Тёмный
No video :(

Workload Identity in GKE to fetch data from Google Cloud Storage. 

OutOfDevOps
Подписаться 1,8 тыс.
Просмотров 4,5 тыс.
50% 1

How to use Workload Identity in GKE to fetch data from Google Cloud Storage.
In this video, I will show you how to use Workload Identity in GKE to fetch data from Google Cloud Storage. Workload Identity allows your Kubernetes workloads to impersonate Google service accounts, which gives them access to Google Cloud APIs.
To get started, you will need to create a Kubernetes service account and a Google service account. You will also need to grant the Google service account permission to access the Google Cloud Storage bucket that you want to fetch data from.
Once you have created the service accounts and granted permissions, you can use the gcloud command-line tool to bind the Kubernetes service account to the Google service account. You can then use the kubectl command-line tool to deploy the modified workload workload.
In the deployment, you will need to specify the Kubernetes service account that you want to use and the name of the Google Cloud Storage bucket that you want to fetch data from.
Once you have deployed your workload, you can access the data from Google Cloud Storage using the NGINX container.
I hope this video was helpful. Please let me know if you have any questions in the comments below.
WHO AM I:
Hey friends, welcome to my RU-vid channel @outofdevops . If you're new my name is Anto, here I talk about software engineering and software engineers. Don't forget to comment like and subscribe 👍🏻.
RU-vid GEAR:
🎥 My RU-vid Camera Gear - kit.co/outofde...
MY SOCIAL LINKs:
🐦 Twitter - / outofdevops
📘 Facebook - / outofdevops
📰 My blog - amasucci.com
📸 Instagram - / outofdevops
GET IN TOUCH:
If you’d like to talk, I’d love to hear from you. Tweeting @OutOfDevOps directly will be the quickest way to get a response, but if your question is very long, feel free to email me at hi@OutOfDevOps.com.
PS: Some of the links in this description are affiliate links that I get a kickback from 😜

Опубликовано:

 

28 авг 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 19   
@alexanderpopov9801
@alexanderpopov9801 Месяц назад
Thank you, Anto, that was useful to me! ❤
@OutOfDevOps
@OutOfDevOps 23 дня назад
Glad it was helpful!
@liamray2010
@liamray2010 6 месяцев назад
Thank you for the explanation! I was a bit scared of your hand in the end haha :)
@navinkumar6388
@navinkumar6388 6 месяцев назад
Thanks with Love from India 🇮🇳
@OutOfDevOps
@OutOfDevOps 6 месяцев назад
Thank you for the kind comment
@navinkumar6388
@navinkumar6388 6 месяцев назад
@@OutOfDevOps I am shifting from Java Spring Microsercice to DevOps About to face interviews and Just came across your GCP, Kubernetes and Docker. Hope with the help of your videos 📷 I can win a match
@lifewinsful
@lifewinsful Год назад
nice explanation
@OutOfDevOps
@OutOfDevOps Год назад
Thanks and welcome
@maalamhrez7361
@maalamhrez7361 Год назад
neat and clean, thank!
@OutOfDevOps
@OutOfDevOps Год назад
Thank you
@user-ds5gu4qn7y
@user-ds5gu4qn7y Год назад
great tutorial
@scratchbin
@scratchbin Год назад
Very clear. Thanks
@OutOfDevOps
@OutOfDevOps Год назад
You are very welcome 😎
@prajeetkumbhare8437
@prajeetkumbhare8437 2 месяца назад
I have followed the same but I am unable to put to delete files from bucket
@rohitthakur1628
@rohitthakur1628 2 месяца назад
For deleting objects in a bucket, you need a role with bucket write permission. Video showed the object viewer role only which can only fetch/read the bucket objects
@QuangPham-bc7lc
@QuangPham-bc7lc 10 месяцев назад
i have create firewall but still can't access. And if we use workload identity, which SA will GKE use (SA of nodepool or SA of workload identity) to pull container image from image registry like GAR or GCR?
@rohitthakur1628
@rohitthakur1628 2 месяца назад
If you haven't explicitly provided the workload identity SA name in the pod manifest then Default GKE node pool/machine's SA is used to the pull the images from GCR. That's my understanding. And if you provide the workload identity SA name then its permission is used for required interaction with other gcp resources.
@harkiratsingh5253
@harkiratsingh5253 27 дней назад
Hey thanks for the video.. I am doing the same thing where i need to fetch images for GCP artifact registry, however i am getting issue -> failed to pull and unpack image "us-central1-docker.pkg.dev/xxxxxxxxxxx/jenkins/jenkins-slave:v2": failed to resolve reference "us-central1-docker.pkg.dev/xxxxxxxx/jenkins/jenkins-slave:v2": failed to authorize: failed to fetch oauth token: unexpected status from GET request to ....403 Forbidden, what to do here
Далее
Init containers in Kubernetes: examples and use cases
5:58
Connecting to Cloud SQL from Kubernetes
14:17
Просмотров 19 тыс.
Workload Identity (OIDC) for AKS
15:18
Просмотров 7 тыс.
Don't Use Confluence for Technical Documentation
9:05
Просмотров 2,1 тыс.
GENERATIVE AI in DevOps - Kubiya
10:00
Просмотров 3,2 тыс.