GKE Cluster Prerequisites
Before adding a GKE cluster to Portworx Backup, ensure that the following prerequisites are met:
-
Stork is installed on all application clusters.
-
In GCP console, create a GCP role with the following permissions:
compute.disks.addResourcePoliciescompute.disks.createcompute.disks.createSnapshotcompute.disks.deletecompute.disks.getcompute.disks.getIamPolicycompute.disks.listcompute.disks.removeResourcePoliciescompute.disks.resizecompute.disks.setIamPolicycompute.disks.setLabelscompute.disks.updatecompute.disks.usecompute.disks.useReadOnlycompute.snapshots.createcompute.snapshots.deletecompute.snapshots.getcompute.snapshots.getIamPolicycompute.snapshots.listcompute.snapshots.setIamPolicycompute.snapshots.setLabelscompute.snapshots.useReadOnlycontainer.apiServices.getcontainer.apiServices.getStatuscontainer.apiServices.listcontainer.auditSinks.getcontainer.auditSinks.listcontainer.backendConfigs.getcontainer.backendConfigs.listcontainer.bindings.getcontainer.bindings.listcontainer.certificateSigningRequests.getcontainer.certificateSigningRequests.listcontainer.clusterRoleBindings.getcontainer.clusterRoleBindings.listcontainer.clusterRoles.getcontainer.clusterRoles.listcontainer.clusters.getcontainer.clusters.listcontainer.componentStatuses.getcontainer.componentStatuses.listcontainer.configMaps.getcontainer.configMaps.listcontainer.controllerRevisions.getcontainer.controllerRevisions.listcontainer.cronJobs.getcontainer.cronJobs.getStatuscontainer.cronJobs.listcontainer.csiDrivers.getcontainer.csiDrivers.listcontainer.csiNodeInfos.getcontainer.csiNodeInfos.listcontainer.csiNodes.getcontainer.csiNodes.listcontainer.customResourceDefinitions.getcontainer.customResourceDefinitions.getStatuscontainer.customResourceDefinitions.listcontainer.daemonSets.getcontainer.daemonSets.getStatuscontainer.daemonSets.listcontainer.deployments.getcontainer.deployments.getScalecontainer.deployments.getStatuscontainer.deployments.listcontainer.endpointSlices.getcontainer.endpointSlices.listcontainer.endpoints.getcontainer.endpoints.listcontainer.events.getcontainer.events.listcontainer.frontendConfigs.getcontainer.frontendConfigs.listcontainer.horizontalPodAutoscalers.getcontainer.horizontalPodAutoscalers.getStatuscontainer.horizontalPodAutoscalers.listcontainer.ingresses.getcontainer.ingresses.getStatuscontainer.ingresses.listcontainer.initializerConfigurations.getcontainer.initializerConfigurations.listcontainer.jobs.getcontainer.jobs.getStatuscontainer.jobs.listcontainer.leases.getcontainer.leases.listcontainer.limitRanges.getcontainer.limitRanges.listcontainer.localSubjectAccessReviews.listcontainer.managedCertificates.getcontainer.managedCertificates.listcontainer.mutatingWebhookConfigurations.getcontainer.mutatingWebhookConfigurations.listcontainer.namespaces.createcontainer.namespaces.getcontainer.namespaces.getStatuscontainer.namespaces.listcontainer.namespaces.updatecontainer.namespaces.updateStatuscontainer.networkPolicies.getcontainer.networkPolicies.listcontainer.nodes.getcontainer.nodes.getStatuscontainer.nodes.listcontainer.operations.listcontainer.persistentVolumeClaims.getcontainer.persistentVolumeClaims.getStatuscontainer.persistentVolumeClaims.listcontainer.persistentVolumes.getcontainer.persistentVolumes.getStatuscontainer.persistentVolumes.listcontainer.petSets.getcontainer.petSets.listcontainer.podDisruptionBudgets.createcontainer.podDisruptionBudgets.deletecontainer.podDisruptionBudgets.getcontainer.podDisruptionBudgets.getStatuscontainer.podDisruptionBudgets.listcontainer.podDisruptionBudgets.updatecontainer.podDisruptionBudgets.updateStatuscontainer.podPresets.getcontainer.podPresets.listcontainer.podSecurityPolicies.getcontainer.podSecurityPolicies.listcontainer.podTemplates.getcontainer.podTemplates.listcontainer.pods.getcontainer.pods.getLogscontainer.pods.getStatuscontainer.pods.listcontainer.priorityClasses.getcontainer.priorityClasses.listcontainer.replicaSets.getcontainer.replicaSets.getScalecontainer.replicaSets.getStatuscontainer.replicaSets.listcontainer.replicationControllers.getcontainer.replicationControllers.getScalecontainer.replicationControllers.getStatuscontainer.replicationControllers.listcontainer.resourceQuotas.getcontainer.resourceQuotas.getStatuscontainer.resourceQuotas.listcontainer.roleBindings.getcontainer.roleBindings.listcontainer.roles.getcontainer.roles.listcontainer.runtimeClasses.getcontainer.runtimeClasses.listcontainer.scheduledJobs.getcontainer.scheduledJobs.listcontainer.secrets.getcontainer.secrets.listcontainer.selfSubjectAccessReviews.listcontainer.serviceAccounts.getcontainer.serviceAccounts.listcontainer.services.getcontainer.services.getStatuscontainer.services.listcontainer.statefulSets.getcontainer.statefulSets.getScalecontainer.statefulSets.getStatuscontainer.statefulSets.listcontainer.storageClasses.getcontainer.storageClasses.listcontainer.storageStates.getcontainer.storageStates.getStatuscontainer.storageStates.listcontainer.storageVersionMigrations.getcontainer.storageVersionMigrations.getStatuscontainer.storageVersionMigrations.listcontainer.subjectAccessReviews.listcontainer.thirdPartyObjects.createcontainer.thirdPartyObjects.deletecontainer.thirdPartyObjects.getcontainer.thirdPartyObjects.listcontainer.thirdPartyObjects.updatecontainer.thirdPartyResources.getcontainer.thirdPartyResources.listcontainer.updateInfos.getcontainer.updateInfos.listcontainer.validatingWebhookConfigurations.getcontainer.validatingWebhookConfigurations.listcontainer.volumeAttachments.getcontainer.volumeAttachments.getStatuscontainer.volumeAttachments.listcontainer.volumeSnapshotClasses.getcontainer.volumeSnapshotClasses.listcontainer.volumeSnapshotContents.getcontainer.volumeSnapshotContents.getStatuscontainer.volumeSnapshotContents.listcontainer.volumeSnapshots.getcontainer.volumeSnapshots.getStatuscontainer.volumeSnapshots.listcontaineranalysis.notes.listcontaineranalysis.notes.listOccurrencescontaineranalysis.occurrences.listresourcemanager.projects.getstorage.buckets.createstorage.buckets.deletestorage.buckets.getstorage.buckets.getIamPolicystorage.buckets.liststorage.buckets.setIamPolicystorage.buckets.updatestorage.hmacKeys.createstorage.hmacKeys.deletestorage.hmacKeys.getstorage.hmacKeys.liststorage.hmacKeys.updatestorage.multipartUploads.createstorage.multipartUploads.liststorage.multipartUploads.listPartsstorage.objects.createstorage.objects.deletestorage.objects.getstorage.objects.getIamPolicystorage.objects.liststorage.objects.setIamPolicyAssociate this new GCP role to a service account used on the cluster where you want to install Portworx Backup. Save the JSON key for this service account for future reference. Also, select this service account in the node security settings while deploying the cluster where you want to install Portworx Backup.
-
Generate Kubeconfig for GKE clusters
-
Google cloud account is added in Portworx Backup
Generate kubeconfig for GKE clusters
To add a GKE cluster in Portworx Backup, you need kubeconfig details. You can fetch kubeconfig details either through Cloud Shell or gcloud CLI.
GKE 1.26 and later: Google removed the built-in gcp auth-provider from kubectl in Kubernetes 1.26. You must install the gke-gcloud-auth-plugin binary before running kubectl commands against GKE 1.26+ clusters. Install it with:
gcloud components install gke-gcloud-auth-plugin
After installation, set the environment variable USE_GKE_GCLOUD_AUTH_PLUGIN=True (or remove the False export below) and re-run gcloud container clusters get-credentials to regenerate the kubeconfig using the new exec-based auth method. For more information, see Install the gke-gcloud-auth-plugin.
The kubeconfig generated with the exec-based plugin uses an exec: stanza instead of auth-provider:. The sample output shown below is from the legacy auth-provider method (GKE < 1.26). On GKE 1.26 and later, the user section will show exec: with command: gke-gcloud-auth-plugin instead.
Kubeconfig with Cloud Shell
Run the following commands in Cloud Shell to get kubeconfig data:
-
(GKE versions below 1.26 only) Disable the new binary plugin for authentication:
export USE_GKE_GCLOUD_AUTH_PLUGIN=FalseFor more information, see kubectl authentication in GKE.
-
Connect to your GKE cluster:
gcloud container clusters get-credentials <GKE-clustername> --zone <zone-name> --project <project-name> -
Get the kubeconfig for your GKE cluster:
kubectl config view –-flatten –-minifyThese steps fetch the required kubeconfig information. In the kubeconfig details, ensure the user section holds data related to
auth-providerand not that ofexec.A sample output (fragment from kubeconfig details) from users section with auth-provider related data:
users:- name: <GKE-cluster-name>user:auth-provider:config:access-token: <access-token>cmd-args: config config-helper --format=jsoncmd-path: /root/gcloud/google-cloud-sdk/bin/gcloudexpiry: "2023-03-28T13:05:32Z"expiry-key: '{.credential.token_expiry}'token-key: '{.credential.access_token}'name: gcp
Kubeconfig with gcloud CLI
-
Install the gcloud CLI. See installation instructions for more details.
-
Initialize gcloud CLI:
gcloud init -
Run the commands listed in step 1, 2, and 3 in Kubeconfig with Cloud Shell topic on your gcloud CLI to obtain kubeconfig details.
Related topic: