Access cloud serverless computing power from a self-managed Kubernetes cluster by using ACK Virtual Node

Updated at:

ACK Virtual Node seamlessly connects Kubernetes to cloud serverless computing power. This topic describes how to deploy the ACK Virtual Node component in a Kubernetes cluster in your data center.

Introduction to ACK Virtual Node

ACK Virtual Node seamlessly connects Kubernetes to cloud serverless computing power. This allows your self-managed Kubernetes cluster to easily access elastic computing power from the cloud, including CPU and GPU resources. With ACK Virtual Node, you can create serverless pods in your self-managed Kubernetes cluster and use cloud computing power to efficiently handle business growth and traffic peaks.

image
Note
  • Your data center and Alibaba Cloud VPC must be connected through a leased line.

  • In this document, {region} represents the region ID where you want to access Elastic Container Instance (ECI), such as cn-zhangjiakou for the Zhangjiakou region. For more information about ECI regions, see Endpoints.

  • For each serverless pod, ACK Virtual Node creates an elastic container instance in the cloud. You do not need to maintain extra nodes.

Prerequisites

  • A Kubernetes cluster is deployed. Kubernetes 1.18 or later is recommended.

  • An AccessKey pair is created for the Alibaba Cloud Resource Access Management (RAM) user or role that is used for the ACK Virtual Node Helm chart. The RAM user or role must be granted permissions to call Elastic Container Instance (ECI) OpenAPI operations. For more information, see Grant permissions to a RAM user. The required authorization information is as follows:

Click to view the authorization information

{
    "Version": "1",
    "Statement": [
        {
            "Action": [
                "eci:CreateContainerGroup",
                "eci:DeleteContainerGroup",
                "eci:DescribeContainerGroups",
                "eci:DescribeContainerGroupStatus",
                "eci:DescribeContainerGroupEvents",
                "eci:DescribeContainerLog",
                "eci:UpdateContainerGroup",
                "eci:UpdateContainerGroupByTemplate",
                "eci:CreateContainerGroupFromTemplate",
                "eci:RestartContainerGroup",
                "eci:ExportContainerGroupTemplate",
                "eci:DescribeContainerGroupMetric",
                "eci:DescribeMultiContainerGroupMetric",
                "eci:ExecContainerCommand",
                "eci:CreateImageCache",
                "eci:DescribeImageCaches",
                "eci:DeleteImageCache",
                "vpc:DescribeVSwitches"
            ],
            "Resource": [
                "*"
            ],
            "Effect": "Allow"
        }
    ]
}

Install the component

  1. Create a my-values.yaml file based on the following example and save it to a local folder.

    virtualNode:
      image:
        repository: registry-{Region}.ack.aliyuncs.com/acs/virtual-nodes-eci
        tag: v2.12.1
    env:
      ECI_REGION: cn-zhangjiakou
      ECI_VSWITCH: vsw-8vb***
      ECI_SECURITY_GROUP: sg-8vb***
      ECI_ACCESS_KEY: yourAccessKeyID
      ECI_SECRET_KEY: yourAccessKeySecret

    Parameter description:

    Parameter name

    Description

    Required

    Example

    virtualNode.image.repository

    The address of the virtual-node image repository.

    Required

    registry-cn-zhangjiakou.ack.aliyuncs.com/acs/virtual-nodes-eci

    virtualNode.image.tag

    The tag of the virtual-node image.

    Required

    v2.12.1

    env.ECI_REGION

    The ID of the region where the Elastic Container Instance resides.

    Required

    cn-zhangjiakou

    env.ECI_VSWITCH

    The ID of the vSwitch where the Elastic Container Instance resides. To specify multiple vSwitches, separate their IDs with commas (,). Reserve a sufficient number of IP addresses for the vSwitches based on the number of serverless pods.

    Required

    vsw-8vb***

    env.ECI_SECURITY_GROUP

    The ID of the security group where the Elastic Container Instance resides.

    Required

    sg-8vb***

    env.ECI_ACCESS_KEY

    The AccessKey ID of your Alibaba Cloud account. Make sure that the account has the permissions to call ECI API operations.

    Required

    yourAccessKeyID

    env.ECI_SECRET_KEY

    The AccessKey secret of your Alibaba Cloud account. Make sure that the account has the permissions to call ECI API operations.

    Required

    yourAccessKeySecret

    env.KUBERNETES_APISERVER_HOST

    API Server address. Set this parameter to specify an API Server address.

    Optional

    192.168.0.1

    env.KUBERNETES_APISERVER_PORT

    The port of the private IP address of the API Server.

    Optional

    6443

    env.ECI_VPC

    The ID of the VPC where the Elastic Container Instance resides.

    Optional

    vpc-8vb***

    env.ALIYUN_RESOURCEGROUP_ID

    The ID of the resource group to which the Elastic Container Instance belongs.

    Optional

    rg-acf***

  2. Run the following command to add the Helm repo.

    helm repo add aliyunhub https://aliacs-app-catalog.oss-cn-hangzhou.aliyuncs.com/charts-incubator/
  3. Run the following command to install ack-virtual-node.

    helm install ack-virtual-node aliyunhub/ack-virtual-node --namespace kube-system --values my-values.yaml
  4. Run the following command to check the application status.

    kubectl  get no |grep virtual-kubelet

    Expected output:

    virtual-kubelet-cn-zhangjiakou-c   Ready    agent    10d   v1.18.8

Schedule pods to run on cloud serverless computing power

In your self-managed Kubernetes cluster, you can schedule pods to run on ECI using one of the following three methods.

Method 1: Configure pod labels

  1. Run the following command to deploy the test case with the specified Pod label.

    kubectl apply -f - <<EOF
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      labels:
        app: nginx
      name: nginx-deployment-pod-label
      namespace: default
    spec:
      replicas: 2
      selector:
        matchLabels:
          app: nginx
      template:
        metadata:
          labels:
            alibabacloud.com/eci: 'true'   # Specify the pod label to use cloud serverless computing power
            app: nginx
        spec:
          containers:
            - image: 'registry.cn-hangzhou.aliyuncs.com/eci_open/nginx:1.14.2'
              imagePullPolicy: IfNotPresent
              name: nginx
              ports:
                - containerPort: 80
                  protocol: TCP
              resources:
                limits:
                  cpu: 500m
    EOF
  2. Run the following command to check the application status.

     kubectl get pod -owide | grep nginx-deployment-pod-label

    Expected output:

    nginx-deployment-pod-label-6575548559-7p9hf     1/1     Running   0          33s    192.168.XX.XXX    virtual-kubelet-cn-zhangjiakou-c   <none>           <none>
    nginx-deployment-pod-label-6575548559-tztm6     1/1     Running   0          33s    192.168.XX.XXX    virtual-kubelet-cn-zhangjiakou-c   <none>           <none>

Method 2: Configure namespace labels

  1. Run the following command to create a namespace named vk.

    kubectl create ns vk
  2. Run the following command to add the alibabacloud.com/eci=true label to the namespace.

    kubectl label namespace vk alibabacloud.com/eci=true
  3. Run the following command to deploy the test case to the specified namespace.

    kubectl apply -f - <<EOF
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      labels:
        app: nginx
      name: nginx-deployment-ns-label
      namespace: vk
    spec:
      replicas: 2
      selector:
        matchLabels:
          app: nginx
      template:
        metadata:
          labels:
            app: nginx
        spec:
          containers:
            - image: 'registry.cn-hangzhou.aliyuncs.com/eci_open/nginx:1.14.2'
              imagePullPolicy: IfNotPresent
              name: nginx
              ports:
                - containerPort: 80
                  protocol: TCP
              resources:
                limits:
                  cpu: 500m
    EOF
  4. You can run the following command to check the application status.

    kubectl get po -nvk -owide |grep  nginx-deployment-ns-label

    Expected output:

    nginx-deployment-ns-label-7bc784448c-5llgb   1/1     Running   0          30s   192.168.XX.XXX   virtual-kubelet-cn-zhangjiakou-c   <none>           <none>
    nginx-deployment-ns-label-7bc784448c-8ns9q   1/1     Running   0          30s   192.168.XX.XXX   virtual-kubelet-cn-zhangjiakou-c   <none>           <none>

Method 3: Specify a node name

  1. Run the following command to deploy the test case to the specified node.

    kubectl apply -f - <<EOF
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      labels:
        app: nginx
      name: nginx-deployment-node-name
      namespace: default
    spec:
      replicas: 2
      selector:
        matchLabels:
          app: nginx
      template:
        metadata:
          labels:
            app: nginx
        spec:
          nodeName: virtual-kubelet-cn-zhangjiakou-c             # Specify the nodeName of ack-virtual-node
          containers:
            - image: 'registry.cn-hangzhou.aliyuncs.com/eci_open/nginx:1.14.2'
              imagePullPolicy: IfNotPresent
              name: nginx
              ports:
                - containerPort: 80
                  protocol: TCP
              resources:
                limits:
                  cpu: 500m
    EOF
  2. Run the following command to check the application status.

    kubectl get pod -owide |grep nginx-deployment-node-name

    Expected output:

    nginx-deployment-node-name-864dffd59f-jq58n     1/1     Running   0          23s     192.168.XX.XXX     virtual-kubelet-cn-zhangjiakou-c   <none>           <none>
    nginx-deployment-node-name-864dffd59f-r87zp     1/1     Running   0          23s     192.168.XX.XXX     virtual-kubelet-cn-zhangjiakou-c   <none>           <none>

References