Deckhouse Platform in Yandex Cloud
Before installation, ensure the following:
- Cloud provider quotas for cluster deployment.
- The
cloud-initpackage is installed on the VMs. After the VM starts, servicescloud-config.service,cloud-final.service,cloud-init.servicemust be running. - The virtual machine template contains only one disk.
- Firewall rules and security groups allow UDP traffic between cluster nodes. A new cluster uses the Cilium CNI by default with pod traffic tunneling over VXLAN. Cilium requires Linux kernel 5.8 or newer on the nodes, and the list of ports is available in Network interaction of the platform components.
Prepare the Yandex Cloud environment so that Deckhouse Platform can manage cloud resources. The full procedure is described on the environment preparation page of the cloud-provider-yandex module.
Create a service account for Deckhouse Platform and assign the compute.editor, vpc.admin, and load-balancer.editor roles to it:
-
Create a service account named
deckhouse:yc iam service-account create --name deckhouseThe command response will contain its parameters:
id: <userID> folder_id: <folderID> created_at: "YYYY-MM-DDTHH:MM:SSZ" name: deckhouse -
Assign the roles to the service account in the folder:
yc resource-manager folder add-access-binding --id <folderID> --role compute.editor --subject serviceAccount:<userID> yc resource-manager folder add-access-binding --id <folderID> --role vpc.admin --subject serviceAccount:<userID> yc resource-manager folder add-access-binding --id <folderID> --role load-balancer.editor --subject serviceAccount:<userID> -
Create a JSON file with the authorized key of the service account. Deckhouse Platform uses it to access the cloud:
yc iam key create --service-account-name deckhouse --output deckhouse-sa-key.json