×

Creating a GCP project

To install OKD, you must create a project in your Google Cloud Platform (GCP) account to host the cluster.

Procedure
  • Create a project to host your OKD cluster. See Creating and Managing Projects in the GCP documentation.

    Your GCP project must use the Premium Network Service Tier if you are using installer-provisioned infrastructure. The Standard Network Service Tier is not supported for clusters installed using the installation program. The installation program configures internal load balancing for the api-int.<cluster_name>.<base_domain> URL; the Premium Tier is required for internal load balancing.

Enabling API services in GCP

Your Google Cloud Platform (GCP) project requires access to several API services to complete OKD installation.

Prerequisites
  • You created a project to host your cluster.

Procedure
  • Enable the following required API services in the project that hosts your cluster. You may also enable optional API services which are not required for installation. See Enabling services in the GCP documentation.

    Table 1. Required API services
    API service Console service name

    Compute Engine API

    compute.googleapis.com

    Cloud Resource Manager API

    cloudresourcemanager.googleapis.com

    Google DNS API

    dns.googleapis.com

    IAM Service Account Credentials API

    iamcredentials.googleapis.com

    Identity and Access Management (IAM) API

    iam.googleapis.com

    Service Usage API

    serviceusage.googleapis.com

    Table 2. Optional API services
    API service Console service name

    Google Cloud APIs

    cloudapis.googleapis.com

    Service Management API

    servicemanagement.googleapis.com

    Google Cloud Storage JSON API

    storage-api.googleapis.com

    Cloud Storage

    storage-component.googleapis.com

Configuring DNS for GCP

To install OKD, the Google Cloud Platform (GCP) account you use must have a dedicated public hosted zone in the same project that you host the OKD cluster. This zone must be authoritative for the domain. The DNS service provides cluster DNS resolution and name lookup for external connections to the cluster.

Procedure
  1. Identify your domain, or subdomain, and registrar. You can transfer an existing domain and registrar or obtain a new one through GCP or another source.

    If you purchase a new domain, it can take time for the relevant DNS changes to propagate. For more information about purchasing domains through Google, see Google Domains.

  2. Create a public hosted zone for your domain or subdomain in your GCP project. See Creating public zones in the GCP documentation.

    Use an appropriate root domain, such as openshiftcorp.com, or subdomain, such as clusters.openshiftcorp.com.

  3. Extract the new authoritative name servers from the hosted zone records. See Look up your Cloud DNS name servers in the GCP documentation.

    You typically have four name servers.

  4. Update the registrar records for the name servers that your domain uses. For example, if you registered your domain to Google Domains, see the following topic in the Google Domains Help: How to switch to custom name servers.

  5. If you migrated your root domain to Google Cloud DNS, migrate your DNS records. See Migrating to Cloud DNS in the GCP documentation.

  6. If you use a subdomain, follow your company’s procedures to add its delegation records to the parent domain. This process might include a request to your company’s IT department or the division that controls the root domain and DNS services for your company.

GCP account limits

The OKD cluster uses a number of Google Cloud Platform (GCP) components, but the default Quotas do not affect your ability to install a default OKD cluster.

A default cluster, which contains three compute and three control plane machines, uses the following resources. Note that some resources are required only during the bootstrap process and are removed after the cluster deploys.

Table 3. GCP resources used in a default cluster
Service Component Location Total resources required Resources removed after bootstrap

Service account

IAM

Global

6

1

Firewall rules

Compute

Global

11

1

Forwarding rules

Compute

Global

2

0

In-use global IP addresses

Compute

Global

4

1

Health checks

Compute

Global

3

0

Images

Compute

Global

1

0

Networks

Compute

Global

2

0

Static IP addresses

Compute

Region

4

1

Routers

Compute

Global

1

0

Routes

Compute

Global

2

0

Subnetworks

Compute

Global

2

0

Target pools

Compute

Global

3

0

CPUs

Compute

Region

28

4

Persistent disk SSD (GB)

Compute

Region

896

128

If any of the quotas are insufficient during installation, the installation program displays an error that states both which quota was exceeded and the region.

Be sure to consider your actual cluster size, planned cluster growth, and any usage from other clusters that are associated with your account. The CPU, static IP addresses, and persistent disk SSD (storage) quotas are the ones that are most likely to be insufficient.

If you plan to deploy your cluster in one of the following regions, you will exceed the maximum storage quota and are likely to exceed the CPU quota limit:

  • asia-east2

  • asia-northeast2

  • asia-south1

  • australia-southeast1

  • europe-north1

  • europe-west2

  • europe-west3

  • europe-west6

  • northamerica-northeast1

  • southamerica-east1

  • us-west2

You can increase resource quotas from the GCP console, but you might need to file a support ticket. Be sure to plan your cluster size early so that you can allow time to resolve the support ticket before you install your OKD cluster.

Creating a service account in GCP

OKD requires a Google Cloud Platform (GCP) service account that provides authentication and authorization to access data in the Google APIs. If you do not have an existing IAM service account that contains the required roles in your project, you must create one.

Prerequisites
  • You created a project to host your cluster.

Procedure
  1. Create a service account in the project that you use to host your OKD cluster. See Creating a service account in the GCP documentation.

  2. Grant the service account the appropriate permissions. You can either grant the individual permissions that follow or assign the Owner role to it. See Granting roles to a service account for specific resources.

    While making the service account an owner of the project is the easiest way to gain the required permissions, it means that service account has complete control over the project. You must determine if the risk that comes from offering that power is acceptable.

  3. You can create the service account key in JSON format, or attach the service account to a GCP virtual machine. See Creating service account keys and Creating and enabling service accounts for instances in the GCP documentation.

    If you use a virtual machine with an attached service account to create your cluster, you must set credentialsMode: Manual in the install-config.yaml file before installation.

Required GCP roles

When you attach the Owner role to the service account that you create, you grant that service account all permissions, including those that are required to install OKD. If your organization’s security policies require a more restrictive set of permissions, you can create a service account with the following permissions. If you deploy your cluster into an existing virtual private cloud (VPC), the service account does not require certain networking permissions, which are noted in the following lists:

Required roles for the installation program
  • Compute Admin

  • Role Administrator

  • Security Admin

  • Service Account Admin

  • Service Account Key Admin

  • Service Account User

  • Storage Admin

Required roles for creating network resources during installation
  • DNS Administrator

Required roles for using the Cloud Credential Operator in passthrough mode
  • Compute Load Balancer Admin

The following roles are applied to the service accounts that the control plane and compute machines use:

Table 4. GCP service account roles
Account Roles

Control Plane

roles/compute.instanceAdmin

roles/compute.networkAdmin

roles/compute.securityAdmin

roles/storage.admin

roles/iam.serviceAccountUser

Compute

roles/compute.viewer

roles/storage.admin

roles/artifactregistry.reader

Required GCP permissions for installer-provisioned infrastructure

When you attach the Owner role to the service account that you create, you grant that service account all permissions, including those that are required to install OKD.

If your organization’s security policies require a more restrictive set of permissions, you can create custom roles with the necessary permissions. The following permissions are required for the installer-provisioned infrastructure for creating and deleting the OKD cluster.

Required permissions for creating network resources
  • compute.addresses.create

  • compute.addresses.createInternal

  • compute.addresses.delete

  • compute.addresses.get

  • compute.addresses.list

  • compute.addresses.use

  • compute.addresses.useInternal

  • compute.firewalls.create

  • compute.firewalls.delete

  • compute.firewalls.get

  • compute.firewalls.list

  • compute.forwardingRules.create

  • compute.forwardingRules.get

  • compute.forwardingRules.list

  • compute.forwardingRules.setLabels

  • compute.globalAddresses.create

  • compute.globalAddresses.get

  • compute.globalAddresses.use

  • compute.globalForwardingRules.create

  • compute.globalForwardingRules.get

  • compute.globalForwardingRules.setLabels

  • compute.networks.create

  • compute.networks.get

  • compute.networks.list

  • compute.networks.updatePolicy

  • compute.networks.use

  • compute.routers.create

  • compute.routers.get

  • compute.routers.list

  • compute.routers.update

  • compute.routes.list

  • compute.subnetworks.create

  • compute.subnetworks.get

  • compute.subnetworks.list

  • compute.subnetworks.use

  • compute.subnetworks.useExternalIp

Required permissions for creating load balancer resources
  • compute.backendServices.create

  • compute.backendServices.get

  • compute.backendServices.list

  • compute.backendServices.update

  • compute.backendServices.use

  • compute.regionBackendServices.create

  • compute.regionBackendServices.get

  • compute.regionBackendServices.list

  • compute.regionBackendServices.update

  • compute.regionBackendServices.use

  • compute.targetPools.addInstance

  • compute.targetPools.create

  • compute.targetPools.get

  • compute.targetPools.list

  • compute.targetPools.removeInstance

  • compute.targetPools.use

  • compute.targetTcpProxies.create

  • compute.targetTcpProxies.get

  • compute.targetTcpProxies.use

Required permissions for creating DNS resources
  • dns.changes.create

  • dns.changes.get

  • dns.managedZones.create

  • dns.managedZones.get

  • dns.managedZones.list

  • dns.networks.bindPrivateDNSZone

  • dns.resourceRecordSets.create

  • dns.resourceRecordSets.list

Required permissions for creating Service Account resources
  • iam.serviceAccountKeys.create

  • iam.serviceAccountKeys.delete

  • iam.serviceAccountKeys.get

  • iam.serviceAccountKeys.list

  • iam.serviceAccounts.actAs

  • iam.serviceAccounts.create

  • iam.serviceAccounts.delete

  • iam.serviceAccounts.get

  • iam.serviceAccounts.list

  • resourcemanager.projects.get

  • resourcemanager.projects.getIamPolicy

  • resourcemanager.projects.setIamPolicy

Required permissions for creating compute resources
  • compute.disks.create

  • compute.disks.get

  • compute.disks.list

  • compute.disks.setLabels

  • compute.instanceGroups.create

  • compute.instanceGroups.delete

  • compute.instanceGroups.get

  • compute.instanceGroups.list

  • compute.instanceGroups.update

  • compute.instanceGroups.use

  • compute.instances.create

  • compute.instances.delete

  • compute.instances.get

  • compute.instances.list

  • compute.instances.setLabels

  • compute.instances.setMetadata

  • compute.instances.setServiceAccount

  • compute.instances.setTags

  • compute.instances.use

  • compute.machineTypes.get

  • compute.machineTypes.list

Required for creating storage resources
  • storage.buckets.create

  • storage.buckets.delete

  • storage.buckets.get

  • storage.buckets.list

  • storage.objects.create

  • storage.objects.delete

  • storage.objects.get

  • storage.objects.list

Required permissions for creating health check resources
  • compute.healthChecks.create

  • compute.healthChecks.get

  • compute.healthChecks.list

  • compute.healthChecks.useReadOnly

  • compute.httpHealthChecks.create

  • compute.httpHealthChecks.get

  • compute.httpHealthChecks.list

  • compute.httpHealthChecks.useReadOnly

  • compute.regionHealthChecks.create

  • compute.regionHealthChecks.get

  • compute.regionHealthChecks.useReadOnly

Required permissions to get GCP zone and region related information
  • compute.globalOperations.get

  • compute.regionOperations.get

  • compute.regions.get

  • compute.regions.list

  • compute.zoneOperations.get

  • compute.zones.get

  • compute.zones.list

Required permissions for checking services and quotas
  • monitoring.timeSeries.list

  • serviceusage.quotas.get

  • serviceusage.services.list

Required IAM permissions for installation
  • iam.roles.get

Required permissions when authenticating without a service account key
  • iam.serviceAccounts.signBlob

Optional Images permissions for installation
  • compute.images.list

Optional permission for running gather bootstrap
  • compute.instances.getSerialPortOutput

Required permissions for deleting network resources
  • compute.addresses.delete

  • compute.addresses.deleteInternal

  • compute.addresses.list

  • compute.addresses.setLabels

  • compute.firewalls.delete

  • compute.firewalls.list

  • compute.forwardingRules.delete

  • compute.forwardingRules.list

  • compute.globalAddresses.delete

  • compute.globalAddresses.list

  • compute.globalForwardingRules.delete

  • compute.globalForwardingRules.list

  • compute.networks.delete

  • compute.networks.list

  • compute.networks.updatePolicy

  • compute.routers.delete

  • compute.routers.list

  • compute.routes.list

  • compute.subnetworks.delete

  • compute.subnetworks.list

Required permissions for deleting load balancer resources
  • compute.backendServices.delete

  • compute.backendServices.list

  • compute.regionBackendServices.delete

  • compute.regionBackendServices.list

  • compute.targetPools.delete

  • compute.targetPools.list

  • compute.targetTcpProxies.delete

  • compute.targetTcpProxies.list

Required permissions for deleting DNS resources
  • dns.changes.create

  • dns.managedZones.delete

  • dns.managedZones.get

  • dns.managedZones.list

  • dns.resourceRecordSets.delete

  • dns.resourceRecordSets.list

Required permissions for deleting Service Account resources
  • iam.serviceAccounts.delete

  • iam.serviceAccounts.get

  • iam.serviceAccounts.list

  • resourcemanager.projects.getIamPolicy

  • resourcemanager.projects.setIamPolicy

Required permissions for deleting compute resources
  • compute.disks.delete

  • compute.disks.list

  • compute.instanceGroups.delete

  • compute.instanceGroups.list

  • compute.instances.delete

  • compute.instances.list

  • compute.instances.stop

  • compute.machineTypes.list

Required for deleting storage resources
  • storage.buckets.delete

  • storage.buckets.getIamPolicy

  • storage.buckets.list

  • storage.objects.delete

  • storage.objects.list

Required permissions for deleting health check resources
  • compute.healthChecks.delete

  • compute.healthChecks.list

  • compute.httpHealthChecks.delete

  • compute.httpHealthChecks.list

  • compute.regionHealthChecks.delete

  • compute.regionHealthChecks.list

Required Images permissions for deletion
  • compute.images.list

Required GCP permissions for shared VPC installations

When you are installing a cluster to a shared VPC, you must configure the service account for both the host project and the service project. If you are not installing to a shared VPC, you can skip this section.

You must apply the minimum roles required for a standard installation as listed above, to the service project.

You can use granular permissions for a Cloud Credential Operator that operates in either manual or mint credentials mode. You cannot use granular permissions in passthrough credentials mode.

Ensure that the host project applies one of the following configurations to the service account:

Required permissions for creating firewalls in the host project
  • projects/<host-project>/roles/dns.networks.bindPrivateDNSZone

  • roles/compute.networkAdmin

  • roles/compute.securityAdmin

Required minimal permissions
  • projects/<host-project>/roles/dns.networks.bindPrivateDNSZone

  • roles/compute.networkUser

If you do not supply a service account for control plane nodes in the install-config.yaml file, please grant the below permissions to the service account in the host project.

Details
  • resourcemanager.projects.getIamPolicy

  • resourcemanager.projects.setIamPolicy

Required GCP permissions for user-provided service accounts

When you are installing a cluster, the compute and control plane nodes require their own service accounts. By default, the installation program creates a service account for the control plane and compute nodes. The service account that the installation program uses requires the roles and permissions that are listed in the Creating a service account in GCP section, as well as the resourcemanager.projects.getIamPolicy and resourcemanager.projects.setIamPolicy permissions. These permissions should be applied to the service account in the host project. If this approach does not meet the security requirements of your organization, you can provide a service account email address for the control plane or compute nodes in the install-config.yaml file. For more information, see the Installation configuration parameters for GCP page. If you provide a service account for control plane nodes during an installation into a shared VPC, you must grant that service account the roles/compute.networkUser role in the host project. If you want the installation program to automatically create firewall rules when you supply the control plane service account, you must grant that service account the roles/compute.networkAdmin and roles/compute.securityAdmin roles in the host project. If you only supply the roles/compute.networkUser role, you must create the firewall rules manually.

The following roles are required for user-provided service accounts for control plane and compute nodes respectively.

Required roles for control plane nodes
  • roles/compute.instanceAdmin

  • roles/compute.networkAdmin

  • roles/compute.securityAdmin

  • roles/storage.admin

Required roles for compute nodes
  • roles/compute.viewer

  • roles/storage.admin

  • roles/artifactregistry.reader

Supported GCP regions

You can deploy an OKD cluster to the following Google Cloud Platform (GCP) regions:

  • africa-south1 (Johannesburg, South Africa)

  • asia-east1 (Changhua County, Taiwan)

  • asia-east2 (Hong Kong)

  • asia-northeast1 (Tokyo, Japan)

  • asia-northeast2 (Osaka, Japan)

  • asia-northeast3 (Seoul, South Korea)

  • asia-south1 (Mumbai, India)

  • asia-south2 (Delhi, India)

  • asia-southeast1 (Jurong West, Singapore)

  • asia-southeast2 (Jakarta, Indonesia)

  • australia-southeast1 (Sydney, Australia)

  • australia-southeast2 (Melbourne, Australia)

  • europe-central2 (Warsaw, Poland)

  • europe-north1 (Hamina, Finland)

  • europe-southwest1 (Madrid, Spain)

  • europe-west1 (St. Ghislain, Belgium)

  • europe-west2 (London, England, UK)

  • europe-west3 (Frankfurt, Germany)

  • europe-west4 (Eemshaven, Netherlands)

  • europe-west6 (Zürich, Switzerland)

  • europe-west8 (Milan, Italy)

  • europe-west9 (Paris, France)

  • europe-west12 (Turin, Italy)

  • me-central1 (Doha, Qatar, Middle East)

  • me-central2 (Dammam, Saudi Arabia, Middle East)

  • me-west1 (Tel Aviv, Israel)

  • northamerica-northeast1 (Montréal, Québec, Canada)

  • northamerica-northeast2 (Toronto, Ontario, Canada)

  • southamerica-east1 (São Paulo, Brazil)

  • southamerica-west1 (Santiago, Chile)

  • us-central1 (Council Bluffs, Iowa, USA)

  • us-east1 (Moncks Corner, South Carolina, USA)

  • us-east4 (Ashburn, Northern Virginia, USA)

  • us-east5 (Columbus, Ohio)

  • us-south1 (Dallas, Texas)

  • us-west1 (The Dalles, Oregon, USA)

  • us-west2 (Los Angeles, California, USA)

  • us-west3 (Salt Lake City, Utah, USA)

  • us-west4 (Las Vegas, Nevada, USA)

To determine which machine type instances are available by region and zone, see the Google documentation.

Next steps