Installation

Prerequisite

Cert Manager

Meshless depends on cert-manager ↗ to issue certificates.

You’ve probably been using cert-manager. If so, you can skip this section.

cert-manager is a powerful and extensible X.509 certificate controller for Kubernetes and OpenShift workloads. It will obtain certificates from a variety of Issuers, both popular public Issuers as well as private Issuers, and ensure the certificates are valid and up-to-date, and will attempt to renew certificates at a configured time before expiry.

  1. Install cert-manager ↗
  2. Config Issuer ↗

Trust Manager

Meshless depends on trust-manager ↗ for trusted CAs for validating certificates during TLS handshakes.

You’ve probably been using trust-manager. If so, you can skip this section.

trust-manager is designed to complement cert-manager and works well when consuming CA certificates from a cert-manager Issuer or ClusterIssuer.

  1. Install trust-manager ↗
  2. Config Bundle ↗

Installation/Upgrade

Download a Release

In every release, there’re several docker images and one helm chart.

e.g.

Meshless v1.0.0:
meshless-1.0.0-amd64.tar # docker image of arch amd64
meshless-1.0.0-arm64.tar # docker image of arch arm64
meshless-1.0.0.tgz # helm chart

Upload Docker Image

Choose a docker images which matches your arch, and upload the docker image to your image registry server.

If none image matches your arch, please contact us, we’ll build a docker image for that arch and add it to the release.

Install for the First Time

helm install meshless <path-to-helm-chart> --set namespace=<namespace>,image=<path-to-docker-image>,cert.issuer.name=<issuer>,cert.issuer.kind=<issuer-kind>,trustedCAs.name=<trusted-cas-name>,trustedCAs.key=<trusted-cas-key>,licenseSubject=<license-subject> --set-file license=<path-to-license>

e.g.

helm install meshless meshless-1.0.0.tgz --set namespace=default,image=registry-address/meshless:1.0.0-amd64,cert.issuer.name=issuer,cert.issuer.kind=ClusterIssuer,trustedCAs.name=trusted-cas,trustedCAs.key=cas,licenseSubject=your-company --set-file license=your-company.meshless.license

Upgrade

Meshless is backward compatible, so you can seamlessly upgrade to a new version.

# mostly the same as installation, except the subcommand install is replaced with upgrade
helm upgrade meshless <path-to-helm-chart> ...

e.g.

helm upgrade meshless meshless-1.1.0.tgz ...

Because helm upgrade doesn’t update CRDs, please execute the following to update CRDs.

tar -zxvf <path-to-helm-chart> -C /tmp meshless/crds
kubectl apply -f /tmp/meshless/crds
rm -rf /tmp/meshless

Complete List of Options

As follows is the complete list of options of installation and upgrade.

RequiredOptionDefault ValueMeaning
namespacedefaultThe namespace where to install/upgrade Meshless
imagePath to docker image of Meshless
tzUTCLocal time zone in containers of Meshless
lease15sLease duration, used in leader election
agentPortHost1058Host port of Meshless Node Agent
maxConnMax number of concurrent connections to Meshless Node Agent. Default to no limit.
idleTimeout1mIdle timeout. If no data is sent from a connection in the specified duration, close the connection.
handshakeTimeout10sHandshake timeout. If handshake does not finish in the specified duration, close the connection.
dialTimeout3sConnection timeout. See also Go DialTimeout ↗ .
tlsHandshakeTimeout10sTLS handshake timeout. If TLS handshake does not finish in the specified duration, close the connection.
udsBaseDirHost/var/tmp/meshlessMeshless UDS base directory on Host
cert.durationDuration (i.e. lifetime) of Certificate. Default to 90 days as per cert-manager doc.
cert.renewBeforeHow long before expiry a certificate should be renewed. Default to 1⁄3 of cert.duration as per cert-manager doc.
cert.issuer.kindKind of cert-manager issuer. Valid values are ClusterIssuer, Issuer.
cert.issuer.nameName of cert-manager issuer.
trustedCAs.kindConfigMapKind of trust-manager Bundle target. Valid values are ConfigMap, Secret.
trustedCAs.nameName of trust-manager Bundle target
trustedCAs.keyKey of trust-manager Bundle target
resource.mem.requestMemory request of a container of Meshless Node Agent
resource.mem.limitMemory limit of a container of Meshless Node Agent
resource.cpu.requestCPU request of a container of Meshless Node Agent
resource.cpu.limitCPU limit of a container of Meshless Node Agent
resourceMgt.mem.requestMemory request of a container of Meshless Mgt
resourceMgt.mem.limitMemory limit of a container of Meshless Mgt
resourceMgt.cpu.requestCPU request of a container of Meshless Mgt
resourceMgt.cpu.limitCPU limit of a container of Meshless Mgt
licenseSubjectLicense subject, usually the name of your company
licensePath to license. License subject and license file will be sent to you once you purchase a commercial license.
log.fileSize10Max size in MB of a log file. If a file exceeds this size, the file will be rotated.
log.baks2Max number of old log files. Older files will be removed.

Log Aggregation

You’ve probably been using a log aggregation system for gathering, querying and displaying logs.
If not, try Loki ↗ .