Google Kubernetes Services (GCP) Deployment Example
This how-to guide is an example GCP Kubernetes deployment. This is not the only way to deploy a Kubernetes cluster.
Follow your organization’s security requirements for Kubernetes clusters.
Setup Summary
The following Azure resources are used in this example deployment.
- GCP Authentication
- GCP Service Account
- Google Cloud Storage
- Google Kubernetes Engine
Google Kubernetes Engine must be enabled for the project you want to use.
Other tools needed
To deploy a HiddenLayer product to a Kubernetes cluster, you may need the following:
GCP Authentication
-
Authenticate the GCP CLI to your GCP tenant.
a. If you want to authorize the gcloud CLI on a machine that doesn’t have a browser, use the following command. It provides a URL to copy and paste to get a verification code.
-
A web browser opens, and you need to verify your log in. After logging in, you may need to select a project to use.
a. If you want to use gcloud Auth Login on a machine that doesn’t have a browser, use the following command. It provides a URL to copy and paste to get a verification code.
-
You can change the project for the GCP CLI at any point by using the following command
-
Find the GCP Compute Zone. Note: This should be a zone the AI Supply Chain Security should be deployed to, you will provide the zone name in the following steps.
-
Replace
<zone>with your desired compute zone.
Service Account
Select your operating system to view installation instructions. Note: Instructions for Windows systems will be available soon.
macOS
Windows
Ubuntu
-
Create a Service Account (SA). The command below will create a service account with the name hl-modelscanner-sa and the display name of “HL Supply Chain Service Account”
This command will output JSON file containing your key.
-
Download the JSON key for your Service Account created above. Replace
<your-project-id>with your GCP Project ID.
Pay attention where this file is downloaded as it will be needed later in set up as <pathtocredentialfile>.
-
Assign the following roles and permissions to the SA. Replace
<your-project-id>with your GCP Project ID in each role assignment.
In each IAM policy binding (there are three bindings), there are two places to replace <your-project-id>.
Google Cloud Storage (GCS)
-
Create a GCS bucket, if one doesn’t exist. Replace
<project-id>with your designated project,<region>with the preferred region of your bucket, and<bucket-name>with the chosen name of your bucket.a. Remember GCS Bucket names must be globally unique across all of Google Cloud.
Google Kubernetes Engine (GKE)
Select your operating system to view installation instructions. Note: Instructions for Windows systems will be available soon.
macOS
Windows
Ubuntu
-
Create an GKE Cluster, if one doesn’t exist.
- Replace
<zone>with a compute zone and<cluster-name>with the preferred name of your container . - If you’ve never activated Kubernetes service in GCP before, this step will error with a message to ERROR: (gcloud.container.clusters.create) ResponseError: code=403, message=Kubernetes Engine API has not been used in project
<projectid>before or it is disabled. - Enable it by visiting
https://console.developers.google.com/apis/api/container.googleapis.com/overview?project=<projectid>then retry. - If this happens, follow the provided link and enable Kubernetes, and retry.
-
Fetch the kubeconfig for the GKE cluster.
Replace
<cluster-name>with the name of the GKE cluster, the<zone>with your compute zone of the cluster, and<your-project-id>with your Project ID.
- Replace
This command updates your kubeconfig file to work with the GKE cluster.
-
Create modelscanner namespace and add your auth file to GKE