New Relic Kubernetes 整合服務會運用 New Relic 基礎架構代理程式,收集叢集的遙測資料 (透過 Kubernetes 事件整合服務、Prometheus 代理程式和 New Relic Logs Kubernetes 外掛程式等 New Relic 整合服務),讓您掌握環境的健康狀態和效能。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-01 (世界標準時間)。"],[],[],null,["# Autopilot partners\n\n[Autopilot](/kubernetes-engine/docs/concepts/autopilot-overview)\n\n*** ** * ** ***\n\nThis page provides information about Google Kubernetes Engine (GKE)\nAutopilot partner organizations and the specialized workloads that they\nmake available in Autopilot clusters.\n\nWhat are Autopilot partner workloads?\n-------------------------------------\n\nGoogle Kubernetes Engine (GKE) Autopilot clusters don't usually allow\nworkloads that require elevated privileges, such as access to `/var/run`,\n`privileged: true`, or highly-privileged Linux file capabilities such as\n`NET_RAW` and `SYS_ADMIN`.\n\nThe exceptions to this restriction are Autopilot *partner workloads* . A\nsubset of [Google Cloud Partners](/partners) provide specially-privileged\nworkloads for Autopilot clusters. You can deploy these partner\nworkloads to meet requirements such as collecting node-level metrics without\nneeding to run a sidecar container in every Pod.\n\n### Overview of the allowlisting process\n\nEvery partner workload goes through a review process to ensure that they meet\nbaseline requirements for GKE, such as having the least amount of\npermissions required to run correctly, and fine-grained control over the\nresources that the workloads can access.\n\nWe take measures such as the following to restrict the capabilities of these\ndeployed workloads:\n\n- Verify that the containers are pulled from the approved location.\n- Reject Pod specs that don't match the approved specification.\n\nIf you're a Google Cloud partner with an Autopilot workload that\nrequires elevated privileges and needs to be added to an allowlist, contact your\npartner manager for information about the Autopilot partner program.\n\n### Run privileged partner workloads in Autopilot\n\nIn GKE version 1.32.2-gke.1652000 and later,\nsome partners provide *allowlists* that correspond to their privileged\nworkloads. These workloads can't run in your clusters unless you install the\ncorresponding allowlist. This method has the following benefits:\n\n- You have explicit control over whether a partner workload can run in your cluster.\n- GKE automatically synchronizes the allowlists in your cluster with the latest version from a Google-managed repository that stores allowlist files for partner workloads.\n- Partner workloads that don't meet the strict criteria of an installed allowlist are rejected during deployment.\n\nFor more information, see\n[Run privileged workloads from GKE Autopilot partners](/kubernetes-engine/docs/how-to/run-autopilot-partner-workloads).\n\nPrivileged partner workloads that were added between 2021 and 2024 can run on\nAutopilot mode without an allowlist. Cluster operators who have the\ncorresponding permissions can deploy these workloads in your cluster at any\ntime.\n\nPricing\n-------\n\nAny resources that partner workloads create in your Autopilot clusters\nare billed according to the\n[Autopilot pricing model](/kubernetes-engine/pricing#autopilot_mode).\nFor information about any additional pricing for partner solutions, consult the\nrelevant partner's documentation.\n\nAutopilot partner workloads\n---------------------------\n\nThe following table describes the partner workloads for Autopilot. The\npartner workloads available for each of your clusters depends on the\nGKE version of the cluster. Some of the entries in this table\ninclude the path to a partner's workload allowlists, which you can use\nto [configure allowlist installation and synchronization](/kubernetes-engine/docs/how-to/run-autopilot-partner-workloads#create-allowlistsynchronizer) for your cluster.\n\nThis table only describes the Google Cloud partners that have\nAutopilot workloads that need elevated privileges. Other\nGoogle Cloud partners have products that work with Autopilot\nwithout needing elevated privileges. For a full list of Google Cloud\npartners, refer to the [Partner Directory](/find-a-partner)."]]