Helm tool builder Using this builder with GCE
10K+
To use this builder, your Cloud Build Service Account will need IAM permissions sufficient for the operations you want to perform. For typical read-only usage, the "Kubernetes Engine Viewer" role is sufficient. To deploy container images on a GKE cluster, the "Kubernetes Engine Developer" role is sufficient. Check the GKE IAM page for details.
For most use, kubectl will need to be configured to point to a specific GKE cluster. You can configure the cluster by setting environment variables.
# Set region for regional GKE clusters or Zone for Zonal clusters
CLOUDSDK_COMPUTE_REGION=<your cluster's region>
or
CLOUDSDK_COMPUTE_ZONE=<your cluster's zone>
# Name of GKE cluster
CLOUDSDK_CONTAINER_CLUSTER=<your cluster's name>
# (Optional) Project of GKE Cluster, only if you want helm to authenticate
# to a GKE cluster in another project (requires IAM Service Accounts are properly setup)
GCLOUD_PROJECT=<destination cluster's GCP project>
Setting the environment variables above will cause this step's entrypoint to
first run a command to fetch cluster credentials as follows.
gcloud container clusters get-credentials --zone "$CLOUDSDK_COMPUTE_ZONE" "$CLOUDSDK_CONTAINER_CLUSTER"`
Then, kubectl and consequently helm will have the configuration needed to talk to your GKE cluster.
To build this builder, run the following command in this directory.
gcloud builds submit . --config=cloudbuild.yaml
You can also build this builder setting Helm version via in cloudbuild.yaml, no need to do that in Dockerfile anymore.
args: ['build', '--tag=gcr.io/$PROJECT_ID/helm', '--build-arg', 'HELM_VERSION=v2.10.0', '.']
This builder supports two install options of Helm:
tiller gets installed into your GKE cluster.Tillerless Helm where tiller runs outside the GKE cluster.Check the examples folder for examples of using Helm in Cloud Build pipelines.
Note: Do not forget to update zone and GKE cluster settings in the cloudbuild.yaml files.
The default one when the tiller gets installed into your GKE cluster (oh all those tiller security issues).
You can test e.g. installing a chart via Helm, running the following command.
gcloud builds submit . --config=examples/chart-install/cloudbuild.yaml
And to list Helm releases.
$ gcloud builds submit . --config=examples/releases-list/cloudbuild.yaml
Tillerless Helm which solves all those tiller security issues, as tiller runs outside the GKE cluster.
I wrote a blog post how to use Helm local tiller plugin.
You can test e.g. installing a chart via Tillerless Helm, running the following command.
gcloud builds submit . --config=examples/chart-install-tillerless/cloudbuild.yaml
And to list Helm releases.
$ gcloud builds submit . --config=examples/releases-list-tillerless/cloudbuild.yaml
Note: Also if your GKE cluster has RBAC enabled, you must grant Cloud Build Service Account cluster-admin role (or make it more specific for your use case), but for some reason Cloud Build uses Cloud Build Service Account uniqueId to authenticate to the GKE cluster instead of it's email address.
Below is example how to set it up with uniqueId.
# Get Cloud Build Service Account uniqueId
user=$(gcloud iam service-accounts describe [email protected] | grep -o 'uniqueId.*' | awk -v FS="('|')" '{print $2}')
# Grant Cloud Build Service Account `cluster-admin` role
kubectl create clusterrolebinding cluster-admin-$user --clusterrole cluster-admin --user $user
Content type
Image
Digest
Size
998.5 MB
Last updated
over 6 years ago
docker pull swordhealth/helm