Examtopics

Associate Cloud Engineer
  • Topic 1 Question 71

    You are using Container Registry to centrally store your company's container images in a separate project. In another project, you want to create a Google Kubernetes Engine (GKE) cluster. You want to ensure that Kubernetes can download images from Container Registry. What should you do?

    • In the project where the images are stored, grant the Storage Object Viewer IAM role to the service account used by the Kubernetes nodes.

    • When you create the GKE cluster, choose the Allow full access to all Cloud APIs option under 'Access scopes'.

    • Create a service account, and give it access to Cloud Storage. Create a P12 key for this service account and use it as an imagePullSecrets in Kubernetes.

    • Configure the ACLs on each image in Cloud Storage to give read-only access to the default Compute Engine service account.


    シャッフルモード