|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/istio-service-mesh-masterclass-kubernetes-aws-eks-2020/
课程评论:没有评论
课程名称:完整的Istio服务网格(1.8)大师班 + AWS EKS 课程概述:本课程将通过实践概念和实验,教授如何在Kubernetes中使用Istio服务网格(演示使用AWS EKS)。您将学习准确配置和管理服务网格的各个方面,包括网关、虚拟服务、目标规则、金丝雀部署、负载均衡规则、流量镜像、故障注入、断路器、JWT认证及授权、TLS代理、Kiali仪表板等内容。 适合人群: - 希望学习如何使用Istio服务网格保障Kubernetes集群网络安全的人 - 对Istio服务网格在Kubernetes中的应用感到困惑的人 - 曾使用Nginx Ingress Controller但希望转向更适合生产环境的Ingress Controller的人 - 寻求控制微服务应用程序内流量的人 - 希望使用JWT进行终端用户的身份验证和授权的人 - 需要通过Istio Ingress Gateway Service YAML配置AWS ELB的SSL的人 - 想学习如何使用Kiali和Jaeger仪表板监控微服务应用程序的分布式请求跟踪的人 不适合人群: - 已经深入了解Kubernetes中的Istio服务网格的人 - 不打算使用Kubernetes的人 - 不计划在Kubernetes集群中处理安全问题的人 - 从未使用过Kubernetes的人 学习内容包括: - 使用网关、虚拟服务和目标规则控制Ingress流量 - 使用K8s服务YAML为Istio Ingress Gateway配置SSL终止 - 使用虚拟服务和目标规则配置金丝雀部署/加权路由/流量拆分 - 配置标识/头部基础的路由 - 测试故障恢复功能(延迟和中止注入、重试和超时设置) - 镜像实时流量到不同版本的应用工作负载 - 配置和测试速率限制和断路器 - 验证服务网格中相互TLS的默认“宽松模式”,并如何启用严格模式 - 设置基于JWT的终端用户身份验证和授权 - 使用服务条目和虚拟服务控制Egress流量 - 为Egress流量启用TLS代理 - 使用Kiali仪表板可视化网格拓扑、日志、指标和YAML验证 为什么选择这门课程: 1. 由在美国公司工作的云DevOps工程师授课,具有6.5年以上的行业经验,并获得专业认证。 2. 复杂的Istio概念通过图解形式详细讲解,提升学习效率。 3. 更新的Istio服务网格知识,适用于2020年以后的版本。 4. 大量动手实践,课程不乏味。 5. 整个课程压缩在五小时内,帮助学生在繁忙的工作中迅速学习。 制作人背景:云DevOps软件工程师,拥有6.5年以上经验,加拿大大学计算机科学学士,擅长Java、C#、C++、Bash、Python、JavaScript等,精通AWS和Kubernetes。期待在课程中见到你!
If I summarize this course in one sentence?Learn Istio Service Mesh in Kubernetes (demo is done using AWS EKS) using Handson concepts and labs (e.g. Gateway, Virtual Service, Destination Rule, Canary Rollout, Load Balancing Rules, Mirror Live Traffic, Fault Injection, Circuit Breaker, JWT Authentication and Authentication, TLS Origination, Kiali Dashboard, etc).☆Please check preview videos to see if this course is really for you☆Are you one of the below?You want to learn how to secure K8s in-cluster network with Istio Service MeshYou feel overwhelmed and don't know where to start with Istio Service Mesh in Kubernetes You used Nginx Ingress Controller but want to use production-ready Ingress ControllerYou used AWS ALB Ingress Controller but its limitation with ingress YAML pushed you away from using itYou want to learn service mesh so that you can control in-cluster traffic to microservice applicationsYou want to authenticate and authorize end users using JWT using IstioYou want to be able to configure SSL for AWS ELB using Istio Ingress Gateway Service YAMLYou want to learn how to monitor microservice app's distributed request tracing using Kiali and Jaeger dashboards Who should take this courseyou have learned Kubernetes fundamentals (pod, service, deployment, ingress, configmap, role, etc)you don't know how to go about learning Istio Service mesh in Kubernetesyou have development experience in Kubernetes YAML resourcesyou want to learn about production-level in-cluster security such as mutual TLS using Istio Service Mesh in Kubernetesyou want to learn ins and outs of Istio Service Mesh features (traffic control, security, observability) from a cloud DevOps working at an US company in SFwho should NOT need to take this courseyou already know a lot of Istio Service Mesh in Kubernetesyou are not planning on using Kuberenetesyou are not planning on working on security in Kuberenetes clusteryou have never used Kubernetes beforeIn this course, you will learn various aspects of Istio Service Mesh in Kubernetes such as:how to control Ingress Traffic using Gateway, VirtualService, DestinationRuleshow to configure SSL Termination at AWS ELB created by Istio ingress gateway using k8s service YAMLhow to configure canary rollouts/weight-based routing/traffic splitting using Virtual Service and Destination Rulehow to configure identity/header based routinghow to configure and test failure recovery features (injecting delay and abort, setting retries and timeout)how to configure and test mirroring live traffic to different versions of app workloadshow to configure and test rate limiting and circuit breakerhow to verify default "permissive mode" of mutual TLS in service mesh, and how to enable STRICT mode of mutual TLShow to set up end user authentication and authorization with JWT using Request Authentication and Authorization Policyhow to control egress traffic using Service Entry and Virtual Servicehow to enable TLS Origination for egress traffic using Destination Rulehow to use Kiali dashboard to visualize mesh topology, logs, metrics, and YAML validation5 Reasons why you should take this course:1. Instructed by a cloud DevOps engineer (with CKA and certified AWS DevOps pro) working at US company in SFI have been pretty handson with Istio Service Mesh, Kubernetes, AWS, AWS EKS with 6.5+ industry experience in both North America and Europe.2. Abstract Istio Concepts Explained with DiagramsIstio is pretty complex, and its operational complexities are pretty high. That means, a learning curve is also high.Especially with Istio, its documentation page offers LITTLE to NO diagrams explaining relationships between `Gateway`, `Virtual Service`, `Destination Rule`, `Service Entry`, etc. So I created a whole bunch of diagrams from high level architectures to low level YAML resources for Istio features such as canary rollout/traffic splitting, JWT Authentication and Authorization, and much more. You will have the most VISUAL-oriented learning experience you can EVER find on the Internet for Istio.3. Updated Knowledge about Istio Service Mesh v1.6~ in 2020Some of the Istio Architecture and Componets are outdated. I will demonstrate 2020-updated version of resources and concepts.4. Tons of handson!I won't bore you with dry lectures. Instead every concepts are paired with handson demo.5. Entire course under FIVE HOURSI tried to make this course compact and concise so students can learn the concepts and handson skills in shorted amount of time, because I know a life of software engineer is already pretty busy:)My background & Education & Career experienceCloud DevOps Software Engineer with 6.5+ years experienceBachelor of Science in Computing Science from a Canadian universityKnows Java, C#, C++, Bash, Python, JavaScript, Terraform, IaCExpert in AWS (holds AWS DevOps Professional certification) and Kubernetes (holds Certified Kubernetes Administrator, CKA)I will see you inside!