# Welcome to gopaddle

## Meet gopaddle: You AI-Powered Kubernetes Companion

Imagine having a smart assistant dedicated to making your life easier when managing Kubernetes, the powerhouse behind your apps. That's gopaddle for you — not just any Integrated Development Environment (IDE) but an AI-assisted one, crafted to navigate the complexities of Kubernetes with ease. Here’s a peek at what makes gopaddle stand out:

* **Live Discovery**: Ever wished you could have a live map of your Kubernetes resources and events? gopaddle turns this wish into reality, letting you see everything happening in real-time.
* **Filter with Ease**: Finding exactly what you’re looking for among endless resources and events can be daunting. gopaddle simplifies this with smart filtering, letting you zoom in on what matters using Field and Label Selectors.
* **Navigate Your Way**: Whether you prefer an overhead view or a detailed path, gopaddle offers both flat and tree views to explore resources, making it a breeze to find your way around.
* **Edit on the Fly**: With YAML and OpenAPI Form-based editors, tweaking Kubernetes resources is as easy as pie. Whether you’re a code wizard or prefer a more visual approach, gopaddle has you covered.
* **Troubleshoot Like a Pro**: Dive into container logs, open a terminal to poke around, or chat with the AI assistant for troubleshooting tips. gopaddle packs all the developer tools you need for quick fixes.
* **Smart AI Chat Assistant**: This isn't just any chatbot. gopaddle’s AI assistant is like having a Kubernetes expert by your side, offering interactive troubleshooting, advice, and even handling sensitive info with care.

<figure><img src="/files/3J5im2coA4ZdEju5fW9P" alt=""><figcaption><p>AI Assistant (ChatGPT) Chat Window</p></figcaption></figure>

And there’s more. gopaddle doesn’t just help you fix things; it also helps you keep track of everything:

* **Sensitive Info? Secured**: gopaddle knows the importance of privacy and secures sensitive information away from prying eyes.
* **Streamlined Reviews**: Collaborate and approve changes smoothly, ensuring that every tweak meets your standards.
* **Never Lose Track**: A detailed history of your chats and changes with the AI is kept, so you’re always in the know.
* **Documentation, Done Right**: Say goodbye to scattered notes. gopaddle captures outcomes in Runbooks and Jira tickets, turning solutions into easy-to-follow documentation.

With gopaddle, you’re not just managing Kubernetes; you’re mastering it, with an AI-powered partner to guide you every step of the way.

<figure><img src="/files/YPhzDbfSHZiIJf5dOx19" alt=""><figcaption><p>gopaddle AI Workflow</p></figcaption></figure>

## Benefits

### Quick Issue Resolution

* **Live Discovery and Filtering:** By providing a live discovery feature for Kubernetes resources and events, gopaddle enables developers to quickly identify changes or anomalies within the cluster. The easy filtering capabilities using Field and Label Selectors help narrow down potential issues, allowing for faster identification of the root cause.
* **Flat and Tree View Navigation:** The ability to navigate Kubernetes resources in both flat and tree views makes it easier for developers to understand the relationships between different resources and how they might be affecting one another. This comprehensive visibility can be critical in diagnosing complex issues.
* **YAML and Form-based Editors:** gopaddle’s inclusion of YAML and OpenAPI Form-based editors simplifies the process of editing Kubernetes resources. This allows developers to make quick adjustments or fixes directly within the IDE, speeding up the resolution process.
* **Developer Tools for Troubleshooting:** Integrated tools such as container logs and terminals offer immediate access to diagnostic information. Developers can quickly view logs to understand the behavior of containers or use terminals to execute commands directly in the context of specific resources or pods, leading to quicker issue identification and resolution.
* **AI Chat Assistant:** The AI Chat Assistant can interactively guide developers through troubleshooting processes, suggesting potential fixes or highlighting areas that require attention. By redacting sensitive information and facilitating a review process, it ensures that troubleshooting remains secure and efficient.

### Context-Aware Knowledge Base

* **Documentation of Interactions:** By capturing the outcomes from interactions with the AI assistant in the form of context-aware documentation, such as Runbooks and Jira tickets, gopaddle ensures that the knowledge gained from troubleshooting is preserved and easily accessible. This documentation can be referred to in future incidents, speeding up resolution times and improving the efficiency of troubleshooting efforts.

### Automatic Support Ticketing

* **Capture Outcome in Jira Tickets:** gopaddle can automatically generate Jira tickets based on the interactions with the AI Assistant and the identified issues. This feature ensures that every issue is recorded, prioritized, and assigned within an organization’s existing workflow, making sure nothing falls through the cracks.
* **Facilitate Review and Approval Process:** The platform’s ability to facilitate a review and approval process for the documentation and actions suggested by the AI assistant helps maintain quality control and adherence to organizational policies. This process ensures that the solutions proposed are vetted and approved by the necessary stakeholders before implementation.
* **History of Data Exchanged:** Maintaining a history of the data exchanged with the AI assistant not only helps in the immediate resolution of issues but also improves the automatic support ticketing process by providing detailed context and background information for each ticket. This can be invaluable for teams who may not have been involved in the initial troubleshooting process but are responsible for implementing or verifying the fix.


# Getting Started

Flexible models suited for Developers, Startups and Enterprises

## Subscription and Installation Modes

gopaddle is offered in two modes:&#x20;

1. **SaaS subscription** - gopaddle is available as a pay-as-go SaaS subscription. The SaaS platform is hosted and managed by the gopaddle team. You can subscribe to gopaddle at <https://portal.gopaddle.io>
2. &#x20;**On-premise installation** - gopaddle can be installed on your own infrastructure. gopaddle on-premise is available in two editions:&#x20;

{% hint style="info" %}
**Dive Into gopaddle 5.0: Where AI Meets Innovation**

**Exciting news!** The latest gopaddle 5.0 is here, and it's bringing some game-changing features to the table — including our smart AI Assistant and the comprehensive Runbook capabilities. Right now, these AI capabilities are exclusively available on our **SaaS Edition**.

Can't wait to explore these features on Lite or Enterprise Edition? We've got you covered! For early access and a sneak peek into the future of Kubernetes management, just reach out to us at <hello@gopaddle.io>
{% endhint %}

**(a) Community Edition** - The Community Edition is a life-time free edition, designed for single user, single-node installation. This edition manages the local Kubernetes cluster and the workloads running on the cluster. The Community Edition is available on a variety of marketplaces as a single command installer.&#x20;

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>MicroK8s Community Add-On - <a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon">Installation Guide</a></td><td></td><td></td><td><a href="/files/ZcPqhCKIr4stg2KOgIFI">/files/ZcPqhCKIr4stg2KOgIFI</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon</a></td></tr><tr><td>Docker Desktop Extension - <a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/docker-desktop">Installation Guide</a></td><td></td><td></td><td><a href="/files/x1WliqWUdXj1mxjvhIMs">/files/x1WliqWUdXj1mxjvhIMs</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/docker-desktop">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/docker-desktop</a></td></tr><tr><td>SUSE Rancher RKE Prime - <a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/suse-rancher-prime">Installation Guide</a></td><td></td><td></td><td><a href="/files/21JiX8GWA7lsZuPyLiKC">/files/21JiX8GWA7lsZuPyLiKC</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/suse-rancher-prime">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/suse-rancher-prime</a></td></tr><tr><td>DigitalOcean Marketplace - <a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/digital-ocean">Installation Guide</a></td><td></td><td></td><td><a href="/files/KzGaoHeoyMZUeoXzPq4U">/files/KzGaoHeoyMZUeoXzPq4U</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/digital-ocean">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/digital-ocean</a></td></tr><tr><td>Akamai Linode Marketplace - <a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/akamai-linode">Installation Guide</a></td><td></td><td></td><td><a href="/files/5mBwg9a0KhhV38KQG7Ev">/files/5mBwg9a0KhhV38KQG7Ev</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/akamai-linode">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/akamai-linode</a></td></tr><tr><td><a href="https://artifacthub.io/packages/helm/gopaddle-lite/gopaddle">ArtifactHub Marketplace</a></td><td></td><td></td><td><a href="/files/AA2PqjrI3wW7HgJuQB6l">/files/AA2PqjrI3wW7HgJuQB6l</a></td><td><a href="https://artifacthub.io/packages/helm/gopaddle-lite/gopaddle">https://artifacthub.io/packages/helm/gopaddle-lite/gopaddle</a></td></tr></tbody></table>

**(b) Enterprise Edition** - The Enterprise Edition is designed for multi-node installation and is suitable for larger teams looking to provision and manage multi-cluster environments across on-premise and cloud. If you already have a community edition, you upgrade to Enterprise edition. Talk to [our support](emailto:hello@gopaddle.io) for an upgrade.


# Register a Cluster

Register and manage pre-existing clusters as an external cluster in gopaddle

{% hint style="info" %}
This section is applicable only for SaaS and Enterprise Editions only.
{% endhint %}

A pre-existing self-managed or a cloud managed EKS, GKE cluster can be registered in gopaddle as an external cluster. Once the cluster is registered, gopaddle can be used to visualize and manage the resources in the cluster. gopaddle also installs gopaddle's discovery kubegent, Prometheus and Grafana in the `gopaddle-servers` namespace to monitor the cluster and the workloads.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/MBHx8hStZTclgqY2Cmgx">Register K3S Cluster</a></td><td></td><td></td><td><a href="/files/e1Q0eSWDmxRhUiQvQatY">/files/e1Q0eSWDmxRhUiQvQatY</a></td><td><a href="/pages/MBHx8hStZTclgqY2Cmgx">/pages/MBHx8hStZTclgqY2Cmgx</a></td></tr><tr><td></td><td><a href="/pages/hXsaJd22AItN8bOYGC6Z">Register Rancher Prime RKE2</a></td><td></td><td><a href="/files/QLi9n8oEYSsMYB6ZIenr">/files/QLi9n8oEYSsMYB6ZIenr</a></td><td><a href="/pages/hXsaJd22AItN8bOYGC6Z">/pages/hXsaJd22AItN8bOYGC6Z</a></td></tr><tr><td></td><td><a href="/pages/cgplQ34RDURXoRsiexjd">Register K3S Cluster</a></td><td></td><td><a href="/files/he9cKj44RaoQAN57FIv1">/files/he9cKj44RaoQAN57FIv1</a></td><td><a href="/pages/cgplQ34RDURXoRsiexjd">/pages/cgplQ34RDURXoRsiexjd</a></td></tr><tr><td></td><td><a href="/pages/FIhF6kSEZHw3cl69lNjH">Register Kind Cluster</a></td><td></td><td><a href="/files/uhUYyKmstEJKj6eCRpVC">/files/uhUYyKmstEJKj6eCRpVC</a></td><td><a href="/pages/FIhF6kSEZHw3cl69lNjH">/pages/FIhF6kSEZHw3cl69lNjH</a></td></tr><tr><td><a href="/pages/cnmSOol9IqevdKgHZoLK">Register minikube Cluster</a></td><td></td><td></td><td><a href="/files/vzlq6NpJ3vbY8c8X5qn4">/files/vzlq6NpJ3vbY8c8X5qn4</a></td><td><a href="/pages/cnmSOol9IqevdKgHZoLK">/pages/cnmSOol9IqevdKgHZoLK</a></td></tr><tr><td><a href="/pages/j78n9dnxwNa92avtRt8g">Register AWS EKS Cluster</a></td><td></td><td></td><td><a href="/files/6iNqyjLKX52YqKzvsmPw">/files/6iNqyjLKX52YqKzvsmPw</a></td><td><a href="/pages/j78n9dnxwNa92avtRt8g">/pages/j78n9dnxwNa92avtRt8g</a></td></tr><tr><td><a href="/pages/BUcCuViUo8DxWTVIo1P6">Register Google GKE Cluster</a></td><td></td><td></td><td><a href="/files/TxETOV9nfEbinxBoSTXh">/files/TxETOV9nfEbinxBoSTXh</a></td><td><a href="/pages/BUcCuViUo8DxWTVIo1P6">/pages/BUcCuViUo8DxWTVIo1P6</a></td></tr><tr><td>Register Azure AKS Cluster</td><td></td><td></td><td><a href="/files/14hWFbN766SVZ3mmJPID">/files/14hWFbN766SVZ3mmJPID</a></td><td></td></tr><tr><td><a href="/pages/DeDhk1JCz3CjlpjjHvn9">Register On-premise Cluster</a></td><td></td><td></td><td><a href="/files/2PwV38RgR735ezXwMEUU">/files/2PwV38RgR735ezXwMEUU</a></td><td><a href="/pages/DeDhk1JCz3CjlpjjHvn9">/pages/DeDhk1JCz3CjlpjjHvn9</a></td></tr><tr><td><a href="/pages/zaimzrrzl2Lxn0ooZb78">Register Huawei Container Engine</a></td><td></td><td></td><td><a href="/files/ITwL4nGgivVpC4eGTifb">/files/ITwL4nGgivVpC4eGTifb</a></td><td><a href="/pages/zaimzrrzl2Lxn0ooZb78">/pages/zaimzrrzl2Lxn0ooZb78</a></td></tr></tbody></table>


# Register Rancher Prime - RKE2

Steps to register Rancher Prime RKE2 Cluster in gopaddle

Rancher Prime RKE2 cluster can be registered in gopaddle either using its public IP address or a fully qualified domain name (FQDN) or securely via a Bastion Host or a Jump server.

### 1. Prepare Kubernetes Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

### Port Configuration

{% hint style="info" %}
Make sure port the cluster API server port **(default 6443)** is open to public.&#x20;
{% endhint %}

### Configure Subject Alternative Names (SAN)

Add Subject Alternative Names (SAN) on the RKE2 server TLS cert. If SAN does not exist for the API endpoint,  add the below  in the cluster configuration.&#x20;

a) Login to the RKE2 master node.

b) Create/edit the file **/etc/rancher/rke2/config.yaml** file with the below configuration :&#x20;

{% hint style="info" %}
If you are using a `config.yaml` file in a different folder, make sure the environment variable **`$RKE2_CONFIG_FILE`** is set to the path of your custom **`config.yaml`** file.
{% endhint %}

```
tls-san:
  <public-ip-address> # or <fully-qualified-domain-name> 
  # <private_ip_addres> in case of bastion host configuration
  
```

c) Restart the **rke2-server** service

```
sudo systemctl restart rke2-server.service
```

d) Check the status of the **rke2-server** service and make sure it is in **running** state.

```
sudo systemctl status rke2-server.service
```

<figure><img src="/files/7sPhes64Li8I3sF8iVuW" alt=""><figcaption><p>RKE Server Service in running state</p></figcaption></figure>
{% endtab %}

{% tab title="Bastion Host" %}

### Port Configuration

{% hint style="info" %}
Make sure the cluster API server port (**default 6443**) is open to the Bastion host and the Bastion host / Jump server SSH port (**default 22**) is open to public.
{% endhint %}
{% endtab %}
{% endtabs %}

### 2. Copy Kubernetes Config file

Copy **/etc/rancher/rke2/rke2.yaml** in to your local desktop as **kube.config**

### 3. Validate Connection from Local Desktop Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

1. Edit the server section in **kube.config** to point to the cluster API server public IP address or its FQDN.&#x20;

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: https://<public-ip_or_fqdn>::<cluster_port>
  name: default
contexts:
- context:
    cluster: default
    user: default
  name: default
current-context: default
kind: Config
preferences: {}
users:
- name: default
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

2. Verify if Kubernetes configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

3. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}

{% tab title="Bastion Host" %}

1. Set up SSH Tunnel locally to validate bastion host configuration

```
ssh -v -L <local_port>:<cluster_private_ip>:<cluster_port> <bastion_user>@<bastion_public_ip> -i <bastion-ssh-pem-file> -N
```

Eg:

```
ssh -v -L 6443:10.0.141.106:6443 ubuntu@34.201.100.49 -i bastion.pem -N
```

2. Verify if tunnel configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

3. **IMPORTANT**: Update the **kube.config** file such that the server attribute points to the private cluster IP address.&#x20;

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: https://<private_ip>:<cluster_port>
  name: default
contexts:
- context:
    cluster: default
    user: default
  name: default
current-context: default
kind: Config
preferences: {}
users:
- name: default
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

3. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}
   {% endtabs %}

### 4. Register the Cluster in gopaddle

1. In the gopaddle UI, navigate to the **Clusters** section
2. Click on **Add a Cluster** and select **Register an existing Cluster**
3. In the Cluster registration wizard, select the **Cluster Access Method** as **Kube Config**&#x20;
4. Choose the **Cluster Provider** type as **Other**
5. In the **Authentication** Step, upload the Kubernetes config file gathered under section "Validate Connection from Local Desktop Environment"

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

6. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

7. Click on **Finish** to register the On-premises Cluster.
8. If you see the error - <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>, while view the cluster resources, then check this [troubleshooting](/troubleshooting/cluster-resource-view-issues/network-error-servererror-response-not-successful-received-status-code-503) section for more information.


# Register K3S

Steps to register K3S Cluster in gopaddle

K3S cluster can be registered in gopaddle either using its public IP address or a fully qualified domain name (FQDN) or securely via a Bastion Host or a Jump server.

### 1. Prepare Kubernetes Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

### Port Configuration

{% hint style="info" %}
Make sure port the cluster API server port **(default 6443)** is open to public.&#x20;
{% endhint %}

### Configure Subject Alternative Names (SAN)

Add Subject Alternative Names (SAN) on the K3S server TLS cert. If SAN does not exist for the API endpoint,  add the below  in the cluster configuration.&#x20;

a) Login to the K3S master node.

b) Create/edit the file **/etc/rancher/k3s/config.yaml** file with the below configuration :

<pre><code><strong>tls-san:
</strong>  &#x3C;public-ip-address> # or &#x3C;fully-qualified-domain-name> 
  # &#x3C;private_ip_addres> in case of bastion host configuration
  
</code></pre>

c) Restart the k3s server service

```
sudo systemctl stop k3s
sudo systemctl start k3s
```

d) Check the status of the **k3s** service and make sure it is in **running** state.

```
systemctl status k3s
```

<figure><img src="/files/MZcfWY5DmwWc0zDrG1kw" alt=""><figcaption><p>K3S in running state</p></figcaption></figure>
{% endtab %}

{% tab title="Bastion Host" %}

### Port Configuration

{% hint style="info" %}
Make sure the cluster API server port (**default 6443**) is open to the Bastion host and the Bastion host / Jump server SSH port (**default 22**) is open to public.
{% endhint %}
{% endtab %}
{% endtabs %}

### 2. Copy Kubernetes Config file

Copy **/etc/rancher/k3s/k3s.yaml** in to your local desktop as **kube.config**

### 3. Validate Connection from Local Desktop Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

1. Edit the server section in **kube.config** to point to the Cluster API server public IP address or its FQDN.

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: https://<public-ip_or_fqdn>::<cluster_port>
  name: default
contexts:
- context:
    cluster: default
    user: default
  name: default
current-context: default
kind: Config
preferences: {}
users:
- name: default
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

2. Verify if kube configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

3. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}

{% tab title="Bastion Host" %}

1. Set up SSH Tunnel locally to validate bastion host configuration

```
ssh -v -L <local_port>:<cluster_private_ip>:<cluster_port> <bastion_user>@<bastion_public_ip> -i <bastion-ssh-pem-file> -N
```

Eg:

```
ssh -v -L 6443:10.0.141.106:6443 ubuntu@34.201.100.49 -i bastion.pem -N
```

2. Verify if tunnel configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

3. **IMPORTANT**: Update the **kube.config** file such that the server attribute points to the private cluster IP address.&#x20;

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: https://<private_ip>:<cluster_port>
  name: default
contexts:
- context:
    cluster: default
    user: default
  name: default
current-context: default
kind: Config
preferences: {}
users:
- name: default
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

{% endtab %}
{% endtabs %}

### 4. Register the Cluster in gopaddle

1. In the gopaddle UI, navigate to the **Clusters** section
2. Click on **Add a Cluster** and select **Register an existing Cluster**
3. In the Cluster registration wizard, select the **Cluster Access Method** as **Kube Config**&#x20;
4. Choose the **Cluster Provider** type as **Other**
5. In the **Authentication** Step, upload the Kubernetes config file gathered under section "Validate Connection from Local Desktop Environment"

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

6. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

7. Click on **Finish** to register the On-premises Cluster.
8. If you see the error - <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>, while view the cluster resources, then check this [troubleshooting](/troubleshooting/cluster-resource-view-issues/network-error-servererror-response-not-successful-received-status-code-503) section for more information.


# Register MicroK8s

Steps to register Microk8s Cluster in gopaddle

Microk8s cluster can be registered in gopaddle either using its public IP address or a fully qualified domain name (FQDN) or securely via a Bastion Host or a Jump server.

### 1. Prepare Kubernetes Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

### Port Configuration

{% hint style="info" %}
Make sure port the cluster API server port **(default 16443)** is open to public.&#x20;
{% endhint %}

### Configure Subject Alternative Names (SAN)

Add Subject Alternative Names (SAN) on the microk8s server TLS cert.

a) Login to the microk8s master node.

b) Edit or create the file **/var/snap/microk8s/current/certs/csr.conf.template** file with the below configuration :

<pre><code>[ alt_names ]
DNS.1 = kubernetes
DNS.2 = kubernetes.default
DNS.3 = kubernetes.default.svc
DNS.4 = kubernetes.default.svc.cluster
DNS.5 = kubernetes.default.svc.cluster.local
DNS.6 = &#x3C;cluster-fqdn> # FQDN in case of domain name access
IP.1 = 127.0.0.1
IP.2 = 10.152.183.1
<a data-footnote-ref href="#user-content-fn-1">IP.3 = &#x3C;public-ip_address></a>
#MOREIPS
  
</code></pre>

c) Restart the microk8s service

```
sudo microk8s stop
sudo microk8s start
```

d) Check the status of the microk8s service and make sure it is in **running** state.

```
sudo microk8s status --wait-ready
```

{% endtab %}

{% tab title="Bastion Host" %}

### Port Configuration

{% hint style="info" %}
Make sure the cluster API server port (**default 16443**) is open to the Bastion host and the Bastion host / Jump server SSH port (**default 22**) is open to public.
{% endhint %}
{% endtab %}
{% endtabs %}

### 2. Copy Kubernetes Config file

Get kube config and save in your local desktop as **kube.config**

```
sudo microk8s config view
```

### 3. Validate Connection from Local Desktop Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

1. Edit the server section in **kube.config** to point to the Cluster API server public IP address or its FQDN.

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert_auth_data>
    server: https://<public-ip_or_fqdn>::<cluster_port> # typically 16443
  name: microk8s-cluster
contexts:
- context:
    cluster: microk8s-cluster
    user: admin
  name: microk8s
current-context: microk8s
kind: Config
preferences: {}
users:
- name: admin
  user:
    token: <cluster_token>
```

2. Verify if kube configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

3. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}

{% tab title="Bastion Host" %}

1. Set up SSH Tunnel locally to validate bastion host configuration

```
ssh -v -L <local_port>:<cluster_private_ip>:<cluster_port> <bastion_user>@<bastion_public_ip> -i <bastion-ssh-pem-file> -N
```

Eg:

```
ssh -v -L 16443:x.x.x.x:16443 ubuntu@y.y.y.y -i bastion.pem -N
```

2. Edit the **kube.config** file and make the server endpoint to point to the 127.0.0.1:\<local\_port>

{% hint style="info" %}
Do not replace 127.0.0.1 with localhost as the default Subject Alternative Names (SAN) in microk8s is configured only for IP address - 127.0.0.1 and not for DNS name - localhost.
{% endhint %}

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert_auth_data>
    server: https://127.0.0.1:<local_port> # eg. 16443
  name: microk8s-cluster
contexts:
- context:
    cluster: microk8s-cluster
    user: admin
  name: microk8s
current-context: microk8s
kind: Config
preferences: {}
users:
- name: admin
  user:
    token: <cluster_token>
```

3. Verify if tunnel configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

4. **IMPORTANT**: Use the **kube.config** file obtained under section "Copy Kubernetes Config file" to register the cluster in gopaddle.
   {% endtab %}
   {% endtabs %}

### 4. Register the Cluster in gopaddle

1. In the gopaddle UI, navigate to the **Clusters** section
2. Click on **Add a Cluster** and select **Register an existing Cluster**
3. In the Cluster registration wizard, select the **Cluster Access Method** as **Kube Config**&#x20;
4. Choose the **Cluster Provider** type as **Other**
5. In the **Authentication** Step, upload the Kubernetes config file obtained under section "Validate Connection from Local Desktop Environment"

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

6. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

7. Click on **Finish** to register the On-premises Cluster.
8. If you see the error - <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>, while view the cluster resources, then check this [troubleshooting](/troubleshooting/cluster-resource-view-issues/network-error-servererror-response-not-successful-received-status-code-503) section for more information.

[^1]: Enter public IP address of the Cluster API server


# Register Kind

Steps to register Kind Cluster in gopaddle

Kind cluster can be registered in gopaddle either using its public IP address or a fully qualified domain name (FQDN) or securely via a Bastion Host or a Jump server.

### 1. Port Configuration

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}
{% hint style="info" %}
In the steps to follow, we will be configuring Nginx server to proxy the requests to the Cluster API server. Make sure port the Nginx server port **(default 80)** is open to public.&#x20;
{% endhint %}
{% endtab %}

{% tab title="Bastion Host" %}

### Port Configuration

{% hint style="info" %}
In the steps to follow, we will be configuring Nginx server to proxy the requests to the Cluster API server. Make sure the Nginx server port **(default 80)** is open to the Bastion host and the Bastion host / Jump server SSH port (**default 22**) is open to public.
{% endhint %}
{% endtab %}
{% endtabs %}

### 2. Set up Nginx Proxy

1. Install Python3 and Pip, if not already installed.

```
sudo apt install python3 -y
sudo apt install python3-pip -y
python3 --version
```

2. Make a temporary directory to download the scripts

```
export TMP_DIR=$HOME/gp_temp/
mkdir -p $TMP_DIR
```

3. Set the cluster name

```
export CLUSTER_NAME=<cluster_name>
```

4. Download the script to extract the API server URL, CA Authority, Client certificate and key data from the default Kubernetes Configuration file.

```
curl -o $TMP_DIR/cluster-extract-config.py https://gpscripts.s3.amazonaws.com/cluster-extract-config.py
chmod +x $TMP_DIR/cluster-extract-config.py
```

5. Save the Kubernetes configuration in a temporary file named **kube.config**

```
sudo kind get kubeconfig --name=$CLUSTER_NAME > $TMP_DIR/kube.config
```

6. Verify if the extraction script works as expected.&#x20;

<pre><code><strong>python3 $TMP_DIR/cluster-extract-config.py API_SERVER_URL --tmp-dir $TMP_DIR
</strong></code></pre>

The output of this execution must result in a similar output like this - Eg output. `https://127.0.0.1:40773`  Note that the ports might differ based on the cluster configuration.

7. Install Nginx and set HTTP basic authentication for the user named **kind**.

```
sudo apt-get install apache2-utils -y
sudo mkdir /etc/nginx/
sudo htpasswd -c /etc/nginx/.htpasswd kind
```

8. Download the scripts to prepare the Nginx configuration and SSL certificate files

```
curl -o $TMP_DIR/cluster-setup-nginx-config.sh https://gpscripts.s3.amazonaws.com/cluster-setup-nginx-config.sh
chmod +x $TMP_DIR/cluster-setup-nginx-config.sh
```

9. Prepare the Nginx configuration and SSL certificate files

<pre><code><strong>sudo mkdir /etc/nginx/certs
</strong>sudo mkdir /etc/nginx/conf.d
sudo sh $TMP_DIR/cluster-setup-nginx-config.sh $TMP_DIR
</code></pre>

10. Install docker, if not already installed. Check the steps [here](https://docs.docker.com/engine/install/ubuntu/) to install docker.
11. Run Nginx container with the configuration and SSL certificate files.

```
sudo docker run -d --name nginx  --network host -v /etc/nginx/conf.d/:/etc/nginx/conf.d -v /etc/nginx/.htpasswd:/etc/nginx/.htpasswd -v /etc/nginx/certs/cluster.cert:/etc/nginx/certs/cluster.cert -v /etc/nginx/certs/cluster.key:/etc/nginx/certs/cluster.key nginx
```

12. Check if Nginx proxy works **(skip this step for bastion host setup)**

Open a browser session with the public IP address or the FQDN of the cluster master node. Eg. http\://\<public\_ip>

This must show a popup for authentication. Enter the Username as **kind** and password set in step 6.

<figure><img src="/files/SS2h7tG2ewnWaqr93L1S" alt=""><figcaption></figcaption></figure>

13. Copy the **kube.config** file to your local desktop environment

```
cat $TMP_DIR/kube.config
```

### 3. Validate Connection from Local Desktop Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

1. Edit the **kube.config** and replace the server with the Nginx endpoint with basic authentication like this - http\://\<httpd\_user>:\<http\_password>@\<public-ip\_or\_fqdn>&#x20;

{% hint style="info" %}
Based our Nginx configuration in this example, the protocol must be **http** and not **https**
{% endhint %}

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: http://kind:<http_passwd>@<public-ip_or_fqdn>
  name: kind-test
contexts:
- context:
    cluster: kind-test
    user: kind-test
  name: kind-test
current-context: kind-test
kind: Config
preferences: {}
users:
- name: kind-test
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

2. Verify if kube configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

```
$ kubectl get ns
NAME                 STATUS   AGE
default              Active   9m32s
kube-node-lease      Active   9m32s
kube-public          Active   9m32s
kube-system          Active   9m32s
local-path-storage   Active   9m28s
```

3. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}

{% tab title="Bastion Host" %}

1. Set up SSH Tunnel locally to validate bastion host configuration

```
ssh -v -L <local_port>:<cluster_private_ip>:<cluster_nginxx_port> <bastion_user>@<bastion_public_ip> -i <bastion-ssh-pem-file> -N
```

Eg:

```
ssh -v -L 8090:10.0.138.148:80 ubuntu@34.201.100.49 -i bastion.pem -N
```

2. Edit the **kube.config** and replace the server with the Nginx endpoint with basic authentication like this - http\://\<httpd\_user>:\<http\_password>@\<public-ip\_or\_fqdn>&#x20;

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: http://kind:<http_password>@127.0.01:<bastion_port> # eg.8090
  name: kind-test
contexts:
- context:
    cluster: kind-test
    user: kind-test
  name: kind-test
current-context: kind-test
kind: Config
preferences: {}
users:
- name: kind-test
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

3. Verify if tunnel configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

4. **IMPORTANT**: Revert the **kube.config** file such the server points to the private cluster IP address and the cluster port.&#x20;

```
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: http://kind:<http_password>@<cluster_private_ip>:80
  name: kind-test
contexts:
- context:
    cluster: kind-test
    user: kind-test
  name: kind-test
current-context: kind-test
kind: Config
preferences: {}
users:
- name: kind-test
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

4. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}
   {% endtabs %}

### 4. Register the Cluster in gopaddle

1. In the gopaddle UI, navigate to the **Clusters** section
2. Click on **Add a Cluster** and select **Register an existing Cluster**
3. In the Cluster registration wizard, select the **Cluster Access Method** as **Kube Config**&#x20;
4. Choose the **Cluster Provider** type as **Other**
5. In the **Authentication** Step, upload the Kubernetes config file gathered under section "**Validate Connection from Local Desktop Environment**"

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

6. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

7. Click on **Finish** to register the On-premises Cluster.
8. If you see the error - <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>, while view the cluster resources, then check this [troubleshooting](/troubleshooting/cluster-resource-view-issues/network-error-servererror-response-not-successful-received-status-code-503) section for more information.


# Register minikube

Steps to register minikube Cluster in gopaddle

minikube cluster can be registered in gopaddle either using its public IP address or a fully qualified domain name (FQDN) or securely via a Bastion Host or a Jump server.

### 1. Port Configuration

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}
{% hint style="info" %}
In the steps to follow, we will be configuring Nginx server to proxy the requests to the Cluster API server. Make sure port the Nginx server port **(default 80)** is open to public.&#x20;
{% endhint %}
{% endtab %}

{% tab title="Bastion Host" %}

### Port Configuration

{% hint style="info" %}
In the steps to follow, we will be configuring Nginx server to proxy the requests to the Cluster API server. Make sure the Nginx server port **(default 80)** is open to the Bastion host and the Bastion host / Jump server SSH port (**default 22**) is open to public.
{% endhint %}
{% endtab %}
{% endtabs %}

### 2. Set up Nginx Proxy

1. Install Python3 and Pip, if not already installed.

```
sudo apt install python3 -y
sudo apt install python3-pip -y
python3 --version
```

2. Install **pyyaml** dependency

```
pip install pyyaml
```

3. Make a temporary directory to download the scripts

```
export TMP_DIR=$HOME/gp_temp/
mkdir -p $TMP_DIR
```

4. Download the script to extract and expand the CA Certificate, Client Certificate and Key data in the Kubernetes configuration.

<pre><code><strong>curl -o $TMP_DIR/replace-cert-data.sh https://gpscripts.s3.amazonaws.com/replace-cert-data.sh
</strong>chmod +x $TMP_DIR/replace-cert-data.sh
</code></pre>

5. Install kubectl command line tool, if not installed already.

```
sudo snap install kubectl --classic
```

6. Install yq tool to filter Kubernetes YAML file contents.

```
sudo snap install yq
```

7. Run the replace script to extract and expand the CA Certificate, Client Certificate and Key data in the Kubernetes configuration

<pre><code><strong>sh $TMP_DIR/replace-cert-data.sh $TMP_DIR
</strong></code></pre>

8. Download the script to extract the API server URL, CA Authority, Client certificate and key data from the default Kubernetes Configuration file.

```
curl -o $TMP_DIR/cluster-extract-config.py https://gpscripts.s3.amazonaws.com/cluster-extract-config.py
chmod +x $TMP_DIR/cluster-extract-config.py
```

9. Verify if the extraction script works as expected.&#x20;

<pre><code><strong>python3 $TMP_DIR/cluster-extract-config.py API_SERVER_URL --tmp-dir $TMP_DIR
</strong></code></pre>

The output of this execution must result in a similar output like this - Eg output. `https://127.0.0.1:40773`  Note that the ports might differ based on the cluster configuration.

10. Install Nginx and set HTTP basic authentication for the user named **minikube**.&#x20;

```
sudo apt-get install apache2-utils -y
sudo mkdir /etc/nginx/
sudo htpasswd -c /etc/nginx/.htpasswd minikube
```

11. Download the scripts to prepare the Nginx configuration and SSL certificate files

```
curl -o $TMP_DIR/cluster-setup-nginx-config.sh https://gpscripts.s3.amazonaws.com/cluster-setup-nginx-config.sh
chmod +x $TMP_DIR/cluster-setup-nginx-config.sh
```

12. Prepare the Nginx configuration and SSL certificate files

<pre><code><strong>sudo mkdir /etc/nginx/certs
</strong>sudo mkdir /etc/nginx/conf.d
sudo sh $TMP_DIR/cluster-setup-nginx-config.sh  $TMP_DIR
</code></pre>

13. Install docker, if not already installed. Check the steps [here](https://docs.docker.com/engine/install/ubuntu/) to install docker.
14. Run Nginx container with the configuration and SSL certificate files.

```
sudo docker run -d --name nginx  --network host -v /etc/nginx/conf.d/:/etc/nginx/conf.d -v /etc/nginx/.htpasswd:/etc/nginx/.htpasswd -v /etc/nginx/certs/cluster.cert:/etc/nginx/certs/cluster.cert -v /etc/nginx/certs/cluster.key:/etc/nginx/certs/cluster.key nginx
```

15. Check if Nginx proxy works **(skip this step for bastion host setup)**

Open a browser session with the public IP address or the FQDN of the cluster master node. Eg. http\://\<public\_ip>

This must show a popup for authentication. Enter the Username as **kind** and password set in step 6.

<figure><img src="/files/SS2h7tG2ewnWaqr93L1S" alt=""><figcaption></figcaption></figure>

16. Copy the **kube.config** file to your local desktop environment

```
cat $TMP_DIR/kube.config
```

### 3. Validate Connection from Local Desktop Environment

{% tabs %}
{% tab title="Public Access (Public IP / FQDN)" %}

1. Edit the **kube.config** and replace the server with the Nginx endpoint with basic authentication like this - http\://\<httpd\_user>:\<http\_password>@\<public-ip\_or\_fqdn>&#x20;

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Based our Nginx configuration in this example, the protocol must be <strong>http</strong> and not <strong>https</strong></p></div>

```yaml
apiVersion: v1
clusters:
- cluster:
    certificate-authority-data: <cert-auth-data>
    server: http://minikube:<http_passwd>@<public-ip_or_fqdn>
  name: minikube
contexts:
- context:
    cluster: minikube
    user: minikube
  name: minikube
current-context: minikube
kind: Config
preferences: {}
users:
- name: minikube
  user:
    client-certificate-data: <client-cert-data>
    client-key-data: <client-key-data>
```

2. Verify if kube configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

3. **Use this kube.config file to register the cluster in gopaddle.**
   {% endtab %}

{% tab title="Bastion Host" %}

1. Set up SSH Tunnel locally to validate bastion host configuration

```
ssh -v -L <local_port>:<cluster_private_ip>:<cluster_nginxx_port> <bastion_user>@<bastion_public_ip> -i <bastion-ssh-pem-file> -N
```

Eg:

```
ssh -v -L 8090:10.0.138.148:80 ubuntu@34.201.100.49 -i bastion.pem -N
```

2. Edit the **kube.config** and replace the server with the Nginx endpoint with basic authentication like this - http\://\<httpd\_user>:\<http\_password>@\<public-ip\_or\_fqdn>

```yaml
apiVersion: v1
clusters:
  - cluster:
      server: http://minikube:<http_passwd>:localhost:<bastion_port> # Eg. 8090
      certificate-authority-data: <certificate-authority-data>
    name: minikube
contexts:
  - context:
      cluster: minikube
      namespace: default
      user: minikube
    name: minikube
current-context: minikube
kind: Config
preferences: {}
users:
  - name: minikube
    user:
      client-certificate-data: <client-certificate-data>
      client-key-data: <client-key-data>
```

3. Verify if tunnel configuration works.

```
export KUBECONFIG=$(pwd)/kube.config
kubectl get ns
```

4. **IMPORTANT**: Revert the **kube.config** file such the server points to the private cluster IP address and the cluster port.&#x20;

```yaml
apiVersion: v1
clusters:
  - cluster:
      server: http://minikube:<http_passwd>:<private_ip>:80
      certificate-authority-data: <certificate-authority-data>
    name: minikube
contexts:
  - context:
      cluster: minikube
      namespace: default
      user: minikube
    name: minikube
current-context: minikube
kind: Config
preferences: {}
users:
  - name: minikube
    user:
      client-certificate-data: <client-certificate-data>
      client-key-data: <client-key-data>
```

4. Use this **kube.config** file to register the cluster in gopaddle.
   {% endtab %}
   {% endtabs %}

### 4. Register the Cluster in gopaddle

1. In the gopaddle UI, navigate to the **Clusters** section
2. Click on **Add a Cluster** and select **Register an existing Cluster**
3. In the Cluster registration wizard, select the **Cluster Access Method** as **Kube Config**&#x20;
4. Choose the **Cluster Provider** type as **Other**
5. In the **Authentication** Step, upload the Kubernetes config file gathered under section "**Validate Connection from Local Desktop Environment**".

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

6. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

7. Click on **Finish** to register the On-premises Cluster.
8. If you see the error - <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>, while view the cluster resources, then check this [troubleshooting](/troubleshooting/cluster-resource-view-issues/network-error-servererror-response-not-successful-received-status-code-503) section for more information.


# Register Kubeadm Cluster

Steps to register a Cluster provisioned by kubeadm in gopaddle

1. Fetch the Kubernetes config file
2. Prepare the Kubernetes config file to register the cluster in gopaddle.

{% hint style="info" %}
If you don't have a Bastion Host setup and the **server** value in your Kubernetes config points to a private IP address, do the following:

a) Change the server value to a publicly accessible Cluster API Endpoint. b) Verify that the firewall allows traffic through the Cluster API port (usually 6443 or 16443). c) Check that the Cluster certificate includes the public IP address. This guide explains how to update the certSANs with the public IP: [Adding a name to Kubernetes API server certificate](https://blog.scottlowe.org/2019/07/30/adding-a-name-to-kubernetes-api-server-certificate/).

If you don't have a Bastion Host setup and the server value in your Kubernetes config points to a domain name, make sure there is a DNS entry that correctly resolves the cluster name.If you don't have a Bastion Host setup and the server value in your Kubernetes config points to a private IP address, do the following:

a) Change the server value to a publicly accessible Cluster API Endpoint. b) Verify that the firewall allows traffic through the Cluster API port (usually 6443 or 16443). c) Check that the Cluster certificate includes the public IP address. This guide explains how to update the certSANs with the public IP: [Adding a name to Kubernetes API server certificate](https://blog.scottlowe.org/2019/07/30/adding-a-name-to-kubernetes-api-server-certificate/).

If you don't have a Bastion Host setup and the server value in your Kubernetes config points to a **domain name**, make sure there is a DNS entry that correctly resolves the cluster name.
{% endhint %}

2. Verify if Kubernetes configuration works

```
export KUBECONFIG=<path to kubeconfig>
kubectl config view
```

3. In the gopaddle UI, navigate to the **Clusters** section

4. Click on **Add a Cluster** and select **Register an existing Cluster**

5. In the Cluster registration wizard, select the **Cluster Access Method** as **Kube Config**&#x20;

6. Choose the **Cluster Provider** type as **Other**

7. In the **Authentication** Step, upload the Kubernetes config file gathered in step 1.

   <figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

8. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.</p></div>

   <figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

9. Click on **Finish** to register the On-premises Cluster.

10. If you see the error - <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>, while view the cluster resources, then check this [troubleshooting](/troubleshooting/cluster-resource-view-issues/network-error-servererror-response-not-successful-received-status-code-503) section for more information.


# Register AWS EKS Cluster

{% hint style="info" %}
In case of gopaddle community edition, the installer automatically registers the local Kubernetes cluster in gopaddle. Upon upgrading the community edition to paid version, you can register additional clusters to gopaddle and start managing the clusters centrally from the gopaddle dashboard.

In case of SaaS or Enterprise edition, this section needs to be followed to register a cluster
{% endhint %}

{% hint style="info" %}
In case of SaaS or Enterprise edition, this section needs to be followed to register a cluster
{% endhint %}

If you already have a managed Kubernetes cluster like Amazon EKS or Azure AKS or an on-premise Kubernetes cluster, you can register and manage the cluster in gopaddle.

{% hint style="info" %}
Supported Kubernetes versions: v1.31
{% endhint %}

{% hint style="info" %}
Currently gopaddle uses SSH tunnel via Bastion Host to connect to an all private Kubernetes access type. This requires the SSH port on Bastion Host to be opened to the public internet. In case of AWS EKS clusters, gopaddle is working on a Secure Systems Manager (SSM) session based tunnelling to connect to an all private EKS cluster. This is a work in progress and will be rolled out in future releases.
{% endhint %}

## Registering an AWS EKS Cluster with gopaddle <a href="#h_57643de116" id="h_57643de116"></a>

1. Create an IAM User with least privileges. Let's call this User as the - gopaddle IAM User whose credentials will be used to register the EKS cluster with gopaddle.
   1. Create an IAM policy with the least privileges as defined [here](https://gp-cloudformation-roles.s3.amazonaws.com/eks-external-readonly.json);
   2. Create an IAM User with programmatic API access and associate the IAM policy defined.
   3. Grab the Access Key and the Secret Key of the IAM User. These credentials will be used to register the EKS Cluster in gopaddle.
2. Connect to the Kubernetes API server in your local desktop environment and update the Kubernetes Role Based Access Control (RBAC) to allow the gopaddle IAM User to access the Kubernetes resources.
   1. [Install AWS CLI ](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html)in your local environment
   2. [Install](https://kubernetes.io/docs/tasks/tools/install-kubectl-linux/) kubectl in your local environment
   3. Connect to your EKS Cluster using AWS CLI
      1. [Configure kubeconfig for EKS Cluster with public or public/private access point](/overview/register-a-cluster/register-aws-eks-cluster/eks-cluster-with-public-or-public-private-access-point)
      2. [Configure kubeconfig for EKS Cluster with private only access point](/overview/register-a-cluster/register-aws-eks-cluster/eks-cluster-with-private-access-endpoint-and-a-bastion-host)
3. In the AWS console, select the EKS cluster. Under the "**Access**" tab, add the access policy to the gopaddle IAM User created in step 1. Provide the "**AmazonEKSClusterAdminPolicy**" for the access scope to "**Cluster**". Click "**Add access policy**" and save.
4. In the gopaddle UI, navigate to the **Environments** section
5. Click on **Add a Cluster** and select **Register an external Cluster**

   In the **General** Step, ensure the Cluster Name is same as the EKS cluster name in the AWS Console and choose the **Cluster Provider** as AWS.

   <figure><img src="https://downloads.intercomcdn.com/i/o/633156482/237803249a1edb25cd4e11a7/eks-cluster-register-general.png" alt=""><figcaption></figcaption></figure>
6. In the **Authentication** Step, provide the gopaddle IAM User access credentials and the cluster access details.

   1. For an EKS cluster with public and public/private access endpoint - Provide the Certificate Authority data, the gopaddle IAM User credentials created in step 1, the EKS cluster endpoint and the ARN details.
   2. For an EKS cluster with private access endpoint - Skip TLS Verification and provide the gopaddle IAM User credentials created in step 1, the EKS cluster endpoint and the ARN details.

   <figure><img src="https://downloads.intercomcdn.com/i/o/634045725/1f7f278ae725720e4686fe74/Screen+Shot+2022-12-13+at+2.09.33+AM.png" alt=""><figcaption></figcaption></figure>
7. In the Bastion Host Step, either skip or configure the bastion host details based on the EKS cluster access type.

   1. For an EKS cluster with public and public/private access endpoint - In the Bastion Host Step, skip the *Use Bastion Host ?* configuration and click on Finish.
   2. For an EKS cluster with private access endpoint - Provide the bastion host public IP, SSH port, upload the bastion host PEM file and click on **Finish**.

   <figure><img src="https://downloads.intercomcdn.com/i/o/634046122/a4666d623e9b1917d1878c88/Screen+Shot+2022-12-13+at+2.11.17+AM.png" alt=""><figcaption></figcaption></figure>

### Firewall Access <a href="#h_e7a890f9a6" id="h_e7a890f9a6"></a>

gopaddle connects with the Kubernetes cluster using the Kubernetes API server endpoint specified at the time of registration. Hence ensure that the INBOUND firewall ports are open for the kubernetes master IP and the port for INGRESS type for global CIDR (0.0.0.0/0).

In case of registering the cluster via Bastion Host, ensure that the SSH tunnel port is opened for the SSH server IP and port for INGRESS type for global CIDR (0.0.0.0/0).


# EKS Cluster with public or public/private access point

Follow the instructions [here](https://docs.aws.amazon.com/eks/latest/userguide/create-kubeconfig.html) to connect to your EKS cluster. For example, you can configure the AWS CLI to use the credentials of the IAM User who created the EKS Cluster and update the kubeconfig file in the local machine as below:

```sh
aws configure
aws eks update-kubeconfig --region <eks-region> --name <eks-cluster-name>
```


# EKS Cluster with private access endpoint and a bastion host

You can connect to the private Kubernetes access endpoint via Systems Manager Session.

{% hint style="info" %}
Bastion Host must be within the same VPC as the EKS cluster and must have access to the Kubernetes API server endpoint.
{% endhint %}

{% hint style="info" %}
INBOUND access to port 22 of the Bastion Host must be open.
{% endhint %}

1. Create a Systems Manager Host Configuration for the bastion host. You can follow the [AWS Systems Manager Quick Start guide](https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-quick-setup.html) to create a host configuration for the bastion host.

   For example, you can open this link in the browser. https\://\<eks-region>.console.aws.amazon.com/systems-manager/quick-setup?region=\<eks-region>

   Choose Create to create a new Host Configuration

   <figure><img src="https://downloads.intercomcdn.com/i/o/634520321/c65a2209192c7d05ef8c6ffb/Screen+Shot+2022-12-13+at+12.33.25+PM.png" alt=""><figcaption></figcaption></figure>

   Choose Host Management Option and choose Create;

In the creation wizard, select the instances based on the tags or select the instance ID manually and choose Create.

<figure><img src="https://downloads.intercomcdn.com/i/o/634521973/f3bee0150353735c097f7e3c/Screen+Shot+2022-12-13+at+12.35.26+PM.png" alt=""><figcaption></figcaption></figure>

Once the Host Configuration is complete, proceed with the next steps.You can connect to the private Kubernetes access endpoint via Systems Manager Session.

2. [Install SSM Agent](https://docs.aws.amazon.com/systems-manager/latest/userguide/sysman-manual-agent-install.html) in the Bastion Host. For example, you can run these commands in an Ubuntu 18.04 based Bastion Host.

```sh
ssh -i <pemfile> ubuntu@<bastionhost-public-ip>
sudo apt update
sudo snap install amazon-ssm-agent --classic
sudo snap switch --channel=candidate amazon-ssm-agent
sudo snap start amazon-ssm-agent
sudo snap services amazon-ssm-agent
```

You should be able to see the ssm agent is listed as below.

```
Service Startup Current Notes 
amazon-ssm-agent.amazon-ssm-agent enabled active -
```

Note: If the ssh to the bastion host fails with this error, make sure the port 22 is open in the security group for INBOUND access from global CIDR 0.0.0.0/0

`ssh: connect to host <bastionhost-public-ip> port 22: Operation timed out`

3. [Install SSM plugin](https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager-working-with-install-plugin.html#install-plugin-debian) in your local machine
4. Create an SSM IAM User with the SSM priviledges - *AmazonSSMFullAccess* and provide programatic access to the AWS APIs.
5. Grab the SSM IAM User credentials.
6. In your local machine, configure the SSM IAM User and the EKS region.

   ```sh
   aws configure
   ```

Make sure the Access Key, Secret Key and the Region are added to the \~/.aws/config file.

```sh
cat ~/.aws/config 
[default]
aws_access_key_id=<SSMUser_ACCESS_KEY>
aws_secret_access_key=<SSMUser_SECRET_KEY>
region = <EKS_REGION>
```

7. In your local machine, start the SSM port forwarding session.

```sh
aws ssm start-session --target <instance ID of the bastion host> --document-name AWS-StartPortForwardingSessionToRemoteHost  --parameters '{"host":["EKS API Server endpoint DNS Name"],"portNumber":["443"], "localPortNumber":["9444"]}'
```

If you get the below error, make sure the EKS point is just a DNS Name and NOT a URL.

```sh
SessionId: gp-ssm-user-0057180c6d1d1ec44 : lookup https://CC725FE9FA351D0C306F597C47491BE7.gr7.us-east-1.eks.amazonaws.com: no such host
```

8. Form the Kubernetes Configuration file - *kube.conf*. Edit the template below and replace the configurations based on your EKS cluster

```yaml
---
apiVersion: v1
clusters:
- cluster:
    server: https://localhost:9444
    insecure-skip-tls-verify: true
  name: <EKS_CLUSTER_ARN>
contexts:
- context:
    cluster: <EKS_CLUSTER_ARN>
    user: cluster/<EKS_CLUSTER_NAME>
  name: <EKS_CLUSTER_ARN>
current-context: <EKS_CLUSTER_ARN>
kind: Config
preferences: {}
users:
- name: cluster/<EKS_CLUSTER_NAME>
  user:
    exec:
      apiVersion: client.authentication.k8s.io/v1beta1
      args:
      - --region
      - <EKS_REGION>
      - eks
      - get-token
      - --cluster-name
      - <EKS_CLUSTER_NAME>
      command: /usr/local/bin/aws
      env:
      - name: AWS_ACCESS_KEY_ID
        value:  <EKS_OWNER_ACCESS>
      - name: AWS_SECRET_ACCESS_KEY
        value: <EKS_OWNER_SECRET>
```

{% hint style="info" %}
AWS does not accept localhost as a SAN IP (Subject Alternative Name) for the EKS Cluster. Because of this, the certificate authority data in the Kubernetes config file cannot be used when querying the Kubernetes API server via a tunneling proxy. We need to skip the TLS verification in this scenario.
{% endhint %}

9. Set the Kubernetes configuration file.

```sh
export KUBECONFIG=kube.conf
```

Once configured, Check Cluster Connectivity to proceed further.


# Validate Cluster Connectivity

Before validating the EKS Cluster Connectivity, make sure the kubeconfig file is configured in the local machine. Follow these steps to configure kubeconfig file.

* [Configure kubeconfig for public or public/private access point](/overview/register-a-cluster/register-aws-eks-cluster/eks-cluster-with-public-or-public-private-access-point)
* [Configure kubeconfig for private only access point](/overview/register-a-cluster/register-aws-eks-cluster/eks-cluster-with-private-access-endpoint-and-a-bastion-host)

&#x20;Check the EKS  Cluster connectivity by executing the command below

```sh
kubectl cluster-info
Kubernetes control plane is running at https://localhost:9444
CoreDNS is running at https://localhost:9444/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy
```

## Troubleshoot Cluster Connectivity

1. If the cluster-info command fails, to debug and diagnose cluster problems, use 'kubectl cluster-info dump'.
2. If the *cluster-info* command fails with the below error make sure the INBOUND access to port 443 from the Bastion Host Security Group is open in the Additional Security Group of the EKS cluster.

   ```
   W1213 13:04:18.835859   17344 transport.go:243] Unable to cancel request for *exec.roundTripper
   I1213 13:04:18.835992   17344 versioner.go:56] Remote kubernetes server unreachable
   ```

Edit the Additional Security Group in the EKS Network Configuration.

<figure><img src="https://downloads.intercomcdn.com/i/o/634569279/31c84ef8fd4df67c1cf8294e/Screen+Shot+2022-12-13+at+1.20.33+PM.png" alt=""><figcaption></figcaption></figure>

Add the INBOUND Access to the Bastion Host Security Group

<figure><img src="https://downloads.intercomcdn.com/i/o/634570616/c074e4c779606c44bdce233c/Screen+Shot+2022-12-13+at+1.40.22+PM.png" alt=""><figcaption></figcaption></figure>


# Register Azure AKS Cluster

1. In order to register an Azure Cluster, you must first register the Azure Cloud Account in gopaddle. Follow [these](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/register-cloud-account/azure) steps to register the Azure Cloud Account.
2. Download and install Azure CLI by following [these](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli) steps.
3. Login to Azure account and get the KubeConfig to access the cluster:

```sh
az login
az account set --subscription <subscription-id>
KUBECONFIG=./aks.config az aks get-credentials --resource-group <resource-group-name> --name <azure-cluster-name> --overwrite-existing
```

{% hint style="info" %}
If you don't have a Bastion Host setup, and if the **`server`** value in the Kubeconfig points to a private IP address:

a) Replace the **`server`** value to a publicly accessible Cluster Master API Endpoint

b) Make sure the firewall is open for the Cluster Master API port

c) Make sure the Cluster certificate is attached to the Public IP. Here is an example of how to update the certSANs with the public IP. - <https://blog.scottlowe.org/2019/07/30/adding-a-name-to-kubernetes-api-server-certificate/>
{% endhint %}

3. In the gopaddle UI, navigate to the **Environments** section and click on **Add a Cluster**.
4. Choose **Register an existing Cluster**
5. Provide the cluster name. The cluster name must match the AKS Cluster name in the azure portal.
6. Select the **Cloud Provider** as **Azure**
7. Select the **Azure Cloud Account** registered in step 1 and Provide the **Subscription ID** and the **Resource Group Name**

<figure><img src="/files/tS9GEyhGIGcez14yEGCM" alt=""><figcaption><p>Register Azure AKS Cluster in gopaddle</p></figcaption></figure>

8. In the **Authentication** Step, upload the Kubeconfig file gathered in step 2.

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

8. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

8. Click on **Finish** to register the AKS Cluster.

<br>


# Register Google GKE Cluster

{% hint style="warning" %}
In case of gopaddle community edition, the installer automatically registers the local Kubernetes cluster in gopaddle. Ignore this section if you are running a community edition

In case of SaaS or Enterprise edition, this section needs to be followed to register a cluster
{% endhint %}

1. Install [gcloud CLI](https://cloud.google.com/sdk/docs/install) in your local environment
2. Install **jq**. For instance, you can install **jq** in Ubuntu environments, as below:

```sh
apt update
apt install jq
```

3. Login to your Google Cloud account using gcloud command line utility. For more information check out - <https://cloud.google.com/sdk/gcloud/reference/auth>

```sh
gcloud auth login
```

4. Export the KUBECONFIG environment variable and describe the GKE cluster. This writes the kubernetes configuration to the file specified in the KUBECONFIG environment variable.

```sh
KUBECONFIG=./gke.config  gcloud container clusters describe <clustername> --zone <cluster-zone> --project <project-name> --format json | jq '.masterAuth.clusterCaCertificate'
```

{% hint style="info" %}
If you don't have a Bastion Host setup, and if the **`server`** value in the Kubeconfig points to a private IP address:

a) Replace the **`server`** value to a publicly accessible Cluster Master API Endpoint

b) Make sure the firewall is open for the Cluster Master API port (default 443)

c) Make sure the Cluster certificate is attached to the Public IP. Here is an example of how to update the certSANs with the public IP. - <https://blog.scottlowe.org/2019/07/30/adding-a-name-to-kubernetes-api-server-certificate/>
{% endhint %}

5. Navigate to the **Environments** section.
6. Click on **Add a Cluster** and choose **Register an existing Cluster**.
7. Provide the Google GKE Cluster name. The cluster name must match the cluster name in the Google portal.
8. Choose the Cloud provider as **Google**. Select the Cloud Account and the Google project ID and the Regions.

<figure><img src="/files/KtX5wb13plIkQ4RQqXDV" alt=""><figcaption></figcaption></figure>

9. In the **Authentication** Step, upload the Kubeconfig file gathered in step 2.

<figure><img src="/files/FCrjUeLC0TY8PM17mT4F" alt=""><figcaption><p>Upload the Kubeconfig file</p></figcaption></figure>

10. If you have configured a bastion host, provide the Bastion Host IP, SSH Pem file, SSH port

{% hint style="info" %}
If you are using a Bastion Host setup, make sure the Bastion Host IP and Port are accessible publicly. If you are looking for a private only setup, get in touch with us to  explore gopaddle Enterprises.
{% endhint %}

<figure><img src="/files/xXy7XylFkZIet6s4eyKS" alt=""><figcaption><p>Provide the Bastion Host Connection Details</p></figcaption></figure>

11. Click on **Finish** to register the GKE Cluster.


# Register Huawei Cloud Container Engine

How to build and deploy container workloads to Huawei Cloud Container Engine using gopaddle

Huawei Container Service can be securely registered with gopaddle as an external cluster via Bastion Host. To use the Huawei Cloud Container Engine with gopaddle, a Bastion host needs to be created in the same region and VPC as the Cloud Container Engine.

## Create an Elastic Cloud Server as bastion host <a href="#h_bce8559810" id="h_bce8559810"></a>

a) From the Huawei cloud console, create an Elastic Cloud Server. While creating an Elastic Cloud Server, choose the VPC where the Cloud Container Engine exists or is about to be created.

b) Choose the Public sub-net to access the Cloud Server.

c) Add tcp:5443 in the inbound security group rules to forward the requests on port 5443 to kubernetes API server.

<figure><img src="https://downloads.intercomcdn.com/i/o/316511702/7952f0c838d8c22f740467e4/Screenshot+2021-03-26+at+11.51.23+AM.png?expires=1619611200&#x26;signature=c1227936de1226efbf9371b70ba5dd6d9495f594a17e967cf3565b0431ec25c1" alt=""><figcaption></figcaption></figure>

d) Assign an EIP to the Elastic Cloud Server, so that it can be accessed publicly.

[![](https://downloads.intercomcdn.com/i/o/316511812/833e6dc6ebb50b25a7356413/Screenshot+2021-03-26+at+11.51.46+AM.png?expires=1619611200\&signature=f6c04652b1f6f94957f9573ec739e6dcf90e7d1d379a403005c1a5f8bc82b633)](https://downloads.intercomcdn.com/i/o/316511812/833e6dc6ebb50b25a7356413/Screenshot+2021-03-26+at+11.51.46+AM.png?expires=1619611200\&signature=f6c04652b1f6f94957f9573ec739e6dcf90e7d1d379a403005c1a5f8bc82b633)

e) Generate a keypair to access the Elastic Cloud Server

<figure><img src="https://downloads.intercomcdn.com/i/o/316511851/9672be6f6b1f888770072586/Screenshot+2021-03-26+at+11.53.29+AM.png?expires=1619611200&#x26;signature=71ab89548877f4e77bf643f566aa5ab87b971a0ad1b4df41cec3f63188563408" alt=""><figcaption></figcaption></figure>

## Create a Cloud Container Engine cluster <a href="#h_a9aaeb25dd" id="h_a9aaeb25dd"></a>

f) From the Huawei console, create a Cloud Container Engine cluster. While creating the cluster, choose the Automatically assign EIP to the nodes.

<figure><img src="https://downloads.intercomcdn.com/i/o/316515832/88a93d534cd2b904a60e5a63/Screenshot+2021-03-26+at+12.02.12+PM.png?expires=1619611200&#x26;signature=4bb945d01ae493aba5acc407be29671676af783797af3972fa0e4d7546f33902" alt=""><figcaption></figcaption></figure>

g) Once the cluster moves to Running state, download the kubeconfig file from the kubectl section

```
Ensure the Public API Server address is NOT bound before downloading the kubeconfig file.
```

<figure><img src="https://downloads.intercomcdn.com/i/o/316516332/56383dec02d9d0b0fc0bbec0/Screenshot+2021-03-26+at+12.11.59+PM.png?expires=1619611200&#x26;signature=a8dbecee1e18ee5e6dc6902f7c5900ae00ccf7a43339dbecbb5aaad853cf3c34" alt=""><figcaption></figcaption></figure>

h) Once the kubeconfig file is downloaded, note down the cluster Internal API Server Address address

<figure><img src="https://downloads.intercomcdn.com/i/o/316558153/b216fb09cf5158778ebe4b3f/Screenshot+2021-03-26+at+2.50.44+PM.png?expires=1619611200&#x26;signature=3c5f9f8c4ca9c905f553c0e289d1f70a2f71a00c09a43288e2efef75598ddce1" alt=""><figcaption></figcaption></figure>

## Create a Load Balancer with Elastic IP <a href="#h_d48ca5a71b" id="h_d48ca5a71b"></a>

i) If you wish to deploy applications with Ingress and Loadbalancer, create a Loadbalancer from the Huawei cloud console and note down the Loadbalancer ID and the IP Address.

<figure><img src="https://downloads.intercomcdn.com/i/o/317459403/6fc9a39c21ac245e521a096c/Screenshot+2021-03-29+at+5.07.45+PM.png?expires=1619611200&#x26;signature=f0f212d5d981a4087975b037ad4500fefeed19ec1b8c375c5c759a08ef30720c" alt=""><figcaption></figcaption></figure>

## Register the ECS cluster in gopaddle portal via bastion host <a href="#h_2043d2dfe0" id="h_2043d2dfe0"></a>

j) From the gopaddle console, navigate to the cluster section to register an external cluster.

In the registration wizard, provide the kubernetes master IP address noted from the earlier step (h) as the Host IP Address and the port.

k) Select the Provider Type as Huawei.

l) Choose the Bastion Host Connection type

[![](https://downloads.intercomcdn.com/i/o/316533147/ccc174d986b86df5b9ab5023/Screenshot+2021-03-26+at+10.51.18+AM.png?expires=1619611200\&signature=e6e3b053a6067ded495c023bb847fb8a67815d5a19bf329d7a9b4b5b9f4684eb)](https://downloads.intercomcdn.com/i/o/316533147/ccc174d986b86df5b9ab5023/Screenshot+2021-03-26+at+10.51.18+AM.png?expires=1619611200\&signature=e6e3b053a6067ded495c023bb847fb8a67815d5a19bf329d7a9b4b5b9f4684eb)

m) In the Kubernetes API Server details, choose the Authentication Type as config

n) Choose the kubeconfig file downloaded in step (g)

o) Provide the EIP of the Elastic Container Server, its SSH User, SSH Port 22 and the SSH Key file generated in step (e). Register the cluster.

[![](https://downloads.intercomcdn.com/i/o/316533023/e31a3f097df076d87a96f937/Screenshot+2021-03-26+at+11.19.18+AM.png?expires=1619611200\&signature=2414e41117963f6a1da66eae54741b00ab34f6bc101f7f1a6b4d4ffe94ed367a)](https://downloads.intercomcdn.com/i/o/316533023/e31a3f097df076d87a96f937/Screenshot+2021-03-26+at+11.19.18+AM.png?expires=1619611200\&signature=2414e41117963f6a1da66eae54741b00ab34f6bc101f7f1a6b4d4ffe94ed367a)

Once the cluster is registered, it can be used for build and deploying applications.

p) While launching an application on Huewai cluster, if you choose to access the application using ingress and LoadBalancer, provide the LoadBalancer ID and IP created in step (i) in the Deployment Template launch wizard.

<figure><img src="https://downloads.intercomcdn.com/i/o/317459595/ef2563ccfeaa7432b57723e7/Screenshot+2021-03-29+at+5.10.10+PM.png?expires=1619611200&#x26;signature=36d2d0d47ac45f399231018fe844130c1c814e727f6cf9f6479934fce2732ce7" alt=""><figcaption></figcaption></figure>

Once the application is launched, map the public IP of the Huawei load balancer to the domain name in your domain service provider.

## Launching a stateful application in Huawei Container Service <a href="#h_1a5f6c9e1d" id="h_1a5f6c9e1d"></a>

a) Create an EVS Volume in the Huawei cloud console. Under the Elastic Container Service, choose the Resource Management Option and select storage to provision an EVS Volume.

[![](https://downloads.intercomcdn.com/i/o/316532544/c6008943bec8728c105fd2b9/Screenshot+2021-03-26+at+11.21.49+AM.png?expires=1619611200\&signature=ee95713470905d13be0e0a3eee4725ec8798033e878b55051950459e5c44a1f7)](https://downloads.intercomcdn.com/i/o/316532544/c6008943bec8728c105fd2b9/Screenshot+2021-03-26+at+11.21.49+AM.png?expires=1619611200\&signature=ee95713470905d13be0e0a3eee4725ec8798033e878b55051950459e5c44a1f7)

b) From the gopaddle console, create a Provision Policy by choosing the region and the zone where the Cloud Container Engine exists.

<figure><img src="https://downloads.intercomcdn.com/i/o/316532234/099bf16cf575034d9b072f06/Screenshot+2021-03-26+at+1.31.28+PM.png?expires=1619611200&#x26;signature=95826ff4083190231961fd769057c0408081569230ac5ee871be66563aebcf9c" alt=""><figcaption></figcaption></figure>

c) At the time of launching the application from the gopaddle portal, choose the Huawei provision policy created in the earlier step.

<figure><img src="https://downloads.intercomcdn.com/i/o/316517503/1b03eb1aded7681bbe249a11/Screenshot+2021-03-26+at+11.29.43+AM.png?expires=1619611200&#x26;signature=a254f97cbaea8c565562344810100bc5b88001777dbee9c8e6a6ca47857dde9b" alt=""><figcaption></figcaption></figure>


# Register GitHub Account

This page provides a step-by-step guide on how to register your GitHub account with our platform, enabling you to access and manage runbook hubs for context-driven troubleshooting documentation

Registering a GitHub account with gopaddle allows you to unlock the full potential of runbook hubs for efficient, context-aware troubleshooting. Discover existing hubs or easily create new ones for streamlined documentation and faster issue resolution. Follow the steps to create a repository in GitHub account and register the GitHub account

### Step 1 - Create a new private repository

Create a new private repository (**say demo-hub**) in a GitHub account that would act as a Runbook Hub.

### Step 2 - Create a GitHub Access Token

Create an access token in the GitHub account with permission to read the repository.

1. Select the user profile in GitHub account and click on **Settings**
2. In the **Settings** page, select **Developer Settings** in the left panel.
3. Choose **Personal access tokens** and **Tokens (classic)**

<div align="left"><figure><img src="/files/Dr5q8OLInAuR8VykTi0p" alt="" width="311"><figcaption></figcaption></figure></div>

4. Select **Generate new token** and **Generate new token (classic)**
5. Add a note “gopaddle runbook access” to the token for future reference
6. Under **Select scopes**, choose **repo**.

<figure><img src="/files/ysC7kkWnpxs5PmO2mdo6" alt=""><figcaption></figcaption></figure>

7. Copy the token

### Step 3 - Register Source Control Account

1. In the gopaddle UI, in the left panel under **Settings**, choose **Code** and then **Accounts**
2. Choose **Register Source Control Account**
3. Select **Token** and provide the GitHub token

<div align="left"><figure><img src="/files/te0zcZzquj9pWuV9Iowx" alt="" width="375"><figcaption><p>Register GitHub Account in gopaddle</p></figcaption></figure></div>

4. Click **Register**: This will register and discover any pre-existing runbook hubs (ie., repositories with **.gp.yaml**). If there are no pre-existing hubs, a new hub can be created at a later stage.


# Register Jira Account

This page outlines the process for registering a Jira account, enabling users to seamlessly create support tickets directly from AI Assistant troubleshooting tips within the chat window for efficient issue resolution.

1. Generate an API token in Jira account by following the steps [here](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/)
2. In the Jira account, make sure a project exists and it has an Issue Type as Bug. Navigate to the Project Settings&#x20;

![](https://lh7-us.googleusercontent.com/F9f9sicMCUnS9gISaMKVUzVaCmY5UBeKve_e9uq5YUJGLnzD2o0ivexZgs9jdRuARYCe6XO-G5EGn374ZmqbJRGRCX-jHwoAuL0_DZOBxpsnGlPYrC9Djd7LyKdwyA4cQ4paUt0tfuFVRMWBvKHAvaQ)

3. Click on **“Add issue type”** to create an Issue Type as **“Bug”**

![](https://lh7-us.googleusercontent.com/GD20tukD8ugbLAyOfcpA0lfiaderY3f7GWIV159Ltvjv1Z40cR9H2a_Y2wS8-rVjGW6YM-O9SiVwPkfFBo68_Nj-fMmDJ_OGXyoOSnsauN9PLbUXi9ey2pTTg6VoCtR8cxGM5e594HXRMjxMvL1zzoo)

4. In gopaddle UI, under **Settings**, navigate to **Jira**
5. Choose **Add Jira** to create a new Jira account
6. Add the Jira domain, registered Jira email and the API token and click on **Create** to register the account in gopaddle

<figure><img src="https://lh7-us.googleusercontent.com/q35uJ0JDD-iu42phyela_foMuxZJjwJW2yjd8I15nvdU_ohSSinL4Wp2wMfHDnw53apWUnF2pf_M5IZbM0GcJt8Vx46oa4IOnr6RA1o_ose2ovhHfGQEQrq0SafZi4Eq7ouidSL4ySfXSova-DNQhQs" alt=""><figcaption><p>Register a Jira Account</p></figcaption></figure>

\
\
\ <br>


# Register ChatGPT Assistant

This page guides you on integrating gopaddle's AI Assistant in gopaddle.

Registering gopaddle's AI Assistant transforms your Kubernetes management experience, providing expert interactive troubleshooting and advice, all while meticulously safeguarding your sensitive information. Follow these steps to register a ChatGPT AI Assistant in gopaddle.

1. Generate an API token in OpenAI account
2. In gopaddle UI, under **Settings**, choose **ChatGPT**
3. Choose **Create ChatGPT Assistant**

<div align="left"><figure><img src="/files/FusoXk9rFXKBxjlAme2O" alt="" width="354"><figcaption><p>Create ChatGPT Assistant</p></figcaption></figure></div>

4. Provide a name, description,  OpenAI API token and select a model name.

<div align="left"><figure><img src="/files/2XNv9uzttpiHKczKRHMj" alt=""><figcaption><p>Choose AI type, model and provide API key</p></figcaption></figure></div>

4. Click on **Add** to add the AI assistant to gopaddle


# Kubernetes IDE

Kubernetes IDE streamlines cluster management with intuitive navigation, advanced filtering, and developer tools like container logs and terminals, enhancing troubleshooting and operational efficiency

Kubernetes IDE offers a comprehensive platform for developers and DevOps teams to efficiently navigate, view, and interact with the resources and events managed within a Kubernetes cluster.

#### Key Features:

* **Easy Navigation of Cluster Resources and Events:** Users can quickly access cluster details through a user-friendly interface, navigating to the Clusters section and diving into the specifics of localhost or any cluster listed. This central access point simplifies the process of monitoring and managing cluster resources.
* **Enhanced Visibility with Filtering Options:** The IDE provides options to list and filter resources and events, including those associated with runbooks, through a simple click. Whether you're looking at resources or specific Kubernetes events, the tool offers tailored filtering options to streamline your view.
* **Versatile Viewing Modes - Flat vs. Tree View:** Users can toggle between Flat and Tree views. The Flat view lists resources without showing their parent/child relationships, while the Tree view organizes resources hierarchically, offering a clearer understanding of dependencies and associations among resources.
* **Advanced Filtering Capabilities:** The IDE allows for sophisticated filtering of resources and events using JSONPathSelectors and LabelSelectors. This means users can quickly find exactly what they're looking for by specifying criteria that match resource specifications or metadata labels.
* **Viewing and Editing Resources with Ease:** gopaddle supports viewing and editing of resources through two main editors - a YAML Editor for direct manipulation of the YAML specification, and an OpenAPI Schema Form for a more structured and guided editing experience. While events can be viewed for detailed diagnostics, they cannot be edited.
* **Developer Tools: Container Logs and Terminal:** Gain instant access to live logs from your containers, providing real-time insights into application behavior and performance.

#### How These Capabilities Help:

This Kubernetes IDE facilitates a more intuitive and efficient management of Kubernetes environments. By simplifying navigation, offering flexible viewing and filtering options, and providing powerful editing tools, it empowers users to:

* **Quickly Diagnose and Resolve Issues:** With easy access to resources, events, and associated runbooks, teams can swiftly identify and address issues within their clusters.
* **Optimize Cluster Organization:** The Flat and Tree views help users understand the structure and relationships of their deployments, enhancing cluster organization and planning.
* **Customize and Control Resource Management:** Advanced filtering options and editing capabilities allow for precise control over resources, enabling tailored management strategies that fit specific operational needs.

### Efficient Navigation and Management of Kubernetes Resources and Events

Resources and events managed by a cluster can be viewed by navigating to the Cluster page.

* Navigate to the **Clusters** section in the left navigation panel and click on cluster name to view the cluster
* Click on **View -> Resources** to list all the resources discovered under the cluster.&#x20;

<div align="left"><figure><img src="/files/GlIWiu2pu0hAIJUxtt4Y" alt=""><figcaption><p>Cluster  - View Resources</p></figcaption></figure></div>

* This section  describes the different options available to navigate the kubernetes resources and events efficiently.

<figure><img src="https://lh7-us.googleusercontent.com/77vwawIq-di7IaeJOZfSsyj7fApryMzrmscAFBedhryAb8QRWt8PGsteAmuAeLss01tIkDhKbQBlJuiQXrl3CPIIhNQ8KBUPe75dAeQOuHM87zjbV7TMoNW9x0glpMteAyxY_l0UuHNzQLXO61ujdJk" alt=""><figcaption><p>Resource Filtering Options</p></figcaption></figure>


# Filters

### Filtering Resources and Events

1. **Using Hyperlinks:** Resources and events can be filtered **by clicking on the links and labels** in the resources table.

<figure><img src="/files/QgAik2Dfz7Iiy13jKpko" alt=""><figcaption><p>Cluster Filter Links</p></figcaption></figure>

2. **Using Filters:**\
   Resources and Events can be filtered using 2 types of filters
   1. **JSONPathSelector:** JSON path in a resource specification. Eg.`{.reason}=BackOff` (or) `{.status.phase}=Pending`
   2. **LabelSelector:** A key / value pair that matches the labels in the resource metadata. Eg. `app=image-pull-failure-pod`

### Filtering Resources with Runbooks

This option helps to filter the resources and events (when View Events option is enabled) that have one or more runbooks associated with them.

<figure><img src="/files/DOqHlBLMBAF6i5cUYR9U" alt=""><figcaption><p>Filter Kubernetes Resources with Runbooks</p></figcaption></figure>


# Editor

Only resources can be viewed and edited. Events can only be viewed but not edited. gopaddle offers 2 types of editors:

1. **YAML Editor:** Click on the view icon<img src="https://lh7-us.googleusercontent.com/wBAKNMpI990XUJjgUnfffwnZUKdPRXcDcRY9LWTRqgx-2fnwRL3mqm1G0d2Ra2MFAddoYZdUTnE-1R9pjFID9fVd902PgEdAHXUzXLdsF8JfLb63-kKArg8Fkb1psovRuyYmkGYlRx2R285faKG6ijk" alt="" data-size="line"> to view and edit the YAML specification of the resource.

<figure><img src="/files/0g6iTSx5tWaTrJv6pOSB" alt=""><figcaption><p>YAML Editor</p></figcaption></figure>

2. **OpenAPI Schema Form:** Click on the editor icon<img src="https://lh7-us.googleusercontent.com/dBsrlx3-nsBp8PYa7L9XsZDOyC2jrDC0IvVjki5SzXBJQKwk3LnAYa3qSu6Yk7_P9i9z9yJNtP3SjT7xtc3rpX6JEp6Ntvf7WmwBFYy6yVB4sH26V82FNVkoi7ED10DdYjYWaaQCAf1fuA8CJKmi73U" alt="" data-size="line"> to view and edit the resource using an OpenAPI schema form based editor.

<figure><img src="/files/SpYB8tnDfByLaZpDUTcF" alt=""><figcaption><p>OpenAPI Schema Editor</p></figcaption></figure>


# Flat vs Tree View

By default, the resources and events will be listed in a flat view ie., without a parent/child association. By enabling **Tree View**, gopaddle renders the resources in a hierarchical format.

**Eg. Flat view for Deployments**

<figure><img src="/files/xfUHXsUcBj4jzbYLaeoa" alt=""><figcaption><p>Cluster Flat View</p></figcaption></figure>

**Eg. Tree view for Deployments**

<figure><img src="https://lh7-us.googleusercontent.com/BfnP9PieOfozZENFaFSfi3M2z723rO-FjhpmTBWaK0lednxZzwjmO9mnW47e1GUT3aueD5Un5_Fw49Iaw80zqPhVbBXxEcodZnpwpg-7mI72BgH1Mwfw2ztWOdn8zdED8vzD07cjS-Slgq7Inoxym7I" alt=""><figcaption><p>Tree View</p></figcaption></figure>

{% hint style="info" %}
**Performance Considerations**

Tree View is a resource intensive operation and thus can be slow. However, tree view is helpful in situations where the users need additional context during troubleshooting. Check [Enhancing contents of runbooks](/overview/runbook-hub/enhancing-contents-of-runbooks-with-ai) and [AI Chat](/overview/ai-assistant/chat-with-ai) sections for more information on tree view helps.

In case of Lite or Enterprise edition, it is possible to fine tune the filter performance for a kubernetes cluster. Check the [Improving performance of resource discovery](/overview/improving-performance-of-resource-discovery) section for improving the performance.
{% endhint %}


# Developer Tools

gopaddle IDE provides an in-built option to view multiple Container Logs and Terminals in parallel for quick troubleshooting.

<figure><img src="/files/hexNufKfvd8bVCFWMFhU" alt=""><figcaption><p>Kubernetes IDE with Container Logs</p></figcaption></figure>


# AI Assistant

Discover how to engage with your AI assistant in gopaddle for Kubernetes management. This guide covers initiating chats, selecting contexts, and receiving AI-powered troubleshooting tips.

### How to Supercharge gopaddle with AI Assistance

Bringing the power of AI to your Kubernetes management just got easier with gopaddle. Ready to chat with an AI Assistant right within gopaddle? Here’s a quick guide on how to bring ChatGPT into your workflow:

1. **Register Your OpenAI Key**: Jump into the [ChatGPT registration section](/overview/register-chatgpt-assistant) and register your OpenAI key. It’s the first step to unlock AI-driven insights and assistance directly in gopaddle.
2. **Seamless Data Handling**: As you navigate through your Kubernetes clusters, gopaddle is your smart middleman. It gathers context from your Kubernetes environment and preps the information for you. And don’t worry about sensitive data — we automatically take care of redacting that for you.
3. **Approval Before Action**: Review the AI-prepped content, and once you give the green light, gopaddle forwards it to the AI. It’s collaboration with a safety net.
4. **History at Your Fingertips**: Keep track of all your AI interactions neatly under **Settings -> ChatGPT -> History**. Never lose context or forget a conversation.

<figure><img src="https://lh7-us.googleusercontent.com/cP4xsvPMpY1a4nzvqL8f3TZ_3DvGnqRZR33iMlvVk0y1LkA9eBh7N_Io34hMxwvnStAeZHooTQlWiaxVVkFrKecJorCcwDUb4l-5F-pTWjcXEVkse_i0XKnHdMdApgy3vpCxGhkGZgybwux3dsymGt0" alt=""><figcaption><p>AI Chat Window</p></figcaption></figure>

### Starting a Chat: It's as Easy as Clicking on a Resource

Whether you're troubleshooting a specific Kubernetes resource or an event has caught your attention, initiating a chat is pretty simple. Just head over to **Cluster -> Resources**, and you're all set to start the dialogue.

#### What Can You Chat About?

When launching a chat from a Kubernetes resource, gopaddle collects the below context to faciliate the chat:

* **Resource Specifications**: Dive deep into the nitty-gritty of your resources. In Tree View, you’ll get insights into not just your primary resource but its related children too.
* **Node Specifications**: Get specifics when your resource is cozily sitting on a node.
* **Container Logs**: Specifically for Pods in Flat View, and broadened to Deployments, ReplicaSets, Jobs, and StatefulSets with Tree View.
* **Kubernetes Events**: Start a conversation directly from a Kubernetes resource’s event.
* **Prometheus Alerts & Metrics**: Get the lowdown on alerts in a "Fired" state and explore available metrics.

And if your chat is initiated from a Kubernetes event, the dialogue can include:

* **Event Specifications**: Like with resources, Tree View gives you a comprehensive look at related specifications.
* **Involved Object**: Dive into the details of the object at the heart of the event.
* **Node Specifications & Prometheus Insights**: Just as with resources, these contexts are at your fingertips.

Bringing AI into your Kubernetes management with gopaddle not only enhances your ability to understand and react to your environment but does so with an emphasis on security, ease of use, and comprehensive support for your Kubernetes landscape.


# Chat with AI

This page guides users on how to seamlessly integrate and interact with an AI assistant in gopaddle for Kubernetes resource management.

### Kickstart Conversations with Your AI Assistant in gopaddle

After you've got your AI assistant up and running in gopaddle, diving into the details of your Kubernetes clusters becomes not just insightful but also interactive. Here's how to get started:

1. **Spot the Chat Icon**: Head over to the Clusters section on the left navigation bar and select the cluster name to view your cluster. When you click on **View -> Resources**, you'll notice a friendly chat icon next to each resource ![](https://lh7-us.googleusercontent.com/XIUZTvtPMsFrfX_cLsxDNGcQIhGh5MaUZ0F_6N8WsEtEPJeg1whZxNfcoUz-CdJjtfKtjfq-SXoQ4eKB-cH26obtHwTYD1c_dxPARt_CQP8V_WlAlC2tJ7ZhHLxUzPD3dU20GuebBA-13xeL3UMp_Sw).
2. **Open the Chat**: Click on that chat icon to bring up the chat dialog. On the left side of this dialog, you'll see a list of topics or "contexts" related to the resource you're interested in. These contexts give your conversation direction and depth.
3. **Choose Your Context**: Found a context that piques your interest? Click the <mark style="color:red;">**+**</mark> icon next to it. This action moves the context into the chat dialog, setting the stage for your query or command.
4. **Give the Green Light**: To send this information over to the AI, type <mark style="color:purple;">`/approve`</mark>. Not quite what you wanted? <mark style="color:purple;">`/deny`</mark> will keep it out of the chat. Need a bit of guidance? <mark style="color:purple;">`/help`</mark> brings up all the options you have at your disposal.

<div align="left"><figure><img src="https://lh7-us.googleusercontent.com/Em7JnBWfNLTtO51J_u8ZPgh5wV_moN_blcySPPXZxXpGh2PJe4iSvMUoL_z9nDWyrvPqmjCDu2HqtJ4ZEoqWmjeZnkTvA4QM3ZEec9uZTAQk3XkAMHDnekg71fftpcjPJL5pwQYjEJ0eg_RNiRxM1fk" alt=""><figcaption><p>Approve Context to Share with AI</p></figcaption></figure></div>

5. **Dive Deeper**: With the context approved, you're ready to get specific. Use <mark style="color:purple;">`/troubleshoot`</mark> or <mark style="color:purple;">`/optimize`</mark> to refine your query, whether you're looking to fix an issue or improve resource performance. Feel free to add more context or ask additional questions in your own words beyond the specific commands.

<div align="left"><figure><img src="https://lh7-us.googleusercontent.com/N8o__eLAtSBKNpbp3F4ZDl8IM4wI62zAjQFNBuDHszQhYxM4K6NcMND4ee6FkrzV-ZrFm6dXnxRf0Oi8paG57tIBMKJaIh30IVZrTpHFZxLIFNKgN3inbWJGboggvYl8cODxKQsY3AuNy043fNkhdM4" alt=""><figcaption><p>Troubleshoot Issues</p></figcaption></figure></div>

5. **Gather Insights**: After you've sent off your request, the AI, powered by ChatGPT, will serve up troubleshooting tips or optimization advice, complete with the context you've provided.

<div align="left"><figure><img src="https://lh7-us.googleusercontent.com/aFgzdM7EoDkkAdjUSR_7vjphj2qoQ3JMWCnaK2z4SD7ojBaXXXe7NMXSqT9ihI-PopmmSQP-AHWfwDXN5yBPUSrE0aXJMFYYaZ2CdAcxakwGtVq5jdD0MAFYHTMN79ksN5q-Fooal1kjN4obC4XL0oo" alt=""><figcaption><p>Response from ChatGPT AI Assistant</p></figcaption></figure></div>


# Raise a Jira Ticket from Chat Window

gopaddle features handy built-in commands for chatting your way into seamless Jira integration. Effortlessly turn the AI's troubleshooting insights into a new Jira ticket or update an existing one with fresh info, directly from the chat window.

{% hint style="info" %}
**Setting up Your Jira Account & Project**

**Note:** The chat window currently doesn't remember your preferred Jira account and project settings. Each time you start a chat, it will automatically pick the first Jira account and project available as the default choices.
{% endhint %}

### **Setting default Jira Account and Project (Optional)**

1. List the Jira accounts registered with gopaddle.&#x20;

<figure><img src="https://lh7-us.googleusercontent.com/8PWRNUvSMTM0jKDwjiOc7i-nNYl5x60w8mGYd1LDS-RlhGj1M4c86XJb7UV85QqLttSCmVoTKOjNyFXuj4YWBhYW8G644TNlQVc50k8WmEWJUF29BRnlxdZyRk4_wnbQcODdOlujy0jDb0dJZHSWSt4" alt=""><figcaption><p>List Registered Jira Accounts</p></figcaption></figure>

2. Select a Jira account.

<figure><img src="https://lh7-us.googleusercontent.com/wkuz_yyaWPUNFuLkX8oQHY8dMNXyQ6TiXoj1-XCqf7z4mon46KsXSrysOmX3wGIlMNRDw9zdctkVkUXlW3CohkoaoyVf8VzK3qVDIUNqau82zLUdolPJ1fnVxtD9iRbqeBnMzYOfq616e7tAIxdN7bQ" alt=""><figcaption><p>Select a Jira Account</p></figcaption></figure>

3. Once the account is selected, list the projects and select a project.

<figure><img src="https://lh7-us.googleusercontent.com/FWfnBoGUvbK6_g3M0_tWpReo4zWYk3x_TEMHtFx-1PBmrerxv_W4XTOc14KproKSsK_ROrKTw9zKq3D1wZjIRWSSLl9k3EQQRmIk5y0VMW8UPOUsTqC5JkpWKCaKsubvBFKtbLVYSjjD59NXswgqHiI" alt=""><figcaption><p>List Jira Projects</p></figcaption></figure>

### **Creating or Updating Jira Issue with AI Content**

A new Jira issue of type **“Bug”** can be created with the information generated by the AI. All the contexts added to the Chat will be added as an attachment to the issue.

{% hint style="info" %}
**Issue Type - Bug**

Make sure an issue type “Bug” exists in your Jira Project.
{% endhint %}

1. Use <mark style="color:purple;">`/jira create issue`</mark> to create a new issue.

<figure><img src="https://lh7-us.googleusercontent.com/a5rqbr8NZZa9dQPjhkE8LCEWmwiZz06m_1KTqrrWfDnXK8k7xjbNFHFBhMauZ36fzNHY7Fw1wDnz-qS5J1vVnVXnctuPwRgbm4qjAGRNyHJeWoHVDpg-Lg3M3QDiAP2LKcjFp-rizfqHzu1EQqBKSLk" alt=""><figcaption><p>Create a Jira Issue</p></figcaption></figure>

2. Use <mark style="color:purple;">`/jira issue list`</mark> to list all the Jira issues associated with this chat window

<figure><img src="https://lh7-us.googleusercontent.com/Y2UFn0FWbfplpg9tOqlmgtGiUvk8d_8qauezPanTy7dn7qIZ7x1P9aH0nTKr5voGGZaeIvPJbot9624AElOfOyh_Tgxy_OgV8qAxXvNPWMTTmJRb_ubxmaTLimoxfyJqCLYcWINLdTmKK2U7QabLh6g" alt=""><figcaption><p>List Jira Issues created from the Chat context</p></figcaption></figure>

List of all available commands to interact with Jira

<figure><img src="https://lh7-us.googleusercontent.com/-cSTZr8qEodvR-vUmiICFNYeSXFEZVoxP4pJZgpFkKou-n2T6iQzxjAAuvkUju6aN6O72BmJVHECmDnvhsl8cof-L1e5Z5s8w6YC6LKGEHcVfse0hKFgH6LYyM81CNMnxzG9B7OrLRv_jzphyuZcsBc" alt=""><figcaption></figcaption></figure>

<br>


# Create Runbook from Chat Window

The troubleshooting information generated by AI can be stored as a runbook.&#x20;

If a runbook hub exists, then this hub can be used to store the troubleshooting information.

{% hint style="info" %}
**Default Runbook Hub**

Currently Chat Window does not persist the default Runbook Hub details. Every time the chat window is opened, the first available Runbook Hub (if any) will be set as the default Runbook Hub.
{% endhint %}

### **Setting default Runbook Hub (Optional)**

1. List the available Runbook Hubs

<figure><img src="https://lh7-us.googleusercontent.com/Gwu7i9NMf0rM-Zom2y-DhQN5zuCU3UuXgj6ukPD2WPd_qyhwoBLHjTyqmUwVg6X5iIjS805Fge8wXjRHaakJiZKhlvNBzttbbbNXHYNwMscQ8LLvUJYLp775T6sVlVRBJEQkkTxjY8p-Lq5yDBGatBQ" alt=""><figcaption><p>List all available Runbook Hubs</p></figcaption></figure>

2. Select the default Runbook Hub

<figure><img src="https://lh7-us.googleusercontent.com/oN77C5yILjKjSBUTpSiu4Xd5bzAFwkSj2QSYZPI5tBaZzI_w3WmUba9Px5V6LxCSQy8y6TTrEnplCEYBIqxZ0SJJqr7WeriBBHpg_c9O5S1OuUw-kXS_ckyRi-b3VVP4V3ydw-S-tdToGMrD-g6XlJg" alt=""><figcaption><p>Select a Runbook Hub</p></figcaption></figure>

### **Creating Runbook with AI Content**

A new Runbook can be created with the information generated by the AI.&#x20;

1. Create a runbook by sending the command <mark style="color:purple;">`/runbook create`</mark>

<figure><img src="https://lh7-us.googleusercontent.com/-y5uEXFCybNJOUpzjxNtJKrD0oE-IVjDFRIHkKGznSXZdocHOqh5IsHS6pt6y3o14IOCzk60jmM0qBa10IoAXSbDzHdvJ5UO3zX--A8zDLqcdtjC_Hcqy4waBK3AFgimUJHUw9Gxoq5GMfcfNQLPxos" alt=""><figcaption><p>Create a Runbook</p></figcaption></figure>

Once the runbook is created, to attach it to a resource or an event, check the [Filters](/overview/kubernetes-ide/filters) section on how to add the JSONPath or Label Selectors.

List of all commands to interact with Runbook Hub:<br>

<figure><img src="https://lh7-us.googleusercontent.com/txJwcxAWfKmLMCcIprWCSVjm-lTh89IW8WQm6JM4LH-8aV2yp4EUhIt7O5xZIHgOTAfGD9zhN1woz56Fq5fHVYVTWP_iocTJz3RDN8JYzurrhL1E75nW9yt-GwcPG3XP3Ew65iBfVg8tQad8MXXopFc" alt=""><figcaption><p>Runbook Commands</p></figcaption></figure>

\ <br>


# Runbook Hub

Runbook Hub acts as a central repository within GitHub for organizing and storing runbook definitions, essential for automated troubleshooting and documentation in IT and development operations. A **`.gp.yaml`** file at the root of the repository specifies the hub and its runbooks, detailing their purpose, associated selectors for identifying relevant resources or events, and documentation paths. Users can create this file directly on GitHub or via the gopaddle UI, though the latter requires a linked GitHub account. Each runbook, identified by a unique name, links to specific resources or events through JSONPath or Label selectors, guiding towards relevant troubleshooting documentation stored as Markdown files within the repository.

<figure><img src="/files/pP5MIPjkAT318tnpXgkx" alt=""><figcaption><p>Runbook Hub Illustration</p></figcaption></figure>

<details>

<summary>Runbook Hub</summary>

A hub is a GitHub repository that holds one or more runbook definitions. A **`.gp.yaml`** file in the root directory of the repository in the default branch (Eg. main) defines a runbook hub. Format of the **`.gp.yaml`** definition looks like below:

```json
{
   "name":"Runbook Hub for BackOff failures",
   "desc":"Runbooks for container backoff related issues",
   "runbooks":[
      {
         "name":"Pod-Pending",
         "desc":"Runbook for Pod level CrashLoopBackOff and ImagePullBackOff",
         "selectors":[
            {
               "type":"labelSelector",
               "selector":"app=image-pull-failure-pod"
            },
            {
               "type":"jsonPathSelector",
               "selector":"{.status.phase}=Pending"
            }
         ],
         "doc":"backoff/pod-crash-runbook.md"
      },
      {
         "name":"Event-Pulling",
         "desc":"Runbook for ImagePullBackOff event",
         "selectors":[
            {
               "type":"jsonPathSelector",
               "selector":"{.involvedObject.kind}=Pod"
            },
            {
               "type":"jsonPathSelector",
               "selector":"{.reason}=BackOff"
            },
            {
               "type":"jsonPathSelector",
               "selector":"{.type}=Normal"
            }
         ],
         "doc":"backoff/pod-image-runbook.md"
      }
   ]
}
```

Users can create a **`.gp.yaml`** file in the repository directly or create it through the gopaddle UI. In order to create the **`.gp.yaml`** file from the gopaddle UI, the GitHub account must be registered in gopaddle.

</details>

<details>

<summary>Runbook</summary>

A runbook is documentation that is attached to a Kubernetes resource or an event based on a set of selectors. **A runbook name acts as a unique identifier and cannot have spaces.**

</details>

<details>

<summary>Selectors</summary>

A set of selectors when applied, filters one or more Kubernetes resources or events. Runbooks supports 2 types of selectors:

**a. JSONPathSelector:** JSON path in a resource specification. Eg.`{.reason}=BackOff` (or) `{.status.phase}=Pending`

**b. LabelSelector:** A key / value pair that matches the labels in the resource metadata. Eg. `app=image-pull-failure-pod`

</details>

<details>

<summary>Doc</summary>

Contains the troubleshooting documentation or knowledgebase associated with the Kubernetes resources or events. Has a **.md** extension and exists in a folder path relative to the repository root directory.

</details>


# Create Runbook Hub

### Pre-requisites

* GitHub account registered in gopaddle.
* GitHub repository dedicated for hub configuration.

### Steps to create a Runbook Hub

1. In the gopadle UI, in the left panel, select **Runbook Hubs**
2. Click on **Create Runbook Hub**

<div align="left"><figure><img src="/files/3vUESIgd4KvYSEbHFt3R" alt="" width="352"><figcaption><p>Create Runbook Hub</p></figcaption></figure></div>

3. In the pop up window, select the registered GitHub Code account and the repository (say **demo-hub**). Provide the hub name, hub description and runbook name, runbook description and the documentation path.
4. Add Knowledge base content and click on **Commit** to commit the changes to the repository. This creates a **.gp.yaml** file, creates a file with **.md** extension in the documentation file path, adds the runbook content and commits the changes to the selected repository.

<div align="left"><figure><img src="/files/RJvoUfgxqF8sjphwTayg" alt=""><figcaption><p>Runbook Hub Sample Knowledge Base</p></figcaption></figure></div>

5. Runbook Hub can now be viewed by clicking on the Runbook Hub name


# Attach Runbook Hub to Cluster

A hub can be attached to one or more clusters. When a hub is attached to a cluster, gopaddle filters the Kubernetes resources and events in the cluster matching the selectors across all the runbooks within the hub. The filtered resources and events are then annotated with the runbook information.

### Prerequisite to test Runbooks with a sample application

To test the runbook functionality,&#x20;

a) create a sample repository in your GitHub Account and initialize a `.gp.yaml` file. Check the [runbook hub section](/overview/runbook-hub) to learn more about initializing a repository as a Hub.&#x20;

b) [Register the source control account](/overview/register-github-account) and make sure the Runbook Hub is discovered.

c) Deploy the below sample application such that we have a application that matches the selectors in the Runbook Hub.

<details>

<summary>Sample Application to create an Event</summary>

For the purpose of testing, a sample Pod with ImagePullBackOff can be deployed by applying the yaml below:

```sh
kubectl apply -f - <<EOF
apiVersion: v1
kind: Namespace
metadata:
  name: demo-1
---
apiVersion: v1
kind: Pod
metadata:
  name: image-pull-failure-pod
  namespace: demo-1
  labels:
    app: image-pull-failure-pod
spec:
  containers:
  - name: image-error-container
image: non-existent-image:latest # This image intentionally does not exist
EOF
```

</details>

### Steps to attach Hub to a Cluster

1. In the left navigation panel, select **Runbook Hubs**.&#x20;
2. Click on a Runbook Hub to view the Runbook Hub
3. Click on the attach icon <img src="https://lh7-us.googleusercontent.com/LdmdTGTeHRvsg8pD9Eqwm_nIlsMJsMP3xmrKNb7ZXoBbeGNtXCw4wPxk0rvr17RtJszo0wym8ijojeNJPJphVNBR0lw6ZMmvy_8XtsNSdsgm9JpmOhBtMAhQjLRwAbz3BnyFOPTxF7nyMKtuiZsGyi0" alt="" data-size="line"> under the **Clusters** section
4. In the popup choose the localhost cluster and select **Attach**

<figure><img src="https://lh7-us.googleusercontent.com/oOoD0gBLRDD9ffgg_GjxDjwnokARvjQcM4lstg6bflCDERPStQ31VRAhzVF8xsBcc9HIbaLXOHR0n3ycCoo6crhDlImJxZYPobHcWD06ng9BSwkhWa7FIPCF9kFJllV6J3bTix-9jt_Gip5GFkmZ-dA" alt=""><figcaption><p>Select the cluster to attach</p></figcaption></figure>

5. Navigate to the **Clusters** section in the left navigation panel and click on the cluster name to view the cluster
6. All the runbook hubs associated with the cluster can be viewed under the **Runbook Hubs** section.

<figure><img src="https://lh7-us.googleusercontent.com/pijdKd2j4RoQ3SlAeimoBUqVrfCGQXG1F_9IEoxFDc8-md4qbCDbH_5rJQP5vBY0xIx0WT7FPOP5RRqNM_r4rhu9matR2f0GUikDAk1ynDukZcpZ00DFRlRtjqEd8NI_uCP9QcXVnX_jcEtNn_x4few" alt=""><figcaption><p>List of Runbook Hubs in Cluster Page</p></figcaption></figure>

6. Click on **View -> Resources** to list all the resources discovered under the cluster
7. Choose the **List filtered resources with runbooks** to view the resources tagged with runbooks. The demo pending Pod gets listed with a runbook icon.

<figure><img src="https://lh7-us.googleusercontent.com/GjWKeBdtcolK1LhBYnVODdqcxEwwRaiVCuvHw0Q1r7pfZ4L_c5SxOjxy7dCSUkQqmYJErMTsmbAS6-ZJ3NTBkrm7XWM-IDcLaWmb8-GLvdpFi7yaNqu-EXq_hbE3zMiBmrNhq5JHPMDAT39AMXK2X-Y" alt=""><figcaption><p>View Filtered Resources with Runbooks</p></figcaption></figure>

8. Click on the runbook icon to view the runbook.

<figure><img src="/files/uChGLjtFh8e2fUd2FPrl" alt=""><figcaption><p>Cluster View Runbook Attached to Resource</p></figcaption></figure>


# Enhancing contents of Runbooks with AI

Similar to the AI chat capability, the contents of the runbooks can be enhanced with the help of AI Assistant. When a runbook is edited from a Cluster Resource View page, gopaddle provides the option to add additional context.

1. Navigate to the Clusters section in the left navigation panel and click on localhost to view the cluster
2. Click on **View -> Resources** to list all the resources discovered under the cluster
3. Click on the runbook icon ![](https://lh7-us.googleusercontent.com/m6hAq5yvLnd3E1s0uOBZJGjCwkJsskzARdbcuaPKUYi8Qk0dOuhXqk3UFMaweXUOi9KsE6WgxKfkv_rfCCw7IVKUPUWRCKdL9xEXG5OKb8SbQEFK72j3o5r-YWTlLaU-h_AXhRGpqQfFBvSZMSaAXGA)to view and edit an existing runbook (or) click on the add icon ![](https://lh7-us.googleusercontent.com/HVLiffH7A44uyALOWSqol4ynzwOE80ACyD7JJfUfyleoPnh6vmzRHLs0HuUHPVJPLJkDOBm6y050f1EFkB259BrqaV71JoVRGvhNsLXRwY-c1dtbHIujMqB_9BsvXtPqT8ciD2Xikbd_MOHvyyyW9HY) to add a new runbook.
4. In the runbook editor, add a context from the context panel by clicking on the + icon. This adds the content of the context to the bottom of the existing runbook content. Users can edit this content before using the AI assistant to enhance the content.
5. Click on the AI Assistant icon ![](https://lh7-us.googleusercontent.com/PI_1RaRyj71AoxAzUaUEh5oqlya4r_xi90SYm2iKhvRMMx8tnVWol11HWPANyd_5JaR2hhVIWIMNsQ_DKHfgxKZPtOARtAhstk4Td2vFPfRrRnVdoXGd6vak-REfTQM_BuucIlTk6tQu3UfYO8o9H4c) to enhance the content<br>

**Eg. Demo Runbook after adding the context**

<figure><img src="https://lh7-us.googleusercontent.com/VGCjHr6jA-Oae12oWk2_nqTKJmSgwQ7hc_Vj3TtwU03AiJ0JvIIhO75sHOoP9yQlojNra53WIYSs4sDP41oo3k3VYg8krvmRSeCul5ZoYeSDXuwhtXBh-aJ4QoSAyfxah_DaAiMNkQ8RZf1jC6Es5cw" alt=""><figcaption><p>Base version of the Runbook Contents</p></figcaption></figure>

**Eg. Demo Runbook enhanced with the help of AI Assistant**

<figure><img src="https://lh7-us.googleusercontent.com/k0VmJdakFx0hGjB19P8JAzwJPufNONiMzji-rCcWC3ACsaCszQp6RjUywA5O7w5G_r5JUXbUvWA8DyV6avkCISM-HQLYAxFks5YqHhM-rv70Io9RqP27dR7aqg-DEsgtFTUOemEZd-7iTs_eJL8vAMg" alt=""><figcaption><p>Enhanced Version of the Runbook Contents</p></figcaption></figure>

\
\
\
\
\ <br>


# Detach Runbook Hub from Cluster

Detaching a hub from a cluster removes the annotations across the resources and events that were tagged with runbook information matching the selectors in the hub.

1. In the left navigation panel, select **Runbook Hubs**.&#x20;
2. Click on a Runbook Hub to view the Runbook Hub
3. Under the Clusters section, select the cluster to detach.
4. Click on the detach icon <img src="https://lh7-us.googleusercontent.com/WCGQhf3ncAnS6E5z4yJ-WH7O-7WsBSojmlLp1lifvj1TBJxxaIPlZEzW6GpVOg52DiPAhucXcAYuLzidB1MdnvkqPW02Jj4tOzg6iseGuQQV3OQ693c3rRExtX0YqdtfzY2pwLKwshzx8AywYyA8Q1M" alt="" data-size="line">to detach the cluster
5. Navigate to the Clusters section in the left navigation panel and click on the cluster name to view the cluster
6. Click on **View -> Resources** to list all the resources discovered under the cluster

<figure><img src="/files/GlIWiu2pu0hAIJUxtt4Y" alt=""><figcaption><p>View Cluster Resources</p></figcaption></figure>

7. Choose the List filtered resources with runbooks to view the resources tagged with runbooks. The demo application pending Pod will no longer be listed with the runbook tag.

<div align="left"><figure><img src="/files/EruRR831lP1GOwsBR6fa" alt=""><figcaption><p>No Cluster Resources with Runbooks</p></figcaption></figure></div>


# Syncing Runbook Hub with GitHub

Any updates done directly to a hub in the Github repository (say updating a .gp.yaml file or changing the contents of the documentation) has to be synced up with the gopaddle manually.

### Option 1 - Refresh a single hub

1. In the gopaddle UI, select **Runbook Hubs** in the left panel
2. Click on a Runbook Hub to view the Runbook Hub&#x20;
3. Click on **Refresh** option to refresh the hub

<div align="left"><figure><img src="/files/FT12hiauAA78LpLHlD28" alt=""><figcaption><p>Refresh a single runbook hub</p></figcaption></figure></div>

### Option 2 - Refresh all the hubs within a Source Control Account

1. In the gopaddle UI, under **Settings**, select **Code -> Account**
2. Click on the **dots** icon and select **Refresh Runbook Hubs** option

<div align="left"><figure><img src="/files/D2fWw8FoSkDGoQbTOr67" alt=""><figcaption><p>Refresh multiple runbook hubs</p></figcaption></figure></div>


# Delete Runbook / Runbook Hub

gopaddle UI does not support the capability to delete a Runbook Hub or a Runbook from the UI.

1\. To delete a runbook or a runbook Hub, update or delete the **.gp.yaml** file in the GitHub repository directly.

2\. In the gopaddle UI, refresh the Runbook Hub by following the steps under the [Syncing Runbook Hub with GitHub section.](/overview/runbook-hub/syncing-runbook-hub-with-github)


# Installing Community Edition

{% hint style="info" %}
**Dive Into gopaddle 5.0: Where AI Meets Innovation**

**Exciting news!** The latest gopaddle 5.0 is here, and it's bringing some game-changing features to the table — including our smart AI Assistant and the comprehensive Runbook capabilities. Right now, these AI capabilities are exclusively available on our **SaaS Edition**.

Can't wait to explore these features on Lite or Enterprise Edition? We've got you covered! For early access and a sneak peek into the future of Kubernetes management, just reach out to us at <hello@gopaddle.io>
{% endhint %}


# MicroK8s Addon

The gopaddle-lite addon on microk8s installs gopaddle community edition (lite) on microk8s.

To enable the addon:

```auto
microk8s enable gopaddle-lite
```

The addon can be disabled at any time with:

```auto
microk8s disable gopaddle-lite
```

For OS Distribution specific instruction on installing gopaddle on microk8s, checkout the sections below:

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon/on-ubuntu">Enable gopaddle microk8s add-on on Ubuntu</a></td><td></td><td></td><td><a href="/files/qAFqX6lbl4jnbap21Wgh">/files/qAFqX6lbl4jnbap21Wgh</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon/on-ubuntu">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon/on-ubuntu</a></td></tr><tr><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon/on-macos">Enable gopaddle microk8s add-on on MacOS</a></td><td></td><td></td><td><a href="/files/MhhK9zOsHLHEiqxKpWK2">/files/MhhK9zOsHLHEiqxKpWK2</a></td><td><a href="https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon/on-macos">https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/microk8s-addon/on-macos</a></td></tr><tr><td></td><td></td><td></td><td></td><td></td></tr></tbody></table>


# On Ubuntu

Install gopaddle lite as microk8s add-on on Ubuntu

gopaddle lite - A lifetime free community edition of gopaddle is now available as an add-on to microk8s.

### Pre-requisites <a href="#h_67032f91ff" id="h_67032f91ff"></a>

1. **OS distribution:** Ubuntu 18.04 or higher; MicroK8s version: 1.25 or higher;
2. **System resource requirements:** 4 vCPU (Intel Arch), 8 GB RAM, 50 GB Disk
3. '`snap`' tool must already be installed.

   If not installed, the following steps can be used on Ubuntu 18.04:

   ```sh
   sudo apt-get install snapd -y 
   sudo snap install core
   ```

   Set the path for snap tool to be executed as a command:

   ```sh
   export PATH=$PATH:/snap/bin
   ```
4. microk8s must already be installed and must be running.

   If not installed, use the below step to install the same:

   ```sh
   sudo snap install microk8s --classic --channel=1.26
   ```

   If already installed, you may want to refresh microk8s:

   ```sh
   sudo snap refresh microk8s --channel=1.26
   ```

   Check and ensure that microk8s service is running:

   ```sh
   sudo microk8s status --wait-ready
   ```

### Steps to install gopaddle lite addon for microk8s <a href="#h_1f89b480e9" id="h_1f89b480e9"></a>

1. Enable microk8s community addon and enable gopaddle lite addon.

   ```sh
   sudo microk8s enable community
   sudo microk8s enable gopaddle-lite -v 4.2.9
   ```

   Optional parameters while enabling the add-on.

   ```
   sudo microk8s enable gopaddle-lite [-i <IP Address>] [-v <gopaddle version>] 
   Basic Options: 
   --ip|-i : static IP address to assign to gopaddle endpoint. This can be a public or private IP address of the microk8s node 
   --version|-v : gopaddle lite helm chart version (default 4.2.5)
   ```

   If *-i* option is omitted, then the gopaddle endpoint is decided based on the node's private IP address. Please take a look at the '[gopaddle dashboard endpoint](http://help.gopaddle.io/en/articles/6654354-install-gopaddle-lite-microk8s-addon-on-ubuntu#h_e2848eb34e)' section for more details.

   ### Example: <a href="#h_b1a39a5238" id="h_b1a39a5238"></a>

   ```sh
   sudo microk8s enable gopaddle-lite -i 130.198.9.42 -v 4.2.9
   ```
2. Make a note of the gopaddle lite access endpoint from the above command. You can also obtain the endpoint by listing the node IPs in the cluster. Check the [gopaddle dashboard endpoint](http://help.gopaddle.io/en/articles/6654354-install-gopaddle-lite-microk8s-addon-on-ubuntu#h_e2848eb34e) section for more information.
3. Wait for gopaddle services to move to running state

   ```sh
   sudo microk8s.kubectl wait --for=condition=ready pod -l released-by=gopaddle -n gp-lite
   ```

   If you see this error message `timed out waiting for the condition on pods`, you can execute the above command once again to wait for all the gopaddle services to move to running state.
4. Access the gopaddle dashboard. If static IP is provided as an input using `-i` option in step 1, then accesss the gopaddle UI @ `http://<STATIC_IP>:30003` , else access the gopaddle UI @ `http://<NODE_IP>:30003` . The Node IP can be determined by executing the command below. If the node has a public IP, open the firewall ports in the next step.

   ```sh
   sudo microk8s.kubectl kubectl get nodes -o wide
   ```
5. Enable Firewall ports (if installing gopaddle lite on a cloud based VM)

The following TCP network ports have to be enabled/opened to use the gopaddle lite dashboard:

* Ports 30000 to 30006: for accessing gopaddle endpoints .
* Port 32000: Service node port for Grafana dashboard on Kubernetes
* Any node port assigned for an application deployed on microk8s

### Steps to disable gopaddle addon for microk8s <a href="#h_34c452e03c" id="h_34c452e03c"></a>

Issue the below command to disable gopaddle addon for microk8s:

```sh
sudo microk8s disable gopaddle-lite
```

### Steps to update gopaddle addon for microk8s <a href="#h_d55ce7f13d" id="h_d55ce7f13d"></a>

At a later time, if you want to update gopaddle addon repo (that you previously added at the time of installation of gopaddle addon for microk8s), use the below command:

1. Update the repository

   ```sh
   sudo microk8s addons repo update gp-lite
   ```
2. If any new updates are pulled above, in order for this to take effect, you need to execute the following steps:\
   [Disable gopaddle add-on](#h_34c452e03c)

   [Enable gopaddle add-on](#h_1f89b480e9)

### Steps to uninstall gopaddle addon for microk8s <a href="#h_b18fd24cfc" id="h_b18fd24cfc"></a>

Follow the below steps to uninstall gopaddle addon for microk8s:

1. Disable gopaddle addon for microk8s - [see the section above](#h_34c452e03c)
2. Delete all PVs created by gopaddle

   After disabling gopaddle addon for microk8s, the persistent volumes used by gopaddle are still around. Use the below command to delete the persistent volumes created by gopaddle:

   ```sh
   sudo microk8s kubectl delete pv -l gp-install-pv=microk8s-hostpath-gp-retain
   ```
3. Delete the storage class

   ```sh
   sudo microk8s kubectl delete sc microk8s-hostpath-gp-retain
   ```
4. Remove the node label added by gopaddle

   ```sh
   sudo microk8s kubectl label nodes <nodename> gp-install-node-
   ```
5. Remove the gopaddle addon repo in microk8s

   ```sh
   sudo microk8s addons repo remove gp-lite
   ```


# On MacOS

Install gopaddle lite as microk8s add-on on MacOS

gopaddle lite - A lifetime free community edition of gopaddle is now available as an add-on to microk8s.

### Pre-requisites <a href="#h_f1b48acbdb" id="h_f1b48acbdb"></a>

1. OS distribution: MacOS Monterey 12.6 or higher; MicroK8s version: 1.25 or higher;
2. System resource requirements: 4 vCPU (Intel Arch), 8 GB RAM, 50 GB Disk
3. '`brew`' tool must already be installed.

   If not installed, install brew:

   ```sh
   /bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
   ```
4. microk8s must already be installed and must be running.

   If not installed, use the below step to install the same:

   ```sh
   brew install ubuntu/microk8s/microk8s
   microk8s install --channel 1.26
   ```

   Check and ensure that microk8s service is running:

   ```sh
   microk8s status --wait-ready
   ```
5. Update the VM configuration to set the CPU & Mem allocation
   1. Unload the multipass config

      ```sh
      sudo launchctl unload /Library/LaunchDaemons/com.canonical.multipassd.plist
      ```
   2. Edit the file

      ```sh
      sudo vi /var/root/Library/Application\ Support/multipassd/multipassd-vm-instances.json
      ```

      Set the num\_cores": 4 and "mem\_size": "8589934592". Final JSON file would look like this.

      ```sh
      {
         "microk8s-vm":{
            "deleted":false,
            "disk_space":"53687091200",
            "extra_interfaces":[
               
            ],
            "mac_addr":<mac-address>,
            "mem_size":"8589934592",
            "metadata":{
               
            },
            "mounts":[
               
            ],
            "num_cores":4,
            "ssh_username":"ubuntu",
            "state":4
         }
      }
      ```
   3. Load the config

      ```sh
      sudo launchctl load /Library/LaunchDaemons/com.canonical.multipassd.plist
      ```
   4. Wait for the microk8s-vm to move to Running state

      ```sh
      multipass info microk8s-vm
      ```
   5. Wait for microk8s service to move to ready state

      ```sh
      microk8s status --wait-ready
      ```

### Steps to install gopaddle lite addon for microk8s <a href="#h_bf66786b77" id="h_bf66786b77"></a>

1. Enable microk8s community addon and enable gopaddle lite addon.

   ```sh
   microk8s enable community
   microk8s enable gopaddle-lite -v 4.2.9
   ```

   Optional parameters while enabling the addon.

   ```sh
   microk8s enable gopaddle-lite [-i <IP Address>] [-v <gopaddle version>] 
   Basic Options: 
   --ip|-i : static IP address to assign to gopaddle endpoint. This can be a public or private IP address of the microk8s node 
   --version|-v : gopaddle lite helm chart version (default 4.2.5)
   ```

   If *-i* option is omitted, then the gopaddle endpoint is decided based on the node's private IP address. Please take a look at the '[gopaddle dashboard endpoint](http://help.gopaddle.io/en/articles/6654354-install-gopaddle-lite-on-ubuntu#h_e2848eb34e)' section for more details.

   ### Example: <a href="#h_ecc63f462c" id="h_ecc63f462c"></a>

   ```sh
   microk8s enable gopaddle-lite -i 130.198.9.42 -v 4.2.9
   ```

2. Make a note of the gopaddle lite access endpoint from the above command. You can also obtain the endpoint by listing the node IPs in the cluster.&#x20;

3. Wait for gopaddle services to move to running state

   ```sh
   microk8s kubectl wait --for=condition=ready pod -l released-by=gopaddle -n gp-lite
   ```

   If you see this error message `timed out waiting for the condition on pods`, you can execute the above command once again to wait for all the gopaddle services to move to running state.

4. Access the gopaddle dashboard. If static IP is provided as an input using `-i` option in step 1, then accesss the gopaddle UI @ `http://<STATIC_IP>:30003` , else access the gopaddle UI @ `http://<NODE_IP>:30003` . The Node IP can be determined by executing the command below. If the node has a public IP, open the firewall ports in the next step.

   ```sh
   microk8s.kubectl kubectl get nodes -o wide
   ```

5. Enable Firewall ports (if installing gopaddle lite on a cloud based VM)

   The following TCP network ports have to be enabled/opened to use the gopaddle lite dashboard:

   * Ports 30000 to 30006: for accessing gopaddle endpoints .
   * Port 32000: Service node port for Grafana dashboard on Kubernetes
   * Any node port assigned for an application deployed on microk8s

### gopaddle dashboard endpoint <a href="#h_76a04756ce" id="h_76a04756ce"></a>

An IP address is required to access the gopaddle lite end point. When not supplied from the command line, the default IP address is determined in the order mentioned below:

* If the first node in microk8s cluster is configured with an External/Public IP address, this is chosen as the IP address for the access end point
* Else, the Internal/Private IP address of the first node configured in microk8s cluster is used as the IP address for the access end point

Note: The node IP address configured in the microk8s cluster above can be determined using the 'get nodes' command as follows:

```sh
microk8s kubectl get nodes -o wide
NAME          STATUS   ROLES    AGE   VERSION   INTERNAL-IP    EXTERNAL-IP   OS-IMAGE             KERNEL-VERSION       CONTAINER-RUNTIME
microk8s-vm   Ready    <none>   41m   v1.25.2   192.168.64.2   <none>        Ubuntu 18.04.6 LTS   4.15.0-194-generic   containerd://1.6.6
```

### Steps to disable gopaddle addon for microk8s <a href="#h_a3de53a9b2" id="h_a3de53a9b2"></a>

Issue the below command to disable gopaddle addon for microk8s:

```sh
microk8s disable gopaddle-lite
```

### Steps to update gopaddle addon for microk8s <a href="#h_808fbc003e" id="h_808fbc003e"></a>

At a later time, if you want to update gopaddle addon repo (that you previously added at the time of installation of gopaddle addon for microk8s), use the below command:

1. Update the repository

   ```sh
   microk8s addons repo update gp-lite
   ```

   This results in pulling any updates done to gopaddle addon repo. If it is already up-to-date, you will get the below output:

   ```sh
   Updating repository gp-lite Already up to date.
   ```
2. If any new updates are pulled above, in order for this to take effect, you need to execute the following steps:\
   [Disable gopaddle add-on](#h_a3de53a9b2)

   [Enable gopaddle add-on](#h_bf66786b77)

### Steps to uninstall gopaddle addon for microk8s <a href="#h_e817df7ff6" id="h_e817df7ff6"></a>

Follow the below steps to uninstall gopaddle addon for microk8s:

1. Disable gopaddle addon for microk8s - [see the section above](#h_a3de53a9b2)
2. Delete all PVs created by gopaddle

   After disabling gopaddle addon for microk8s, the persistent volumes used by gopaddle are still around. Use the below command to delete the persistent volumes created by gopaddle:

   ```sh
   microk8s kubectl delete pv -l gp-install-pv=microk8s-hostpath-gp-retain
   ```
3. Delete the storage class

   ```sh
   microk8s kubectl delete sc microk8s-hostpath-gp-retain
   ```
4. Remove the node label added by gopaddle

   Usage:

   ```sh
   microk8s kubectl label nodes microk8s-vm gp-install-node-
   ```
5. Remove the gopaddle addon repo in microk8s

   ```sh
   microk8s addons repo remove gp-lite
   ```


# Docker Desktop

Steps to install gopaddle extension on Docker Desktop

gopaddle Lite is now available as a Docker Desktop community extension, enabling Docker Desktop users to manage multiple cloud & onpremise Kubernetes environments from a single dashboard. Docker users can start building a complete DevSecOps automation using gopaddle.

### Pre-requisites <a href="#h_c6366beecf" id="h_c6366beecf"></a>

a) **Docker Desktop requirements:** Minimum 4vCPU, 8GB RAM and minimum 10GB free disk space

Under Docker Desktop Settings, make sure the minimum CPU and Memory resources are configured.

<figure><img src="https://downloads.intercomcdn.com/i/o/782105813/01cae9bde94d5810d021b50a/Screen+Shot+2023-07-10+at+2.58.56+PM.png" alt=""><figcaption></figcaption></figure>

b) **Docker Engine** - v20.10.24 or later

c) **Kubernetes Engine** - v1.25.4

d) Enable Kubernetes Engine

<figure><img src="https://downloads.intercomcdn.com/i/o/729328541/3fe063b66a7f38ed7571fc9b/Screen+Shot+2023-04-26+at+3.04.47+PM.png" alt=""><figcaption></figcaption></figure>

### Installation Steps <a href="#h_4be1033b5f" id="h_4be1033b5f"></a>

If you already have Docker Desktop installed, click on the [link](https://open.docker.com/extensions/marketplace?extensionId=gopaddle/gopaddle-extension\&tag=4.2.9) to download and install the extension.

If not, follow the below steps to install gopaddle extension.

1. Download and Install Docker Desktop - <https://www.docker.com/products/docker-desktop/>
2. Search for gopaddle in the Docker Extensions Marketplace

   <figure><img src="https://downloads.intercomcdn.com/i/o/729328635/bc05c7a1061ecc03cb641879/Screen+Shot+2023-04-26+at+3.01.52+PM.png" alt=""><figcaption></figcaption></figure>
3. Install the gopaddle extension.

   <figure><img src="https://downloads.intercomcdn.com/i/o/758895825/a55c1fe1b1c87aaed93a5055/Docker-Desktop-Extension.png" alt=""><figcaption></figcaption></figure>

### Getting started <a href="#h_2bb94a40b2" id="h_2bb94a40b2"></a>

1. Subscribe to gopaddle using your email ID. gopaddle then sends an email to the registered email ID with an initial password.

   <figure><img src="https://downloads.intercomcdn.com/i/o/758886594/8fa74ce10df0e3a28d4fe755/Screen+Shot+2023-06-07+at+6.09.17+PM.png" alt=""><figcaption></figcaption></figure>
2. Login to the gopaddle dashboard using the registered email ID and the initial password.
3. Enable the Kubernetes cluster under the Docker Desktop Settings.

   <figure><img src="https://downloads.intercomcdn.com/i/o/758890499/2f44fecf45bd4c0e53d9b1c9/Screen+Shot+2023-06-07+at+6.10.18+PM.png" alt=""><figcaption></figcaption></figure>
4. Wait until the Kubernetes cluster moves to ready state.

   [![](https://downloads.intercomcdn.com/i/o/758894008/376927673405d252f8ef7b10/Screen+Shot+2023-06-07+at+6.28.52+PM.png)](https://downloads.intercomcdn.com/i/o/758894008/376927673405d252f8ef7b10/Screen+Shot+2023-06-07+at+6.28.52+PM.png)
5. Once the Kubernetes status icon in the Docker Desktop moves to ready state, execute the below command in the local terminal to get the Kubernetes cluster configuration.

   ```sh
   kubectl config view --minify=true -o yaml --context=docker-desktop --flatten
   ```
6. Register the local cluster in the gopaddle dashboard

   <figure><img src="https://downloads.intercomcdn.com/i/o/758898947/cd6bac9d08314c08f30a0006/Screen+Shot+2023-06-07+at+6.42.57+PM.png" alt=""><figcaption></figcaption></figure>

gopaddle automatically triggers a discovery process, that discovers the resources in the *docker-desktop* Kubernetes cluster. Once the discovery process is complete, you can view the namespaces under the Applications tab and the Kubernetes specifications under the Design Studio.

### Uninstalling gopaddle extension <a href="#h_aee0e3edc9" id="h_aee0e3edc9"></a>

a) Cancel the subscription (if any). You can ignore this step, if you are on free version of gopaddle lite.

Under the Profile, choose Billing

[![](https://downloads.intercomcdn.com/i/o/729457230/addd130322465bbb46de4c4e/Screen+Shot+2023-04-26+at+7.28.39+PM.png)](https://downloads.intercomcdn.com/i/o/729457230/addd130322465bbb46de4c4e/Screen+Shot+2023-04-26+at+7.28.39+PM.png)

Copy the URL from the Manage gopaddle Subscriptions pop up. Open the URL in the browser. Login using the gopaddle registered email ID and manage your billing and subscription.

<figure><img src="https://downloads.intercomcdn.com/i/o/729458713/18ee491c9fc602f270011d2d/Screen+Shot+2023-04-26+at+7.33.51+PM.png" alt=""><figcaption></figcaption></figure>

b) Uninstall the gopaddle extension from docker desktop

<figure><img src="https://downloads.intercomcdn.com/i/o/729335164/b7ba7c3e1fd97724cba4c497/Screen+Shot+2023-04-26+at+3.14.24+PM.png" alt=""><figcaption></figcaption></figure>

c) Switch to docker-destop Kubernetes context

```sh
kubectl config use-context docker-desktop
```

e) Uninstall the gopaddle-servers namespaces

```sh
kubectl delete ns gopaddle-servers gp-lite-4-2
```

Note. If deleting the gopaddle-servers is stuck, then edit the namespace and remove the finalizers

```sh
kubectl get namespace gopaddle-servers -o json \ | tr -d "\n" | sed "s/\"finalizers\": \[[^]]\+\]/\"finalizers\": []/" \ | kubectl replace --raw /api/v1/namespaces/gopaddle-servers/finalize -f -
```

g) Delete the gopaddle clusterroles

```sh
kubectl delete clusterrole gopaddle gopaddle:nginx-ingress-clusterrole gopaddle:prometheus-tool-kube-state-metrics gopaddle:prometheus-tool-server 
```

\
h) Delete the gopaddle clusterrolebindings

```sh
kubectl delete clusterrolebinding gopaddle gopaddle:event-exporter-rb gopaddle:prometheus-tool-kube-state-metrics gopaddle:prometheus-tool-server
```

i) Delete the default backend

```sh
kubectl delete deploy/default-http-backend 
kubectl delete service/default-http-backend
```


# SUSE Rancher Prime

gopaddle lite in Rancher Prime marketplace

gopaddle lite is a life-time free single-node, single-user evaluation edition that can be installed on [Rancher Prime by SUSE](https://www.rancher.com/products/rancher)

## Pre-requisites <a href="#h_3ab485cdaa" id="h_3ab485cdaa"></a>

### Rancher Prime Cluster Node requirements <a href="#h_0c841476fc" id="h_0c841476fc"></a>

1. Ubuntu 18.04
2. RAM 32GB
3. CPU 8vCPU
4. Disk 50GB

### Prometheus tool server requirements <a href="#h_61806dbc18" id="h_61806dbc18"></a>

Increase the open file descriptor in the nodes

1. Edit the file as root /etc/sysctl.conf
2. Add these lines to the file

   ```sh
   fs.file-max = 500000
   fs.inotify.max_user_watches=100000
   fs.inotify.max_user_instances=100000
   ```
3. Reload the configuration

   ```sh
   sysctl -p
   ```
4. check if the file systems limit is set

   ```sh
   cat /proc/sys/fs/file-max
   ```

### Connect to the Rancher Prime cluster <a href="#h_16e6efedc8" id="h_16e6efedc8"></a>

The Rancher Prime cluster configuration file is usually available @ /etc/rancher/rke2/rke2.yaml in the master node.

```sh
export KUBECONFIG=/etc/rancher/rke2/rke2.yaml
```

### Configure Default Storage Class <a href="#h_b1285d94c0" id="h_b1285d94c0"></a>

gopaddle requires a default storage class to install its dependent stateful services like mongodb, influxdb etc. The below steps can be ignored, if the cluster already has a default storage class configured. Otherwise, install the CSI driver based on the Rancher Prime environment.

***

#### Example - AWS EBS CSI Driver <a href="#h_e372c8d5c8" id="h_e372c8d5c8"></a>

For instance, if you are running Rancher Prime on AWS, enable the AWS EBS CSI driver. For more information on the AWS EBS CSI Driver - \[<https://github.com/kubernetes-sigs/aws-ebs-csi-driver#kubernetes-version-compatibility-matrix> ]

```
export AWS_KEYID=<aws-access-key>
export AWS_ACCESSKEY=<aws-secret-key>
```

```
kubectl create secret generic aws-secret --namespace kube-system --from-literal "key_id=$AWS_KEYID" --from-literal "access_key=$AWS_ACCESSKEY" kubectl apply -k "github.com/kubernetes-sigs/aws-ebs-csi-driver/deploy/kubernetes/overlays/stable/?ref=release-1.13"
```

Patch the node labels topology.kubernetes.io & topology.kubernetes.io/zone, so that the AWS EBS CSI driver schedules the persistent volumes on the selected region and the availability zone.

```
export REGION='us-east-1'
export ZONE='us-east-1a'
apt install jq -y node=$(kubectl get nodes -o json | jq -r '.items[0].metadata.annotations["rke2.io/hostname"]') kubectl patch node $node -p '{"metadata": {"labels":{"topology.kubernetes.io/region": "$REGION"}}}' kubectl patch node $node -p '{"metadata": {"labels":{"topology.kubernetes.io/zone":"$ZONE"}}}'
```

***

#### Create Standard storageClass <a href="#h_02391e56eb" id="h_02391e56eb"></a>

a) From the Rancher Prime UI, create a new storage class named - standard and choose the provisioner.

<figure><img src="https://downloads.intercomcdn.com/i/o/669520002/451c6b3ff1c0ab8e77bf56fd/AWS-EBS.png" alt=""><figcaption></figcaption></figure>

b) Patch the standard storage class and set it as the default storage class.

```sh
kubectl patch storageclass standard -p '{"metadata": {"annotations":{"storageclass.kubernetes.io/is-default-class":"true"}}}'
```

## Install gopaddle-lite from marketplace <a href="#h_ce5bb26f1e" id="h_ce5bb26f1e"></a>

In the Rancher Prime dashboard, in the Charts section, search for the gopaddle chart and install.

<figure><img src="https://downloads.intercomcdn.com/i/o/669517753/b502d8fbd3e477bca35440f9/Screen+Shot+2023-01-10+at+1.45.58+PM.png" alt=""><figcaption></figcaption></figure>

This will install all the gopaddle services. Wait for the gopaddle services to move to ready state.

<figure><img src="https://downloads.intercomcdn.com/i/o/669516584/4ccacddd4f306d64f8fb7059/Screen+Shot+2022-12-14+at+10.59.08+PM.png" alt=""><figcaption></figcaption></figure>

## Accessing gopaddle dashboard <a href="#h_9670a03a65" id="h_9670a03a65"></a>

Once the installation is complete, open the firewall ports 30000-30006 and 32000 in the Rancher Prime nodes.

gopaddle dashboard can be accessed @ `http://<NODE_IP>:30003`

NODE\_IP can be obtained by listing the nodes in the cluster.

```sh
kubectl get nodes -o wide
```

NOTE: If the cluster is installed on cloud based VMs, then the NODE\_IP can be the public IP of the node.

Subscribe to gopaddle using your email ID. gopaddle will then send an initial password to the registered email ID. You can now login to the gopaddle dashboard using the email ID and the initial password.&#x20;


# Digital Ocean

gopaddle One-Click Install on Digital Ocean

{% hint style="info" %}
gopaddle Installation on Digital Ocean Kubernetes cluster requires a minimum of 2 nodes, 32 GB RAM and 50 GB Hard disk. O
{% endhint %}

## Option 1 - Install through Marketplace Listing

1. Click on the Digitial Ocean Marketplace listing below:

{% embed url="<https://marketplace.digitalocean.com/apps/gopaddle>" %}
App Listing
{% endembed %}

2. Click on **Install App** in the top right corner of the app listing.
3. Sign In to your Digital Ocean Account and launch the application.

<figure><img src="/files/XyVT7Wvx1pNXC6DAG11Z" alt="" width="375"><figcaption><p>Ditigal Ocean Kubernetes - gopaddle 1-Click Install</p></figcaption></figure>

4. Once gopaddle is installed, access the gopaddle UI by following [these](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/accessing-gopaddle-ui) steps.

## Option 2 -  Install Using Command Line

1. Follow [these](/overview/provision-new-cluster/provision-clusters-on-cloud) steps to Download and configure Digital Ocean command line utility
2. Execute the below command to create a Digitial Ocean Kubernetes cluster and install gopaddle

```
doctl kubernetes clusters create --size s-4vcpu-8gb $CLUSTER_NAME --1-clicks gopaddle-lite
```

3. Once gopaddle is installed, access the gopaddle UI by following [these](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/accessing-gopaddle-ui) steps.


# Akamai Linode

gopaddle One-Click install on Akamai Linode

1. Access the Linode Marketplace

{% embed url="<https://www.linode.com/marketplace/apps/gopaddle/gopaddle/>" %}
Akamai Lined marketplace listing
{% endembed %}

2. Click on Deploy This App
3. Log in to the [Cloud Manager](https://cloud.linode.com/) and select the **Marketplace** link from the left navigation menu. This displays the Linode **Create** page with the **Marketplace** tab pre-selected.
4. Under the **Select App** section, select the app you would like to deploy.
5. Complete the form by following the steps and advice within the [Creating a Compute Instance](https://www.linode.com/docs/guides/creating-a-compute-instance/) guide. Depending on the Marketplace App you selected, there may be additional configuration options available. See the [Configuration Options](https://www.linode.com/docs/products/tools/marketplace/guides/hashicorp-vault/#configuration-options) section below for compatible distributions, recommended plans, and any additional configuration options available for this Marketplace App.
6. Click the **Create Linode** button. Once the Compute Instance has been provisioned and has fully powered on, **wait for the software installation to complete**. If the instance is powered off or restarted before this time, the software installation will likely fail.
7. To verify that the app has been fully installed, see [Get Started with Marketplace Apps > Verify Installation](https://www.linode.com/docs/products/tools/marketplace/get-started/#verify-installation). Once installed, follow the instructions within the [Getting Started After Deployment](https://www.linode.com/docs/products/tools/marketplace/guides/mastodon/#getting-started-after-deployment) section to access the application and start using it.
8. Once gopaddle is installed, access the gopaddle UI @ `http://<VM_IP>:30003`.

**Estimated deployment time:** gopaddle should be fully installed within 15-20 minutes after the Compute Instance has finished provisioning.

* **Supported distributions:** Ubuntu 22.04 LTS
* **Recommended minimum plan:** A minimum plan size of 8GB Shared CPU Linode is recommended for gopaddle.


# Kind Cluster

Install gopaddle community edition on Kind cluste

1. Download and install kind in your local environment by following [these](https://kind.sigs.k8s.io/docs/user/quick-start/#installation) steps.
2. Create a kind.conf file with the below contents

```yaml
kind: Cluster
apiVersion: kind.x-k8s.io/v1alpha4
nodes:
- role: control-plane
  extraPortMappings:
  - containerPort: 30000
    hostPort: 30000
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30001
    hostPort: 30001
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30002
    hostPort: 30002
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30003
    hostPort: 30003
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30004
    hostPort: 30004
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30005
    hostPort: 30005
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30006
    hostPort: 30006
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 32000
    hostPort: 32000
    listenAddress: "127.0.0.1"
    protocol: TCP
  - containerPort: 30033
    hostPort: 30033
    listenAddress: "127.0.0.1"
    protocol: TCP

```

3. Create a kind cluster using the kind.conf file

```sh
kind create cluster --name gopaddle --config kind.conf
```

4. Perform [these](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/helm) steps to install gopaddle helm chart
5. Once gopaddle is installed, access the gopaddle UI by following [these](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/accessing-gopaddle-ui) steps.


# Helm

Steps to install gopaddle community edition using Helm Chart

## Minimum System Requirements

gopaddle installation requires a minimum of `8GB RAM`, `4 vCPUs` and `50 GB Hard disk`

## Steps to install Helm Chart

1. Add the helm repo

```
helm repo add gopaddle https://gopaddle-io.github.io/gopaddle-lite/
helm repo update
```

2. Install the chart

```
helm install gp-lite gopaddle/gopaddle --namespace gp-lite --create-namespace
```

3. Once gopaddle is installed, access the gopaddle UI by following [these](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/overview/getting-started/installing-community-edition/accessing-gopaddle-ui) steps.


# Docker Compose

Install gopaddle community edition using Docker Compose

1. Install Docker Engine in your local environment by following [these](https://docs.docker.com/engine/install/) steps
2. Install Docker Compose in your local environment by following [these](https://docs.docker.com/compose/install/) steps
3. Create a directory to save the docker compose file.

```
mkdir -p gopaddle
cd gopaddle
```

3. Create a Docker compose file with the following content and save the file

```
services:
  gopaddle:
    depends_on: 
      - mongodb
      - redis
    image: gopaddle/gplite
    ports:
      - "8006:8006"
      - "8080:8080"
      - "8017:8017"
      - "8009:8009"
      - "8011:8011"
      - "9090:9090"
    environment:
      BASE_SERVER: http://localhost:8006
      GP_RELEASE: 4.2.7
      INSTALL_SOURCE: lite
      CLUSTER_TYPE: docker
      NODE_IP: http://localhost:8006
      DOMAIN_NAME: http://localhost:8006
      WEBHOOK_NODE_IP: http://localhost:9090
    healthcheck:
      test: curl --fail http://localhost:8080 || exit 1
      interval: 10s
      retries: 5
      start_period: 30s
      timeout: 30s
  mongodb:
    container_name: mongodb
    image: mongo:4.0.4
    restart: always
    environment:
      MONGO_INITDB_ROOT_USERNAME: admin
      MONGO_INITDB_ROOT_PASSWORD: cGFzc3dvcmQ
      MONGO_LITE_USERNAME: lite
    volumes:
      - type: bind
        source: ~/mongodb
        target: /var/lib/mongodb
        bind:
          create_host_path: true
  redis:
    image: gopaddle/redis:3.2-alpine
    container_name: redis
  influxdb:
    image: gopaddle/influxdb:1.7.0
    container_name: influxdb
    environment:
      INFLUXDB_ADMIN_PASSWORD: cGFzc3dvcmQ
      INFLUXDB_ADMIN_USER: admin
      INFLUXDB_HTTP_AUTH_ENABLED: "true"
    volumes:
      - type: bind
        source: ~/influxdb
        target: /var/lib/influxdb
        bind:
          create_host_path: true
  esearch:
    image: elasticsearch:7.12.0
    container_name: esearch
    environment:
      discovery.type: single-node
      ELASTIC_PASSWORD: cGFzc3dvcmQ
  rabbitmq:
    image: gopaddle/rabbitmq:3.8.5
    container_name: rabbitmq
```

3. Deploy the docker compose file as below:

```
docker compose up
```

5. Access the gopaddle UI @ `http://localhosts:8080`


# Accessing gopaddle UI

Steps to get the gopaddle UI endpoint for the gopaddle community edition

## Kubernetes based installation

Follow these steps, if you have installed gopaddle community edition on MicroK8s, SUSE Rancher Prime, Digital Ocean,  Artifact Hub, Kind, Minikube or Helm bassed Installations.

1. Once the gopaddle community is installed, wait for gopaddle services to move to running state

   ```sh
   kubectl wait --for=condition=ready pod -l released-by=gopaddle -n gp-lite
   ```

   If you see this error message `timed out waiting for the condition on pods`, you can execute the above command once again to wait for all the gopaddle services to move to running state.
2. Enable Firewall ports (if installing gopaddle lite on a cloud based VM)

   The following TCP network ports have to be enabled/opened to use the gopaddle lite dashboard:

   * Ports 30000 to 30006: gopaddle endpoints
   * Port 32000: Service node port for Grafana dashboard on Kubernetes
   * Any node port assigned for an application deployed on Kubernetes
3. Access the gopaddle dashboard @ `http://<NODE_IP>:30003`NODE\_IP can be obtained by listing the nodes in the cluster.

```sh
kubectl get nodes -o wide
```

{% hint style="info" %}
If the cluster is installed on cloud based VMs, then the NODE\_IP can be the public IP of the node.
{% endhint %}

Subscribe to gopaddle using your email ID. gopaddle will then send an initial password to the registered email ID. You can now login to the gopaddle dashboard using the email ID and the initial password.

## Docker Compose Installation

gopaddle UI can be accessed @ `http://localhost:8080`

Subscribe to gopaddle using your email ID. gopaddle will then send an initial password to the registered email ID. You can now login to the gopaddle dashboard using the email ID and the initial password.


# Improving performance of resource discovery

As soon as a cluster is registered in gopaddle, gopaddle installs a few add-ons under gopaddle-servers namespace. The `kubeagent` add-on is responsible for discovering Kubernetes resources, tracking resource updates, and annotating the resources with runbook information. For large multi-node clusters, it is recommended to increase the capacity of the `kubeagent` to improve the performance of the Cluster Resource View and Runbook discovery.

### Increasing capacity of multipass VM in case of MacOS

1. Before increasing the capacity of the kubeagent, check the current memory capacity and consumption of the multipass microk8s vm on MacOS.

```
multipass info microk8s-vm
```

2. To increase the capacity of the microk8s multipass VM on MacOS, please follow the prerequisites step 5 stated  [here](https://help.gopaddle.io/overview/getting-started/installing-community-edition/microk8s-addon/on-macos).

### Increasing capacity of kubeagent

1. Enable metrics-server to check the current consumption of the kubeagent pod.

```
microk8s enable metrics-server
```

2. Get the current usage of the kubeagent pod.

```
kubectl top pod -n gopaddle-servers
```

3. If the resource usage of the kubeagent exceeds the limits set for the deployment, increase the limits of the kubeagent deployment. The default requests and limits of the kubeagent deployment is as below:

```
        resources:
          limits:
            cpu: 1200m
            memory: 4G
          requests:
            cpu: 500m
            memory: 1G
```

4. Update the requests and limits of the kubeagent, if necessary.

```
kubectl edit deploy/kubeagent -n gopaddle-servers
```

5. Once the kubeagent deployment is updated, wait for the kubeagent to move to ready state

```
kubectl wait --for=condition=ready pod -l app=kubeagent -n gopaddle-servers  --timeout=15m
```

6. In the gopaddle UI, Refresh the cluster View -> Resources to check the performance

### Increase QPS and Burst limits of kubeagent

1. Check the kubeagent logs and look for any throttling issues:

```
kubectl logs -l app=kubeagent -n gopaddle-servers --all-containers=true --tail=100
```

A sample throttling message would look like this:

`Waited for 1.01761187s due to client-side throttling, not priority and fairness, request: GET:https://10.152.183.1:443/api/v1/nodes`<br>

2. Increase the QPS and Burst parameters by editing the command line arguments of the container in the kubeagent deployment. The default QPS and Burst values are 100 and 200 respectively.
3. Edit the kubeagent deployment.

```
kubectl edit deploy/kubeagent -n gopaddle-servers
```

4. Update the command line arguments in the kubeagent specification.

```
containers:
      - args:
        - |-
          #!/bin/bash
          # echo "----------- start conatainer ------------"
          ./kubeagent --qps=200 --burst=400
        command:
        - /bin/sh
        - -c
```

5. Once the kubeagent deployment is updated, wait for the kubeagent to move to ready state.

```
kubectl wait --for=condition=ready pod -l app=kubeagent -n gopaddle-servers  --timeout=15m
```

6. In the gopaddle UI, Refresh the cluster **View -> Resources** to check the performance<br>


# Provision new Cluster


# Register Cloud Account

Cloud account needs to be registered in order to use Docker Registry or to provision a managed Kubernetes cluster in the cloud platform ...

{% hint style="info" %}
Multi-cloud Cluster Provisioning and external Cluster Registration capability is available only on gopaddle SaaS and Enterprise editions.
{% endhint %}

A Cloud account needs to be registered with gopaddle in order to use a Cloud managed Docker Registry or to provision a managed Kubernetes cluster or use notification services like AWS SNS provided by the cloud platform.

gopaddle supports the following Cloud Platforms :

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td>Amazon Web Services (AWS)</td><td><p>In order to use gopaddle for any of the tasks described below, you must first register your AWS account in gopaddle.</p><ul><li>Provision a new EKS Cluster</li><li>Register an existing EKS Cluster</li><li>Push images to ECR</li><li>Use SNS as a notification channel to send Kubernetes events</li></ul></td><td></td><td><a href="/files/zh50HDKkAM29xnN9O2zc">/files/zh50HDKkAM29xnN9O2zc</a></td></tr><tr><td>Microsoft Azure</td><td></td><td><p>In order to use gopaddle for any of the tasks described below, you must first register your Azure account in gopaddle.</p><ul><li>Provision a new AKS Cluster</li><li>Register an existing AKS Cluster</li><li>Push images to ACR</li></ul><p></p></td><td><a href="/files/8fkMWf4QrM8NIBEdnrIp">/files/8fkMWf4QrM8NIBEdnrIp</a></td></tr><tr><td>Google Cloud Platform</td><td>In order to use gopaddle for any of the tasks described below, you must first register your Google account in gopaddle.</td><td><p></p><ul><li>Provision a new GKE Cluster</li><li>Register an existing GKE Cluster</li><li>Push images to GCR</li></ul></td><td><a href="/files/K8Vk1veYlvAc6RAPAF8H">/files/K8Vk1veYlvAc6RAPAF8H</a></td></tr></tbody></table>


# AWS

Registering an AWS Account provides authenticates gopaddle to provision and manage subnets, VPC, AWS EKS clusters, push or pull Docker ...

Registering an AWS Account in gopaddle, provides gopaddle the required  AWS Account credentials to create EKS clusters, push or pull container images to ECR, use AWS SNS as a notification channel to send Kubernetes events. Registering an AWS Account in gopaddle is simplified through a quick start wizard.

1. [Quickstart AWS Setup](/overview/provision-new-cluster/register-cloud-account/aws/quickstart-aws-setup) to select the AWS Services to use in gopaddle and generate an AWS Setup script
2. Review the [IAM Access policies](/overview/provision-new-cluster/register-cloud-account/aws/iam-access-policies)
3. [Execute the AWS Setup script](/overview/provision-new-cluster/register-cloud-account/aws/aws-setup-script) locally to create a new IAM user, role, assign IAM Access policies and register the IAM User in gopaddle.


# Quickstart AWS Setup

Create IAM Roles and User and Register AWS Cloud Account quickly

The Launch Kubernetes quickstart wizard provides a simple mechanism to registser an AWS Account.

1. Navigate to the **Environments** section.
2. Choose the QuickStart wizard to **Launch Kubernetes**. Select **AWS** as the option.

<figure><img src="/files/C1bvlZis84uZPaIJIWwU" alt="" width="257"><figcaption><p>Launch Kubernetes Quickstart Wizard</p></figcaption></figure>

3. In the **IAM User** Step, provide the **AWS Account ID**. This will automatically generate a shell script that can be run from your local computer.

<figure><img src="/files/0t45udMTEsKnOciKR47E" alt=""><figcaption></figcaption></figure>

4. Select the AWS region under which you would like to use the AWS Services.&#x20;
5. Under **Select Operation Type**, select the AWS services you would like to use in gopaddle in the AWS Account. For instance, select AWS EKS, AWS ECR and/or AWS SNS services.

{% hint style="info" %}
In case of AWS EKS service, select **Grant access to create Application Load Balancer** if you need an Application Load Balancer to be provisioned while launching an EKS cluster.
{% endhint %}

5. Copy and execute the generated AWS Setup script. Please follow the steps in [Executing AWS Setup script](/overview/provision-new-cluster/register-cloud-account/aws/aws-setup-script) to execute the scripts locally.


# IAM Access Policies

Review the IAM Access Policies before executing the AWS Initialization script

Registering an IAM User in gopaddle requires different permissions assigned to the IAM user/role. Please find a complete list of fine-grained, region and account specific permissions required based on the capabilities used in gopaddle.

<table><thead><tr><th width="223">Capability</th><th width="212">AWS Services</th><th>IAM Permissions</th></tr></thead><tbody><tr><td>Creating EKS Cluster and managed Nodegroups</td><td><p></p><p>VPC</p></td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-vpc-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-vpc-policy.json</a></td></tr><tr><td></td><td>Subnet </td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-subnet-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-subnet-policy.json</a></td></tr><tr><td></td><td>Gateway </td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-gateway-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-gateway-policy.json</a></td></tr><tr><td></td><td>EKS and Nodegroup </td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-eks-nodegroup-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-eks-nodegroup-policy.json</a></td></tr><tr><td></td><td> Instance </td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-instance-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-instance-policy.json</a></td></tr><tr><td></td><td>Roles and Security Group</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-role-sg-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-role-sg-policy.json</a></td></tr><tr><td></td><td>Cloudformation Template </td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-stack-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-stack-policy.json</a></td></tr><tr><td></td><td>Cloudwatch</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-cloudwatch-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-cloudwatch-policy.json</a></td></tr><tr><td></td><td>Create Application Load Balancer </td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-alb-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-alb-policy.json</a></td></tr><tr><td>AWS ECR Registry </td><td>ECR</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-repository-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-repository-policy.json</a></td></tr><tr><td>AWS SNS Amazon</td><td>SNS</td><td><span data-gb-custom-inline data-tag="emoji" data-code="1f511">🔑</span> <a href="https://gp-cloudformation-roles.s3.amazonaws.com/gp-sns-policy.json">https://gp-cloudformation-roles.s3.amazonaws.com/gp-sns-policy.json</a></td></tr></tbody></table>


# AWS Setup Script

Setup the IAM User, Roles and Policies and register the IAM User in gopaddle

## AWS Setup Script

The setup script creates an IAM user, role and assigns [required permissions](/overview/provision-new-cluster/register-cloud-account/aws/iam-access-policies) to use the AWS Services in gopaddle platform. It then registers the newly created IAM User Credentials in gopaddle.

{% hint style="info" %}
You can choose to execute the steps manually. The script can be downloaded from <https://gp-quickstart.s3.amazonaws.com/gp-aws-init.sh>
{% endhint %}

The script assigns [fine-grained permissions](/overview/provision-new-cluster/register-cloud-account/aws/iam-access-policies) to the newly created IAM User based on the region and the services selected.

## Executing AWS Setup script

Perform these steps in your local desktop environment

1. Install & Configure AWS CLI and the required utilities - jq, unzip.

```sh
apt update
apt install -y jq unzip
curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
unzip awscliv2.zip
sudo ./aws/install
```

2. Create an AWS IAM User with [these](https://gp-cloudformation-roles.s3.amazonaws.com/quickstart-IAM-permissions.json) admin privileges. These privileges are required to create a new IAM user, assign roles to the user and register the IAM User in gopaddle. To review the policies associated with these roles, check the [IAM Access Policies](/overview/provision-new-cluster/register-cloud-account/aws/iam-access-policies).
3. Configure the AWS CLI with the IAM **admin** user credentials

```sh
aws configure
```

4. Execute the script generated in [Quickstart AWS Setup](/overview/provision-new-cluster/register-cloud-account/aws/quickstart-aws-setup) in your local environment


# Azure

Register Azure Account to create new AKS Clusters or register an existing AKS Cluster

Register an Azure Account in gopaddle is a 3 step process.

1. [Create an Azure Application](/overview/provision-new-cluster/register-cloud-account/azure/create-azure-application) in the Azure Portal
2. [Register Cloud Authenticator](/overview/provision-new-cluster/register-cloud-account/azure/register-azure-cloud-authenticator) in gopaddle
3. Perform a Single-Sign-On to [register the Azure Account](/overview/provision-new-cluster/register-cloud-account/azure/register-azure-account) in gopaddle


# Create Azure Application

Create Azure Application before registering a Cloud Authenticator

1. **Activate a Subscription:** Activate at least one subscription by navigating to <https://portal.azure.com/#allservices> in Azure Account and Select Subscriptions service. If no subscriptions are available, click on Add to add a new subscription.

<figure><img src="https://downloads.intercomcdn.com/i/o/198357465/f40738dcc8fdfe45ff0d0183/aks-add-subscription-wizard.png" alt=""><figcaption></figcaption></figure>

Copy the Subscription ID. This ID will be used at the time of creating an AKS cluster via gopaddle.

**2. Register Resource Providers:** Click on the subscription created in step 1 and select **Resource Providers**. Select the following Resource Providers and register them.<br>

<figure><img src="/files/rpmXW8204BeFcjMJMxsV" alt=""><figcaption><p>Resource Providers to be registered</p></figcaption></figure>

3\. **Add a User:** To add a new user, go to <https://portal.azure.com/#allservices> and filter & select Azure Active Directory. Under **Manage option**, select **Users**. Create a New User.

4\. **Create Custom Role:** Add Owner role to the newly created user, by navigating to Subscriptions under <https://portal.azure.com/#allservices>. Select the subscription. Filter and select IAM. Under Access Control (IAM) Section, choose **+ Add to add a custom role**.

<figure><img src="https://downloads.intercomcdn.com/i/o/471030096/eb27901fdca1d8aaebea9c84/add-azure-custom-role.png" alt=""><figcaption></figcaption></figure>

In the role creation wizard, choose the JSON tab. Click Edit to edit the permissions list.

[Download Custom Role ACL Template](https://gopaddle-marketing.s3.ap-southeast-2.amazonaws.com/azure-acl-premissions.json) and replace ***\<role-name>*** with the custom role name and ***\<subscription-id>*** with the Azure subscription id.&#x20;

Update the JSON permissions list in the Azure Console with the updated permissions from the template.

<figure><img src="https://downloads.intercomcdn.com/i/o/471030052/82fc76e644cc57fc4fe804cc/add-azure-permissions.png" alt=""><figcaption></figcaption></figure>

Click on **Review + create** to create the custom role.

5\. Access Control (IAM) Section, 'Add role assignments'. Select the custom role and assign it to the newly created user.

> :bulb: **Note**: The permssions for the custom role does not allow the newly created user to create or delete a Container registry. Either a root user or a different sub-user with sufficient permissions, can create the Container registry. The newly created sub-user can then push or pull the Docker images from this registry.

6\. **Add Application Administrator Role**: Navigate to this users list from here <https://portal.azure.com/#blade/Microsoft_AAD_IAM/UsersManagementMenuBlade/MsGraphUsers>. Select the user and choose the Assigned Roles. Add 'Application administrator' role to the user.

<figure><img src="https://downloads.intercomcdn.com/i/o/380374173/8d62d429cdd4bd374869dc58/Screenshot+2021-08-25+at+2.52.05+PM.png" alt=""><figcaption></figcaption></figure>

7\. **Add an Application**: Login to the Azure portal as the new User. Go to <https://portal.azure.com/#allservices> and select Azure Active Directory. Under Manage option, select App Registrations. Click on New Registration and add a new Application.\
Choose the account type as : **Accounts in any organizational directory (Any Azure AD directory - Multitenant)**<br>

<figure><img src="https://downloads.intercomcdn.com/i/o/284777957/80cfb7dadc35ee7c82a000f8/gp-azure-registerapplication.png" alt=""><figcaption></figcaption></figure>

To create Azure Cluster from a SaaS gopaddle account, provide the redirect URL as <https://portal.gopaddle.io/cloudaccounts> . To create Azure Cluster from an on-premise gopaddle installation, provider the redirect URL as \<http (or) https>://\<gopaddlehomeIP/domain>/clouds.\
\
8\. Once the application is created, click on the Application to manage the application. Note down the Application (client) ID.

9\. **Add Client Secret** : Under Manage option, select Certificates and Secrets. Create a New client secret. Note down the Value of the client secret. The Application (client) ID and the client secret Value generated in step 5 and 6 will be used to register a new Cloud Account Authenticator.


# Register Azure Cloud Authenticator

Register an Azure Cloud Authenticator to authenticate Single-Sign-On (SSO) requests from gopaddle

1\. In the gopaddle console, navigate to the Settings option in the top navigation bar. Choose **Cloud** and select the **Authenticators** option.

2\. Choose the **Add Cloud Authenticator** Option.

3\. In the registration wizard, provide an authenticator name. If you are using the managed gopaddle, then set the re-direct URL as <https://portal.gopaddle.io/cloudaccounts>. If you are using on-premise gopaddle installation, then set the re-direct URL as \<http/https>://\<gopaddlehomeIP/domain>/cloudaccounts.

[![](https://downloads.intercomcdn.com/i/o/475909270/25173a9788891ee64af8e403/gopaddle-cloudauth-register.png)](https://downloads.intercomcdn.com/i/o/475909270/25173a9788891ee64af8e403/gopaddle-cloudauth-register.png)

4\. Under Client ID and Client Secret, copy/paste the Client ID and Client Secret Value created while [Creating Azure Application](/overview/provision-new-cluster/register-cloud-account/azure/create-azure-application).

5\. Click **Register** to register the authenticator.

<br>


# Register Azure Account

Register Azure Account in gopaddle UI

1. Once the Azure Authenticator is registered, register the Azure Account by navigating to the **Settings** option in the top navigation panel in gopaddle.
2. Click on **Cloud** and select **Cloud Accounts**.
3. Click on Register Azure Account
4. Choose the [Azure Cloud Authenticator](/overview/provision-new-cluster/register-cloud-account/azure/register-azure-cloud-authenticator) created earlier, to authenticate the Azure Registration.

[![](https://downloads.intercomcdn.com/i/o/284780109/5657f40b7042233705958eb4/gp-azure-select-authenticator.png)](https://downloads.intercomcdn.com/i/o/284780109/5657f40b7042233705958eb4/gp-azure-select-authenticator.png)

5. Click on **Register**. This will open a new window with a Single-Sign-On window to Azure portal. Use the user login created while [Creating the Azure Application.](https://help.gopaddle.io/en/articles/3871017-create-azure-application)

[![](https://downloads.intercomcdn.com/i/o/284780603/011318f46bf9be358f67868b/gp-azure-accept-sso.png)](https://downloads.intercomcdn.com/i/o/284780603/011318f46bf9be358f67868b/gp-azure-accept-sso.png)

5\. Select **Confirm** to confirm the authenticator request. You will be redirected back to gopaddle portal and the Azure account will be registered with the gopaddle portal.


# Google

Registering a Google Account authenticates gopaddle to provision and manage Google GKE clusters, push or pull Docker Images ..

Registering a Google Account in gopaddle, provides gopaddle the required Google Account credentials to provision and manage Google GKE clusters, push or pull Docker Images to the Artifact (Docker) Registry.  Registering a Google Account is a three step process. First a role with the necessary access privileges needs to be created in the Google Cloud Console. This role is assigned to a newly created Service Account. The Service account credentials are then used to register the Google Account in the gopaddle portal.

## Pre-requisite <a href="#pre-requisite" id="pre-requisite"></a>

gopaddle uses Google's Kubernetes Engine API in order to provision and manage GKE clusters. Before registering a Google Cloud Account ensure that the API is enabled in the Google Cloud [Kubernetes Engine page](https://console.cloud.google.com/projectselector/kubernetes?_ga=2.66341549.224307538.1596556232-303781057.1596556232)

### Step-1 : Create a Role <a href="#h_e3ad8233c8" id="h_e3ad8233c8"></a>

You can create a new role either using the gcloud command line utility or from the Google Cloud Console.

1. Install gcloud utility by following the step [here](https://cloud.google.com/sdk/docs/install).
2. Download the google IAM role permissions file.

[Download IAM permissions file](https://gopaddle-marketing.s3.ap-southeast-2.amazonaws.com/gopaddle-gke-sa-iam-role.yaml)

3. Edit the gopaddle-gke-sa-iam-role.yaml file locally and change the title from **'IAM role demo'** to a desired title.
4. Login to Google Cloud Account

```
gcloud auth login
```

5. Using gcloud command-line utility, create a new role with the required permissions.

```sh
gcloud iam roles create <role-name> --project=<Project_ID> --file=<permissions-file-path>
```

When the following message pops up, type 'Y' to proceed.

```
Note: permissions [container.clusterRoles.escalate, container.namespaces.finalize, container.pods.initialize, 
container.roles.escalate] are in 'TESTING' stage which means the functionality is not mature and they can go away in 
the future. This can break your workflows, so do not use them in production systems!

Are you sure you want to make this change? (Y/n)?  Y
```

### Step -2 Creating a Service Account <a href="#h_ef2630ef4b" id="h_ef2630ef4b"></a>

1. From the Google Cloud Console,  select the top navigation bar.

<figure><img src="/files/2CgAO31Chi0QLOHZkSAJ" alt="" width="198"><figcaption></figcaption></figure>

2. Choose **API & Services** and Choose **Credentials**
3. Click on **CREATE CREDENTIALS** to create a new credential of type Service account
4. Name the Service account and choose the newly created Role to associate with the Service Account. If you have created the role using the gcloud utility, then choose the role IAM demo role.
5. Create a Key for the Service Account by clicking on CREATE KEY
6. Create a JSON file based key.
7. Save the JSON file generated

<figure><img src="https://downloads.intercomcdn.com/i/o/377480989/49a12d7f709fa93bec6f3d81/Screenshot+2021-08-18+at+6.00.53+PM.png" alt="" width="375"><figcaption></figcaption></figure>

7\. Note down the Service Account email ID.&#x20;

<figure><img src="https://downloads.intercomcdn.com/i/o/200426387/c07c96c8abaabbc324fd4e19/gp-gke-serviceaccount-details.png" alt="" width="375"><figcaption></figcaption></figure>

Note down the Google Project Name, Service Account Email ID, JSON file generated in the previous steps to register the Google Cloud Account in gopaddle.

## Registering a Google Account in gopaddle <a href="#h_cfd1d2f84e" id="h_cfd1d2f84e"></a>

1. In the gopaddle UI, navigate to the **Settings** option in the top navigation bar.
2. Select the **Cloud** and then the **Cloud Accounts** tab.
3. Click on **Add Cloud Account** to register the Google Cloud Account.
4. In the account registration wizard, choose the **Provider** as Google.
5. Provide the **Service Account Email ID**, and upload the **Service Account** JSON Key file.
6. Click on Create to **Register** the Google Cloud Account.

<figure><img src="https://downloads.intercomcdn.com/i/o/475915817/86ef8e755e07c99786e9c8b0/gopaddle-google-register.png" alt=""><figcaption></figcaption></figure>


# Provision Clusters on Cloud

Provision managed Kubernetes clusters across AWS, Azure and Google

{% hint style="info" %}
Multi-cloud Cluster Provisioning and external Cluster Registration capability is available only on gopaddle SaaS and Enterprise editions.
{% endhint %}

{% hint style="info" %}
Provisioning Clusters on Cloud Required corresponding Cloud Accounts to be registered first.
{% endhint %}

gopaddle integrates with Cloud APIs and SDKs to provision and centrally manage clusters across multiple Cloud Accounts without having to navigate across different Cloud portals.

gopaddle supports the following managed Kubernetes Clusters :

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th></tr></thead><tbody><tr><td>Amazon Web Services (AWS) EKS</td><td><ul><li>Provision EKS across multiple HA zones with <strong>Public</strong> Access Endpoint</li><li>Provision EKS across multiple HA with <strong>Private</strong> Access Endpoint (with SSM agent and bastion host configuration)</li><li>Add and update Node pools with default or custom AMI images</li><li>Create New VPCs and Subnets </li><li>Re-use existing VPCs and subnets</li><li>Automation of Cert Manager, OIDC configuration and Application Load Balancers</li><li>Automatic Configuration of Prometheus Monitoring and Grafana dashboard</li></ul></td><td></td><td><a href="/files/zh50HDKkAM29xnN9O2zc">/files/zh50HDKkAM29xnN9O2zc</a></td></tr><tr><td>Microsoft Azure AKS</td><td></td><td><ul><li>Provision a new multi-region AKS Cluster</li><li>Add and update Node pool with fine grained scaling rules</li><li>Automatic Configuration of Prometheus Monitoring and Grafana dashboard</li></ul></td><td><a href="/files/8fkMWf4QrM8NIBEdnrIp">/files/8fkMWf4QrM8NIBEdnrIp</a></td></tr><tr><td>Google Cloud Platform GKE</td><td><ul><li>Provision new GKE across multiple HA zones</li><li>Add and update node pools</li><li>Automatic Configuration of Prometheus Monitoring and Grafana dashboard</li></ul></td><td></td><td><a href="/files/K8Vk1veYlvAc6RAPAF8H">/files/K8Vk1veYlvAc6RAPAF8H</a></td></tr></tbody></table>


# AWS EKS

Provision new AWS EKS Cluster from gopaddle UI


# AWS EKS Reference Architecture

Production Ready EKS Reference Architecture used while provisioning clusters through gopaddle

<figure><img src="/files/sEhGHA1Vv51Zm5magwQd" alt=""><figcaption><p>EKS Reference Architecture provisioned through gopaddle</p></figcaption></figure>

### VPC has public or private subnets

### Configuring Subnets

<table><thead><tr><th>VPC Access Type</th><th width="172">Route Table Config</th><th>Auto-assign public IP</th><th>Endpoints</th><th>AWS Loadbalancer Controller</th></tr></thead><tbody><tr><td>Public Only</td><td>Route table - outbound to 0.0.0.0/0</td><td>Yes</td><td></td><td><code>kubernetes.io/role/elb=1</code></td></tr><tr><td>Public/Private</td><td>Route table - outbound to NAT gateway, allow only outbound</td><td>No</td><td></td><td><code>kubernetes.io/role/elb=1 kubernetes.io/role/internal-elb=1</code></td></tr><tr><td>Private Only</td><td>NA</td><td>No</td><td><p><code>com.amazonaws.your_region.ec2 com.amazonaws.your_region.ecr.api com.amazonaws.your_region.ecr.dkr</code> <code>com.amazonaws.your_region.s3</code><br></p><p><strong>cloudwatch</strong> - </p><p><code>com.amazonaws.your_region.logs</code> </p><p></p><p><strong>sts</strong> - com.amazonaws.your_region.sts</p><p>com.amazonaws.your_region.elasticloadbalancing</p><p><br><strong>K8s cluster autoscaler</strong> - </p><p><code>com.amazonaws.your_region.autoscaling</code> </p><p></p><p><strong>K8s App mesh (Envoy)</strong> - <code>com.amazonaws.your_region.appmesh- envoy-management</code><br></p><p><strong>XRay</strong> - <code>com.amazonaws.your_region.xray</code></p></td><td><code>kubernetes.io/role/internal-elb=1</code></td></tr></tbody></table>

Application Load Balancer and OIDC

<figure><img src="/files/sJGrSfioWbPmqj1jzRNF" alt=""><figcaption></figcaption></figure>

OIDC Configuration and Sub-net configurations

<figure><img src="/files/9Pl62pUubD9aq3EbNQDK" alt=""><figcaption></figcaption></figure>

### Domain Certificate Manager

Provision, manage and deploy SSL/TLS Certificates with AWS Services & User Applications

Associate managed certificate ARN as an annotation in the Application Loadbalancer Ingress controller

`service.beta.kubernetes.io/aws-load-balancer-ssl-cert: arn:aws:acm:us-west-2:xxxxx:certificate/xxxxxxx`

### Self-Managed Nodepools

Bottlerocket - Linux Based AMIs - light weight and quick up time

CFT with custom instance profile

Define your own ASG

### Detailed overview of configuring production ready EKS Cluster.

{% embed url="<https://www.youtube.com/live/XSDA01f0F54?feature=share>" %}


# Adding an AWS IAM Role (EKS Master / Node Pool)

gopaddle offers a pre-defined Cloud Formation Template to create Roles to associate with the AWS EKS master and Node pool.

gopaddle offers a pre-defined Cloud Formation Template to create Roles to associate with the AWS EKS master and Node pool. While creating an AWS EKS cluster through gopaddle, you will be provided with an option to create a Role.&#x20;

In the cluster creation wizard, click the Create option next to the Role ARN to take you to the AWS Console to create a Stack. If you are not already logged in to the AWS Console, login using the IAM User that was used to register the AWS Cloud Account or with the root login.

## Steps to Create an IAM Role  <a href="#steps-to-create-an-iam-role" id="steps-to-create-an-iam-role"></a>

1. gopaddle uses 2 different templates to create a Master Role and a Node Pool Role.

You can review the templates here :

* Master Role Template : <https://gp-cloudformation-roles.s3.amazonaws.com/clusterrole.yaml>
* Node Pool template : [https://gp-cloudformation-roles.s3.amazonaws.com/nodegrouprole.yaml ](https://gp-cloudformation-roles.s3.amazonaws.com/nodegrouprole.yaml)(used for both managed and custom AMI node pools)

2\. Proceed with the default values and select Next

<figure><img src="https://downloads.intercomcdn.com/i/o/197091978/2dd02af972d2932a89bfe822/gp-cluster-arn-stackspec.png" alt=""><figcaption></figcaption></figure>

3\. The stack name is automatically generated by gopaddle every time a new stack is created. Proceed with the default and select Next.<br>

<figure><img src="https://downloads.intercomcdn.com/i/o/197092317/71863fd0729b4434c42e5e2e/gp-cluster-arn-configstack.png" alt=""><figcaption></figcaption></figure>

4\. Confirm the changes by clicking on the Check box and then choose Create Stack.

5\. Once the stack is created, copy the ARN from the output section.<br>

<figure><img src="https://downloads.intercomcdn.com/i/o/197092737/a31ca34ab94d5380de0dcbb5/gp-cluster-role-arncopy.png" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Master and Node pool Roles are not managed by gopaddle. Hence the corresponding role needs to be deleted manually once a cluster or a node pool is deleted.
{% endhint %}


# Public EKS Cluster

Provision EKS cluster with Public Access Endpoint

{% hint style="info" %}
Multi-cloud Cluster Provisioning and external Cluster Registration capability is available only on gopaddle SaaS and Enterprise editions.
{% endhint %}

{% hint style="info" %}
Provisioning Clusters on Cloud Required corresponding Cloud Accounts to be registered first.
{% endhint %}

## Steps to create an Amazon EKS cluster <a href="#steps-to-create-an-amazon-eks-cluster" id="steps-to-create-an-amazon-eks-cluster"></a>

1. In gopaddle UI, navigate to the **Environments** section
2. Click on **Add a Cluster** and choose **Create Cluster on Cloud**
3. In the Cluster Creation **Cluster** step, choose the **Cloud Provider** type as **AWS,** the **Cloud Accoun**t registered in gopaddle.

<figure><img src="/files/YbeESgyvwPtNFBFqsXo8" alt=""><figcaption><p>AWS EKS Cluster Configuration in gopaddle</p></figcaption></figure>

4. Choose **Enable ALB** to uses AWS Application Load Balancer as ingress while deploying workloads on EKS.
5. **Select a region** where EKS needs to be provisioned.
6. Choose the Cluster Access Type - **Public** or **Private**. In case of Private, Please refer to the [All Private EKS Cluster (beta)](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/aws-eks/all-private-eks-cluster-beta) documentation on more information.&#x20;

In case of EKS clusters with **Public** Access and if you are using **Application LoadBalancer**, VPC Subnets can be one of the following

* Public Only Subnets (minimum of 2 subnets required)
* Private Only (minimum of 2 subnets required)
* Public and Private (minimum of 4 subnets required)

In case of EKS clusters with **Private** Access and if you are using **Application LoadBalancer**, VPC Subnets can be only of the following type

* Private Only (minimum of 2 subnets required)

Check the [Configuring Subnets](/overview/provision-new-cluster/provision-clusters-on-cloud/aws-eks/aws-eks-reference-architecture) section in the AWS EKS Reference Architecture to configure and use your own VPC Subnets.

4. You can either **Use Existing VPC** with the above subnet category or let gopaddle provision VPC and subnets automatically.&#x20;
5. **Master Role ARN**: Creating an EKS cluster requires an IAM role to be associated with the master node and to the node pools in the Cluster as well. Since the IAM policy provided during the AWS Cloud Account registration assumes permissions to create an IAM role, you need to create an IAM role manually by clicking on the **Add Master Role** option. This will redirect you to the AWS Management Console. Navigate through the Cloud Formation Stack creation process. Once the stack creation is complete, navigate to the output section to copy the Master Role ARN. Paste the ARN in Add Master Role input. For more information on the Master Role, please check the [Adding AWS IAM Role (EKS Master / Node Pool)](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/aws-eks/adding-an-aws-iam-role-eks-master-node-pool)
6. Creating an EKS cluster requires at the least 1 node pool to be created at the time of cluster creation. Follow the steps [here](https://help.gopaddle.io/en/articles/4966430-creating-an-eks-node-pool) to create a node pool.
7. Add Node Pool by following the steps in [Creating a Node Pool](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/aws-eks/creating-a-nodepool)
8. Click on **Finish** to provision a new EKS cluster.


# All Private EKS Cluster (beta)

Provisioning a secure, all private AWS EKS Cluster within a private VPC

gopaddle cluster provisioning provides multiple options to provision an AWS EKS cluster in a customer's AWS cloud account. In an all private EKS cluster, the access ends points of the cluster are private and the nodepools and the nodes within the cluster are provisioned in private subnets without an Internet gateway. Since there is no external access, the cluster resources are accessible within a private VPC.

In gopaddle v4.2.6, it is possible to provision an all private EKS cluster. You can use an existing VPC with all private subnets (a minimum of 3 subnets requried) or you can let gopaddle provision a new VPC and 3 new subnets within the VPC;

Currently, this capability requires an IAM user with Administrator Access. We are working on granular access privileges to streamline the access control. Hence please use this capability only in test environments.

{% hint style="info" %}
Multi-cloud Cluster Provisioning and external Cluster Registration capability is available only on gopaddle SaaS and Enterprise editions.
{% endhint %}

{% hint style="info" %}
Provisioning Clusters on Cloud Required corresponding Cloud Accounts to be registered first.
{% endhint %}

## Provision all private EKS cluster <a href="#h_dec5258d7d" id="h_dec5258d7d"></a>

Under the Environments section, choose Add a Cluster and then Create new Cluster.

<figure><img src="https://downloads.intercomcdn.com/i/o/729584973/1cfad1811e0d20213dbdd2b9/Screen+Shot+2023-04-27+at+2.25.58+AM.png" alt=""><figcaption></figcaption></figure>

## Step - 1 (Cloud Account, VPC/Subnet, Access & Master Role) <a href="#h_37bcc63748" id="h_37bcc63748"></a>

a) Cloud Account and Kubernetes Configuration

* Provide a Cluster Name
* Choose the Cloud Provider type as AWS EKS
* Select the AWS Cloud Account
* Choose the Kubernetes version
* Select a Region

b) Access Configuration

* Select the Cluster Access Type as Private

  <figure><img src="https://downloads.intercomcdn.com/i/o/729595590/3789f1ca0fdb767ea5eb6dcc/Screen+Shot+2023-04-27+at+2.31.47+AM.png" alt=""><figcaption></figcaption></figure>

c) VPC and Subnet Configuration

* Existing VPC: In order to use an existing VPC, select Use Existing VPC and provide the VPC ID. gopaddle will auto-discover the subnets within the VPC. Select the subnets to be used.
* Create new VPC: By default, gopaddle provides the option to create a new VPC. Provide the CIDR for the VPC and subnets.

d) Master Role Configuration

* Click on Add Master Role to create a role in the AWS account. Copy the role ARN from the stack output from the AWS console and paste in the gopaddle cluster creation wizard.

  ```
  Make sure there are no trailing spaces in the role ARN.
  ```

## Step - 2 (Bastion Host) <a href="#h_be30a74ce8" id="h_be30a74ce8"></a>

In the next step, provide the bastion host configuration,

<figure><img src="https://downloads.intercomcdn.com/i/o/729596666/7088f3eedaba58c1c0fd00e2/Screen+Shot+2023-04-27+at+2.36.48+AM.png" alt=""><figcaption></figcaption></figure>

* Select the AWS Instance Key, AMI ID, Availability zone and the subnet CIDR where the bastion host needs to be created

  ```
  Only Ubuntu 18.04 images are supported
  ```
* The AWS Instance Key and the private PEM file will will be used to access the bastion host and register the cluster with gopaddle. You can use the PEM file to SSH to the bastion host and access the cluster once the cluster is ready.
* Click on Add Automation Role to add bastion host instance profile to the cluster. Copy the role ARN from the stack output from the AWS console and paste in the gopaddle cluster creation wizard.

  ```
  Make sure there are no trailing spaces in the role ARN.
  ```

## Step - 3 (Node Pool Configuration) <a href="#h_d7dc1cd890" id="h_d7dc1cd890"></a>

In the last step, provide the node pool details:

<figure><img src="https://downloads.intercomcdn.com/i/o/729598038/cebb2a0e98ad14bde45a3a47/Screen+Shot+2023-04-27+at+2.40.25+AM.png" alt=""><figcaption></figcaption></figure>

* Provide a node pool name, minimum/maximum/desired node count and the disk space required
* Choose a minimum of 2 availability zones.
* Click on Create Node Role to create a node instance role. Copy the role ARN from the stack output from the AWS console and paste in the gopaddle cluster creation wizard. Make sure there are no trailing spaces in the role ARN.

Click on finish to create the EKS cluster. This process may take 20 - 30 minutes to complete.

Once the cluster is provisioned, gopaddle will automatically trigger a discovery process to discover existing resources in the EKS cluster. Once the discovery is complete, you can view the Kubernetes specifications under the Design Studio and the namespaces under the Applications tab.

## Troubleshooting a cluster provision error <a href="#h_e3a21c0850" id="h_e3a21c0850"></a>

If the cluster provisioning fails, you can find more logs under the Cluster Activities.

### Cluster Activities <a href="#h_f0d5cffa19" id="h_f0d5cffa19"></a>

<figure><img src="https://downloads.intercomcdn.com/i/o/729600613/b3f054b699384f28023eaf8b/Screen+Shot+2023-04-27+at+2.57.51+AM.png" alt=""><figcaption></figcaption></figure>

### Cloud Formation Stack Logs <a href="#h_e5829ae856" id="h_e5829ae856"></a>

You can find the AWS Cloud Formation stack logs under the logs tab.

<figure><img src="https://downloads.intercomcdn.com/i/o/729600679/2df7c297689e262f8de49bd4/Screen+Shot+2023-04-27+at+2.58.10+AM.png" alt=""><figcaption></figcaption></figure>

Click on view option to view a specific stack log.

<figure><img src="https://downloads.intercomcdn.com/i/o/729600763/0c8df7f715b857a882e9e8f1/Screen+Shot+2023-04-27+at+3.00.02+AM.png" alt=""><figcaption></figcaption></figure>


# Creating a Node Pool

Create and manage 2 different types of nodepools in EKS - managed, custom

Nodepool can be added to AWS EKS cluster at the time of cluster creation or to an existing EKS cluster.

gopaddle supports 2 different types of nodepools :

(a) Managed - Uses EKS AMIs and standard nodepool supported by AWS

(b) Custom - Supports Custom AMI. For example, you can choose an ubuntu custom AMI from [here](https://cloud-images.ubuntu.com/docs/aws/eks/) based on the region and cluster version that you choose to provider.

### Common Attributes : <a href="#h_3958a419e6" id="h_3958a419e6"></a>

* AWS Key - All the AWS private keys available within the selected region will be listed. If no keys are available, then create a new private Key in AWS console before adding a node pool. To create a private key, follow the AWS documentation on [Amazon EC2 key pairs.](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html)
* Disk Size - Minimum disk size in GB
* Min Nodes - Minimum Number of nodes in the node pool.
* Max Nodes - Maximum Number of nodes in the node pool.
* Desired Size - The desired number of nodes to be created while creating the node pool. Desired size must be within the min and max node counts.\
  Node Type (GPU) - Choose GPU for compute intensive workloads like Deep Learning.
* AMI Type - Available type is AL2\_x86\_64, AL2\_x86\_64\_GPU and AL2\_ARM\_64. Only when GPU node type is selected, AL2\_x86\_64\_GPU type will be available.
* Availability Zone - One or more availability zones where the nodes within the nodepool needs to be provisioned.

{% tabs %}
{% tab title="Managed Node Pool" %}
Fill the common attributes required to create a node pool and add the node pool to the cluster.

<figure><img src="/files/1WgySJq8uXmIK1sVFVIr" alt=""><figcaption></figcaption></figure>

Create a new node pool role and enter the nodepool role ARN before adding the node pool. Check the Role ARN reference [here](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/aws-eks/adding-an-aws-iam-role-eks-master-node-pool) for more information.

Once the nodepool is provisioned, AWS sets a label *"eks.amazonaws.com/nodegroup:\<nodepoolname>"* to group the nodes within the nodepool and identify their readiness. These labels can be used as nodeSelectors at the time of deploying workloads to this node pool. When an autoscaling event occurs, new nodes are labeled with nodepool name as well.
{% endtab %}

{% tab title="Custom Node Pool" %}
When custom node pool type is chosen, provide the custom AMI to be used while creating the node pool.

<figure><img src="/files/wyXAQWoyzgueKDreTBhl" alt=""><figcaption></figcaption></figure>

Create a new node pool role and enter the nodepool role ARN before adding the node pool. Check the Role ARN reference [here](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/aws-eks/adding-an-aws-iam-role-eks-master-node-pool) for more information. gopaddle uses Cloud Formation Template (CFT) to provision the custom node pool. You can check the Stack Log section for the CFT logs for further debugging.

Once the nodepool is provisioned, gopaddle sets 2 labels *"nodePoolName:\<nodepoolname>"* and "nodePoolType:customNodePool" to group the nodes within the nodepool and identify their readiness. These labels can be used as nodeSelectors at the time of deploying workloads to this node pool. When an autoscaling event occurs, new nodes are labeled with nodepool name as well.
{% endtab %}
{% endtabs %}


# Azure AKS

Provision Azure AKS Cluster using gopaddle

{% hint style="info" %}
Multi-cloud Cluster Provisioning and external Cluster Registration capability is available only on gopaddle SaaS and Enterprise editions.
{% endhint %}

{% hint style="info" %}
Provisioning Clusters on Cloud Required corresponding Cloud Accounts to be registered first.
{% endhint %}

1. In gopaddle UI, navigate to the **Environments** section
2. Click on **Add a Cluster** and choose **Create Cluster on Cloud**
3. In the Cluster Creation **Cluster** step, choose the **Cloud Provider** type as **Azure,** the **Cloud Accoun**t registered and the **Azure Subscription** in the account.

<figure><img src="/files/ANimcAnRBmKarPsfAiic" alt=""><figcaption><p>Azure Cluster Configuration in gopaddle</p></figcaption></figure>

4. Select the **SKU** - either Free or Paid and **Select Regions** where the cluster has to be created.
5. Proceed the steps in [Creating a Node Pool](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/azure-aks/creating-a-nodepool) to add the configurations to provision a System Nodepool.
6. In the Autoscaling Rule Sets, configure the VMSS Autoscaling rule. Please check the [VMSS Autoscaling Rules](https://app.gitbook.com/o/kaNNkk5MWdImsh5Ur4MO/s/5QxXxCob5M5VXQJTryRc/~/changes/7/provision-multi-cloud-clusters/provision-clusters-on-cloud/azure-aks/vmss-autoscaling-rules) for more information.
7. Click on **Finish** to provision the AKS Cluster.


# Creating a Node Pool

Create a System or User Node pool in AKS cluster

Nodepools can be added to an Azure AKS cluster at the time of cluster creation or to an existing AKS cluster.

At the time of creating an AKS cluster, by default a **System** Node pool is chosen that Node pool type.

If you are adding a Nodepool to a pre-existing AKS cluster, you can choose to create a **User Node pool**.

<figure><img src="/files/JM6lZ8M7xENXgOvob1iS" alt=""><figcaption><p>Azure System Node pool configuration in gopaddle</p></figcaption></figure>

{% hint style="warning" %}
Select more than one Availability Zones
{% endhint %}

{% hint style="info" %}
To access the cluster over public IP, choose the Enable Node Public IP option. Additional, follow the steps under [**Enable Public IP Node Access for Azure Deployments**](/overview/provision-new-cluster/provision-clusters-on-cloud/azure-aks/enable-public-ip-node-access-for-azure-deployments)
{% endhint %}


# Enable Public IP Node Access for Azure Deployments

Steps to enable public IP access to the work loads deployed on Azure AKS Node pools

The public IP feature has to be enabled for the Azure account before we could set public IP access for a specific node pool.

1. Download and install Azure CLI by following [these](https://learn.microsoft.com/en-us/cli/azure/install-azure-cli) steps.
2. Log in to Azure account.

```sh
az login
```

3. Add **aks-preview** extension using azure-cli

```sh
az extension add --name aks-preview
```

4. Register the NodePublicIPPreview feature

```sh
az feature register --name NodePublicIPPreview --namespace Microsoft.ContainerService
```

5. Check status using the following command if it moved to 'registered' then the NodePublicIPPreview enabled successfully. It takes nearly 20-30 minutes.

```sh
az feature list -o table --query "[?contains(name, 'Microsoft.ContainerService/NodePublicIPPreview')].{Name:name,State:properties.state}"
```

6. While adding NodePools to the Azure cluster, choose the “Enable Node Public IP “ option in the gopaddle UI.
7. Open the firewall port from your azure account to access the workloads.

→ Login to azure portal.

→ In the search bar filter “**Network security**”. In that list choose your agent pool.

→ On the left side panel, click on the ‘**Inbound rule**’ option, in that you have to add the port number which you want to open.


# VMSS Autoscaling Rules

Azure Autoscaling rules can be attached to an Azure Node pool to dynamically scale up or down the nodes within the nodepool.

### Pre-requisite: <a href="#h_867b447ce4" id="h_867b447ce4"></a>

1. In order to use the Azure Autoscaling rules, enable the `microsoft.insights` in the Azure Subscription.
2. Login to your Azure account.
3. Choose the Subscription and Under Resource Providers search for `microsoft.insights` and enable it.

### Adding autoscaling rules to Azure node pool <a href="#h_5919565695" id="h_5919565695"></a>

While creating the cluster via gopaddle or while adding a node pool to the cluster via gopaddle, you can set the scaling rules for the node pool.

<figure><img src="/files/tHGeo3wFDs6xUz6AgqaS" alt=""><figcaption><p>Azure VMSS Scaling Rules in gopaddle</p></figcaption></figure>

Metric defines the attribute to be monitored. Scaling can be performed based on the below mentioned metrics.

1. Percentage CPU
2. Network In
3. Network Out
4. Disk Read Bytes
5. Disk Write Bytes
6. Disk Read Operations/Sec
7. Disk Write Operations/Sec
8. CPU Credits Remaining
9. CPU Credits Consumed

Measure specifies the measure of the metrics to be watched for. Measure can be one of the blow:

1. Average
2. Minimum
3. Maximum
4. Total
5. Last
6. Count

'When' specifies the operator. It can be :

Capacity specifies the value of the metric.

* \>=
* <
* <=
* \=
* !=

Scale specifies whether to increase or decrease the node count in the node pool.

Scale by specifies the number of nodes to increase or decrease.

Scale Type specifies the behaviour once the scaling condition matches. It can be

1. **ChangeCount**: Increase or decrease the number of nodes
2. **ExactCount**: Maintain a specified number of nodes
3. **PertcentChangeCount**: Increase or decrease the number of nodes by a percentage of the current nodes.

Watch Duration is the duration to watche the change in metric before triggering an autoscaling event.

Cooldown Period is the duration to wait before triggering the subsequent autoscaling event.

Time Window is the sampling duratin and is used to normalize the metrics collected. Say aggregate the data every 1 minute.

Statistic specifies the aggregation method for the time window. It can be :

1. Average
2. Min
3. Max
4. Sum

For more information on Azure Virtual Machine Scaling Set (VMSS), please check the document [here](https://docs.microsoft.com/en-us/azure/azure-monitor/autoscale/autoscale-understanding-settings).


# Google GKE

Provision GKE Cluster using gopaddle

{% hint style="info" %}
Multi-cloud Cluster Provisioning and external Cluster Registration capability is available only on gopaddle SaaS and Enterprise editions.
{% endhint %}

{% hint style="info" %}
Provisioning Clusters on Cloud Required corresponding Cloud Accounts to be registered first.
{% endhint %}

1. In gopaddle UI, navigate to the **Environments** section
2. Click on **Add a Cluster** and choose **Create Cluster on Cloud**
3. In the Cluster Creation **Cluster** step, choose the **Cloud Provider** type as **Google GKE**
4. Choose the registered **Cloud Account,** Google **Project ID** and **Select Regions**

<figure><img src="/files/9fVajyBxQtFtz7ZvDT6m" alt=""><figcaption></figcaption></figure>

5. Under the Node Pool section, provide the node pool configuration and click on Finish to create a new GKE Cluster.


# Creating a Node Pool

Configure and add a node pool to a new GKE cluster or add a node pool to an existing cluster

Nodepools can be added to Google GKE cluster at the time of cluster creation or to an existing GKE cluster.

<figure><img src="/files/p1hA2TBsZqIysi3Ayygl" alt=""><figcaption><p>GKE Node pool configuration in gopaddle</p></figcaption></figure>

**Initial Node Count** - Number of Nodes that will be provisioned in the Node pool at the time of node pool creation.

**Min Count** - Minimum Number of Nodes that will be maintained in the Node pool at any time.

**Max Count** - Maximum Number of Nodes that will be permitted in the Node pool at any time.

{% hint style="warning" %}
Select more than one Availability Zones
{% endhint %}

{% hint style="info" %}
To access the cluster over public IP, choose the Enable Node Public IP option.
{% endhint %}


# Cluster Resource View Issues


# Network Error ! ServerError: Response not successful: Received status code 503

### Scenario

Viewing the resources under a cluster, may fail with error.  <mark style="color:red;">**Network Error !**</mark> <mark style="color:red;"></mark><mark style="color:red;">ServerError: Response not successful: Received status code 503</mark>. This happens when you try to view the cluster resources immediately after registering the Cluster in gopaddle.

<figure><img src="/files/z8ob4oaslejRuPhdym0d" alt=""><figcaption><p><strong>Network Error !</strong> ServerError: Response not successful: Received status code 503</p></figcaption></figure>

### Solution

###

1. Navigate to the cluster Home folder.
2. Under the **Installed Add Ons** section, verify if the **kubeagent-server** is listed.

<figure><img src="/files/eZmWfwRCBx2Kq1F5l9z8" alt=""><figcaption></figcaption></figure>

3. Click on cluster **Refresh** option to refresh the discovered resources

<figure><img src="https://lh7-us.googleusercontent.com/E6aFPXycWyCsSeBSZLOggdAnDas6A_Rm2K5QOleJZwOomHb5b4LvTy5_IeEueShZ5jQQJIigYHf_ZFrk0L6UJ0_CK60Np8Twe-yvEL7Xj1Bc4Ax0un2G369Uy7X9KZuVToAYN0NeBd-ZGKgyj5Qh69E" alt=""><figcaption><p>Refresh the Cluster Page</p></figcaption></figure>

4. If the problem persists, then perform the below step to make sure the kubeagent pod is in running state.

   ```
   kubectl wait --for=condition=ready pod -l app=kubeagent -n gopaddle-servers
   ```


# Network Error ! TypeError: Failed to fetch

### Scenario

In a gopaddle community edition, viewing the resources under a cluster, may fail with error.  <mark style="color:red;">Network Error ! TypeError: Failed to fetch</mark> This happens immediately after initial login and while refreshing, or viewing the resources under a cluster.&#x20;

<figure><img src="https://lh7-us.googleusercontent.com/pkZFXxS_z_hJIiYNAC6fMK2UytagXezuxhP0sL2GKCLZa4KlY5s228rgapAFyAB8f3AJ8w2kn--r1-TPDOM1qCckDwDxPrut6ilwolLVrx2fOcgpeTMAyMNtNkNPL4L3A_hFhodxkHaW5S63EFVT0Pw" alt=""><figcaption><p>Network Error ! TypeError: Failed to fetch</p></figcaption></figure>

### Solution

1. Wait until the kubeagent addon is moved to ready state

```
kubectl wait --for=condition=ready pod -l app=kubeagent -n gopaddle-servers
```

2. Click on cluster **Refresh** option to refresh the discovered resources

<figure><img src="https://lh7-us.googleusercontent.com/E6aFPXycWyCsSeBSZLOggdAnDas6A_Rm2K5QOleJZwOomHb5b4LvTy5_IeEueShZ5jQQJIigYHf_ZFrk0L6UJ0_CK60Np8Twe-yvEL7Xj1Bc4Ax0un2G369Uy7X9KZuVToAYN0NeBd-ZGKgyj5Qh69E" alt=""><figcaption><p>Refresh the Cluster Page</p></figcaption></figure>

3. If the problem persists, then perform a full page reload


# Network Error ! ServerParseError: Unexpected token 'j', "json: erro"... is not valid JSON

### Scenario

Viewing the resources under a cluster, may fail with error. <mark style="color:red;">Network Error ! ServerParseError: Unexpected token 'j', "json: erro"... is not valid JSON</mark>

### Solution

Click on cluster **Refresh** option to refresh the discovered resources

<figure><img src="https://lh7-us.googleusercontent.com/E6aFPXycWyCsSeBSZLOggdAnDas6A_Rm2K5QOleJZwOomHb5b4LvTy5_IeEueShZ5jQQJIigYHf_ZFrk0L6UJ0_CK60Np8Twe-yvEL7Xj1Bc4Ax0un2G369Uy7X9KZuVToAYN0NeBd-ZGKgyj5Qh69E" alt=""><figcaption><p>Refresh the Cluster View Page</p></figcaption></figure>

<br>


# Updating Labels and Annotations does not get reflected in resources list

### Scenario

Updating Labels and Annotations of a Kubernetes resource using YAML Editor or OpenAPI Schema form does not get reflected in the resources list table.

### Solution

Updating annotations and labels on a Kubernetes resource updates the resource's metadata, however this type of update does not trigger an update event. In order to fetch the updated information click on the **Refresh** option to refresh the resources list.

<figure><img src="https://lh7-us.googleusercontent.com/E6aFPXycWyCsSeBSZLOggdAnDas6A_Rm2K5QOleJZwOomHb5b4LvTy5_IeEueShZ5jQQJIigYHf_ZFrk0L6UJ0_CK60Np8Twe-yvEL7Xj1Bc4Ax0un2G369Uy7X9KZuVToAYN0NeBd-ZGKgyj5Qh69E" alt=""><figcaption><p>Refresh the Cluster Page</p></figcaption></figure>

<br>


# Filtered resources are not fully listed

### Scenario

Sometimes filtered resources under **Cluster -> View -> Resources** are not listed fully. Only a few entries are listed.

### Solution

Click on cluster **Refresh** option to refresh the discovered resources

<figure><img src="https://lh7-us.googleusercontent.com/E6aFPXycWyCsSeBSZLOggdAnDas6A_Rm2K5QOleJZwOomHb5b4LvTy5_IeEueShZ5jQQJIigYHf_ZFrk0L6UJ0_CK60Np8Twe-yvEL7Xj1Bc4Ax0un2G369Uy7X9KZuVToAYN0NeBd-ZGKgyj5Qh69E" alt=""><figcaption><p>Refresh the Cluster Page</p></figcaption></figure>

<br>


# Runbook Issues


# Deleting a runbook from .gp.yaml does not detach annotation in resources

### Scenario

After deleting a runbook from the `.gp.yaml` file in the Github repository and refreshing the Runbook Hub in the gopaddle UI, does not remove the runbook icon ![](https://lh7-us.googleusercontent.com/m6hAq5yvLnd3E1s0uOBZJGjCwkJsskzARdbcuaPKUYi8Qk0dOuhXqk3UFMaweXUOi9KsE6WgxKfkv_rfCCw7IVKUPUWRCKdL9xEXG5OKb8SbQEFK72j3o5r-YWTlLaU-h_AXhRGpqQfFBvSZMSaAXGA)for the associated resources.

### Solution

* [Detach the Runbook Hub](/overview/runbook-hub/detach-runbook-hub-from-cluster) from the cluster.
* [Attach the Runbook](/overview/runbook-hub/attach-runbook-hub-to-cluster) Hub to the cluster.

<br>


# Deleting a Code Account from gopaddle UI does not detach annotation in resources

### Scenario

After deleting a registered GitHub account from gopaddle UI, some of the Kubernetes resources still show the runbook icon ![](https://lh7-us.googleusercontent.com/m6hAq5yvLnd3E1s0uOBZJGjCwkJsskzARdbcuaPKUYi8Qk0dOuhXqk3UFMaweXUOi9KsE6WgxKfkv_rfCCw7IVKUPUWRCKdL9xEXG5OKb8SbQEFK72j3o5r-YWTlLaU-h_AXhRGpqQfFBvSZMSaAXGA)

### Solution

* List filtered resources with runbooks
* Edit the resource using a YAML editor and remove the annotation <mark style="color:purple;">`gopaddle.io/runbookHub`</mark> and the label <mark style="color:purple;">`runbook: 'true'`</mark>  and Submit the changes.
* Click on the **Refresh** option to refresh the resources list.


# Jira Issues


# Creating, Updating or Appending a Jira issue fails with error INVALID\_INPUT

### Scenario

Creating a Jira Issue from Chat window fails with the error  <mark style="color:red;">"received non-ok status code: 400, body: {"errorMessages":\["INVALID\_INPUT"],"errors":{}}\n"</mark>\ <br>

<figure><img src="https://lh7-us.googleusercontent.com/GliOQIL6K_bUoKlug5cYUSTlEe3SMmeRKv6goNDahkGnc4xsrRDcML8SZJGbblgofgvdspDBgiAv4ihaxwHyxZo_oapoMDGGKHtuFzhcVd3BTxZTwvyrJ2D_mm1WAGL2QYIFQrP3xNYiP-HGLvGbZzE" alt=""><figcaption><p>Jira Issue Create Fails</p></figcaption></figure>

### Solution

This happens where there are special characters in the troubleshooting tips that cannot be converted to Atlassian Document Format. Try recreating the troubleshooting or optimization tips and then repeat the Jira issue create/update/append calls.


# EKS Issues

<details>

<summary>EKS creation fails with 'Cross-account pass role is not allowed.' in activity log</summary>

### Reason

This error happens if the AWS Cloud Account you have chosen at the time of cluster creation is different from the one where the cluster role and the node pool roles were created.

<img src="https://downloads.intercomcdn.com/i/o/287516988/b49ffc7be7c414dedc095686/gp-eks-cross-account-error.png" alt="" data-size="original">

### Resolution

Delete the cluster and recreate it by choosing the right AWS Account.

</details>

<details>

<summary>Application access endpoint is missing for application launched on EKS with ALB</summary>

### Scenario <a href="#h_9be640d810" id="h_9be640d810"></a>

When an application is launched on AWS EKS with ALB using gopaddle, the access endpoint for the application does not show a valid URL.

<img src="https://downloads.intercomcdn.com/i/o/513876076/7528f84bd23a6f24562e5779/Screenshot+2022-05-16+at+7.05.05+PM.png" alt="" data-size="original">

Under the application view page, the endpoint show 'AWS Application Load Balancer'.

Application, Service, its replicas and containers are in a running state. However, under the application Activities page, an IngressWarning is observed. Expanding on the warning, shows the error message "Failed build model due to WebIdentityErr: failed to retrieve credentials caused by: AccessDenied: Not authorized to perform sts:AssumeRoleWithWebIdentity status code: 403"

<img src="https://downloads.intercomcdn.com/i/o/513861939/577feeeae1016ccb4950b331/Screenshot+2022-05-16+at+6.49.01+PM.png" alt="" data-size="original">

### Reason <a href="#h_6c4022d5cc" id="h_6c4022d5cc"></a>

The ALB ARN used while creating the EKS cluster does not match the cluster details. Check the cluster view page and check the section Kube Master. Note down the Cluster ID and the region details.

<img src="https://downloads.intercomcdn.com/i/o/513874809/61cb02a4352fe54e82b7c556/Screenshot+2022-05-16+at+7.06.24+PM.png" alt="" data-size="original">

Under the ALB Cloud Formation Template section. Under the AmazonEKSLoadBalancerControllerRole in the Principal section for the ARN. Verify if the cluster ID and the region details match.

<img src="https://downloads.intercomcdn.com/i/o/513874985/1b47db108c9aec3856bd2298/Screenshot+2022-05-16+at+7.06.39+PM.png" alt="" data-size="original">

This could be because of uploading a wrong ALB Cloud Formation Template through gopaddle UI at the time of installing ALB controller in the newly created EKS cluster.

### Resolution <a href="#h_591179bd91" id="h_591179bd91"></a>

Currently gopaddle does not support updating the ARN. The cluster needs to be deleted and re-created. Once the new cluster is created, download the ALB template and make sure the right ALB template is uploaded while installing the ALB controller.

</details>

<details>

<summary>Creating an EKS Cluster fails with 'Cannot create a VPC'</summary>

### Scenario <a href="#scenario" id="scenario"></a>

Creating an EKS cluster through gopaddle fails with the error "Cannot create a VPC". The cluster moves to Unknown status and the Activity Logs shows the below messages.

<img src="https://downloads.intercomcdn.com/i/o/214617242/39f8d97ccd2810285aee4c9b/gp-vpccreation-failed.png" alt="" data-size="original">

### Solution <a href="#solution" id="solution"></a>

The above issue could happen for various reasons. To identify the exact cause of failure, select the Stack Logs section and choose VPC Stack from the drop down. In this scenario, you can find the corresponding reason for CREATE\_FAILED as "API: ec2:ModifySubnetAttribute You are not authorized to perform this operation."

<img src="https://downloads.intercomcdn.com/i/o/214617342/88d99c7f9a851d6ed5a7255b/gp-subnetpermission-missing.png" alt="" data-size="original">

This indicates that the IAM User used to register the corresponding AWS Cloud Account needs ec2:ModifySubnetAttribute to update the subnets within the VPC. Once the IAM user is updated with the new permission, create a new cluster once again from the gopaddle portal.

</details>

<details>

<summary>Creating an EKS cluster fails with "The security token included in the request is invalid"</summary>

### Scenario <a href="#scenario" id="scenario"></a>

Creating an EKS cluster through gopaddle fails with the error "The security token included in the request is invalid". The cluster moves to Unknown status and the Activity Logs shows the below messages.

<img src="https://downloads.intercomcdn.com/i/o/207092484/64286d5538e2dc17bac569a9/gp-eks-securitytoken.png" alt="" data-size="original">

### Solution <a href="#solution" id="solution"></a>

The above issue happens when either the master or the node pool ARN is incorrect. Recreate the Cluster with valid ARNs.

</details>

<details>

<summary>Node Pool is not created while creating an EKS Cluster</summary>

### Scenario

While creating an EKS cluster, Cluster moves to Running state but the node pool is not created.

<img src="https://downloads.intercomcdn.com/i/o/208292432/2dbb4957b4b1ee5bd82e2dc3/eks-no-nodepool.png" alt="" data-size="original">

Under Activity Logs, Event GETTING\_EKS\_CLUSTER\_KUBEVERSION fails with timeout message as below:<br>

<img src="https://downloads.intercomcdn.com/i/o/208292550/a338d8145c9f78ad8321b20b/eks-gettingversion-failed.png" alt="" data-size="original">

\
In the Cloud Account section, Accessibility Check shows Failed status.<br>

<img src="https://downloads.intercomcdn.com/i/o/208290846/f4fe8f1fd8f709d25ef45815/eks-unverified.png" alt="" data-size="original">

This happens when EKS Cluster takes too long to respond with its Kubernetes version. This may happen due to network delays or when EKS cluster is not in ready state.

### Solution

Click on Verfiy option to Accessibility Check. Once the Accessibility is verified, you can start creating a node pool under the Node Pool section.

<img src="https://downloads.intercomcdn.com/i/o/208293925/81095dc91d2fc17886d546b5/eks-verified.png" alt="" data-size="original">

<br>

</details>

<details>

<summary>Deleting a Node pool in EKS fails</summary>

## Scenario <a href="#scenario" id="scenario"></a>

Deleting a node pool in EKS cluster fails and the node pool is moved to "Failed" state, however the nodes within the pool are deleted.

<img src="https://downloads.intercomcdn.com/i/o/182422597/5ad10ef2d70131af124ce940/gp-nodepool-delete-fail.png" alt="" data-size="original">

The Activity log show the following failure message.

<img src="https://downloads.intercomcdn.com/i/o/182423047/fb064dbc00b74f2296a3d68b/gp-nodepool-activitylog.png" alt="" data-size="original">

\
This happens when an application is deployed on the EKS cluster and is scheduled on the nodepool which is being deleted. The network interfaces for the nodepool are not deleted automatically. Security group has a dependency on the Network interface and thus the node pool deletion fails with a Dependency Violation error.

## Solution <a href="#solution" id="solution"></a>

```
Deleting a nodepool when in use can cause unpredictable application behavior.
```

1. Detach and Delete the network interfaces from the AWS console directly.
2. Delete the nodepool from the gopaddle console or from the AWS console.

</details>


# Deployment Issues

<details>

<summary>Service stuck in pending state - Reason : 0/1 nodes are available: Too many pods.</summary>

### Scenario <a href="#h_1cc8b253ab" id="h_1cc8b253ab"></a>

When an application is deployed, the services are stuck in pending state in the application view page. When a specific replica is viewed, it shows the error - 0/1 nodes are available: \<nodecount> Too many pods.

[![](https://downloads.intercomcdn.com/i/o/488035700/d44beecab5ca4e261f152db7/Drawing.sketchpad.png)](https://downloads.intercomcdn.com/i/o/488035700/d44beecab5ca4e261f152db7/Drawing.sketchpad.png)

Under containers, there are no containers provisioned.

### Resolution <a href="#h_991175dad4" id="h_991175dad4"></a>

This error could happen due to 2 reasons.

1. The number of replicas provisioned on a specific node exceeded the maximum limit assigned on that node.
2. The number of private IP addresses assigned to the replicas exceeded the maximum number of private IPs possible for node size.

In both scenarios, the cluster does not automatically scale and add another node. To overcome this issue, you can increase the desired node code in the cluster.

Navigate to the cluster view page, click on the node pool and edit the desired node count.

<img src="https://downloads.intercomcdn.com/i/o/488042721/236aea38aad53720b1484773/Drawing.sketchpad+%281%29.png" alt="" data-size="original">

Below are the list of node pool fields to be edited for different types of managed clusters.

* AWS EKS - Desired Capacity
* Google GKE - Initial Count
* Azure AKS - Desired Count

</details>

<details>

<summary>exec user process caused "exec format error"</summary>

### Scenario <a href="#scenario" id="scenario"></a>

When the application is deployed, the service moves to pending state and the container moves to Waiting state with the reason as CrashLoopBackOff. The container logs show the error standard\_init\_linux.go:178: exec user process caused “exec format error”

<img src="https://downloads.intercomcdn.com/i/o/232747885/d5f37c1fa942489e612969bb/gp-troubleshoot-execformaterror.png" alt="" data-size="original">

#### Reason 1: <a href="#h_993f05d162" id="h_993f05d162"></a>

This error is encountered when trying to run a go binary inside a Docker container. This is because the host machine and the Docker container have different architectures and operating systems. The go binary must be compiled for the architecture and operating system of the Docker container in order for it to be executed.

#### Solution <a href="#h_8381f82485" id="h_8381f82485"></a>

If you are onboarding a Dockerfile based container then make sure the right architecture is specified in your build command. Say, for instance, if you are building the binary on a MacOS, but your runtime Docker container is based on Ubuntu, you can compile your binary like below:

```sh
GOOS=linux go build -o myprogram
```

#### Reason 2 : <a href="#h_e14d24e453" id="h_e14d24e453"></a>

This error could appear due to missing script header like #!/bin/bash or #!/bin/sh in the container start script. The error may also occur due to any empty line or space before the script header.

### Solution <a href="#solution" id="solution"></a>

Click on the info link for the container, and edit the start script to include the header as the first line of the start script. Save the start script.

Here is an example of how a startscript with script header:

```sh
#!/bin/bash
npm start
```

This will automatically restart the replica after a few seconds. If you desire to restart the replica immediately, you can click on the Delete option next to the replica. This will bring down the replica and create a new replica with the updated start script in the container.

</details>

<details>

<summary>pod has unbound immediate PersistentVolumeClaims : node(s) had taints that the pod didn't tolerate.</summary>

## Scenario <a href="#scenario" id="scenario"></a>

Deploying an application with Stateful services, results in Stateful Service stuck in pending state for long. Examining the Service replica log shows the error :&#x20;

Failed to provision volume with StorageClass "gp-landingpage-sc-uj2z": InvalidZone.NotFound: The zone 'us-east-1a' does not exist.\
pod has unbound immediate PersistentVolumeClaims\
0/1 nodes are available: 1 node(s) had taints that the pod didn't tolerate.\
no nodes available to schedule pods

This happens when the Service is scheduled on a nodepool in a different availability zone where as the Volume Provision Policy provisions the volume in a different availability zone.

## Resolution <a href="#resolution" id="resolution"></a>

Modify the Volume Provision Policy to the availability zone to match the node pool availability zone.

</details>


# Node Issues

Troubleshooting node events when node is not in ready status

<details>

<summary>🔔  Event: FreeDiskSpaceFailed</summary>

🔍 **Reason:** Not enough disk space in the node

By default, the Kubernetes garbage collection (GC) gets triggered when the disk usage on a node crosses the HighThresholdPercent value (90% default). The ImageGCManager deletes images starting with the oldest and last used image until the disk usage reaches the LowThresholdPercent value. In some cases, GC does not get triggered. In such scenarios, the FreeDiskSpaceFailed event occurs.

💡 **Solution**

Clean up some space or resize the volume. Look for unused docker images and clean up the unused images. Say, for instance, you can run the Spotify's GC to manually clean up the images on the node.

```
docker run --rm --privileged -v /var/run/docker.sock:/var/run/docker.sock -v /etc:/etc:ro spotify/docker-gc
```

</details>

<details>

<summary>🔔 Event: ImageGCFailed</summary>

**🔍 Reason:** If the disk space threshold hits default 90%, then ImageGCManager does the cleanup automatically. Sometimes ImageGCFailed error appears in the node events if the garbage collection fails.

**💡 Solution:** Same as FreeDiskSpaceFailed

</details>

<details>

<summary>🔔 Event: ContainerGCFailed</summary>

**🔍 Reason:** Node is overloaded (not always reflected as disk or memory pressure). Not enough resources are allocated to Docker and it fails to respond in time.

**💡 Solution**

1. Set limits for pods to prevent overloading the Nod
2. Cordon and evict the pods
3. Reboot the server

🔍 **Reason 2:** Evictions thresholds are too close to the node's physical memory limits

💡 **Solution 2:** Leave some buffer while setting eviction thresholds

For more troubleshooting check - <https://kubernetes.feisky.xyz/v/en/index/cluster>

</details>

<details>

<summary>🔔 Event: InvalidDiskCapacity</summary>

**🔍 Reason 1:** invalid capacity 0 on image filesystem & the node is in 'NotReady' status

This occurs when kubelet does not recognize the disk availability.

💡 **Solution 1:** Restart containerd and kubelet daemons on the node.

```
systemctl restart containerd
systemctl restart kubelet
```

(or on microk8s)

```
sudo systemctl restart snap.microk8s.daemon-kubelet
sudo systemctl status snap.microk8s.daemon-kubelet
```

🔍 **Reason 2:** cgroups not enabled on the node(edge ARM)

💡 **Solution 2:** Enable cgroups and reboot the node

```
sudo echo "cgroup_enable=memory cgroup_memory=1" >> /boot/firmware/cmdline.txt
reboot
```

</details>


# Huawei Issues

<details>

<summary>Cluster registration fails with : no configuration has been provided, try setting KUBERNETES_MASTER environment variable</summary>

### Reason

Registering Huawei Cloud Container Service via bastion host in gopaddle fails with error : no configuration has been provided, try setting KUBERNETES\_MASTER environment variable

### Resolution

Ensure that Huawei Cloud Container Service does not have an EIP assigned while downloading the kubeconfig file from the Huawei Cloud Console.

If an EIP is assigned, then unbind the EIP, and re-download the kubeconfig file.

Use the new kubeconfig file to register the Huawei Cluster in gopaddle.

</details>


