Part 2 — Build the platform · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Shared VPC
gcloud compute shared-vpc enable net-host-prod | Make a project a Shared VPC host |
gcloud compute shared-vpc associated-projects add gke-prod --host-project net-host-prod | Attach a service project to the host |
gcloud compute networks create prod-vpc --subnet-mode custom --project net-host-prod | A custom-mode VPC (no automatic subnets) |
gcloud compute networks subnets create gke-prod-ew1 --network prod-vpc --region europe-west1 --range 10.10.0.0/22 --secondary-range pods=10.20.0.0/16,services=10.30.0.0/20 --enable-private-ip-google-access | Subnet with Pod and Service secondary ranges, Private Google Access on |
Egress
gcloud compute routers create nat-router --network prod-vpc --region europe-west1 | Cloud Router for Cloud NAT |
gcloud compute routers nats create nat-ew1 --router nat-router --region europe-west1 --auto-allocate-nat-external-ips --nat-all-subnet-ip-ranges | Cloud NAT for every range in the region (nodes and Pods) |
gcloud compute firewall-rules list --filter='network:prod-vpc' | Firewall rules on the VPC, including the ones GKE created |
Plan and check
gcloud container clusters describe prod --region europe-west1 --format='value(ipAllocationPolicy.clusterIpv4CidrBlock,ipAllocationPolicy.servicesIpv4CidrBlock)' | The cluster's Pod and Service ranges |
kubectl get nodes -o custom-columns=NODE:.metadata.name,PODCIDR:.spec.podCIDR | The Pod block each node received |
gcloud compute networks subnets describe gke-prod-ew1 --region europe-west1 --format='yaml(secondaryIpRanges)' | Secondary ranges on the subnet |
Grow
gcloud compute networks subnets update gke-prod-ew1 --region europe-west1 --add-secondary-ranges pods-2=10.21.0.0/16 | Add another secondary range to the subnet |
gcloud container node-pools create pool-2 --cluster prod --region europe-west1 --pod-ipv4-range pods-2 --max-pods-per-node 64 | A node pool that takes Pod IPs from the new range |
gcloud container clusters update prod --region europe-west1 --additional-pod-ipv4-ranges pods-2 | Make an extra Pod range available cluster-wide (newer versions) |
Cluster
gcloud container clusters create prod --region europe-west1 --release-channel regular --network projects/net-host-prod/global/networks/prod-vpc --subnetwork projects/net-host-prod/regions/europe-west1/subnetworks/gke-prod-ew1 --cluster-secondary-range-name pods --services-secondary-range-name services --enable-private-nodes --enable-dns-access --workload-pool my-prod-project.svc.id.goog --enable-dataplane-v2 --service-account gke-nodes@my-prod-project.iam.gserviceaccount.com --num-nodes 1 | A private, VPC-native, Workload-Identity-enabled Standard cluster on a Shared VPC |
gcloud container clusters get-credentials prod --region europe-west1 --dns-endpoint | kubeconfig that uses the DNS-based control-plane endpoint |
gcloud container clusters update prod --region europe-west1 --enable-master-authorized-networks --master-authorized-networks 10.0.0.0/8 | Restrict the IP-based endpoint to listed ranges |
Node pools
gcloud container node-pools create apps --cluster prod --region europe-west1 --machine-type n2-standard-8 --num-nodes 1 --enable-autoscaling --min-nodes 1 --max-nodes 10 --node-labels pool=apps | An autoscaled application pool (counts are per zone) |
gcloud container node-pools create spot --cluster prod --region europe-west1 --spot --machine-type e2-standard-4 --node-taints cloud.google.com/gke-spot=true:NoSchedule | A Spot pool, tainted so only tolerant workloads land there |
gcloud container node-pools delete default-pool --cluster prod --region europe-west1 | Remove the default pool once your own pools exist |
People and CI
gcloud projects add-iam-policy-binding my-prod-project --member group:sre@example.com --role roles/container.admin | Full GKE admin for the SRE group on the project |
gcloud projects add-iam-policy-binding my-prod-project --member group:shop-devs@example.com --role roles/container.clusterViewer | Lets the group get credentials; RBAC then decides what they may do |
kubectl auth can-i --list --as alice@example.com -n shop | What a user may do in a namespace (RBAC view) |
Workload Identity
gcloud projects add-iam-policy-binding my-prod-project --member principal://iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/my-prod-project.svc.id.goog/subject/ns/shop/sa/orders --role roles/pubsub.publisher | Grant an IAM role directly to Kubernetes ServiceAccount shop/orders |
kubectl -n shop run wi-test --rm -it --image google/cloud-sdk:slim --overrides='{"spec":{"serviceAccountName":"orders"}}' -- gcloud auth list | Check which identity a pod gets |
gcloud container node-pools update apps --cluster prod --region europe-west1 --workload-metadata GKE_METADATA | Make a pool use the GKE metadata server (hides node credentials) |
See what was created
kubectl get svc,ingress,gateway,httproute -A | Every exposed object and its address |
kubectl get gatewayclass | GatewayClasses the GKE Gateway controller offers |
kubectl describe gateway web -n infra | Gateway status, addresses and events (errors from the controller show here) |
gcloud compute forwarding-rules list | Load balancer front ends in the project |
gcloud compute backend-services get-health <backend> --global | Health of a load balancer's backends (Pods behind NEGs) |
Enable
gcloud container clusters update prod --region europe-west1 --gateway-api standard | Turn on the Gateway API CRDs and controller |
gcloud compute ssl-policies create modern-tls --profile MODERN --min-tls-version 1.2 | A TLS policy for external load balancers |
Artifact Registry
gcloud artifacts repositories create apps --repository-format docker --location europe-west1 --description 'App images' | A Docker repository in a region |
gcloud auth configure-docker europe-west1-docker.pkg.dev | Let local Docker push and pull with your gcloud credentials |
docker push europe-west1-docker.pkg.dev/platform-shared/apps/shop:1.4.2 | Push an image |
gcloud artifacts docker images list europe-west1-docker.pkg.dev/platform-shared/apps --include-tags | Images and tags in a repository |
gcloud artifacts repositories add-iam-policy-binding apps --location europe-west1 --member serviceAccount:gke-nodes@my-prod-project.iam.gserviceaccount.com --role roles/artifactregistry.reader | Let a cluster's nodes pull from the repository |
Deploy and roll out
kubectl set image deploy/shop shop=europe-west1-docker.pkg.dev/platform-shared/apps/shop:1.4.3 -n shop | Change the image (better: change it in Git) |
kubectl rollout status deploy/shop -n shop | Wait for the rollout |
kubectl rollout undo deploy/shop -n shop | Roll back to the previous ReplicaSet |
Inspect
kubectl get storageclass | StorageClasses GKE provides (standard-rwo, premium-rwo…) and your own |
kubectl get pvc,pv -A | Claims and the volumes bound to them |
kubectl get volumesnapshotclass,volumesnapshot -A | Snapshot classes and snapshots |
gcloud compute disks list --filter='name~pvc-' | Disks created for PersistentVolumes |
Enable and back up
gcloud container clusters update prod --region europe-west1 --update-addons GcpFilestoreCsiDriver=ENABLED | Turn on the Filestore CSI driver |
gcloud container clusters update prod --region europe-west1 --update-addons GcsFuseCsiDriver=ENABLED | Turn on the Cloud Storage FUSE CSI driver |
gcloud container clusters update prod --region europe-west1 --update-addons BackupRestore=ENABLED | Turn on the Backup for GKE agent |
gcloud beta container backup-restore backup-plans list --location europe-west1 | Backup plans in a region |
Pods
kubectl autoscale deploy shop -n shop --cpu-percent 70 --min 3 --max 30 | A CPU-based HPA |
kubectl get hpa -A | Current versus target metrics and replica counts |
gcloud container clusters update prod --region europe-west1 --enable-vertical-pod-autoscaling | Enable the VPA on a Standard cluster |
Nodes
gcloud container node-pools update apps --cluster prod --region europe-west1 --enable-autoscaling --min-nodes 1 --max-nodes 20 --location-policy BALANCED | Autoscale a pool (per zone), spreading across zones |
gcloud container clusters update prod --region europe-west1 --autoscaling-profile optimize-utilization | Scale down more aggressively to save cost |
gcloud container clusters update prod --region europe-west1 --enable-autoprovisioning --max-cpu 400 --max-memory 1600 | Node auto-provisioning with cluster-wide limits |
kubectl get events -A --field-selector reason=TriggeredScaleUp | Why and when the autoscaler added nodes |