本頁簡要介紹 GKE On-Prem API,並提供 Google Distributed Cloud (僅限軟體) 的連結,方便您前往參閱 Bare Metal 和 VMware 說明文件,進一步瞭解相關資訊。
GKE On-Prem API 是 Google Cloud代管的 API,可讓您使用標準應用程式管理內部部署叢集的生命週期。GKE On-Prem API 會在 Google Cloud的基礎架構中執行。Google Cloud 主控台、Google Cloud CLI 和 Terraform 都是 API 的用戶端,可透過 API 在資料中心建立、更新、升級及刪除叢集。
使用 VPC Service Controls 保護 API
為了進一步提升 GKE On-Prem API 的安全性,您可以使用 VPC Service Control 對其進行防護。
VPC Service Controls 可為 GKE On-Prem API 提供額外的安全性。您可以透過 VPC Service Controls 將專案加入服務範圍內,如此一來,源自服務範圍外的要求就無法存取相關資源及服務。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-01 (世界標準時間)。"],[],[],null,["# About the GKE On-Prem API\n\nThis page provides a brief overview of the GKE On-Prem API and provides links\nto the Google Distributed Cloud (software only) for bare metal and VMware\ndocumentation where you can learn more.\n\nThe GKE On-Prem API is a Google Cloud-hosted API that lets you manage the\nlifecycle of your on-premises clusters using standard applications. The\nGKE On-Prem API runs in Google Cloud's infrastructure. The\nGoogle Cloud console, the Google Cloud CLI, and Terraform are clients of the API, and\nthey use the API to create, update, upgrade, and delete clusters in your data\ncenter.\n\nProtect the API with VPC Service Controls\n-----------------------------------------\n\nTo further secure the GKE On-Prem API, you can protect it using VPC Service Controls.\n\nVPC Service Controls provides additional security for the GKE On-Prem API.\nUsing VPC Service Controls, you can add projects to service perimeters that\nprotect resources and services from requests that originate outside the\nperimeter.\n\nTo learn more about service perimeters, see\n[Service perimeter details and configuration](/vpc-service-controls/docs/service-perimeters).\n\nFor the greatest protection by VPC Service Controls, ensure that your admin\ncluster isn't publicly accessible. For more information, see the following\nGoogle Distributed Cloud documentation:\n\n- Bare metal: [Hardening your cluster's security](/kubernetes-engine/distributed-cloud/bare-metal/docs/how-to/hardening-your-cluster)\n\n- VMware: [Hardening your cluster's security](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/hardening-your-cluster)\n\nWhat's next\n-----------\n\n- Bare metal:\n\n - [Choose a tool to manage cluster lifecycle](/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/cluster-lifecycle-management-tools)\n - [Create a user cluster using GKE On-Prem API clients](/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/creating-clusters/create-user-cluster-api)\n - [Create an admin cluster using GKE On-Prem API clients](/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/creating-clusters/create-admin-cluster-api)\n - [Configure a cluster to be managed by the GKE On-Prem API](/kubernetes-engine/distributed-cloud/bare-metal/docs/how-to/enroll-cluster)\n- VMware:\n\n - [Choose a tool to manage cluster lifecycle](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/cluster-lifecycle-management-tools)\n - [Create a user cluster](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/create-user-cluster)\n - [Configure a cluster to be managed by the GKE On-Prem API](/kubernetes-engine/distributed-cloud/vmware/docs/how-to/enroll-cluster)"]]