4 ms·
Great article! I‘m running a full-featured three node cluster for less than $10/month on Hetzner Cloud. This kind of setup requires a little more effort, but i
by pstadler 8y ago
Great article!
I‘m running a full-featured three node cluster for less than $10/month on Hetzner Cloud. This kind of setup requires a little more effort, but it can be fully automated and you learn a couple of things about Kubernetes on the way. I published and maintain this guide[1], including provisioning using Terraform and a bunch of example manifests to get you started.
[1] https://github.com/hobby-kube/guide https://github.com/hobby-kube/guide
- rtp 8y agoThis guide is great. Thank you!
- raesene9 8y agoOne thing you might want to look at based on a quick scan over your guide is that, at the moment ,it looks like you're running your etcd cluster with no authentication. Any attacker who was able to get on to the pod network (e.g. if there's a vulnerability in one of the apps running on the cluster) could hit the etcd endpoint and dump the contents of the database, which generally includes sensitive information like k8s secrets.
- merb 8y agonice guide, the only problem i see with hetzner cloud is that they do not allow to have a operating system like coreos or even the coreos (Container Linux) fork flatcar or even RancherOS.
- mahesh_rm 8y agoHow long did it take you to migrate from your previous infrastructure (including time spent learning)?
- pstadler 8y agoAlthough this is a valid question, it doesn't apply here. See, I try to teach myself something new every year, whether it's a new programming language, platform or whatever else. It was curiosity that turned my non-existent infrastructure into having a cheap, small-scale Kubernetes cluster ready for my shenanigans. My tiny cluster gives me great freedom. Setup is fully automated. When a new k8s release comes around, I simply tear down my old cluster and ramp up a new one in mere minutes. If I want to deploy a service or application, all I need to do is to write a couple of manifests and roll all the moving parts out. Hassle-free - no SSH, no additional costs, no accounts, no 3rd-party services, persistent storage and TLS certificates out of the box. Currently, a Unifi controller is the only long-term resident on my cluster; other services and projects come and go. Besides that, the following agents are deployed as Kubernetes pods: Datadog (free tier) for basic monitoring & alerting and Papertrail ($5-10/month) which acts as a centralized log sink for all my hosts, NAS and networking gear.
- mahesh_rm 8y agoThank you for your answer. All this makes sense, I am trying to ponder how much of a migration would be cool-driven and how much of it utility-driven, for a small company. All in all, as of now, my conclusion would be not to migrate infrastructure to k8s with no allocated devops engineer on it (at least one).