Production GKE Platform — From Zero to Production›Part 2 · Cheat sheet & self-check

Part 2 — Build the platform · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

03 · Organisation, projects & Shared VPC

Shared VPC

gcloud compute shared-vpc enable net-host-prodMake a project a Shared VPC host
gcloud compute shared-vpc associated-projects add gke-prod --host-project net-host-prodAttach a service project to the host
gcloud compute networks create prod-vpc --subnet-mode custom --project net-host-prodA custom-mode VPC (no automatic subnets)
gcloud compute networks subnets create gke-prod-ew1 --network prod-vpc --region europe-west1 --range 10.10.0.0/22 --secondary-range pods=10.20.0.0/16,services=10.30.0.0/20 --enable-private-ip-google-accessSubnet with Pod and Service secondary ranges, Private Google Access on

Egress

gcloud compute routers create nat-router --network prod-vpc --region europe-west1Cloud Router for Cloud NAT
gcloud compute routers nats create nat-ew1 --router nat-router --region europe-west1 --auto-allocate-nat-external-ips --nat-all-subnet-ip-rangesCloud NAT for every range in the region (nodes and Pods)
gcloud compute firewall-rules list --filter='network:prod-vpc'Firewall rules on the VPC, including the ones GKE created

04 · VPC-native networking & IP planning

Plan and check

gcloud container clusters describe prod --region europe-west1 --format='value(ipAllocationPolicy.clusterIpv4CidrBlock,ipAllocationPolicy.servicesIpv4CidrBlock)'The cluster's Pod and Service ranges
kubectl get nodes -o custom-columns=NODE:.metadata.name,PODCIDR:.spec.podCIDRThe Pod block each node received
gcloud compute networks subnets describe gke-prod-ew1 --region europe-west1 --format='yaml(secondaryIpRanges)'Secondary ranges on the subnet

Grow

gcloud compute networks subnets update gke-prod-ew1 --region europe-west1 --add-secondary-ranges pods-2=10.21.0.0/16Add another secondary range to the subnet
gcloud container node-pools create pool-2 --cluster prod --region europe-west1 --pod-ipv4-range pods-2 --max-pods-per-node 64A node pool that takes Pod IPs from the new range
gcloud container clusters update prod --region europe-west1 --additional-pod-ipv4-ranges pods-2Make an extra Pod range available cluster-wide (newer versions)

05 · The cluster: control plane access, node pools & compute

Cluster

gcloud container clusters create prod --region europe-west1 --release-channel regular --network projects/net-host-prod/global/networks/prod-vpc --subnetwork projects/net-host-prod/regions/europe-west1/subnetworks/gke-prod-ew1 --cluster-secondary-range-name pods --services-secondary-range-name services --enable-private-nodes --enable-dns-access --workload-pool my-prod-project.svc.id.goog --enable-dataplane-v2 --service-account gke-nodes@my-prod-project.iam.gserviceaccount.com --num-nodes 1A private, VPC-native, Workload-Identity-enabled Standard cluster on a Shared VPC
gcloud container clusters get-credentials prod --region europe-west1 --dns-endpointkubeconfig that uses the DNS-based control-plane endpoint
gcloud container clusters update prod --region europe-west1 --enable-master-authorized-networks --master-authorized-networks 10.0.0.0/8Restrict the IP-based endpoint to listed ranges

Node pools

gcloud container node-pools create apps --cluster prod --region europe-west1 --machine-type n2-standard-8 --num-nodes 1 --enable-autoscaling --min-nodes 1 --max-nodes 10 --node-labels pool=appsAn autoscaled application pool (counts are per zone)
gcloud container node-pools create spot --cluster prod --region europe-west1 --spot --machine-type e2-standard-4 --node-taints cloud.google.com/gke-spot=true:NoScheduleA Spot pool, tainted so only tolerant workloads land there
gcloud container node-pools delete default-pool --cluster prod --region europe-west1Remove the default pool once your own pools exist

06 · Identity & access: IAM, RBAC and Workload Identity Federation

People and CI

gcloud projects add-iam-policy-binding my-prod-project --member group:sre@example.com --role roles/container.adminFull GKE admin for the SRE group on the project
gcloud projects add-iam-policy-binding my-prod-project --member group:shop-devs@example.com --role roles/container.clusterViewerLets the group get credentials; RBAC then decides what they may do
kubectl auth can-i --list --as alice@example.com -n shopWhat a user may do in a namespace (RBAC view)

Workload Identity

gcloud projects add-iam-policy-binding my-prod-project --member principal://iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/my-prod-project.svc.id.goog/subject/ns/shop/sa/orders --role roles/pubsub.publisherGrant an IAM role directly to Kubernetes ServiceAccount shop/orders
kubectl -n shop run wi-test --rm -it --image google/cloud-sdk:slim --overrides='{"spec":{"serviceAccountName":"orders"}}' -- gcloud auth listCheck which identity a pod gets
gcloud container node-pools update apps --cluster prod --region europe-west1 --workload-metadata GKE_METADATAMake a pool use the GKE metadata server (hides node credentials)

07 · Load balancing: Services, Ingress & Gateway API

See what was created

kubectl get svc,ingress,gateway,httproute -AEvery exposed object and its address
kubectl get gatewayclassGatewayClasses the GKE Gateway controller offers
kubectl describe gateway web -n infraGateway status, addresses and events (errors from the controller show here)
gcloud compute forwarding-rules listLoad balancer front ends in the project
gcloud compute backend-services get-health <backend> --globalHealth of a load balancer's backends (Pods behind NEGs)

Enable

gcloud container clusters update prod --region europe-west1 --gateway-api standardTurn on the Gateway API CRDs and controller
gcloud compute ssl-policies create modern-tls --profile MODERN --min-tls-version 1.2A TLS policy for external load balancers

08 · Artifact Registry & application delivery

Artifact Registry

gcloud artifacts repositories create apps --repository-format docker --location europe-west1 --description 'App images'A Docker repository in a region
gcloud auth configure-docker europe-west1-docker.pkg.devLet local Docker push and pull with your gcloud credentials
docker push europe-west1-docker.pkg.dev/platform-shared/apps/shop:1.4.2Push an image
gcloud artifacts docker images list europe-west1-docker.pkg.dev/platform-shared/apps --include-tagsImages and tags in a repository
gcloud artifacts repositories add-iam-policy-binding apps --location europe-west1 --member serviceAccount:gke-nodes@my-prod-project.iam.gserviceaccount.com --role roles/artifactregistry.readerLet a cluster's nodes pull from the repository

Deploy and roll out

kubectl set image deploy/shop shop=europe-west1-docker.pkg.dev/platform-shared/apps/shop:1.4.3 -n shopChange the image (better: change it in Git)
kubectl rollout status deploy/shop -n shopWait for the rollout
kubectl rollout undo deploy/shop -n shopRoll back to the previous ReplicaSet

09 · Storage: Persistent Disk, Hyperdisk, Filestore & Cloud Storage

Inspect

kubectl get storageclassStorageClasses GKE provides (standard-rwo, premium-rwo…) and your own
kubectl get pvc,pv -AClaims and the volumes bound to them
kubectl get volumesnapshotclass,volumesnapshot -ASnapshot classes and snapshots
gcloud compute disks list --filter='name~pvc-'Disks created for PersistentVolumes

Enable and back up

gcloud container clusters update prod --region europe-west1 --update-addons GcpFilestoreCsiDriver=ENABLEDTurn on the Filestore CSI driver
gcloud container clusters update prod --region europe-west1 --update-addons GcsFuseCsiDriver=ENABLEDTurn on the Cloud Storage FUSE CSI driver
gcloud container clusters update prod --region europe-west1 --update-addons BackupRestore=ENABLEDTurn on the Backup for GKE agent
gcloud beta container backup-restore backup-plans list --location europe-west1Backup plans in a region

10 · Autoscaling: Pods, nodes and compute classes

Pods

kubectl autoscale deploy shop -n shop --cpu-percent 70 --min 3 --max 30A CPU-based HPA
kubectl get hpa -ACurrent versus target metrics and replica counts
gcloud container clusters update prod --region europe-west1 --enable-vertical-pod-autoscalingEnable the VPA on a Standard cluster

Nodes

gcloud container node-pools update apps --cluster prod --region europe-west1 --enable-autoscaling --min-nodes 1 --max-nodes 20 --location-policy BALANCEDAutoscale a pool (per zone), spreading across zones
gcloud container clusters update prod --region europe-west1 --autoscaling-profile optimize-utilizationScale down more aggressively to save cost
gcloud container clusters update prod --region europe-west1 --enable-autoprovisioning --max-cpu 400 --max-memory 1600Node auto-provisioning with cluster-wide limits
kubectl get events -A --field-selector reason=TriggeredScaleUpWhy and when the autoscaler added nodes