1 · Words 2 · Machines 3 · Cluster 4 · YAML 5 · Run it 6 · Fix it 7 · When

☸️ Kubernetes Lab

In the Docker Lab you made a box and you started it. You were the boss. You started it, you watched it, and you stopped it. That works for one box on one computer. Kubernetes is a boss that never sleeps. You tell it what you want. Then it makes it true, and it keeps it true, all day and all night. 在 Docker 实验室里,你做了一个盒子并启动它。你是老板:你启动它、盯着它、停掉它。 一台电脑上的一个盒子,这样就够了。Kubernetes 是一个永不睡觉的老板。 你告诉它你要什么,它就让它成真,并且日夜不停地保持成真。 ในแล็บ Docker คุณสร้างกล่องแล้วสั่งให้มันทำงาน คุณคือเจ้านาย คุณเปิดมัน เฝ้ามัน แล้วปิดมัน แบบนั้นใช้ได้กับกล่องเดียวบนเครื่องเดียว Kubernetes คือเจ้านายที่ไม่เคยหลับ คุณบอกว่าคุณต้องการอะไร แล้วมันทำให้เป็นจริง และรักษาให้เป็นจริงตลอดทั้งวันทั้งคืน

🐳 Do the Docker Lab first. This page uses the image you built and pushed there: yourname/my-site:1.0. If you have not made it yet, go and make it. Come back after. It takes about one hour.
请先做 Docker 实验室。本页会用到你在那里构建并推送的镜像 yourname/my-site:1.0。还没做的话先去做,大约一小时,做完再回来。

ทำแล็บ Docker ก่อน หน้านี้ใช้อิมเมจที่คุณสร้างและ push ไว้ที่นั่น yourname/my-site:1.0 ถ้ายังไม่ได้ทำ ไปทำก่อน ใช้เวลาประมาณหนึ่งชั่วโมง แล้วค่อยกลับมา
Open ▸

Today you will do five things. You will learn the words. You will drive five machines: the loop, labels, the service, the update, and the scheduler. You will start a real cluster on your own computer, free. You will run your own image on it. Then you will break it on purpose and fix it. 今天你会做五件事:学词;玩五台机器——循环、标签、服务、更新、调度器; 在自己电脑上免费启动一个真的集群;把自己的镜像跑上去;然后故意弄坏它,再修好它。 วันนี้คุณจะทำห้าอย่าง เรียนคำศัพท์ เล่นเครื่องมือห้าตัว: ลูป, เลเบล, เซอร์วิส, การอัปเดต และตัวจัดคิว เปิดคลัสเตอร์จริงบนเครื่องของคุณเองแบบฟรี รันอิมเมจของคุณเองบนมัน แล้วตั้งใจทำให้พัง และซ่อมมัน

A promise first. Kubernetes has many words and many files. That is real, and it is why people find it hard. But under all of it there is one idea: you write what you want, and a loop makes the world match it. Hold on to that one idea. Everything else on this page is a detail hanging off it. 先给你一个承诺:Kubernetes 有很多词、很多文件,这是真的, 也正是大家觉得难的原因。但这一切下面只有一个念头你写下你要什么,一个循环让现实去匹配它。抓住这个念头,本页其他内容都只是挂在它上面的细节。 ขอสัญญาก่อนหนึ่งข้อ Kubernetes มีคำเยอะและไฟล์เยอะ เรื่องนั้นจริง และนั่นคือเหตุผลที่คนรู้สึกว่ามันยาก แต่ใต้ทั้งหมดนั้นมีแนวคิดเดียว: คุณเขียนว่าคุณต้องการอะไร แล้วลูปหนึ่งจะทำให้โลกจริงตรงกับสิ่งนั้น จับแนวคิดนี้ไว้ให้แน่น ทุกอย่างที่เหลือในหน้านี้เป็นแค่รายละเอียดที่ห้อยอยู่กับมัน

🔤 The words you need

Summary

Twenty-two words. Kubernetes has more words than Docker, and that is the hard part for most people. Learn these first and the files stop looking strange. You will type nearly all of them today. Tap say it to hear one word. Tap tell me more to read a long answer.

摘要

二十二个词。Kubernetes 的词比 Docker 多,这对大多数人来说正是难点。先把这些学会,那些文件就不再奇怪了。今天你几乎全都会亲手敲一遍。点 say it 听发音,点 tell me more 读详细解释。

สรุป

ยี่สิบสองคำ Kubernetes มีคำมากกว่า Docker และนั่นคือส่วนที่ยากสำหรับคนส่วนใหญ่ เรียนคำเหล่านี้ก่อน แล้วไฟล์พวกนั้นจะไม่ดูแปลกอีกต่อไป วันนี้คุณจะได้พิมพ์เกือบทุกคำ แตะ say it เพื่อฟังหนึ่งคำ แตะ tell me more เพื่ออ่านคำอธิบายยาว

🔧 Five little machines

Each machine shows a real piece of a Kubernetes file on the left. It shows what that piece does on the right. Press the buttons. The file you see is the file that made the picture. 每台机器左边是 Kubernetes 文件里真实的一段,右边是这一段做的事。按按钮试试。 你看到的文件就是画出这张图的文件。 แต่ละเครื่องแสดงส่วนจริงของไฟล์ Kubernetes ทางซ้าย และแสดงว่าส่วนนั้นทำอะไรทางขวา กดปุ่มดู ไฟล์ที่คุณเห็นคือไฟล์ที่ทำให้เกิดรูปนั้น

🔁 1 · The loop that never sleeps

Summary

Kubernetes runs one small loop again and again. It looks at the world. It compares the world with your file. If they are different, it acts. That is all. Press pause and kill a pod, and nothing comes back. Press start, and it comes back at once. The loop is the whole machine.

摘要

Kubernetes 一遍又一遍地跑一个小循环:看世界、把世界和你的文件比一比、不一样就动手。就这么简单。按下暂停再杀掉一个 pod,什么都不会回来;按下开始,它马上就回来了。这个循环就是整台机器。

สรุป

Kubernetes รันลูปเล็ก ๆ ลูปเดียวซ้ำไปเรื่อย ๆ มันดูโลกจริง เทียบโลกจริงกับไฟล์ของคุณ ถ้าต่างกันก็ลงมือทำ แค่นั้น กดหยุดแล้วฆ่าพ็อดดู จะไม่มีอะไรกลับมา กดเริ่ม มันกลับมาทันที ลูปนี้คือทั้งเครื่อง

# you write this — it is a wish, not an order spec: replicas: 4 # the loop does this, for ever: # 1 watch what is really running? # 2 compare is it the same as the file? # 3 act make more, or remove some
Try this. Pause the loop. Kill a pod. Wait. Nothing happens — the pod stays dead. Now start the loop again. It comes back in one tick. Kubernetes is not magic. It is this loop, watching and comparing and acting, for ever. 试试看:先暂停循环,杀掉一个 pod,等一会儿——什么都不会发生,pod 就那样死着。 再启动循环,它一个节拍就回来了。Kubernetes 不是魔法,它就是这个循环, 一直看、一直比、一直动手,永远跑下去。 ลองแบบนี้ หยุดลูปก่อน แล้วฆ่าพ็อด รอดู ไม่มีอะไรเกิดขึ้น พ็อดตายอยู่อย่างนั้น ทีนี้เริ่มลูปใหม่ มันกลับมาภายในหนึ่งจังหวะ Kubernetes ไม่ใช่เวทมนตร์ มันคือลูปนี้ ที่คอยดู คอยเทียบ และคอยลงมือ ตลอดไป
want 4 · running 4 · the loop is happy

🖥️ Get a free cluster on your own computer

Summary

A real cluster in the cloud costs money every hour. You do not need one to learn. Your own computer can run a small cluster with one node, and it is free. Three tools can do this. If you did the Docker Lab, the first one is already on your computer. Pick that one.

摘要

云上的真集群按小时收费,学习不需要它。你自己的电脑就能跑一个只有一个节点的小集群,而且免费。有三种工具可以做到。如果你做过 Docker 实验室,第一种你电脑上已经有了,就选它。

สรุป

คลัสเตอร์จริงบนคลาวด์เสียเงินทุกชั่วโมง การเรียนไม่จำเป็นต้องใช้ เครื่องของคุณเองรันคลัสเตอร์เล็กที่มีโหนดเดียวได้ และฟรี มีสามเครื่องมือที่ทำได้ ถ้าคุณทำแล็บ Docker มาแล้ว ตัวแรกมีอยู่ในเครื่องคุณอยู่แล้ว เลือกตัวนั้น

Best for you. Nothing new to install. It works the same on Windows and on a Mac. 最适合你:不用装任何新东西,Windows 和 Mac 上用法一样。 เหมาะกับคุณที่สุด ไม่ต้องติดตั้งอะไรใหม่ ใช้เหมือนกันทั้ง Windows และ Mac

1 Turn Kubernetes on

Open Docker Desktop. Click the gear at the top right. Click Kubernetes in the left list. Tick Enable Kubernetes. Click Apply & restart. 打开 Docker Desktop,点右上角齿轮,在左边列表点 Kubernetes, 勾选 Enable Kubernetes,点 Apply & restart เปิด Docker Desktop กดรูปเฟืองมุมขวาบน เลือก Kubernetes ในรายการซ้าย ติ๊ก Enable Kubernetes แล้วกด Apply & restart

2 Wait — and this first wait is long

The first time takes five to ten minutes. It is downloading the cluster. Do not press anything. Wait for a second green light at the bottom left, next to the whale. 第一次要等五到十分钟,它在下载整个集群。什么都别按。 等左下角鲸鱼旁边出现第二个绿灯 ครั้งแรกใช้เวลาห้าถึงสิบนาที มันกำลังดาวน์โหลดคลัสเตอร์ อย่ากดอะไร รอจนมีไฟเขียวดวงที่สองขึ้นมุมล่างซ้าย ข้าง ๆ รูปวาฬ

3 Say hello to your cluster

kubectl get nodes # NAME STATUS ROLES AGE VERSION # docker-desktop Ready control-plane 2m v1.32.2

One node. It is your own computer, wearing a different hat. kubectl came with Docker Desktop, so you did not have to install it. 一个节点,就是你自己的电脑换了顶帽子。kubectl 是 Docker Desktop 自带的,你不用另外安装。 โหนดเดียว มันคือเครื่องของคุณเองที่ใส่หมวกอีกใบ kubectl มากับ Docker Desktop อยู่แล้ว คุณจึงไม่ต้องติดตั้งเอง

Turn it off when you finish. A cluster eats memory even when it is doing nothing. Go back to Settings → Kubernetes and untick the box on the days you are not using it. 用完就关掉。集群就算什么都不干也吃内存。不用的日子, 回到 Settings → Kubernetes 把勾去掉。 ใช้เสร็จแล้วปิดด้วย คลัสเตอร์กินหน่วยความจำแม้ตอนไม่ได้ทำอะไร วันไหนไม่ใช้ ให้กลับไปที่ Settings → Kubernetes แล้วเอาติ๊กออก

📄 How to read a YAML file

Summary

You talk to Kubernetes with YAML files. YAML is not code. It is a list of settings that a person can read. There are only four rules. Learn the four rules and the scary files stop being scary. Spaces matter very much, and a tab key will break the file.

摘要

你用 YAML 文件跟 Kubernetes 说话。YAML 不是代码,它是一份人能读懂的设置清单。规则只有四条。学会这四条,那些吓人的文件就不吓人了。空格非常重要,按 Tab 键会把文件弄坏。

สรุป

คุณคุยกับ Kubernetes ด้วยไฟล์ YAML YAML ไม่ใช่โค้ด มันคือรายการการตั้งค่าที่คนอ่านเข้าใจ มีกฎแค่สี่ข้อ เรียนสี่ข้อนี้แล้วไฟล์ที่ดูน่ากลัวจะไม่น่ากลัวอีกต่อไป ช่องว่างสำคัญมาก และปุ่ม Tab จะทำให้ไฟล์พัง

  • Rule 1 — a name, two dots, a value. replicas: 4 规则一 —— 名字、冒号、值:replicas: 4 กฎข้อ 1 — ชื่อ ทวิภาค ค่า replicas: 4
  • Rule 2 — two spaces means "inside". Things that are further right belong to the line above them. 规则二 —— 两个空格表示“在里面”:越靠右的行,属于它上面那一行。 กฎข้อ 2 — เว้นสองช่องแปลว่า "อยู่ข้างใน" บรรทัดที่ยื่นไปทางขวา เป็นของบรรทัดที่อยู่เหนือมัน
  • Rule 3 — a dash makes a list item. - name: web. Many dashes, many items. 规则三 —— 短横线表示列表项:- name: web。几个短横线就是几项。 กฎข้อ 3 — ขีดกลางทำให้เป็นรายการ - name: web หลายขีด ก็หลายรายการ
  • Rule 4 — never press Tab. Only the space bar. A tab looks the same on the screen and breaks the file. This is the number one YAML mistake in the world. 规则四 —— 绝不要按 Tab,只用空格键。Tab 在屏幕上看起来一模一样, 却会让文件报错。这是全世界最常见的 YAML 错误。 กฎข้อ 4 — ห้ามกด Tab เด็ดขาด ใช้แค่ปุ่มเว้นวรรค แท็บดูเหมือนกันบนหน้าจอ แต่ทำให้ไฟล์พัง นี่คือความผิดพลาด YAML อันดับหนึ่งของโลก

Every Kubernetes file has the same four top lines

apiVersion: apps/v1 # which rule book kind: Deployment # what kind of thing metadata: # its name and its labels name: my-site spec: # what you want — the big one replicas: 4

Read any Kubernetes file in that order and it makes sense. Which rule book, what kind of thing, what is it called, and what do I want. 按这个顺序读任何 Kubernetes 文件都读得懂:用哪本规则书、是什么东西、 它叫什么、我要什么。 อ่านไฟล์ Kubernetes ไฟล์ไหนก็ตามตามลำดับนี้ แล้วจะเข้าใจ: ใช้กฎเล่มไหน เป็นของชนิดอะไร ชื่ออะไร และฉันต้องการอะไร

Two commands that save your evening. The first checks the file without changing anything. The second shows you every field a kind can have, straight from your own cluster — no web search needed. 两条能救你一个晚上的命令:第一条只检查文件,什么都不改; 第二条直接从你自己的集群里列出某种资源的所有字段,不用上网搜。 สองคำสั่งที่ช่วยชีวิตคุณทั้งเย็น คำสั่งแรกตรวจไฟล์โดยไม่เปลี่ยนอะไร คำสั่งที่สองแสดงทุกฟิลด์ที่ชนิดนั้นมี ดึงจากคลัสเตอร์ของคุณเอง ไม่ต้องเปิดเว็บค้น
kubectl apply -f deployment.yaml --dry-run=client kubectl explain deployment.spec.replicas

⚙️ Run your own image on Kubernetes

Summary

Now the real thing. You will take the React image you pushed to Docker Hub and run four copies of it on your cluster. Then you will open it in a browser, make it bigger, give it a new version with no dark screen, and roll it back. Ten steps. Change yourname to your real Docker Hub name every time.

摘要

现在来真的。你要把推送到 Docker Hub 的那个 React 镜像,在集群上跑起四个副本,然后在浏览器里打开它、把它变大、不黑屏地换新版本、再回滚。一共十步。每次都要把 yourname 换成你真正的 Docker Hub 用户名。

สรุป

ทีนี้ของจริง คุณจะเอาอิมเมจ React ที่ push ขึ้น Docker Hub มารันสี่สำเนาบนคลัสเตอร์ แล้วเปิดในเบราว์เซอร์ ขยายให้ใหญ่ขึ้น เปลี่ยนเวอร์ชันใหม่โดยจอไม่ดำ และย้อนกลับ สิบขั้นตอน อย่าลืมเปลี่ยน yourname เป็นชื่อ Docker Hub จริงของคุณทุกครั้ง

1 Check the cluster is awake

kubectl get nodes

If this says Ready, go on. If it says it cannot connect, your cluster is not running. Go back to section 3. 显示 Ready 就继续;提示连不上,说明集群没在跑,回到第 3 节。 ถ้าขึ้น Ready ให้ไปต่อ ถ้าบอกว่าเชื่อมต่อไม่ได้ แปลว่าคลัสเตอร์ยังไม่ทำงาน ให้กลับไปที่หัวข้อ 3

2 Make a folder for your files

mkdir k8s cd k8s

3 Write deployment.yaml

This is your wish: four copies of your image. 这就是你的愿望:你的镜像跑四份。 นี่คือความต้องการของคุณ: อิมเมจของคุณสี่สำเนา

apiVersion: apps/v1 kind: Deployment metadata: name: my-site spec: replicas: 4 selector: matchLabels: app: my-site # ← the question template: metadata: labels: app: my-site # ← the answer. These two MUST match. spec: containers: - name: web image: yourname/my-site:1.0 ports: - containerPort: 80 resources: requests: cpu: "50m" memory: "32Mi"
The two app: my-site lines must be the same word. The first one is the question the Deployment asks. The second one is the label it sticks on the pods it makes. If they are different, the Deployment cannot find its own pods, and it will make new ones for ever. This is the most common beginner mistake. 那两行 app: my-site 必须一模一样。 第一行是 Deployment 问的问题,第二行是它贴在自己造的 pod 上的标签。 两者不同,Deployment 就找不到自己的 pod,会没完没了地造新的。这是新手最常见的错误。 สองบรรทัด app: my-site ต้องเป็นคำเดียวกัน บรรทัดแรกคือคำถามที่ Deployment ถาม บรรทัดที่สองคือเลเบลที่มันแปะบนพ็อดที่มันสร้าง ถ้าต่างกัน Deployment จะหาพ็อดของตัวเองไม่เจอ และจะสร้างใหม่ไปเรื่อย ๆ ไม่หยุด นี่คือความผิดพลาดของมือใหม่ที่พบบ่อยที่สุด

4 Send your wish to the cluster

kubectl apply -f deployment.yaml # deployment.apps/my-site created

apply is the only word you need. Use it the first time and every time after. Kubernetes works out what changed. apply 是你唯一需要的动词:第一次用它,以后每次也用它, Kubernetes 自己算出改了什么。 apply คือคำเดียวที่คุณต้องใช้ ใช้ครั้งแรกและใช้ทุกครั้งต่อจากนั้น Kubernetes จะคิดเองว่าอะไรเปลี่ยนไป

5 Watch the pods arrive

kubectl get pods # NAME READY STATUS RESTARTS AGE # my-site-7d4c9b8f6-2xk9p 1/1 Running 0 12s # my-site-7d4c9b8f6-8mzq4 1/1 Running 0 12s # my-site-7d4c9b8f6-j5rvn 1/1 Running 0 12s # my-site-7d4c9b8f6-w1c8t 1/1 Running 0 12s

Four pods. Look at the names: they all start the same and end differently. You never choose those names, and you should never write one down. 四个 pod。看名字:开头都一样,结尾各不相同。这些名字不是你起的, 也永远不要把它记下来。 สี่พ็อด ดูชื่อสิ ขึ้นต้นเหมือนกันหมด ลงท้ายต่างกัน คุณไม่ได้ตั้งชื่อพวกนี้ และไม่ควรจดมันไว้เลย

kubectl get pods -w # watch — live, press Ctrl+C to stop kubectl get pods -o wide # which node is each pod on?

6 Write service.yaml and open the site

The pods are running, but you cannot reach them yet. They have no door. A Service gives them one door and one address. pod 在跑,但你还够不着它们——它们没有门。Service 给它们一扇门和一个地址。 พ็อดทำงานอยู่ แต่คุณยังเข้าไม่ถึง เพราะยังไม่มีประตู เซอร์วิสจะให้ประตูหนึ่งบานและที่อยู่หนึ่งที่

apiVersion: v1 kind: Service metadata: name: my-site spec: type: LoadBalancer selector: app: my-site # ← same question again ports: - port: 8080 # the door you knock on targetPort: 80 # the door inside the pod
kubectl apply -f service.yaml kubectl get service my-site # NAME TYPE EXTERNAL-IP PORT(S) # my-site LoadBalancer localhost 8080:31674/TCP

Now open http://localhost:8080. Your React page is there, and four pods are sharing the work. 现在打开 http://localhost:8080,你的 React 页面就在那里, 四个 pod 在分担工作。 ตอนนี้เปิด http://localhost:8080 หน้า React ของคุณอยู่ตรงนั้น และมีสี่พ็อดช่วยกันแบ่งงาน

Look at the two port numbers. port is what you knock on. targetPort is the door inside the pod, the one nginx opened. It is exactly the same idea as -p 8080:80 in the Docker Lab, with longer names. 看那两个端口号:port 是你敲的门, targetPort 是 pod 里面 nginx 开的那扇门。跟 Docker 实验室里的 -p 8080:80 是同一个想法,只是名字更长。 ดูเลขพอร์ตสองตัว port คือประตูที่คุณเคาะ targetPort คือประตูข้างในพ็อดที่ nginx เปิดไว้ เป็นแนวคิดเดียวกับ -p 8080:80 ในแล็บ Docker เป๊ะ ๆ แค่ชื่อยาวกว่า
On minikube, localhost will not work. Run minikube service my-site instead and it opens the right address. 在 minikube 上localhost 不管用, 改用 minikube service my-site,它会打开正确的地址。 บน minikube localhost จะใช้ไม่ได้ ให้รัน minikube service my-site แทน แล้วมันจะเปิดที่อยู่ที่ถูกต้องให้

7 Make it bigger, then smaller

kubectl scale deployment my-site --replicas=8 kubectl get pods kubectl scale deployment my-site --replicas=4

Eight pods appear in a few seconds. Four go away just as fast. You did not touch a single computer. 几秒钟内就多出八个 pod,再几秒就少掉四个。你没有碰过任何一台机器。 แปดพ็อดโผล่มาในไม่กี่วินาที แล้วหายไปสี่ตัวเร็วพอ ๆ กัน โดยที่คุณไม่ได้แตะเครื่องไหนเลยสักเครื่อง

8 Make version 1.1

Go back to your React folder. Change one word in src/App.jsx — the title is fine. Then build, tag and push again, with a new number. 回到你的 React 文件夹,在 src/App.jsx 里改一个词, 改标题就行。然后用新号码重新构建、打标签、推送。 กลับไปที่โฟลเดอร์ React แก้คำเดียวใน src/App.jsx แก้หัวข้อก็ได้ จากนั้น build, tag และ push ใหม่ด้วยเลขใหม่

docker build -t my-site:1.1 . docker tag my-site:1.1 yourname/my-site:1.1 docker push yourname/my-site:1.1

9 Roll it out — and watch nothing break

kubectl set image deployment/my-site web=yourname/my-site:1.1 kubectl rollout status deployment/my-site # Waiting for deployment "my-site" rollout to finish: 2 of 4 updated... # deployment "my-site" successfully rolled out

Keep http://localhost:8080 open in another window while this runs. Press reload again and again. It never breaks. That is machine 4, happening for real. 运行的时候在另一个窗口开着 http://localhost:8080, 一遍遍按刷新——它从不出错。这就是第 4 台机器在现实里发生。 ระหว่างรัน ให้เปิด http://localhost:8080 ไว้อีกหน้าต่างหนึ่ง กดรีโหลดซ้ำ ๆ มันไม่พังเลย นั่นคือเครื่องที่ 4 ที่เกิดขึ้นจริง

# do not like it? go back. kubectl rollout undo deployment/my-site kubectl rollout history deployment/my-site

10 Clean up

kubectl delete -f service.yaml -f deployment.yaml

Everything goes. Your two files are still on your disk, so you can bring the whole thing back with one apply. The files are the truth, not the cluster. 全部清空。两个文件还在你硬盘上,一条 apply 就能把整套东西再变回来。 文件才是真相,集群不是。 ทุกอย่างหายไป แต่ไฟล์สองไฟล์ยังอยู่บนดิสก์ของคุณ สั่ง apply ครั้งเดียวก็เอาทั้งหมดกลับมาได้ ไฟล์คือความจริง ไม่ใช่คลัสเตอร์

🔧 Break it on purpose, then fix it

Summary

Things go wrong every day. This is normal, not shameful. Kubernetes tells you what is wrong, but it tells you in a quiet place, at the bottom of a long page. Learn six commands and you can find any problem. Then break your own cluster on purpose, so the first time you see the red words is a day you chose.

摘要

每天都会出问题,这很正常,不丢人。Kubernetes 会告诉你哪里错了,但它说得很小声,藏在一长页的底部。学会六条命令,你就能找出任何问题。然后故意把自己的集群弄坏,让你第一次看到红字的那天,是你自己挑的日子。

สรุป

เรื่องผิดพลาดเกิดขึ้นทุกวัน เป็นเรื่องปกติ ไม่ใช่เรื่องน่าอาย Kubernetes บอกคุณว่าอะไรผิด แต่มันบอกเบา ๆ ตรงท้ายหน้าที่ยาวมาก เรียนหกคำสั่งแล้วคุณจะหาปัญหาไหนก็เจอ จากนั้นตั้งใจทำคลัสเตอร์ของคุณเองให้พัง เพื่อให้วันแรกที่คุณเห็นตัวหนังสือสีแดง เป็นวันที่คุณเลือกเอง

The six commands, in the order you use them

# 1 — what is the state? kubectl get pods # 2 — WHY? the answer is in Events, at the very bottom kubectl describe pod my-site-7d4c9b8f6-2xk9p # 3 — what did my program say? kubectl logs my-site-7d4c9b8f6-2xk9p kubectl logs my-site-7d4c9b8f6-2xk9p --previous # what it said before it died # 4 — go inside and look with your own eyes kubectl exec -it my-site-7d4c9b8f6-2xk9p -- sh # 5 — the whole story of the cluster, oldest first kubectl get events --sort-by=.metadata.creationTimestamp # 6 — talk to ONE pod and skip the Service kubectl port-forward pod/my-site-7d4c9b8f6-2xk9p 9000:80
Command 2 is the one people forget. describe prints a long page and almost nobody reads it. Scroll to the bottom. The part called Events is Kubernetes telling you, in plain English, exactly what it tried and what happened. Read that first, always. 第二条是大家最常忘的。describe 会打印很长一页,几乎没人读完。 直接翻到最下面,那个叫 Events 的部分,就是 Kubernetes 用大白话告诉你它试了什么、 发生了什么。永远先读这一段。 คำสั่งที่ 2 คือคำสั่งที่คนลืมบ่อยที่สุด describe พิมพ์ออกมายาวมากจนแทบไม่มีใครอ่าน ให้เลื่อนไปล่างสุด ส่วนที่ชื่อ Events คือที่ Kubernetes บอกคุณตรง ๆ ว่ามันลองทำอะไรและเกิดอะไรขึ้น อ่านตรงนั้นก่อนเสมอ

Break it now — this is the exercise

1 Ask for a version that does not exist

kubectl set image deployment/my-site web=yourname/my-site:9.9 kubectl get pods

You will see ErrImagePull, then ImagePullBackOff. 你会看到 ErrImagePull,然后是 ImagePullBackOff คุณจะเห็น ErrImagePull แล้วตามด้วย ImagePullBackOff

2 Ask Kubernetes why

kubectl describe pod <the broken pod name> # Events: # Warning Failed kubelet Failed to pull image "yourname/my-site:9.9": # manifest for yourname/my-site:9.9 not found

It says it in plain words. There is no tag 9.9. 它说得清清楚楚:没有 9.9 这个标签。 มันบอกตรง ๆ เลยว่าไม่มีแท็ก 9.9

3 Notice the good news

Open http://localhost:8080. Your site still works. Kubernetes started the new broken pod, saw it was not ready, and refused to stop the old good pods. It protected you. That is a rolling update doing its job on a bad day. 打开 http://localhost:8080你的网站还好好的。 Kubernetes 起了新的坏 pod,发现它没就绪,就拒绝停掉旧的好 pod。它保护了你。 这就是滚动更新在糟糕的一天里干的活。 เปิด http://localhost:8080 ดู เว็บของคุณยังทำงานอยู่ Kubernetes สร้างพ็อดใหม่ที่พัง เห็นว่ามันยังไม่พร้อม จึงไม่ยอมหยุดพ็อดเก่าที่ยังดี มันปกป้องคุณไว้ นั่นคือ rolling update ที่ทำหน้าที่ของมันในวันที่แย่

4 Undo it

kubectl rollout undo deployment/my-site kubectl get pods

The five things you will see, and what they mean

You seeIt meansDo this
ImagePullBackOff
ErrImagePull
Kubernetes cannot get the image. Wrong name, wrong tag, or the image is private.
拿不到镜像:名字错、标签错,或者镜像是私有的。

ดึงอิมเมจไม่ได้ ชื่อผิด แท็กผิด หรืออิมเมจเป็นส่วนตัว
Check the spelling. Check the tag really exists on Docker Hub. Push it again.
检查拼写,去 Docker Hub 确认标签真的存在,再推一次。

ตรวจการสะกด ตรวจว่าแท็กมีจริงบน Docker Hub แล้ว push ใหม่
CrashLoopBackOff The image is fine. Your program starts and then dies, again and again.
镜像没问题,是你的程序起来就死,一次又一次。

อิมเมจไม่มีปัญหา แต่โปรแกรมของคุณเริ่มแล้วตาย ซ้ำแล้วซ้ำอีก
kubectl logs <pod> --previous. The answer is always in there.
kubectl logs <pod> --previous,答案永远在里面。

ใช้ kubectl logs <pod> --previous คำตอบอยู่ในนั้นเสมอ
Pending No node has enough room for it, or it is waiting for storage.
没有节点装得下它,或者在等存储。

ไม่มีโหนดไหนมีที่พอ หรือกำลังรอพื้นที่เก็บข้อมูล
kubectl describe pod and read Events. Ask for less CPU, or add a node.
kubectl describe pod 读 Events。少要点 CPU,或者加个节点。

kubectl describe pod แล้วอ่าน Events ขอ CPU น้อยลง หรือเพิ่มโหนด
0/1 but Running It is alive, but it says it is not ready for visitors yet.
它活着,但它说自己还没准备好接客。

มันมีชีวิตอยู่ แต่บอกว่ายังไม่พร้อมรับแขก
Check the readiness probe path and the port number. A wrong port looks exactly like this.
检查就绪探针的路径和端口号。端口写错了就正是这个样子。

ตรวจ path ของ readiness probe และเลขพอร์ต พอร์ตผิดจะออกมาแบบนี้เป๊ะ
The Service finds nothing
Service 什么也找不到

เซอร์วิสหาอะไรไม่เจอ
The selector and the pod labels are different words.
选择器和 pod 标签不是同一个词。

ซีเลกเตอร์กับเลเบลของพ็อดเป็นคนละคำ
kubectl get pods --selector app=my-site. Empty answer means you found it.
kubectl get pods --selector app=my-site,返回为空就是它。

kubectl get pods --selector app=my-site ถ้าได้ผลว่าง แปลว่าเจอต้นเหตุแล้ว

Probes — how a pod says "I am fine"

Kubernetes does not guess. It asks. Two questions, again and again. Kubernetes 不靠猜,它会问。两个问题,反复地问。 Kubernetes ไม่เดา มันถาม สองคำถาม ถามซ้ำไปเรื่อย ๆ

readinessProbe: # "may I send you visitors?" no → taken out of the Service httpGet: path: / port: 80 initialDelaySeconds: 3 livenessProbe: # "are you alive?" no → the pod is restarted httpGet: path: / port: 80 periodSeconds: 10
Get these two the right way round. Readiness only stops visitors coming. Liveness kills and restarts the pod. A liveness probe that is too strict will restart a healthy program all day and you will not understand why. 这两个千万别搞反:readiness 只是不让访客进来; liveness 会杀掉并重启 pod。liveness 探针设得太严,会整天重启一个健康的程序, 而你还想不明白为什么。 อย่าสลับสองตัวนี้ readiness แค่ห้ามผู้เยี่ยมชมเข้ามา ส่วน liveness ฆ่าและรีสตาร์ตพ็อด ถ้าตั้ง liveness probe เข้มเกินไป มันจะรีสตาร์ตโปรแกรมที่แข็งแรงดีทั้งวัน แล้วคุณจะงงว่าทำไม

🤔 When should you use it — and when should you not?

Summary

Kubernetes is very good at one thing: keeping many services alive on many computers without a person watching. It is bad at being small. It brings a lot of files, a lot of words, and a bill. Most small projects are happier with plain Docker. Learning it is still worth your time, because it is the language of the job.

摘要

Kubernetes 有一件事做得非常好:在很多台机器上让很多服务活着,而且不需要人盯着。它不擅长的是“小”。它带来一堆文件、一堆词,还有一张账单。大多数小项目用普通 Docker 会更舒服。但学它仍然值得,因为它是这一行的通用语言。

สรุป

Kubernetes เก่งมากอยู่เรื่องหนึ่ง คือทำให้หลายบริการอยู่รอดบนหลายเครื่องโดยไม่ต้องมีคนเฝ้า แต่มันไม่เก่งเรื่องการเป็นของเล็ก มันพาไฟล์เยอะ คำเยอะ และใบเรียกเก็บเงินมาด้วย โปรเจกต์เล็กส่วนใหญ่มีความสุขกว่ากับ Docker ธรรมดา แต่การเรียนมันก็ยังคุ้มเวลา เพราะมันคือภาษาของงานสายนี้

✅ Use it when

  • You have many services, not one. 你有很多个服务,不是一个。 คุณมีหลายบริการ ไม่ใช่แค่หนึ่ง
  • You have more than one computer, or you will soon. 你不止一台机器,或者很快就会有。 คุณมีมากกว่าหนึ่งเครื่อง หรือกำลังจะมี
  • It must not stop at night, and nobody wants to wake up. 它晚上不能停,而没人想被叫醒。 มันต้องไม่หยุดตอนกลางคืน และไม่มีใครอยากตื่นมาดู
  • Busy hours and quiet hours are very different. 忙时和闲时差别很大。 ชั่วโมงที่คนเยอะกับชั่วโมงที่เงียบต่างกันมาก
  • More than a few people change the same system. 好几个人一起改同一套系统。 มีคนหลายคนแก้ระบบเดียวกัน

🚫 Do not use it when

  • It is one small web site. Use Docker. 只是一个小网站——用 Docker。 เป็นเว็บเล็กเว็บเดียว ใช้ Docker
  • You are the only person, and it can rest at night. 只有你一个人,而且晚上可以休息。 มีคุณคนเดียว และมันพักตอนกลางคืนได้
  • You are learning the app itself. Learn one hard thing at a time. 你还在学这个应用本身——一次只学一件难事。 คุณกำลังเรียนตัวแอปเอง เรียนของยากทีละอย่าง
  • Nobody on the team has run it before. It is a second job. 团队里没人跑过它——那是一份额外的工作。 ไม่มีใครในทีมเคยรันมันมาก่อน มันคืองานอีกงานหนึ่ง
Honest advice. Learn it on your own computer, free, like today. Use it at work when a real problem asks for it — a night without sleep, a computer that died, a release that broke the site. Do not use it because it sounds clever. The best engineers choose the smallest tool that solves the problem. 老实的建议:像今天这样,在自己电脑上免费学。 工作里等真的遇到问题再用——一个没睡好的夜晚、一台死掉的机器、一次把网站搞坏的发布。 不要因为它听起来厉害就用它。最好的工程师会选能解决问题的最小工具。 คำแนะนำแบบตรงไปตรงมา เรียนบนเครื่องของคุณเองแบบฟรี เหมือนวันนี้ แล้วค่อยใช้ที่ทำงานตอนที่มีปัญหาจริงมาถาม เช่น คืนที่ไม่ได้นอน เครื่องที่ตายไป หรือการปล่อยเวอร์ชันที่ทำเว็บพัง อย่าใช้เพราะมันฟังดูเท่ วิศวกรที่เก่งที่สุดเลือกเครื่องมือที่เล็กที่สุดที่แก้ปัญหาได้

🚀 Where to go next

🐳 Back to the Docker Lab. The image, the ports, the layers and Tailscale. Everything on this page stands on that one.
回到 Docker 实验室:镜像、端口、层和 Tailscale。本页的一切都建在那上面。

กลับไปที่แล็บ Docker: อิมเมจ พอร์ต เลเยอร์ และ Tailscale ทุกอย่างในหน้านี้ตั้งอยู่บนหน้านั้น
Open ▸
📦 Write your own Dockerfile. Before Kubernetes can run your box, the box has to be good. One line at a time.
写你自己的 Dockerfile:Kubernetes 能跑你的盒子之前,盒子得先做好。一行一行来。

เขียน Dockerfile ของคุณเอง ก่อนที่ Kubernetes จะรันกล่องของคุณได้ กล่องต้องดีก่อน ไล่ทีละบรรทัด
Open ▸
🟨 The JavaScript Lab. The React page you are running here is JavaScript. Learn the words behind it: variable, function, event, array.
JavaScript 实验室:你在这里跑的 React 页面就是 JavaScript。 学学它背后的词:变量、函数、事件、数组。

แล็บ JavaScript: หน้า React ที่คุณรันอยู่นี่คือ JavaScript เรียนคำที่อยู่เบื้องหลัง: ตัวแปร ฟังก์ชัน อีเวนต์ อาร์เรย์
Open ▸

📌 Points to remember

  • You write a wish. A loop makes it true. That is the whole of Kubernetes. Every other word is a detail. 你写下愿望,一个循环让它成真——这就是 Kubernetes 的全部,别的词都是细节。 คุณเขียนความต้องการ แล้วลูปทำให้เป็นจริง นั่นคือ Kubernetes ทั้งหมด คำอื่นเป็นแค่รายละเอียด
  • Nothing points at a pod. Everything asks a question. Labels and selectors. 没有东西指向 pod,一切都在提问——靠标签和选择器。 ไม่มีอะไรชี้ไปที่พ็อด ทุกอย่างใช้การถาม ด้วยเลเบลและซีเลกเตอร์
  • Pods die. That is the plan, not the problem. Never write a pod name or a pod address anywhere. pod 会死,这是设计好的,不是故障——永远不要把 pod 的名字或地址写在任何地方。 พ็อดตายได้ นั่นคือแผน ไม่ใช่ปัญหา อย่าเขียนชื่อพ็อดหรือที่อยู่พ็อดไว้ที่ไหนเลย
  • A Service is the address that stays. Pods come and go behind it. Service 是那个不变的地址,pod 在它后面来来去去。 เซอร์วิสคือที่อยู่ที่อยู่คงที่ พ็อดมาแล้วก็ไปอยู่ข้างหลังมัน
  • Two spaces, never a tab. This one line will save you an hour. 两个空格,绝不用 Tab——这一句能帮你省下一小时。 เว้นสองช่อง ห้ามใช้แท็บ บรรทัดนี้ประโยคเดียวช่วยคุณประหยัดไปหนึ่งชั่วโมง
  • Read Events at the bottom of describe. The answer is nearly always already there, in plain English. describe 最底下的 Events——答案几乎总是已经在那里,写得清清楚楚。 อ่าน Events ที่ท้ายผลลัพธ์ของ describe คำตอบเกือบจะอยู่ตรงนั้นแล้วเสมอ และเขียนไว้ชัดเจน
  • The files are the truth, not the cluster. Keep your YAML. You can rebuild everything from it. 文件才是真相,集群不是——留好你的 YAML,靠它就能把一切重建出来。 ไฟล์คือความจริง ไม่ใช่คลัสเตอร์ เก็บ YAML ไว้ให้ดี คุณสร้างทุกอย่างขึ้นมาใหม่จากมันได้
  • Small problem, small tool. One web site does not need a cluster. 小问题用小工具——一个网站不需要一个集群。 ปัญหาเล็กใช้เครื่องมือเล็ก เว็บเดียวไม่ต้องใช้คลัสเตอร์

Thank you for learning with us today. Turn your cluster off, and sleep well — the loop would have kept going without you anyway. See you in the next lab. 感谢今天和我们一起学习。把集群关掉,好好睡一觉——反正就算没有你,那个循环也会继续转下去。下个实验室见。 ขอบคุณที่เรียนกับเราวันนี้ ปิดคลัสเตอร์แล้วนอนหลับให้สบาย ถึงไม่มีคุณ ลูปนั้นก็คงหมุนต่อไปอยู่ดี แล้วเจอกันในแล็บหน้า