Google Cloud 인프라 프로비저닝(Provision Google Cloud Infrastructure)

Google Cloud 인프라 프로비저닝(Provision Google Cloud Infrastructure)

Confident AI가 실행되는 클라우드 인프라를 프로비저닝해요: GKE 클러스터, Cloud SQL PostgreSQL 데이터베이스, GCS 버킷, 그리고 키리스 아이덴티티 연결. 완료되면 실행 중인 클러스터와 다음 페이지의 Helm 차트에 넣을 출력값들이 생겨요.

출처: 문서

본문

프로젝트와 리전을 한 번 설정하고, 모듈이 사용하는 API를 활성화해요:

export PROJECT=my-gcp-project
export REGION=us-central1
gcloud config set project $PROJECT

gcloud services enable \
  container.googleapis.com sqladmin.googleapis.com \
  servicenetworking.googleapis.com compute.googleapis.com \
  artifactregistry.googleapis.com run.googleapis.com \
  iamcredentials.googleapis.com

네트워크 생성 (선택)

파드·서비스용 두 개의 보조 범위(secondary range)가 있는 서브넷과 비공개 노드용 Cloud NAT가 있는 VPC 네트워크를 이미 갖고 있다면 이 단계는 건너뛰세요. 다음 단계에서 기존 이름을 사용하세요.

GKE에는 파드용·서비스용 두 개의 보조 범위가 있는 서브넷 하나와, 비공개 노드가 이미지를 가져올 수 있는 Cloud NAT가 필요해요. 블록을 순서대로 실행하세요.

서브넷을 직접 정의할 수 있도록 커스텀 서브넷 모드로 VPC 네트워크를 만들어요:

gcloud compute networks create confident-prod-vpc --subnet-mode=custom

GKE가 필요로 하는 두 개의 보조 범위가 있는 서브넷을 만들어요:

gcloud compute networks subnets create confident-prod-subnet \
  --network=confident-prod-vpc --region=$REGION \
  --range=10.30.0.0/20 \
  --secondary-range confident-pods=10.30.32.0/19,confident-services=10.30.16.0/20

ClickHouse는 이 모듈이 만드는 IPv4 전용 GKE 클러스터에서 깔끔하게 실행돼요: 차트가 오퍼레이터 파드를 IPv4(0.0.0.0)로 청취하도록 고정해서, 주소 패밀리 오류 없이 듀얼 스택 설정이 필요 없어요. 듀얼 스택 서브넷만으로는 바뀌지 않아요. 클러스터 자체가 듀얼 스택으로 생성되지 않는 한 노드는 IPv4 전용으로 유지돼요.

비공개 노드가 인바운드 노출 없이 아웃바운드 풀을 위해 인터넷에 도달하도록 Cloud Router와 NAT를 추가해요:

gcloud compute routers create confident-prod-router \
  --network=confident-prod-vpc --region=$REGION
gcloud compute routers nats create confident-prod-nat \
  --router=confident-prod-router --region=$REGION \
  --nat-all-subnet-ip-ranges --auto-allocate-nat-external-ips

코드 샌드박스 이미지 미러링 (필수)

코드 기반 및 트랜스포머 지표는 confident-code-sandbox-gcp 이미지를 실행하는 샌드박스형 Cloud Run 서비스에서 실행돼요. Terraform이 서비스를 만들기 전에 반드시 여러분의 Artifact Registry에 있어야 하므로, 공개 이미지를 미러링해요.

Artifact Registry 리포지토리를 만들고 Docker가 인증하게 해요:

gcloud artifacts repositories create confident \
  --repository-format=docker --location=$REGION
gcloud auth configure-docker $REGION-docker.pkg.dev --quiet

공개 이미지를 가져와 리포지토리로 푸시해요:

docker pull confidentai/confident-code-sandbox-gcp:latest
docker tag confidentai/confident-code-sandbox-gcp:latest \
  $REGION-docker.pkg.dev/$PROJECT/confident/confident-code-sandbox-gcp:latest
docker push $REGION-docker.pkg.dev/$PROJECT/confident/confident-code-sandbox-gcp:latest

Terraform 설정 작성

공개 모듈을 참조하는 main.tf를 만들고, 프로젝트와 앞선 단계들의 네트워크 이름을 채워요. 각 변수의 역할:

  • 프로젝트와 네트워크: confident_gcp_project_id, confident_gcp_region, 그리고 네트워크 단계의 네트워크 이름.
  • 네이밍: confident_environment와 confident_environment_code가 prod 네이밍 컨벤션을 모든 리소스에 적용해요.
  • 접근: confident_public_gke는 클러스터 API를 머신에 노출해요. 비공개 전용 엔드포인트를 원하면 false로.
  • 데이터베이스: confident_psql_password는 자체 PostgreSQL 비밀번호를 설정해요. 생략하면 자동 생성해요.
  • 관리형 서비스: confident_create_secret_manager와 confident_managed_redis_enabled가 권장 시크릿 스토어와 Redis를 켜요.
  • 코드 실행기: confident_ar_repository_name은 방금 미러링한 이미지를 담은 Artifact Registry 리포지토리.
provider "google" {
  project = "my-gcp-project"
  region  = "us-central1"
}

module "confident_ai" {
  source  = "confident-ai/confident-ai/google"
  version = "~> 0.1"

  confident_gcp_project_id = "my-gcp-project"
  confident_gcp_region     = "us-central1"

  confident_network_name      = "confident-prod-vpc"
  confident_network_id        = "projects/my-gcp-project/global/networks/confident-prod-vpc"
  confident_subnetwork_name   = "confident-prod-subnet"
  confident_ip_range_pods     = "confident-pods"
  confident_ip_range_services = "confident-services"

  confident_environment      = "prod"
  confident_environment_code = "p"

  confident_public_gke = true

  confident_psql_password = "choose-a-strong-password"

  confident_create_secret_manager = true
  confident_managed_redis_enabled = true

  confident_code_executor_enabled = true
  confident_ar_repository_name    = "confident"
}

output "helm_values" {
  value     = module.confident_ai.helm_values
  sensitive = true
}

리포지토리 안에서 작업하고 싶다면 terraform-google-confident-ai를 클론해 module 블록 대신 terraform.tfvars 파일에 같은 변수를 넣으세요.

원격 상태 구성 (선택)

이걸 건너뛰면 로컬 상태를 사용해요. 팀이나 실제 환경이라면 상태를 GCS 버킷에 두세요.

backend.tf를 만들어요:

terraform {
  backend "gcs" {
    bucket = "confident-tfstate"
    prefix = "confident-ai/gcp"
  }
}

적용(Apply)

terraform init
terraform plan
terraform apply

GKE 클러스터와 Cloud SQL을 만드는 데는 대략 15-20분이 걸려요.

클러스터 연결

eval "$(terraform output -raw configure_kubectl)"
kubectl get nodes

GKE에는 기본 스토리지 클래스(standard-rwo)가 있어서, 클러스터 내부 ClickHouse와 Redis 디스크가 바로 동작해요.

출력값 읽기

다음 페이지의 Helm 차트가 이 값들을 필요로 해요. terraform output helm_values가 바로 붙여 넣을 수 있는 스니펫을 출력하거나, 개별로 읽어요. 각 줄의 주석은 그것이 넣어줄 Helm 값을 나타내요:

terraform output -raw database_url                # secrets.data.DATABASE_URL
terraform output test_cases_bucket                # storage.testCasesBucket
terraform output payloads_bucket                  # storage.payloadsBucket
terraform output -raw app_service_account_email   # serviceAccount annotation
terraform output -raw code_executor_function_url  # codeExecutor.gcp.functionUrl

관리형 시크릿과 Redis (권장)

위의 모듈 블록이 둘 다 프로비저닝해요. Deploy 페이지가 External Secrets Operator를 설치하고 차트에 연결해요:

  • Secret Manager + External Secrets Operator (confident_create_secret_manager = true): Terraform이 시크릿과 ESO용 Workload Identity 바인딩 서비스 계정을 만들어요.
  • Memorystore for Redis (confident_managed_redis_enabled = true): 클러스터 내부 대신 관리형 Redis. terraform output -raw redis_url이 redis.externalUrl 값을 줘요.

더 간단한 구성이 좋다면 둘 다 false로 두어 시크릿을 Kubernetes Secret에 담고 Redis를 클러스터에서 실행하세요. Deploy 페이지의 더 간단한 옵션을 참고하세요.

입력 참조(Inputs reference)

가장 자주 설정할 변수들이에요. 완전하고 항상 최신인 목록은 Terraform Registry의 모듈 입력을 참고하세요.

필수

Variable 설명
confident_gcp_project_id 배포할 GCP 프로젝트.
confident_network_name / confident_network_id 기존 VPC 네트워크 이름과 self-link.
confident_subnetwork_name GKE 노드용 기존 서브넷.
confident_ip_range_pods / confident_ip_range_services 기존 보조 범위 이름 (파드·서비스).

자주 설정 (선택, 프로덕션 기본값 포함)

Variable 기본값 설명
confident_gcp_region us-central1 클러스터와 데이터 플레인 리전.
confident_environment / confident_environment_code stage / s 리소스에 적용되는 네이밍 컨벤션 (prod / p 사용).
confident_public_gke false 클러스터 API 엔드포인트 노출.
confident_psql_password 생성됨 자체 PostgreSQL 비밀번호 설정, 또는 자동 생성을 위해 비워 둠.
confident_node_machine_type / confident_node_group_desired_size n2-standard-8 / 4 노드 풀 크기.
confident_code_executor_enabled / confident_ar_repository_name true / "" 코드 실행기 Cloud Run 서비스와 그 이미지를 담은 Artifact Registry 리포지토리.
confident_create_secret_manager false Secret Manager 시크릿과 ESO Workload Identity.
confident_managed_redis_enabled false 클러스터 내부 대신 Memorystore.

다음 단계

Helm으로 배포

Terraform 출력값으로 앱을 설치하고 HTTPS로 노출.

더 알아보기