Want multi-cluster Kubernetes without all the cost and overhead? Here’s how

Editor’s note: Today, we hear from Mengliao Wang, Senior Software Developer, Team Lead at Geotab, a leading provider of fleet management hardware and software solutions. Read on to hear how the company is expanding on their adoption of Google Cloud to deliver new services for their customers by leveraging Google Kubernetes Engine (GKE) multi-cluster features.Geotab’s customers ask a lot of our platform: They use it to gain insights from vast amounts of telemetry data collected from their fleet vehicles. They rely on it to adhere to strict data privacy requirements. And, because our customers are located all over the world, they need the platform to address their data residency and other jurisdictional processing requirements, which require compute and storage to live within a specific geographic region. Meanwhile, as a managed service provider, we need a cost-efficient business model — that was certainly a driving factor for adopting containers and GKE. As we started architecting the deployment of multiple clusters to support our customers’ data residency requirements, we determined we also needed to explore approaches to reduce the total operational maintenance and costs of our multi-cluster environment.In order to meet customers where they are, we moved forward with running GKE clusters in multiple Google Cloud Platform regions. At the same time, we recently began using GKE multi-cluster services, which provides our customers with the security and low latency they need, while giving us cost savings and an easy-to-maintain solution. Read on to learn more about Geotab, our journey to Google Cloud and GKE, and, more recently, how we deployed multi-cluster Kubernetes using GKE multi-cluster services.The rise of connected fleet vehicles “By 2024, 82% of all manufactured vehicles will be equipped with embedded telematics.”—Berg InsightAs a global leader in IoT and connected transportation, Geotab is advancing security, connecting commercial vehicles to the internet, and providing web-based analytics to help customers better manage their fleet vehicles. With over 2.5 million connected vehicles and processing billions of data points per day, we leverage data analytics and machine learning to support our customers in several ways. We help them improve productivity, optimize fleets by reducing their fuel consumption, enhance driver safety, achieve strong compliance to regulatory changes, and meet sustainability goals. Geotab partners with Original Equipment Manufacturers (OEMs) to help expand customers’ fleet management capabilities through access to the Geotab platform.Our journey to Google Cloud and GKEWe originally chose Google Cloud as our primary cloud provider as we found it to be the most stable of the cloud providers we tried, with the least amount of unscheduled downtime. End-to-end reliability is an important consideration for our customers’ safety and their confidence in Geotab’s driver-assistance features. Since getting started on our public cloud journey, we’ve leveraged Google Cloud to modernize different aspects of the Geotab platform.First, we embarked on a multi-milestone and multi-year initiative to modernize the Geotab Data Platform, adopting a container-based architecture using open source technologies; we continue to leverage Google Cloud services to launch innovative solutions that combine analytics and access to massive data volumes for better transportation planning decisions. Today, Geotab Data Platform is built entirely on GKE, with multiple services such as data ingestion, data digestion, data processing, monitoring and alerting, a management console, and several applications. We are now leveraging this modern platform to introduce new Geotab services to our customers.Exploring multi-cluster KubernetesAs discussed above, we recently began deploying our GKE clusters into multiple regions, to meet our customers’ performance and data residency requirements. However, not every service that makes up the Geotab platform is created equal… For example, data digestion and data ingestion services are at the core of the data platform. Data digestion services are Application Programming Interfaces (API), machine learning models, and business intelligence (BI) tools that consume data from the data environment for various data analysis purposes, and are served directly to customers. Data ingestion services ingest billions of telematics data records per day from Geotab GO devices and are responsible for persisting them into our data environment.But when looking at optimizing operating costs, we identified several services outside of the data platform that did not process sensitive customer information — our monitoring and alerting services are examples of these services. Duplicating these services in multiple regions would result in higher infrastructure costs and would result in additional maintenance complexity and overhead.We decided to deploy the services that do not process any customer data as shared services in a dedicated cluster. Not only does this lower the cost for resources, but it also makes it easier to manage from an operational perspective. However, this approach introduced two new challenges:Services such as data ingestion and data digestion that run in each jurisdiction needed to expose their metrics outside of their cluster to make them available to the shared services (monitoring and alerting / management console) running on the shared cluster, resulting in some security concerns.Since metrics would not be passing within a cluster subnetwork, they would travel via the public network, resulting in higher latency as well as additional security concerns.This is where GKE Multi-cluster Services (MCS) came in, perfectly solving these concerns without introducing any new architectural components for us to configure and maintain. MCS is a cross-cluster Service Discovery and invocation mechanism built-in to GKE. MCS extends the capabilities of the standard Kubernetes Service object. Services that are configured to be exported with MCS are discoverable and accessible across all clusters within a fleet of clusters via a virtual IP address, matching the behavior of a ClusterIP Service that is accessible within a cluster. With MCS, we do not need to expose public endpoints and all traffic is routed within the Google network.With MCS configured, we get the best of both worlds: services between the shared cluster and other regionally hosted clusters communicate as if they are all hosted in one cluster! Problem solved! Reflecting on the journeyOur modernization journey on Google Cloud continues to pay dividends. During the first phase of our journey, we reaped the benefits of being able to scale up our systems with less downtime. With GKE features like MCS, we are able to reduce the time required to roll-out new features to our global customers while addressing our business objectives to manage operating costs. We look forward to continuing on our multi-cluster journey with Google Cloud and GKE. Are you interested in learning more about how GKE multi-cluster services can help with your Kubernetes multi-cluster challenges? Check out this guide to configuring multi-cluster services, or reach out to a Google Cloud expert — we’re eager to help!Related ArticleDriving change: How Geotab is modernizing applications with Google CloudOver time, Geotab converted production servers running Windows Server to containers and open source, saving hundreds of thousands of doll…Read Article
Quelle: Google Cloud Platform

Instance-Tags jetzt im Amazon-EC2-Instance-Metadaten-Service verfügbar

Über den EC2-Instance-Metadaten-Service können Sie jetzt auf die Tags Ihrer Instanz zugreifen. Mit Tags können Sie AWS-Ressourcen auf unterschiedliche Weise kategorisieren (z. B. nach Zweck, Eigentümer oder Umgebung). Dies ist hilfreich, wenn Sie viele Ressourcen desselben Typs haben. Eine bestimmte Ressource kann dann anhand der ihr zugewiesenen Tags schnell identifiziert werden. Bisher konnten Sie die Konsole oder über die describe-tags-API auf Ihre Instance-Tags über zugreifen.
Quelle: aws.amazon.com

AWS Lambda unterstützt jetzt ES-Module und Top-Level Await für Node.js 14

AWS Lambda-Funktionen, die die Node.js 14-Laufzeit verwenden, unterstützen jetzt den in Form von ECMAScript-Modulen verpackten Code, wodurch Lambda-Kunden in ihren Lambda-Funktionen eine breitere Palette von JavaScript-Paketen verwenden können. Darüber hinaus können Lambda-Kunden jetzt die Vorteile von „Top-Level-Await“ nutzen, einer Funktion der Sprache Node.js 14. Bei Verwendung zusammen mit Provisioned Concurrency verbessert dies die Kaltstartleistung für Funktionen mit asynchronen Initialisierungsaufgaben. Weitere Informationen finden Sie im Blogpost Anwendung von Node.JS ES-Modulen und Top-Level Await in AWS Lambda.
Quelle: aws.amazon.com

Die differenzierte Zugriffskontrolle wird jetzt auf bestehenden Amazon-OpenSearch-Service-Domains unterstützt

Amazon OpenSearch Service (Nachfolger von Amazon Elasticsearch Service) unterstützt jetzt die Aktivierung der differenzierten Zugriffskontrolle auf bestehende Domains. Mit der differenzierten Zugriffskontrolle kommen mehrere Funktionen hinzu, mit denen Sie den Zugriff auf die in Ihrer Domäne gespeicherten Daten besser kontrollieren können.
Quelle: aws.amazon.com

Einführung von 37 neuen Ressourcentypen in der CloudFormation Registry

Seit unserem letzten Update im November 2021 wurde AWS CloudFormation Registry zwischen November und Dezember 2021 um die Unterstützung von 37 neuen Ressourcentypen (vollständige Liste siehe unten) erweitert. Ein Ressourcentyp umfasst ein Schema (Ressourceneigenschaften und Handler-Berechtigungen) sowie Handler, die API-Interaktionen mit den zugrunde liegenden AWS- oder Drittanbieter-Services erlauben. Kunden können jetzt den Lebenszyklus dieser neu unterstützten Ressourcen als Teil ihrer Cloud-Infrastruktur über CloudFormation konfigurieren, bereitstellen und verwalten, indem sie sie als Infrastructure as Code behandeln. Darüber hinaus freuen wir uns, Ihnen mitteilen zu können, dass am Tag der Einführung drei neue AWS-Services die CloudFormation-Unterstützung hinzugefügt haben. Bei diesen Services handelt es sich um: Amazon CloudWatch Evidently, Amazon CloudWatch RUM und AWS Resilience Hub. CloudFormation unterstützt jetzt 170 AWS-Services mit über 830 Ressourcentypen sowie über 40 Ressourcentypen von Drittanbietern.
Quelle: aws.amazon.com

Amazon EC2 On-Demand Capacity Reservations unterstützt jetzt Cluster-Placement-Gruppen

Von heute an können Kunden mit Amazon EC2 On-Demand Capacity Reservations Kapazität für Cluster-Placement-Gruppen reservieren. Mit Cluster-Placement-Gruppen können Kunden EC2-Instances in logischen Gruppen innerhalb eines Netzwerksegments mit hoher Bisektionsbandbreite starten und so geringe Latenzzeiten und hohen Durchsatz zwischen den Instanzen innerhalb des Clusters erzielen. Cluster-Placement-Gruppen sind vorteilhaft für Kunden mit Workloads, die eine eng gekoppelte Node-to-Node-Kommunikation erfordern, wie z. B. High-Performance-Computing (HPC)-Workloads oder In-Memory-Datenbanken wie SAP HANA. Mit On-Demand Capacity Reservations für Cluster-Placement-Gruppen können Kunden sicher sein, dass sie beim Skalieren von Rechenressourcen innerhalb ihres Clusters über reservierte Kapazitäten verfügen.
Quelle: aws.amazon.com