terraform CLI to create resources on AWS:

Create DNS Record

Configuring BOSH Director

This topic describes how to configure the BOSH Director tile in Ops Manager on Amazon Web Services (AWS) after Deploying Ops Manager on AWS Using Terraform.

Prerequisites

To complete the procedures in this topic, you must have access to the output from when you ran terraform apply to create resources for this deployment. You can view this output at any time by running terraform output. You use the values in your Terraform output to configure the BOSH Director tile.

Access Ops Manager

Configure AWS BOSH Director

Director Config Page

0.amazon.pool.ntp.org,1.amazon.pool.ntp.org,2.amazon.pool.ntp.org,3.amazon.pool.ntp.org

Create Availability Zones Page

Create Networks Page

Assign AZs and Networks Page

Security Page

Syslog page

Resource Config Page

Complete the BOSH Director Installation

Installing PKS on AWS

This topic describes how to install and configure Pivotal Container Service (PKS) on Amazon Web Services (AWS).

Prerequisites

Before performing the procedures in this topic, you must have deployed and configured Ops Manager. This topic assumes that you used Terraform to prepare the AWS environment for this Pivotal Container Service (PKS) deployment. You retrieve specific values required by this deployment by running terraform output. If you use an instance of Ops Manager that you configured previously to install other runtimes, confirm the following settings before you install PKS:

Install PKS

Configure PKS

Assign AZs and Networks

PKS API

Plans

To activate a plan, perform the following steps:

Kubernetes Cloud Provider

To configure your Kubernetes cloud provider settings, follow the procedures below:

Resource Config

To modify the resource usage of PKS and specify your PKS API load balancer, follow the steps below:

Apply Changes

Retrieve the PKS API Endpoint

To retrieve the PKS API endpoint, do the following:

Installing the PKS CLI and Kubectl

The PKS and Kubernetes CLIs help you interact with your PKS-provisioned Kubernetes clusters and Kubernetes workloads. To install the CLIs, follow the instructions below:

PKS CLI

Kubernetes CLI

Configuring the PKS API

This topic describes how to configure access to the Pivotal Container Service (PKS) API.

Log in to the PKS CLI as a User

On the command line, run the following command to log in to the PKS CLI as an automated client for a script or service:

Creating a Load Balancer for PKS clusters

A load balancer is a third-party device that distributes network and application traffic across resources. Using a load balancer can also prevent individual network components from being overloaded by high traffic.

Define Load Balancer

To define your load balancer using AWS, you must provide a name, select a VPC, specify listeners, and select subnets where you want to create the load balancer. Perform the following steps:

Assign Security Groups

Perform the following steps to assign security groups:

Configure Security Settings

On the Configure Security Settings page, ignore the warning. SSL termination is done on the Kubernetes API.

Configure Health Check

Perform the following steps to configure the health check:

Add EC2 Instances

Creating a Kubernetes Cluster

Create a Kubernetes cluster using the AWS-assigned address of your load balancer as the external hostname when you run the pks create-cluster command.

To track cluster creation, run the following command:

Point the Load Balancer to All Master VMs

Scale the Cluster:

Run the following command below to scale up your cluster.

Deploying Nginx application

We are going to deploy our first application on Kubernetes.

Configure Your Workload

Deploy and Expose Your Workload

Access Your Workload