Prérequis pour les clusters extérieurs à Google Cloud
Restez organisé à l'aide des collections
Enregistrez et classez les contenus selon vos préférences.
Avant d'installer Knative serving dans votre cluster en dehors de Google Cloud, vous devez d'abord vous assurer que vous remplissez les conditions suivantes:
Vous devez vous assurer que vous disposez des autorisations nécessaires dans votre Google Cloud projet pour répondre aux exigences d'installation de votre cluster, de votre parc et de Cloud Service Mesh:
Si vous disposez du rôle Propriétaire pour le projet Google Cloud , vous disposez de bien plus d'autorisations que nécessaires pour créer des clusters, les installer, puis configurer le service Knative.
Pour savoir comment enregistrer votre cluster et activer Workload Identity Federation for GKE dans votre parc, consultez la page Enregistrer un cluster. Les types de clusters compatibles en dehors de Google Cloud sont enregistrés par défaut.
Cloud Service Mesh exige que votre cluster utilise un type de machine comportant au moins quatre vCPU (processeurs virtuels), par exemple e2-standard-4. Consultez le guide d'installation de Cloud Service Mesh pour en savoir plus sur les conditions requises. Si vous devez modifier le type de machine d'un cluster existant, consultez la page Migrer des charges de travail vers différents types de machines.
Pour bénéficier du provisionnement automatique des domaines de test, Cloud Service Mesh utilise une passerelle d'entrée et un service nommé istio-ingress dans l'espace de noms istio-system. Pour activer la création de la passerelle lors de l'installation de la fonctionnalité, utilisez --option legacy-default-ingressgateway du script d'installation asmcli.
Sauf indication contraire, le contenu de cette page est régi par une licence Creative Commons Attribution 4.0, et les échantillons de code sont régis par une licence Apache 2.0. Pour en savoir plus, consultez les Règles du site Google Developers. Java est une marque déposée d'Oracle et/ou de ses sociétés affiliées.
Dernière mise à jour le 2025/09/01 (UTC).
[[["Facile à comprendre","easyToUnderstand","thumb-up"],["J'ai pu résoudre mon problème","solvedMyProblem","thumb-up"],["Autre","otherUp","thumb-up"]],[["Difficile à comprendre","hardToUnderstand","thumb-down"],["Informations ou exemple de code incorrects","incorrectInformationOrSampleCode","thumb-down"],["Il n'y a pas l'information/les exemples dont j'ai besoin","missingTheInformationSamplesINeed","thumb-down"],["Problème de traduction","translationIssue","thumb-down"],["Autre","otherDown","thumb-down"]],["Dernière mise à jour le 2025/09/01 (UTC)."],[],[],null,["# Prerequisites for clusters outside Google Cloud\n\nBefore you install Knative serving in your cluster outside Google Cloud, you\nmust first ensure that you meet the following requirements:\n\n- Review and understand the\n [access permissions of components in Knative serving](/kubernetes-engine/enterprise/knative-serving/docs/install/permissions).\n\n- You must ensure that you have adequate permissions in your Google Cloud project\n to meet the installation requirements for your cluster,\n fleet, and Cloud Service Mesh:\n\n - If you have the [*Owner*](/iam/docs/understanding-roles#basic) role for the Google Cloud project, then you have more than the necessary permissions to create clusters, install, and then configure Knative serving.\n - Your GKE clusters outside of Google Cloud might also require other permissions. [See the documentation and requirements for your cluster](/anthos/clusters/docs).\n - Note that the\n [Cloud Service Mesh permissions requirements](/service-mesh/v1.18/docs/installation-permissions)\n also meet all the permission requirements for installing and configuring\n Knative serving.\n\n - Using other roles and the minimum requirements:\n\n Depending on your organization, you can also meet the permission\n requirements through a combination of the following predefined roles:\n - Google Cloud project permissions: [Basic *Editor* role](/iam/docs/understanding-roles#basic)\n\n - Fleet permissions:\n [*GKE Hub Admin*](/iam/docs/understanding-roles#gke-hub-roles)\n or a role that includes the following permissions:\n\n - `gkehub.features.create`\n - `gkehub.features.update`\n - Cluster permissions:\n [A Kubernetes Engine Admin Role](/iam/docs/understanding-roles#kubernetes-engine-roles):\n\n - *Kubernetes Engine Admin*\n - *Kubernetes Engine Cluster Admin*\n- A cluster with the following configuration is required:\n\n - A supported\n\n [Google Distributed Cloud cluster](/anthos/clusters/docs/on-prem).\n For previous installations on Google Distributed Cloud clusters, you must\n [migrate Knative serving on VMware to a fleet](/kubernetes-engine/enterprise/knative-serving/docs/install/outside-gcp/upgrade-vmware).\n\n **[Preview](/products#product-launch-stages)** : Other GKE clusters\n environments outside Google Cloud are currently available as a \"*Preview* \".\n [Learn more](/kubernetes-engine/enterprise/knative-serving/docs/install/outside-gcp).\n - Registered to a fleet:\n\n [Go to GKE clusters](https://console.cloud.google.com/kubernetes/list/overview)\n | **Tip:** Workload Identity Federation for GKE allows you to authenticate to Google Cloud services and it's also required by Cloud Service Mesh. Enabling fleet Workload Identity Federation in your cluster during fleet registration can reduce the configuration and deployment time.\n\n To learn how to register your cluster and enable Workload Identity Federation for GKE in\n your fleet, see\n [Registering a cluster](/kubernetes-engine/fleet-management/docs/register/gke). Supported cluster types outside Google Cloud are registered by default.\n - In-cluster [Cloud Service Mesh version 1.18 or later is\n installed](/service-mesh/v1.18/docs/unified-install/install-anthos-service-mesh).\n Additionally, note the following prerequisites:\n\n - The [Google-managed Cloud Service Mesh control plane](/service-mesh/docs/supported-features-mcp) is currently not fully supported by Knative serving. Use the in-cluster control plane instead.\n - Cloud Service Mesh requires that your cluster use a machine type with at least 4 vCPUs, such as `e2-standard-4`. See the Cloud Service Mesh installation guide for details about requirements. If you need to change your existing cluster's machine type, see [Migrating workloads to different machine types](/kubernetes-engine/docs/tutorials/migrating-node-pool).\n - In order to benefit from the automated provisioning of test domains - Cloud Service Mesh uses an ingress gateway and a service named `istio-ingress` in namespace `istio-system`. To enable creation of the gateway during the feature installation use `--option legacy-default-ingressgateway` of `asmcli` installation script.\n- [The command-line environment must be set up](/kubernetes-engine/enterprise/knative-serving/docs/install/outside-gcp/command-line-tools).\n\n- The following APIs must be enabled in your Google Cloud project:\n\n - Google Kubernetes Engine API: Build and manage container-based applications.\n - Cloud Build API: Create and manage builds.\n - Container Registry API: Push and pull images in Container Registry.\n\n [Enable the APIs in the Google Cloud console](https://console.cloud.google.com/start/api?id=container.googleapis.com,containerregistry.googleapis.com,cloudbuild.googleapis.com)"]]