Kubernetes V1 Released
googlecloudplatform.blogspot.com
googlecloudplatform.blogspot.com
StackOverflow has at least one quick briefer, but wow, this field is growing quickly:
http://stackoverflow.com/questions/27640633/docker-swarm-kub...
Docker Swarm seems to be the only one that supports one-off interactive containers that bind a TTY, like a Rails console (i.e. does the cluster support `docker run -it --rm busybox sh`). But its scheduling strategies[1] aren't as sophisticated as the others.
Marathon doesn't support linked containers[2], so if you're using Mesos and need linked containers, you probably will want to run Kubernetes on it and use pods.
[1]: https://github.com/docker/swarm/tree/b2182d080956040730cc76c...
[2]: https://support.mesosphere.com/hc/en-us/articles/205006415-H...
[Disclosure - I'm part of the Project Calico team.]
Full disclosure: I work at Google on Kubernetes
Overlay networking is not required if you're running within a bunch of nodes that can see each other. Only if you get more complex will you require something, and there are quite a few solutions (Flannel, Weave, Calico, etc)
Full disclosure: I work at Google on Kubernetes
[Disclosure: i'm currently working on this project]
cluster/kubectl.sh exec pod_name -ti bash
Full disclosure: I work at Google on Kubernetes
[1]: https://github.com/GoogleCloudPlatform/kubernetes/issues/152...
The stack looks something like this for Kubernetes/Mesos (top down):
- Kubernetes and Mesos (client/server packages depending on node type)
- Docker (container engine)
- OS (Ubuntu/RHEL/etc)
What are some use-cases? - you have more work than can fit into one server
- need to distribute load across N+ nodes
- Google heavily uses containers (not k8s, but that inspired these patterns)
- Gmail/Search/etc all run in containers [7]
- Apple, Twitter, and Airbnb are running Mesos today [8, 9]
There are a bunch of revolving services, like: - distributed key/values stores (etcd/zookeeper)
- load balancers
- image registries
- user interfaces
- cli tools
- logging/monitoring/alerting
- etc
But, to answer your question, the main difference between Kubernetes and Mesos, is that Kubernetes offers an opinionated workflow, built-in scheduler, and patterns for how containers are deployed into this cluster of compute notes. The pattern is baked in from the start via Pods, Labels, Services, and Replication Controllers. It also helps to know that Kubernetes comes from Google, where they have been running containers in-house, so much of this workflow (pods, services, replication controllers, etc), comes from their internal use-cases. That's the 10,000 foot view.[1] https://github.com/GoogleCloudPlatform/kubernetes
[3] https://mesosphere.github.io/marathon/
[5] https://hadoop.apache.org/
[6] http://mesos.apache.org/assets/img/documentation/architectur...
[7] http://www.wired.com/2013/03/google-borg-twitter-mesos/
[8] http://www.infoq.com/news/2015/05/mesos-powers-apple-siri
I think it's also interesting to note that Mesos can be used as the Kubernetes minion scheduler backend. And for very large collections of compute nodes, this is reputedly a good choice (though I don't have any personal experience to back that assessment up).
As a maintainer of Fluentd [1], an open source log collector now integrated with Kubernetes [2] and Docker [3], happy to see this out =)
[1] https://www.fluentd.org [2] http://blog.raintown.org/2014/11/logging-kubernetes-pods-usi... [3] http://blog.treasuredata.com/blog/2015/07/07/collecting-dock...
Many, many people believe this is true for them.
Most of them are wrong.
That bet paid off.
I have no idea what "is all the rage right now".
https://github.com/GoogleCloudPlatform/kubernetes/blob/maste...
If you're confused about the differences between similar-sounding products X and Y, the fact that "X runs on Y" or "Y supports X" has never made the situation any better, it only makes the line between X and Y even more blurred.
I think this is especially true of Mesos, because people have a tendency to attribute qualities to Mesos that are actually qualities of a particular Mesos framework like Marathon or Aurora. As it is, Mesos is more of an SDK than anything, giving you the tools to write an orchestration system. It comes with built-in ways to communicate with nodes over a message bus, the ability to look at your nodes as resources, etc... but all of the scheduling logic is up to the frameworks themselves.
I think Mesos has a perception problem because of this. They want to build up hype about what mesos is and can do, so they claim things like Mesos being able to schedule docker images and keep them running, etc... but that's really the job of something like Marathon that runs as a Mesos framework. But if they didn't claim such things, Mesos wouldn't seem very compelling.
To me, the biggest benefit of Mesos is what the gain would be if every datacenter scheduler was a Mesos framework (yarn/spark/kubernetes/marathon/fleet/swarm/aurora, etc), and Mesos was only used to maintain multitenancy on the same hardware. That's where the real advantages come from... if you want to try Kubernetes you shouldn't have to dedicate hardware to it, you should just install it on your existing mesos cluster that is already running the rest of your stuff. In this respect, mesos is only useful insofar as all the big cluster managers use it as their underlying substrate.
As I understand it, Mesos is analogous to an operating system kernel for your cluster, while Kubernetes is a CaaS (containers-as-a-service) layer on top.
Kubernetes can also run directly on VMs or physical machines.
As you say, the primary benefit is that you can provision a single Mesos cluster and share its resources across various frameworks.
This is why Mesosphere built their DCOS; it recognizes that Mesos is a sharp-edged distributed systems kernel and needs to be packaged with convenience layers like Marathon and Chronos and "userland" tools (CLI, graphical UI, packaging system, etc) that make it a complete OS.
- Mesos is a generalized, low level framework for distributing workloads over multiple nodes. It provides mechanism not policy. Therefore it requires quite a bit of up-front work to build something usable for any given application.
- Kubernetes is an opinionated cluster execution tool. It provides tools and a curated workflow for running distributed containerized applications. It's generally pretty quick and easy to get running.
- Mesos has a rich, resource-aware task scheduler. You can specify that your application requires X CPU units and Y RAM units and it will find the optimum node to run the task on.
- By contrast, the Kubernetes scheduler currently is rather dumb[1]. There's no way to specify the expected resource utilization for pods, and the scheduler simply tries to spread out replicas as much as possible throughout the available nodes.
People are (rightly) excited about things like Mesosphere which could allow the best of both worlds: the ease and API of Kubernetes with a powerful Mesos resource scheduler, not to mention nice-to-haves like a Web UI with pretty visualizations.
You can now cut me a check for 50% of the consulting revenue you get from this information. :)
1. The scheduler is intentionally simple and pluggable, to allow improvements easily in the future. My statements only apply to the current state of Kubernetes as deployed today.
So even if the scheduler is vaguely resource-aware (I'm not convinced that's true) it would be entirely static, based on things like container count.
To be more concrete: Within the PodSpec type that you linked to, there is a field of type []Container. Within the Container type there is a field called Resources which is of type ResourceRequirements. ResourceRequirements lets you specify resource requirements of the container. The resource requirements of the Pod are computed by adding up the resource requirements of the containers that run within the Pod.
In addition to resource-based scheduling, we also support "label selectors" which allows you to label nodes with key/value pairs and then say that a Pod should only run on nodes with particular labels. That's specified in the NodeSelector field of the PodSpec (which you linked to).
The Kubernetes scheduler looks at "fit" and "resource availability" to determine the node a pod will run on. Nodes can also have labels like "high-mem" or "ssd", so you can request a particular type of server (via the the nodeSelector field). More details are in the link above.
The documentation on resource-based scheduling is at https://github.com/GoogleCloudPlatform/kubernetes/blob/maste...
The new documentation you linked to has good explanations in it as well.
DCOS is some really nice packaging for marathon, chronos, etc, with a nice cli tool for downloading and installing new frameworks onto mesos. Personally, I find using Aurora a lot nicer.
That being said, I do think the kubernetes-mesos gives you far and above the best of both worlds. You get the developer story of kubernetes, with the ops story of mesos.
From an ops perspective, k8s is a bit clunky. I was actually shocked when I found out after bringing a new kubelet (worker node) online, you have to also update a service on the master. This was in a power training class on Kubernetes at this year's Redhat Summit in Boston. Really underwhelmed with the complexity of k8s compared to mesos, but they aren't an apples to apples comparison.
On AWS that has not been my experience. Nodes can be brought up dynamically and they register themselves with the master.
kubectl get minions
Or usable at all. Really frustrating to me.
- http://insights.ubuntu.com/2015/07/21/introducing-kubernetes...
- https://jujucharms.com/u/kubernetes/kubernetes-cluster
PRs and comments welcome!
Disclaimer: I'm a tech lead on Managed VMs/App Engine at Google
http://www.allthingsdistributed.com/2015/07/under-the-hood-o...
I don't see where the limits on languages, frameworks or data stores comes in.
Languages are extensible in buildpacks, data stores are ordinary services. Heroku pioneered the 12-factor app model, Cloud Foundry lets people run it themselves.
Because I am just not seeing your point. The whole point of a PaaS is to not code to an API. You throw a 12-factor app at one and it Just Works.
It's not up to date with Kubernetes 1.0.0 but I'll update the images as soon as the final version 1 is tagged.
Full disclosure: I work at Google on Kubernetes
"Today, each Kubernetes cluster is a relatively self-contained unit, which typically runs in a single "on-premise" data centre or single availability zone of a cloud provider (Google's GCE, Amazon's AWS, etc)."
https://github.com/GoogleCloudPlatform/kubernetes/blob/relea...
Current ideas are either a single regional cluster or via federation of multiple zonal clusters.
See eg https://github.com/GoogleCloudPlatform/kubernetes/blob/maste... for an proposal on the latter.
This is only one point of data for you, of course.
Apparently, the fact that I've been curious enough to experiment with other Google developer products in the past means I'm not part of the target audience.
I actually find this a common issue with a presumed sales pipeline I encounter.
They think:
1. He finds us. 2. He's interested and signs up for a trial 3. We hopefully convert before the trial is over
What actually tends to happen
1. I find something that looks interesting 2. I sign up 3. Real work intervenes 4. Several months later I have some time to look again but my trial has expired.
To be fair most companies respond to a quick email but they could be proactive and do the following:
1. If no activity is detected after the first day pause the trial 2. Some time later send an email saying "We've paused your trial. Please choose either: 1. to reactivate it, 2. be reminded in another x weeks or 3. never hear from us again.
GitHub and Reddit have conditioned us to think that any halfway decent discussion system must use it :-P
Can you submit a support request and we'll see what we can do?
Also, spinning up a cluster should be incredibly cheap if you just want to mess around for a little bit - we do billing by the minute :)
Full disclosure: I work on Google on Kubernetes
I guess I can understand the cost-cutting mentality that drives Google, AWS, etc. to limit these kinds of offers to "new customers" only. Just remember to consider what kind of incentives you're creating. By effectively punishing developers for being early adopters/experimenters, you're making them wary of signing up early for whatever new and interesting stuff you announce in the future.
Full Disclosure: I work at Google on da Cloudz
1. Current type for new customers. Here's $500. Do whatever you want
2. For old customers who haven't ever used a free trial, give credit without limits (same as new customers)
3. For old customers who have used a free trial give credit only for services they haven't used
We do appreciate the feedback and are looking hard at the right next way to solve this. If it wasn't for bitcoin miners and/or bot nets, this would all be a lot easier :(
Full disclosure: I work at Google on Kubernetes.
"Unfortunately, the system is developed by design to only apply the free trial credit to new email address creating a new billing account and we can't apply it for already existing emails." Bummer.
And that confused me.
1 x MySQL Master
2 x MySQL Slave
5 x PHP Server
1 x Monitoring Script
Each of those would be a docker container. Kubernetes would figure out which host to place them on and verify that they are running, rebooting them on another host if one of your hosts goes down.
Docker also has Docker Swarm, which can be thought of as a competitor in some ways. But Google will be a heavy supporter of their container format for a long time to come.
Full Disclosure: I work at Google on Kubernetes
I had tested Docker just for fun, thinking that maybe I could implement it in the way I work, and sure it is a super tool for developing (far better than Virtual Machines), but deploying was kind of nightmerish, for what I understood Docker wasn't at the time ready for being a deployment tool.
Does Kubernetes fixes or extends Docker in this way
Kubernetes jobs is to start, monitor, and load balance those docker containers.
Docker's job is to run each container.
At the bottom of the stack (most low level) is the Docker runtime. It knows how to run containers on the local machine. It can link them together, manage volumes, etc but at the core it is a single machine system. (That's probably why Docker, Inc has developed their proprietary orchestration tools like swarm).
Layered on top of that are container-native OSes like CoreOS. CoreOS provides facilities for running distributed containers on multiple physical nodes. It handles things like replication and restarting failed containers (actually fleet "units"). This is a huge improvement over vanilla Docker, but it's still pretty low level. If you want to run a real production application with dependencies it can be tedious. For example, linking together containers that run on different nodes. How does container A find container B (which may be running on any one of N nodes)? To solve this you have to do things like the Ambassador Pattern[1]. Any complex application deployment involves essentially building discovery and dependency management from scratch.
Layered on top of this is Kubernetes (it runs on CoreOS but also Ubuntu and others). As said elsewhere in this post, k8s provides an opinionated workflow that allows you to build distributed application deployments without the pain of implementing things like low-level discovery. You describe your application in terms of containers, ports, and services and k8s takes care of spawning them, managing replica count (restarting/migrating if necessary) and discovery (via DNS or environment variables).
One of the very convenient things about k8s (unlike vanilla Docker) is that all containers within a pod can find each other via localhost, so you don't have to maintain tedious webs of container links. In general it takes the world of containerization from "Cool technology, but good luck migrating production over" to "I think we could do this!".
1. https://coreos.com/blog/docker-dynamic-ambassador-powered-by...
Full disclosure: I work at Google on Kubernetes
This is because Docker is building it's own scheduling/orchestration tools, which is what Kubernetes is for. However, as a container runtime, Kubernetes works great with Docker.
[0] http://techcrunch.com/2015/07/21/coreos-launches-preview-of-...
If anyone is interested, I just wrapped up a similar post for deploying containers to Giant Swarm from Wercker, no Docker required: I just got done doing a continuos integration post for containers using Wercker and Giant Swarm: https://github.com/giantswarm/swarm-wercker.
https://blog.kismatic.com/running-rkt-on-kubernetes/
Full Disclosure: I work at Google on Kubernetes
But awesome that there's at least some support! :D
[0] - https://github.com/GoogleCloudPlatform/kubernetes/issues/720...
That seems awfully slow for a fancy chroot. I use KVM to bring up WinXP snapshot VMs in around 2s to a running state...maybe they mean 5ms?
Edit: and I see the Cloud Foundry Foundation logo on the Cloud Native Foundation homepage. It's Foundations all the way down.
(Disclaimer: I work for another CFF member, Pivotal).
I guess I got caught up by the inside baseball.