使用 GKE 附加叢集,即可在 Google Cloud 控制台查看現有的 Kubernetes 叢集和 GKE 叢集,並在這些叢集上啟用多項 GKE 功能,包括透過 Config Sync 集中控管設定。
支援的 Kubernetes 叢集
您可以將任何含有 x86 節點且符合標準的 Kubernetes 叢集附加至機群,以便在 Google Cloud 控制台中查看 (GKE 叢集也會顯示於此)。
Google 已驗證下列叢集類型和版本。如要瞭解附加叢集支援的 GKE 功能,請參閱「GKE 版本和升級支援」。
| 附加叢集類型 | Kubernetes 版本 |
|---|---|
| Red Hat OpenShift Kubernetes Engine (OKE) 4.9、4.10 | 1.23、1.24 |
| Red Hat OpenShift Container Platform (OCP) 4.9、4.10 | 1.23、1.24 |
| Rancher Kubernetes Engine (RKE) 1.3.8 | 1.23、1.24 |
| KIND 0.12 | 1.23、1.24 |
| K3s 1.20 | 1.20 |
| K3d 4.4.3 | 1.20 |
事前準備
- 登入 Google Cloud 帳戶。如果您是 Google Cloud新手,歡迎 建立帳戶,親自體驗產品的實際應用成效。新客戶還能獲得價值 $300 美元的免費抵免額,能用於執行、測試及部署工作負載。
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Anthos API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Anthos API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init - 請查看機群註冊必要條件,確保您具備相關權限並已啟用 API,可以註冊叢集。
- 如要瞭解在 Google Cloud外部附加叢集的具體需求,包括叢集類型可能需要的特殊設定步驟,請參閱「事前準備」指南。
註冊附加的叢集
您必須將要與 GKE 功能搭配使用的所有叢集,註冊到專案的機群。機群能有條理地將 Kubernetes 叢集邏輯群組並正規化,讓基礎架構管理作業更輕鬆。您可以在Google Cloud 控制台中,一併瀏覽及管理同一機群中的叢集,而且許多 GKE 和 Google Cloud 元件都採用身分相同性和命名空間相同性等機群概念,可簡化多叢集作業。如要進一步瞭解機群及其功能,請參閱我們的機群管理指南。
您有權在這些叢集上啟用及使用 GKE 功能,並可從 GKE 功能頁面,在機群層級管理部分 GKE 功能。
設定身分
所有附加的叢集都需要身分,供 Connect 代理程式向 Google 進行驗證。如果叢集符合需求條件,您可以在註冊叢集時啟用機群 Workload Identity 進行驗證。啟用這項功能的叢集會使用機群工作負載身分集區中的身分。如要進一步瞭解機群 Workload Identity 的運作方式和使用優勢,請參閱「使用機群 Workload Identity」。
如果無法使用機群 Workload Identity,註冊連結的叢集時,需要使用 Google Cloud 服務帳戶進行驗證。建議您為要連結的每個叢集建立新的服務帳戶。如要為叢集建立具有適當角色的服務帳戶,請按照「建立具有 gcloud 的服務帳戶 Google Cloud 」一文中的指示操作。建立服務帳戶後,您可以使用含有服務帳戶憑證的 JSON 檔案 (金鑰檔案) 註冊叢集,詳情請參閱下一節。
註冊叢集
建議您在註冊叢集後取得叢集的成員資格狀態,確保叢集已正確連線至 Google Cloud。如果註冊時遇到任何問題,請參閱疑難排解指南。
gcloud
執行下列指令:
gcloud container fleet memberships register MEMBERSHIP_NAME \ --context=KUBECONFIG_CONTEXT \ --kubeconfig=KUBECONFIG_PATH \ --service-account-key-file=SERVICE_ACCOUNT_KEY_PATH
更改下列內容:
- MEMBERSHIP_NAME:您選擇的成員資格名稱,用於唯一代表註冊至機群的叢集。
- SERVICE_ACCOUNT_KEY_PATH:服務帳戶私密金鑰 JSON 檔案的本機檔案路徑,該檔案是在「事前準備」步驟中下載。這個服務帳戶金鑰會以
gke-connect命名空間中名為creds-gcp的密鑰形式儲存。 - KUBECONFIG_CONTEXT:要註冊的叢集結構定義,與 kubeconfig 檔案中顯示的相同。您可以在指令列執行
kubectl config current-context,取得這個值。 - KUBECONFIG_PATH:kubeconfig 檔案儲存位置的本機路徑,其中包含要註冊的叢集項目。如果已設定該環境變數,則預設值為
$KUBECONFIG;否則預設值為$HOME/.kube/config。
註冊採用機群 Workload Identity 的連結叢集
如要註冊已啟用機群 Workload Identity 的附加叢集,請執行下列指令。如要進一步瞭解哪些附加叢集類型可以使用這項功能,以及任何其他需求條件,請參閱「附加叢集必要條件」。
gcloud container fleet memberships register MEMBERSHIP_NAME \ --context=KUBECONFIG_CONTEXT \ --kubeconfig=KUBECONFIG_PATH \ --enable-workload-identity \ --has-private-issuer
控制台
產生註冊指令
您可以使用 Google Cloud 控制台產生gcloud註冊指令,藉此註冊叢集 (僅限服務帳戶)。
如要註冊叢集,請按照下列步驟操作:
在 Google Cloud 控制台中,前往「Google Kubernetes Engine clusters overview」(Google Kubernetes Engine 叢集總覽) 頁面。
按一下「註冊現有叢集」。
按一下「Add external cluster」(新增外部叢集)。
在「Cluster name」(叢集名稱) 欄位中,輸入要註冊的叢集名稱。
選用:為叢集新增 Google Cloud 標籤。
按一下「Generate registration command」(產生註冊指令)。
在 Cloud Shell 或儲存服務帳戶憑證的位置,編輯並執行頁面顯示的
gcloud指令。請指定下列值:- CLUSTER_CONTEXT 是叢集的結構定義,與 kubeconfig 檔案中顯示的相同。您可以在指令列中執行
kubectl config current-context,取得這個值。 - KUBECONFIG_PATH 是 kubeconfig 檔案儲存位置的本機路徑。如果已設定該環境變數,則預設值為
$KUBECONFIG;否則預設值為$HOME/.kube/config。 - LOCAL_KEY_PATH 是服務帳戶金鑰檔案的路徑。
執行這個指令後,系統會在使用者叢集中部署 Connect 代理程式。Connect Agent 連線至叢集並完成註冊後,頁面會顯示成功訊息。 Google Cloud
- CLUSTER_CONTEXT 是叢集的結構定義,與 kubeconfig 檔案中顯示的相同。您可以在指令列中執行
按一下「設定標籤」,如果沒有設定任何標籤,請按一下「略過」。
進階註冊選項 (僅限指令列)
下載 Connect Agent 資訊清單
如要下載 Connect 代理程式安裝資訊清單,但不想部署代理程式 (例如想在安裝前檢查或編輯資訊清單),請將 --manifest-output-file 標記傳遞至 gcloud container fleet memberships register 指令。例如:
--manifest-output-file=[MANIFEST_FILE_PATH]
其中 [MANIFEST_FILE_PATH] 是要儲存 Connect Agent 安裝資訊清單的本機檔案路徑。
使用這個選項不會將 Connect 代理程式部署到叢集。如要部署 Connect 代理程式,請手動將下載的資訊清單套用至叢集。
使用 Proxy 伺服器
如要設定 Proxy 伺服器,請將 --proxy 旗標傳遞至 gcloud container fleet memberships register 指令。例如:
--proxy=[URL]
其中 [URL] 是 Proxy 位址。
Connect Agent 僅支援以 CONNECT 為基礎的 HTTP 和 HTTPS Proxy,並接受 IP 位址和主機名稱。請務必在網址中指定與 Proxy 類型相應的通訊協定。例如,如要傳入 HTTPS 主機名稱:
--proxy=https://mycorpproxy.com:443
除非您另行指定,否則 Connect Agent 會將通訊埠 3128 用於 Proxy。
如果您的 proxy 需要授權,請務必傳遞您的憑證,例如:
--proxy=http://user:password@10.10.10.10:8888
在含有 Windows 和 Linux 節點的叢集中安裝 Connect Agent
Connect 代理程式必須在 Linux 節點上執行。如果您是在同時包含 Linux 和 Windows 節點的混合叢集中安裝,可以在部署定義中新增適當的節點選取器,確保 Connect 代理程式部署至 Linux 節點。
執行下列指令,使用適當的節點選取器更新 Deployment:
kubectl patch deployment \
$(kubectl get deployment -o=jsonpath='{.items[*].metadata.name}' -n gke-connect) \
-p '{"spec":{"template":{"spec":{"nodeSelector":{"kubernetes.io/os":"linux"}}}}}' -n gke-connect
如要驗證更新是否成功,請執行下列指令:
kubectl get deployment -o=jsonpath='{.items[].spec.template.spec.nodeSelector}' -n gke-connect指令應會傳回:
{"kubernetes.io/os":"linux"}疑難排解
如果在設定期間遇到任何問題,請參閱車隊建立疑難排解指南。
在附加叢集上啟用 GKE 功能
註冊叢集後,即可在叢集上為應用程式啟用可用的 GKE 功能。這些功能僅適用於經過驗證的叢集類型。如要查看這些類型目前支援的功能版本,請參閱「版本和升級支援」。
下列指南說明如何在叢集上啟用支援的功能:
Cloud Service Mesh 1.11 以上版本支援 Amazon EKS:
設定與政策管理:
存取附加叢集
註冊連結的叢集後,該叢集會顯示在 Google Cloud console的 GKE 叢集頁面中。不過,如要查看節點和工作負載等更多詳細資料,您需要登入叢集並完成驗證。如要從 Google Cloud 控制台登入附加叢集,請按照「從 Google Cloud 控制台登入叢集」一文中的操作說明進行。請注意,視您選擇的驗證方式而定,您或平台管理員可能需要進行一些額外設定,您或其他使用者才能登入叢集。
如要使用 Google Cloud 身分透過指令列存取連結的叢集,請參閱「透過 Connect 閘道連線至已註冊的叢集」。
如要使用現有的第三方識別資訊提供者 (僅限 AWS 叢集上的 EKS,預先發布版功能) 向附加叢集進行驗證,請參閱「為機群設定 GKE 身分認證服務」和「使用 GKE 身分認證服務存取叢集」。