rahulmotghare/demo-microservice

GitHub: rahulmotghare/demo-microservice

该项目展示了基于 AWS 的生产级云原生平台工程实践,涵盖基础设施即代码、GitOps 部署与全链路可观测性。

Stars: 1 | Forks: 0

# ☁️ 基于 AWS 的云原生平台工程 ## 📖 项目概述 现代平台工程侧重于构建和维护内部平台,使开发人员能够快速、可靠且安全地交付软件。 本项目展示了一个受生产环境启发的云原生平台,该平台构建于 AWS 之上,使用了 Infrastructure as Code、GitOps、Kubernetes 和现代可观测性工具。 该平台使用 Terraform 配置基础设施,通过 ArgoCD 和 Helm 将容器化应用程序部署到 Amazon EKS,将容器镜像存储在 Amazon ECR 中,并使用 Prometheus、Grafana 和 Loki 提供集中的监控和日志记录。 目标是展示端到端的平台工程实践,包括可重复的基础设施配置、声明式应用程序交付,以及跨 Kubernetes 环境的运营可见性。 # 🏗 架构 ![平台架构](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/architecture/platform-architecture.png) # ⭐ 核心亮点 - 使用 Terraform 配置 AWS 基础设施 - 构建受生产环境启发的 Amazon EKS Kubernetes 平台 - 使用 ArgoCD 实现 GitOps 部署工作流 - 使用 Helm 打包和部署应用程序 - 使用 Docker 对 Spring Boot 微服务进行容器化 - 将容器镜像存储在 Amazon ECR 中 - 使用 Prometheus 实现集中式指标收集 - 构建 Grafana 仪表板以实现平台可观测性 - 使用 Loki 集中管理 Kubernetes 日志 - 设计可重复的云原生部署工作流 # 🛠 技术栈 | 类别 | 技术 | |-----------|------------| | 云平台 | AWS | | Infrastructure as Code | Terraform | | 容器化 | Docker | | 容器镜像仓库 | Amazon ECR | | 容器编排 | Amazon EKS (Kubernetes) | | GitOps | ArgoCD | | 包管理 | Helm | | 监控 | Prometheus | | 可视化 | Grafana | | 日志记录 | Loki | | 后端 | Spring Boot | | 编程语言 | Java 21 | | 构建工具 | Maven | # 🚀 平台工作流 ``` Developer │ ▼ Spring Boot Application │ ▼ Docker Build │ ▼ Amazon ECR │ ▼ Update GitOps Repository │ ▼ ArgoCD │ ▼ Helm │ ▼ Amazon EKS │ ▼ Running Application ├────────► Prometheus (Metrics) ├────────► Loki (Logs) ▼ Grafana (Dashboards) ``` # 📂 仓库结构 ``` . ├── docs/ │ ├── architecture/ │ └── screenshots/ ├── src/ ├── Dockerfile ├── pom.xml ├── README.md └── ... ``` # ⚙️ 功能特性 ### 基础设施 - 使用 Terraform 进行基础设施配置 - Amazon VPC 网络 - Amazon EKS 集群部署 - 托管式 Kubernetes 工作节点 - Terraform 远程状态管理 ### GitOps - 声明式 Kubernetes 部署 - 使用 ArgoCD 进行持续同步 - 基于 Helm 的应用程序发布 ### 应用平台 - Docker 化的 Spring Boot 微服务 - 使用 Amazon ECR 进行容器镜像管理 - Kubernetes 原生部署 ### 可观测性 - 使用 Prometheus 收集指标 - 使用 Grafana 进行仪表板可视化 - 使用 Loki 进行集中式日志记录 # 📸 截图 ## 架构 ![架构](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/architecture/platform-architecture.png) ## ArgoCD ![ArgoCD](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/screenshots/argocd.png) ## Grafana 仪表板 ![Grafana](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/screenshots/grafana-dashboard.png) ## Prometheus 目标 ![Prometheus](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/screenshots/prometheus-targets.png) ## Loki 日志 ![Loki](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/screenshots/loki-explore.png) ## Amazon EKS 集群 ![Amazon EKS](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/screenshots/eks-cluster.png) ## Amazon ECR 仓库 ![Amazon ECR](https://raw.githubusercontent.com/rahulmotghare/demo-microservice/main/docs/screenshots/ecr-repository.png) # 🧠 挑战与经验教训 构建该平台涉及解决几个真实的平台工程挑战,包括: - 为 Amazon EBS CSI Driver 配置 IAM 权限 - 排查 Kubernetes Persistent Volume 配置问题 - 解决 ArgoCD 同步问题 - 修复 Apple Silicon 与 Amazon EKS 之间的 Docker 镜像架构不兼容问题 - 管理 GitOps 部署的 Helm chart 配置 - 将 Prometheus、Grafana 和 Loki 集成到 Kubernetes 平台中 - 理解 Kubernetes 网络和服务发现 - 调试云原生基础设施部署 这些挑战为处理受生产环境启发的云基础设施、Kubernetes 运营以及现代平台工程工作流提供了实践经验。 # 🎯 展现的技能 - 平台工程 - DevOps - 云基础设施 - Amazon Web Services (AWS) - Kubernetes - Amazon EKS - Infrastructure as Code (IaC) - Terraform - GitOps - ArgoCD - Helm - Docker - Amazon ECR - 监控与可观测性 - Prometheus - Grafana - Loki - Spring Boot - Java - Linux - IAM - Kubernetes 网络 - 故障排查 # 🛣 路线图 ## ✅ 已完成 - 使用 Terraform 配置基础设施 - Amazon EKS Kubernetes 集群 - Docker 化的 Spring Boot 应用程序 - Amazon ECR 集成 - 基于 Helm 的应用程序部署 - 使用 ArgoCD 的 GitOps 工作流 - Prometheus 监控 - Grafana 仪表板 - Loki 集中式日志记录 ## 🚧 计划增强功能 - GitHub Actions CI/CD pipeline - 自动化镜像部署 - 容器镜像安全扫描 - Kubernetes 策略执行 - 多环境部署(Dev / Stage / Prod) - 密钥管理 - Ingress Controller - Horizontal Pod Autoscaler (HPA) - AI 辅助的运营工作流 # 📚 未来学习目标 本项目将继续演进,增加更多生产级功能,包括自动化 CI/CD、平台安全、Kubernetes 策略管理以及多环境部署策略。 # 👨‍💻 作者 **Rahul Motghare** 平台工程师 • DevOps 工程师 • 云基础设施 - GitHub: https://github.com/rahulmotghare - LinkedIn: https://www.linkedin.com/in/motghare/ ## ⭐ 支持 如果您觉得这个项目有趣,欢迎探索本仓库、查看架构或在 LinkedIn 上与我联系。
标签:API集成, GitOps, Spring Boot, 亚马逊 EKS, 可观测性, 域名枚举, 子域名突变, 平台工程, 漏洞利用检测, 自定义请求头, 请求拦截