HNHacker News
TopNewBestAskShowJobs

hjacobs

348 karma · joined April 21, 2015

Senior Principal Engineer @ Zalando

https://srcco.de

https://floss.social/@hjacobs

https://twitter.com/try_except_

This is an OpenPGP proof that connects my OpenPGP key to this Hackernews account. For details check out https://keyoxide.org/guides/openpgp-proofs

[Verifying my OpenPGP key: openpgp4fpr:CFDC4B62611448B6B47CA8A8294EEE1A896A6F84]

submissionscomments
hjacobs··on Kubernetes Failure Stories
> adoption failures are mostly networking issues specific to their cloud

Do you have any pointers/write-ups with more information or plans in this direction? I would be interested to learn more.

hjacobs··on Kubernetes Failure Stories
IMHO this would be less interesting, some people already run other container runtimes such as containerd with Kubernetes (e.g. Datadog: https://www.youtube.com/watch?v=2dsCwp_j0yQ) --- so Docker might stay as some user interface for local development, but I would not know what "Docker failures" would be in the future.
hjacobs··on Kubernetes Failure Stories
I would argue that the longtail of applications does not really care about the impact of overlay networks. For us, the biggest impact on low-latency applications (where 1ms makes a difference) on Kubernetes was disabling CPU throttling in all clusters (you can also remove container limits). Background: a Kernel CFS quota bug leads to throttling even if quota is not yet reached, see https://www.youtube.com/watch?v=eBChCFD9hfs&feature=youtu.be...
hjacobs··on Kubernetes Failure Stories
ThoughtWorks even has a term for it: "Microservice envy" https://www.thoughtworks.com/radar/techniques/microservice-e...
hjacobs··on Kubernetes Failure Stories
Christian already followed the example and created a similar list for Serverless: https://github.com/cristim/serverless-failure-stories
hjacobs··on Skipper – An HTTP router and reverse proxy for service composition
Skipper is now also part of the CNCF Cloud Native Interactive Landscape https://landscape.cncf.io/category=service-proxy&grouping=ca...
hjacobs··on Public Money, Public Code: Publicly Funded Software Has to Be Free Software
"I can't say how much I support this, it is so obviously a good idea" -- https://twitter.com/hanno/status/907904636283224064

I have nothing to add. Sign the open letter! :-)

hjacobs··on Patroni: A Template for PostgreSQL HA with ZooKeeper, Etcd, or Consul
We also use RDS in Zalando (and it works great!). With running Patroni on Kubernetes we get several benefits over RDS which in our opinion warrant the effort. Some examples include:

* Real superuser access to the cluster

* Installing custom PostgreSQL extensions not available on RDS, PgQ (Queues in PostgreSQL), PgDecode (logical decode to Kafka/Json), PgJobs (minimalistic jobs in PostgreSQL)

* Easier migrations via S3/Streaming replication from and to AWS - RDS currently offers no way out of RDS to another PostgreSQL cluster

* Deployment model allows for more availability/flexibility with less costs - EBS + S3 allow us to run single node PostgreSQL with high uptime

* Multi node PostgreSQL can run on different node types

* OAuth login for PostgreSQL (via PAM)

hjacobs··on Patroni: A Template for PostgreSQL HA with ZooKeeper, Etcd, or Consul
I guess you did not look into Patroni's README, as it states:

> Patroni originated as a fork of Governor, the project from Compose. It includes plenty of new features.

Governor's git repo seems to have no recent activity (last commit 11 months ago).

hjacobs··on Patroni: A Template for PostgreSQL HA with ZooKeeper, Etcd, or Consul
This is a bit off topic, but the mentioned Ingress controller (https://github.com/zalando-incubator/kube-ingress-aws-contro...) is not using the ALB rules, it just provisions ALBs with the right SSL certificate and points to some HTTP proxy doing the actual host/path routing (e.g. Skipper). See http://kubernetes-on-aws.readthedocs.io/en/latest/admin-guid...
hjacobs··on Patroni: A Template for PostgreSQL HA with ZooKeeper, Etcd, or Consul
Here is a more recent talk about Patroni and Kubernetes (KubeCon Berlin 2017): https://www.youtube.com/watch?v=CftcVhFMGSY
hjacobs··on Problems with Swagger
While Swagger might not be perfect (some pain points are addressed with OpenAPI v3) it works IMHO pretty well for us (Zalando) and myself doing API first:

* use a decent editor to write the YAML e.g. https://github.com/zalando/intellij-swagger * do not write any boilerplate code and do not generate code (if that's possible in your env), e.g. by using https://github.com/zalando/connexion (Python API-first) * follow best practices and guidelines to have a consistent API experience, e.g. https://zalando.github.io/restful-api-guidelines/

Most importantly Swagger/OpenAPI gives us a "simple" (everything is relative!) language to define APIs and discuss/review them independent of languages as teams use different ones across Zalando Tech.

hjacobs··on Docker Enterprise Edition
Very well said!
hjacobs··on Docker Enterprise Edition
> Nobody ever deploys kub alone in production.

We do: https://kubernetes-on-aws.readthedocs.io/en/latest/admin-gui...

There are only a few AWS integration components we added, e.g. to use the "new" AWS ALB (see the linked text for details).

hjacobs··on Docker Enterprise Edition
Kubernetes is definitely lacking some best practice guides. We are trying to share our learnings here: https://kubernetes-on-aws.readthedocs.io/en/latest/admin-gui...

Interestingly we had many "hard" problems with Docker itself (race conditions, stuck Docker daemon) so my confidence in Docker getting the Enterprise thing right is not very high.

hjacobs··on Connexion: Swagger-First Python REST Framework with Validation and OAuth
Example "pet store" application using Connexion: https://github.com/hjacobs/connexion-example
← PreviousPage 2 of 2