深色模式
Chaos Mesh 入门
摘要:Chaos Mesh 是 CNCF 孵化项目,用 CRD 描述故障,天然适配 Kubernetes。本文完成 Helm 安装、组件健康校验、Dashboard 访问与第一个 PodChaos 实验。
适用环境
bash
kubectl version --short
helm version --short
# 集群需支持 CRD 与特权容器
kubectl api-resources --api-group=chaos-mesh.org 2>/dev/null | head1
2
3
4
2
3
4
操作步骤
第 1 步:安装 Chaos Mesh
bash
helm repo add chaos-mesh https://charts.chaos-mesh.org
helm repo update
kubectl create ns chaos-mesh
helm install chaos-mesh chaos-mesh/chaos-mesh \
-n chaos-mesh \
--set chaosDaemon.runtime=containerd \
--set chaosDaemon.socketPath=/run/containerd/containerd.sock \
--set dashboard.create=true \
--wait1
2
3
4
5
6
7
8
9
2
3
4
5
6
7
8
9
容器运行时为 docker 时把
runtime与socketPath对应改为docker和/var/run/docker.sock。
第 2 步:校验组件就绪
bash
kubectl -n chaos-mesh get pod
kubectl -n chaos-mesh wait --for=condition=Ready pod -l app.kubernetes.io/component=controller-manager --timeout=120s
kubectl api-resources --api-group=chaos-mesh.org1
2
3
2
3
第 3 步:访问 Dashboard
bash
kubectl -n chaos-mesh port-forward svc/chaos-dashboard 2333:2333 &
# 浏览器打开 http://127.0.0.1:2333 ;如需登录按页面提示生成 token
curl -sS -o /dev/null -w 'HTTP %{http_code}\n' http://127.0.0.1:23331
2
3
2
3
第 4 步:跑通第一个 PodChaos
yaml
# pod-kill-demo.yaml
apiVersion: chaos-mesh.org/v1alpha1
kind: PodChaos
metadata:
name: pod-kill-demo
namespace: test
spec:
action: pod-kill
mode: one
selector:
namespaces: [test]
labelSelectors:
app: demo
duration: '30s'1
2
3
4
5
6
7
8
9
10
11
12
13
14
2
3
4
5
6
7
8
9
10
11
12
13
14
bash
kubectl -n test apply -f pod-kill-demo.yaml
kubectl -n test get podchaos pod-kill-demo -o jsonpath='{.status.phase}{"\n"}'
watch -n 2 'kubectl -n test get pod -l app=demo'1
2
3
2
3
第 5 步:清理实验
bash
kubectl -n test delete -f pod-kill-demo.yaml
kubectl -n test get podchaos1
2
2
验证
bash
# 1. CRD 已注册
kubectl get crd | grep chaos-mesh
# 2. controller-manager 与 daemon 均为 Running
kubectl -n chaos-mesh get pod -o custom-columns='NAME:.metadata.name,STATUS:.status.phase'
# 3. 实验生效:Pod 被重建,AGE 变小
kubectl -n test get pod -l app=demo --sort-by=.metadata.creationTimestamp | tail -31
2
3
4
5
6
7
8
2
3
4
5
6
7
8
常见坑
容器运行时 socket 路径不匹配
Daemon 无法连接 runtime 时实验会一直 Pending。安装前先确认 /run/containerd/containerd.sock 或 /var/run/docker.sock 哪个存在。
命名空间写错导致实验不生效
Chaos Mesh 的 selector 里 namespaces 是数组且必须显式写。不写时不会默认当前命名空间。
在共享集群安装后未做权限收敛
Chaos Mesh 具备杀 Pod、改网络的能力。生产集群安装后必须限制谁有权限创建 chaos CR,避免误操作。