Registering a Google Account in gopaddle, provides gopaddle the required Google Account credentials to provision and manage Google GKE clusters, push or pull Docker Images to the Artifact (Docker) Registry. Registering a Google Account is a three step process. First a role with the necessary access privileges needs to be created in the Google Cloud Console. This role is assigned to a newly created Service Account. The Service account credentials are then used to register the Google Account in the gopaddle portal.
gopaddle uses Google's Kubernetes Engine API in order to provision and manage GKE clusters. Before registering a Google Cloud Account ensure that the API is enabled in the Google Cloud Kubernetes Engine page
Creating a Role
- Login to the Google Cloud Console and select the project under which the Google GKE Clusters need to be managed. If no projects are available, create a new projectC
- Choose IAM & Admin and choose Roles
- Choose CREATE ROLE to create a new Role
- Choose ADD PERMISSIONS to add permissions to manage kubernetes clusters and the Artifact Registry. Under filter roles, select permissions under Kubernetes Engine Admin, Kubernetes Engine Cluster Admin, Artifact Registry Administrator and Service Account User. In addition, select the permissions : container.clusters.get , container.clusters.delete and container.clusters.getCredentials
Here is the final list of permissions to be added to the role :
5. Choose CREATE to save the Role
Creating a Service Account
- Choose API & Services and Choose Credentials
- Click on CREATE CREDENTIALS to create a new credential of type Service account
- Name the Service account and choose the newly created Role to associate with the Service Account
- Create a Key for the Service Account by clicking on CREATE KEY
- Create a p12 file based key.
6. Save the secret password and the p12 file generated
7. Note down the Service Account email ID.
The Google Project Name, Service Account Email ID, P12 file and the Private Key password generated in the previous steps will used to register the Google Cloud Account in gopaddle.