Google Kubernetes Engine (GKE) cluster
A Google Kubernetes Engine (GKE) + Kubernetes Hello World example
This example lives in the pulumi/examples repository. Check out just this directory to use it:
git clone --filter=blob:none --sparse https://github.com/pulumi/examples pulumi-examplesgit -C pulumi-examples sparse-checkout set gcp-java-gke-hello-worldcd pulumi-examples/gcp-java-gke-hello-worldThis example deploys a Google Cloud Platform (GCP) Google Kubernetes Engine (GKE) cluster and deploys a Kubernetes Namespace and Deployment of NGINX.
Prerequisites#
-
Configure GCP auth by logging in with
gcloud:Terminal window gcloud auth logingcloud config set project <YOUR_GCP_PROJECT_HERE>gcloud auth application-default loginNote: This auth mechanism is meant for inner loop developer workflows. If you want to run this example in an unattended service account setting, such as in CI/CD, please follow instructions to configure your service account. The service account must have the role
Kubernetes Engine Admin/container.admin.
Deploying the example#
-
Create a new stack:
Terminal window pulumi stack init dev -
Set the required GCP configuration variables:
Terminal window pulumi config set gcp:project <YOUR_GCP_PROJECT_HERE>pulumi config set gcp:zone us-west1-a -
Stand up the GKE cluster by running
pulumi up. Note that provisioning a new GKE cluster takes ~10 minutes:Terminal window pulumi upUpdating (dev)Type Name Status+ pulumi:pulumi:Stack gcp-java-gke-hello-world-dev created+ ├─ gcp:container:Cluster helloworld created+ ├─ gcp:container:NodePool primary-node-pool created+ ├─ pulumi:providers:kubernetes helloworld created+ ├─ kubernetes:core/v1:Namespace helloworld created+ ├─ kubernetes:apps/v1:Deployment helloworld created+ └─ kubernetes:core/v1:Service helloworld createdOutputs:clusterName : "helloworld-10e2053"deploymentName : "helloworld-krnibosh"kubeconfig : "[secret]"masterVersion : "1.22.6-gke.300"namespaceName : "helloworld-p2a10vq4"serviceName : "helloworld-h7jipvp8"servicePublicIP: "***"Resources:+ 7 createdDuration: 11m18s -
After ~10 minutes, your cluster will be ready, and the kubeconfig JSON you’ll use to connect to the cluster will be available as an output.
As part of the update, you’ll see some new objects in the output: a
Namespacein Kubernetes to deploy into, aDeploymentresource for the NGINX app, and a LoadBalancerServiceto publicly access NGINX.Pulumi understands which changes to a given cloud resource can be made in-place, and which require replacement, and computes the minimally disruptive change to achieve the desired state.
Note: Pulumi auto-generates a suffix for all objects. See the Pulumi Programming Model for more info.
clusterName : "helloworld-10e2053"deploymentName : "helloworld-krnibosh"kubeconfig : "[secret]"masterVersion : "1.22.6-gke.300"namespaceName : "helloworld-p2a10vq4"serviceName : "helloworld-h7jipvp8"servicePublicIP: "***"If you visit the FQDN listed in
servicePublicIPyou should land on the NGINX welcome page. Note that it may take a minute or so for the LoadBalancer to become active on GCP. -
Access the Kubernetes cluster using
kubectl. To access your new Kubernetes cluster usingkubectl, set up thekubeconfigfile and downloadkubectl. Leverage the Pulumi stack output in the CLI, as Pulumi facilitates exporting these objects for us:Terminal window pulumi stack output kubeconfig --show-secrets > kubeconfigexport KUBECONFIG=$PWD/kubeconfigexport KUBERNETES_VERSION=1.11.6 && sudo curl -s -o /usr/local/bin/kubectl https://storage.googleapis.com/kubernetes-release/release/v${KUBERNETES_VERSION}/bin/linux/amd64/kubectl && sudo chmod +x /usr/local/bin/kubectlkubectl versionkubectl cluster-infokubectl get nodesYou can also use the stack output to query the cluster for your newly created Deployment:
Terminal window kubectl get deployment $(pulumi stack output deploymentName) --namespace=$(pulumi stack output namespaceName)kubectl get service $(pulumi stack output serviceName) --namespace=$(pulumi stack output namespaceName)You can also create another NGINX Deployment into the
defaultnamespace usingkubectlnatively:Terminal window kubectl create deployment my-nginx --image=nginxkubectl get podskubectl delete deployment my-nginxBy doing so, these resources are outside of Pulumi’s purview, but this simply demonstrates that all the
kubectlcommands you’re used to will work. -
From here on, feel free to experiment. Simply making edits and running
pulumi upafterwards will incrementally update your stack.
Cleaning up#
Once you’ve finished experimenting, tear down your stack’s resources by destroying and removing it:
pulumi destroypulumi stack rm