Skip to content

docs: add Report GKE environments tutorial - #436

Merged
mbevc1 merged 2 commits into
mainfrom
mintlify/report-gke-envs
Sep 30, 2026
Merged

mbevc1 merged 2 commits into
mainfrom
mintlify/report-gke-envs

Conversation

@mintlify

@mintlify mintlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Adds a tutorial for the new kosli snapshot gke command (kosli-dev/cli#1231), covering both the quick CLI test path and a production scheduled Cloud Run Job.

Modeled on tutorials/report_cloud_run_envs.md, with GKE-specific bits:

  • Reads pods from Cloud Asset Inventory (cloudasset.googleapis.com) — no kubeconfig, no cluster RBAC, no control-plane network access.
  • Prerequisites include enabling the Cloud Asset API and creating a K8S (not Cloud Run) environment.
  • Scheduled-Job least-privilege setup grants a custom role with cloudasset.assets.listContainerPod + serviceusage.services.use instead of roles/run.viewer / roles/artifactregistry.reader.
  • Beta callout — the command is annotated beta in the CLI.
  • Warning about cross-cluster name collisions when snapshotting a wide scope into a single environment.

Added to the nav's Reporting environments group after the Cloud Run tutorial.

Note: the tutorial temporarily says "run kosli snapshot gke --help for the full flag reference" instead of linking to /client_reference/kosli_snapshot_gke, because the reference page hasn't been synced from the CLI repo yet. Swap that line back to a /client_reference/kosli_snapshot_gke link after the next CLI reference sync.

Mint validate + broken-links clean (only pre-existing getting_started/service-accounts broken link in working_with_controls.mdx remains).


Generated by Mintlify Agent.

Requested by: marko

@mintlify
mintlify Bot requested a review from a team as a code owner September 30, 2026 16:13
@mintlify

mintlify Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
kosli 🟢 Ready View Preview Sep 30, 2026, 4:20 PM

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @mintlify[bot]'s task in 1m 2s —— View job


Follow-up review of commit 11e71db (address GKE tutorial review feedback)

  • Fetch previous review findings and the new diff (07c0265..11e71db)
  • Check each previous finding against the new commit
  • Scan changed lines for new bugs/regressions
  • Post summary

Previous findings — status:

  1. Critical: project-level role can't be bound at folder/org scope — ✅ Resolved. The tutorial now creates a separate role at --organization=<your-gcp-org-id> for folder/org-wide snapshots and binds organizations/<your-gcp-org-id>/roles/kosliGkeReporter, matching the fix suggested in the original comment.
  2. v2.18.0 pin doesn't include kosli snapshot gke — ✅ Resolved. Tip now says to pin to a version that includes the command, with a v<version> placeholder instead of a concrete (wrong) version.
  3. Missing quota-project step for ADC on the CLI testing path — ✅ Resolved. Added gcloud auth application-default set-quota-project <your-gcp-project> with an explanatory note, right after the gcloud auth application-default login step.

New issues in the changed lines: none found. No new inline comments.

All three previously raised findings are resolved by this commit.

Comment thread tutorials/report_gke_envs.md Outdated
--role="projects/<your-gcp-project>/roles/kosliGkeReporter"
```

For a folder- or organization-wide snapshot, bind the same role at that level with `gcloud resource-manager folders add-iam-policy-binding` or `gcloud organizations add-iam-policy-binding`.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Critical — factually wrong instruction. The role created above is a project-level custom role (projects/<your-gcp-project>/roles/kosliGkeReporter). GCP only lets you grant a project-level custom role on that project and the resources under it. You can't bind it on a folder or organization, so "bind the same role at that level" fails.

For folder- or organization-wide snapshots, tell readers to create the role at the organization level (gcloud iam roles create kosliGkeReporter --organization=<org-id> ...) and bind organizations/<org-id>/roles/kosliGkeReporter.

Comment thread tutorials/report_gke_envs.md Outdated
```

<Tip>
Pin the CLI image to a specific version (for example `ghcr.io/kosli-dev/cli:v2.18.0`) so the reporter behavior does not change unexpectedly when a new release is published.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Improvement. This example was copied from the Cloud Run tutorial, but kosli snapshot gke is new and doesn't exist in v2.18.0 (it isn't even in v2.45.0's reference). A reader who pins to the example version gets an unknown-command failure on every scheduled run. Use a version that ships the command, or a placeholder.

Suggested change
Pin the CLI image to a specific version (for example `ghcr.io/kosli-dev/cli:v2.18.0`) so the reporter behavior does not change unexpectedly when a new release is published.
Pin the CLI image to a specific version that includes `kosli snapshot gke` (for example `ghcr.io/kosli-dev/cli:v<version>`) so the reporter behavior does not change unexpectedly when a new release is published.

Comment on lines +41 to +45
[Install Kosli CLI](/getting_started/install) if you have not done so, then authenticate to GCP with Application Default Credentials:

```shell
gcloud auth application-default login
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion. When you call cloudasset.googleapis.com with user Application Default Credentials, it commonly fails with "requires a quota project" unless ADC has one set. Consider adding a quota-project step so readers aren't blocked on the testing path:

gcloud auth application-default set-quota-project <your-gcp-project>

@mbevc1 mbevc1 changed the title Add Report GKE environments tutorial docs: add Report GKE environments tutorial Sep 30, 2026
@mbevc1
mbevc1 merged commit d5bb7af into main Sep 30, 2026
8 checks passed
@mbevc1
mbevc1 deleted the mintlify/report-gke-envs branch September 30, 2026 16:31

This branch was successfully deployed

1 active deployment
staging — 11e71db0 Deployed Sep 30, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant