このページでは、GKE On-Prem API の概要と、ベアメタル用 Google Distributed Cloud(ソフトウェアのみ)および VMware の詳細なドキュメントへのリンクをご案内します。
Google Cloudがホストしている GKE On-Prem API を使うと、標準アプリケーションを使用してオンプレミス クラスタのライフサイクルを管理できます。GKE On-Prem API は Google Cloudのインフラストラクチャで動作します。Google Cloud コンソール、Google Cloud CLI、Terraform はこの API のクライアントであり、この API を使ってデータセンター内のクラスタを作成、更新、アップグレード、削除します。
VPC Service Controls で API を保護する
VPC Service Controls を使って保護することで、GKE On-Prem API のセキュリティ性を高められます。
VPC Service Controls によって GKE On-Prem API のセキュリティを強化できます。このサービスを使うことで、境界外からのリクエストからリソースとサービスを保護するサービス境界にプロジェクトを追加できます。
[[["わかりやすい","easyToUnderstand","thumb-up"],["問題の解決に役立った","solvedMyProblem","thumb-up"],["その他","otherUp","thumb-up"]],[["わかりにくい","hardToUnderstand","thumb-down"],["情報またはサンプルコードが不正確","incorrectInformationOrSampleCode","thumb-down"],["必要な情報 / サンプルがない","missingTheInformationSamplesINeed","thumb-down"],["翻訳に関する問題","translationIssue","thumb-down"],["その他","otherDown","thumb-down"]],["最終更新日 2025-09-01 UTC。"],[],[],null,["# About the GKE On-Prem API\n\nThis page provides a brief overview of the GKE On-Prem API and provides links\nto the Google Distributed Cloud (software only) for bare metal and VMware\ndocumentation where you can learn more.\n\nThe GKE On-Prem API is a Google Cloud-hosted API that lets you manage the\nlifecycle of your on-premises clusters using standard applications. The\nGKE On-Prem API runs in Google Cloud's infrastructure. The\nGoogle Cloud console, the Google Cloud CLI, and Terraform are clients of the API, and\nthey use the API to create, update, upgrade, and delete clusters in your data\ncenter.\n\nProtect the API with VPC Service Controls\n-----------------------------------------\n\nTo further secure the GKE On-Prem API, you can protect it using VPC Service Controls.\n\nVPC Service Controls provides additional security for the GKE On-Prem API.\nUsing VPC Service Controls, you can add projects to service perimeters that\nprotect resources and services from requests that originate outside the\nperimeter.\n\nTo learn more about service perimeters, see\n[Service perimeter details and configuration](/vpc-service-controls/docs/service-perimeters).\n\nFor the greatest protection by VPC Service Controls, ensure that your admin\ncluster isn't publicly accessible. For more information, see the following\nGoogle Distributed Cloud documentation:\n\n- Bare metal: [Hardening your cluster's security](/kubernetes-engine/distributed-cloud/bare-metal/docs/how-to/hardening-your-cluster)\n\n- VMware: [Hardening your cluster's security](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/hardening-your-cluster)\n\nWhat's next\n-----------\n\n- Bare metal:\n\n - [Choose a tool to manage cluster lifecycle](/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/cluster-lifecycle-management-tools)\n - [Create a user cluster using GKE On-Prem API clients](/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/creating-clusters/create-user-cluster-api)\n - [Create an admin cluster using GKE On-Prem API clients](/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/creating-clusters/create-admin-cluster-api)\n - [Configure a cluster to be managed by the GKE On-Prem API](/kubernetes-engine/distributed-cloud/bare-metal/docs/how-to/enroll-cluster)\n- VMware:\n\n - [Choose a tool to manage cluster lifecycle](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/cluster-lifecycle-management-tools)\n - [Create a user cluster](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/create-user-cluster)\n - [Configure a cluster to be managed by the GKE On-Prem API](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/enroll-cluster)"]]