
Canary/ Blue-Green Deployment demo with Istio service mesh for kubernetes

Canary Deployment with Istio

System Architecture

The purpose of this demo is to simulate a simple e-commerce event-driven microsercie architecture.

flowchart LR

    APIGW --> Product --> RabbitMQ
    APIGW --> Inventory
    APIGW --> Review
    RabbitMQ --> Inventory

    subgraph Services
            MongoDB[(Database)] <--> Product
            MongoDB <--> Inventory
            MongoDB <--> Review

    subgraph EventBus
        Product --> RabbitMQ
        RabbitMQ --> Inventory


Kind cluster initiation

If you don't already have kind installed, follow the link

kind create cluster --config=kind-cluster.yaml

Install Istio Ingress Gateway CRD

kubectl get crd gateways.gateway.networking.k8s.io &> /dev/null || \
  { kubectl kustomize "github.com/kubernetes-sigs/gateway-api/config/crd?ref=v0.8.0" | kubectl apply -f -; }

Istio Initializing

curl -L https://istio.io/downloadIstio | sh -
# export the istio path
istioctl install --set profile=demo -y

Install and Configure MetalLB

kubectl apply -f https://raw.githubusercontent.com/metallb/metallb/v0.13.7/config/manifests/metallb-native.yaml
  • Setup address pool for LB

    docker network inspect -f '{{ (index .IPAM.Config 0).Gateway }}' kind 

    then configure metallb-conf.yaml accordingly and run k apply

Install RabbitMQ CRDs

kubectl apply -f "https://github.com/rabbitmq/cluster-operator/releases/latest/download/cluster-operator.yml"

Configure RMQ

k exec -it rabbitmq-server-0 -- bash

rabbitmqctl add_user admin admin

rabbitmqctl set_permissions --vhost / admin '.*' '.*' '.*'

rabbitmqctl set_user_tags admin administrator

Or get the default password from cli

# Get Username
kubectl get secret rabbitmq-default-user -o jsonpath="{.data.username}" | base64 --decode
# Get Password
kubectl get secret rabbitmq-default-user -o jsonpath="{.data.password}" | base64 --decode

Install Mongo

k apply -f -r k8s-config/mongod

Configure Mongo ReplicaSet

  • Drop to mongo shell k exec -it mongo-0 -- mongosh
var cfg = rs.conf()

  • Check the replication status rs.status()

Installing the application via helm

Update egcom/applications/templates/egcom-cm.yaml ConfigMap values with the Grafana and RMQ creds.

k create ns egcom

k label namespace default istio-injection=enabled

helm install egcom ./applications -n egcom

Test your setup

~ ❯ k get gtw -n egcom
NAME                CLASS   ADDRESS        PROGRAMMED   AGE
apigw-gateway       istio   True         31h
inventory-gateway   istio   True         31h
product-gateway     istio   True         31h
review-gateway      istio   True         31h

Postman Collection

baseURL is the address of the apigw-gateway

