In this course, students learn how to manage manage complex microservice architected applications using a service mesh.
-
DURATION: 24 hours.
-
MODALITY: ILT
-
PROFICIENCY LEVEL: Advanced
-
PRODUCT: Red Hat Service Mesh
In this course, students will build upon Foundational knowledge of Red Hat OpenShift Service Mesh. All learning objectives of this course will be achieved by applying service mesh functionality to a real-world micro-service architected application. This course will introduce students to the use of securing inter-service communication via the mutual TLS functionality of the product. In addition, students will utilize the multi-tenancy capabilities of the product deployed on a single OpenShift cluster. Performance testing on the service mesh tenants will be conducted and results will be analyzed. Finally, students will plugin a 3scale adapter to the control plane of the Service Mesh product so as to apply API policies to both inbound traffic as well as traffic between services in the mesh. As part of this last exercise, students will observe analytics and tracing of traffic in and throughout the service mesh.
Each course module listed below will consist of a slide presentation and one or more corresponding hands-on labs.
-
01_Multi_Tenancy
-
Labs
-
01_1_Assets_Lab
-
Access to OCP environment
-
Review Service Mesh operator, istio-cni plugin and CRDs
-
Review Service Mesh control plane
-
Introduce Emergency Response demo
-
-
01_2_Multi_Tenancy_Lab
-
Understand importance of Service Mesh multi-tenancy
-
Understand ServiceMeshMemberRoll
-
Understand Envoy Data Plane
-
-
-
Slides: Red Hat Service Mesh Engineering Design Decisions (Kevin Connor)
-
02_Security
-
Slides: Service Mesh Security
-
Labs:
-
02_1_Secure_mTLS_Lab
-
-
-
03_Reliability
-
Slides: ???
-
Labs:
-
03_1_Reliability_Lab (jeff)
-
Add retries to PAM invocations postgresql
-
Add circuit-breaker to clients invoking PAM postgresql
-
-
-
-
04_Observability
-
Slides ???
-
Labs
-
04_1_Distributed_Tracing_Lab (bernard)
-
04_2_Prometheus_AlertManager_Lab (bernard)
-
04_3_Kiali_Service_Graph_Lab (???? …. Bernard)
-
-
-
05_Mixer_Adapters
-
Slides (Jeff)
-
Labs
-
05_1_API_Mgmt_Adapter_Lab
-
-
-
06_Production Considerations
-
Slides: Production_Considerations_and_Load_Testing (Kevin Connor)
-
Labs:
-
06_Chaos_Engineering_Lab (bernard)
-
-
-
07_Homework
-
07_1_Homework_Lab (jeff)
-
-
OCP 4.2
-
Provisioned from labs.opentlc.com → OCP4 Workshop Deployer
-
Instructor uses MachineSet API to scale to appropriately sized cluster
-
Emergency Response (16GB RAM) + Istio Control Plane (6GB RAM) = 22GB RAM per student
-
-
Service Mesh Control Plane
-
Instructor layers 1 Service Mesh Control Plane per student
-
user[1-100] has view access to service mesh control plane
-
admin[1-100] has admin access to service mesh control plane (but is not a cluster admin)
-
-
RH-SSO
-
Used as Identity Provider (via OIDC) for the following:
-
OCP 4
-
3scale
-
Emergency Response Demo ??
-
-
-
3scale Control Plane
-
Insructor provisions 1 3scale Control Plane
-
Instructor creates 1 tenant per student
-
user[1-100] is an API provider for their tenant
-
admin[1-100] is a admin of their tenant
-
-
-
Instructor layers 1 Emergency Response Demo per student
-
Both uer[1-100] and admin[1-100] have admin access to this emergency-response-demo namespace
-
-
-
Client tooling (on student laptop)
-
Browser
-
oc 4.2 utility
-
istioctl
-