Repository navigation
docs: add Report GKE environments tutorial - #436
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
|
|
Claude finished @mintlify[bot]'s task in 1m 2s —— View job Follow-up review of commit
|
| --role="projects/<your-gcp-project>/roles/kosliGkeReporter" | ||
| ``` | ||
|
|
||
| For a folder- or organization-wide snapshot, bind the same role at that level with `gcloud resource-manager folders add-iam-policy-binding` or `gcloud organizations add-iam-policy-binding`. |
There was a problem hiding this comment.
Critical — factually wrong instruction. The role created above is a project-level custom role (projects/<your-gcp-project>/roles/kosliGkeReporter). GCP only lets you grant a project-level custom role on that project and the resources under it. You can't bind it on a folder or organization, so "bind the same role at that level" fails.
For folder- or organization-wide snapshots, tell readers to create the role at the organization level (gcloud iam roles create kosliGkeReporter --organization=<org-id> ...) and bind organizations/<org-id>/roles/kosliGkeReporter.
| ``` | ||
|
|
||
| <Tip> | ||
| Pin the CLI image to a specific version (for example `ghcr.io/kosli-dev/cli:v2.18.0`) so the reporter behavior does not change unexpectedly when a new release is published. |
There was a problem hiding this comment.
Improvement. This example was copied from the Cloud Run tutorial, but kosli snapshot gke is new and doesn't exist in v2.18.0 (it isn't even in v2.45.0's reference). A reader who pins to the example version gets an unknown-command failure on every scheduled run. Use a version that ships the command, or a placeholder.
| Pin the CLI image to a specific version (for example `ghcr.io/kosli-dev/cli:v2.18.0`) so the reporter behavior does not change unexpectedly when a new release is published. | |
| Pin the CLI image to a specific version that includes `kosli snapshot gke` (for example `ghcr.io/kosli-dev/cli:v<version>`) so the reporter behavior does not change unexpectedly when a new release is published. |
| [Install Kosli CLI](/getting_started/install) if you have not done so, then authenticate to GCP with Application Default Credentials: | ||
|
|
||
| ```shell | ||
| gcloud auth application-default login | ||
| ``` |
There was a problem hiding this comment.
Suggestion. When you call cloudasset.googleapis.com with user Application Default Credentials, it commonly fails with "requires a quota project" unless ADC has one set. Consider adding a quota-project step so readers aren't blocked on the testing path:
gcloud auth application-default set-quota-project <your-gcp-project>
Adds a tutorial for the new
kosli snapshot gkecommand (kosli-dev/cli#1231), covering both the quick CLI test path and a production scheduled Cloud Run Job.Modeled on
tutorials/report_cloud_run_envs.md, with GKE-specific bits:cloudasset.googleapis.com) — no kubeconfig, no cluster RBAC, no control-plane network access.cloudasset.assets.listContainerPod+serviceusage.services.useinstead ofroles/run.viewer/roles/artifactregistry.reader.Added to the nav's Reporting environments group after the Cloud Run tutorial.
Note: the tutorial temporarily says "run
kosli snapshot gke --helpfor the full flag reference" instead of linking to/client_reference/kosli_snapshot_gke, because the reference page hasn't been synced from the CLI repo yet. Swap that line back to a/client_reference/kosli_snapshot_gkelink after the next CLI reference sync.Mint validate + broken-links clean (only pre-existing
getting_started/service-accountsbroken link inworking_with_controls.mdxremains).Generated by Mintlify Agent.
Requested by: marko