Google Cloud 인프라 프로비저닝(Provision Google Cloud Infrastructure)
Google Cloud 인프라 프로비저닝(Provision Google Cloud Infrastructure)
Confident AI가 실행되는 클라우드 인프라를 프로비저닝해요: GKE 클러스터, Cloud SQL PostgreSQL 데이터베이스, GCS 버킷, 그리고 키리스 아이덴티티 연결. 완료되면 실행 중인 클러스터와 다음 페이지의 Helm 차트에 넣을 출력값들이 생겨요.
출처: 문서
본문
프로젝트와 리전을 한 번 설정하고, 모듈이 사용하는 API를 활성화해요:
export PROJECT=my-gcp-project
export REGION=us-central1
gcloud config set project $PROJECT
gcloud services enable \
container.googleapis.com sqladmin.googleapis.com \
servicenetworking.googleapis.com compute.googleapis.com \
artifactregistry.googleapis.com run.googleapis.com \
iamcredentials.googleapis.com
네트워크 생성 (선택)
파드·서비스용 두 개의 보조 범위(secondary range)가 있는 서브넷과 비공개 노드용 Cloud NAT가 있는 VPC 네트워크를 이미 갖고 있다면 이 단계는 건너뛰세요. 다음 단계에서 기존 이름을 사용하세요.
GKE에는 파드용·서비스용 두 개의 보조 범위가 있는 서브넷 하나와, 비공개 노드가 이미지를 가져올 수 있는 Cloud NAT가 필요해요. 블록을 순서대로 실행하세요.
서브넷을 직접 정의할 수 있도록 커스텀 서브넷 모드로 VPC 네트워크를 만들어요:
gcloud compute networks create confident-prod-vpc --subnet-mode=custom
GKE가 필요로 하는 두 개의 보조 범위가 있는 서브넷을 만들어요:
gcloud compute networks subnets create confident-prod-subnet \
--network=confident-prod-vpc --region=$REGION \
--range=10.30.0.0/20 \
--secondary-range confident-pods=10.30.32.0/19,confident-services=10.30.16.0/20
ClickHouse는 이 모듈이 만드는 IPv4 전용 GKE 클러스터에서 깔끔하게 실행돼요: 차트가 오퍼레이터 파드를 IPv4(
0.0.0.0)로 청취하도록 고정해서, 주소 패밀리 오류 없이 듀얼 스택 설정이 필요 없어요. 듀얼 스택 서브넷만으로는 바뀌지 않아요. 클러스터 자체가 듀얼 스택으로 생성되지 않는 한 노드는 IPv4 전용으로 유지돼요.
비공개 노드가 인바운드 노출 없이 아웃바운드 풀을 위해 인터넷에 도달하도록 Cloud Router와 NAT를 추가해요:
gcloud compute routers create confident-prod-router \
--network=confident-prod-vpc --region=$REGION
gcloud compute routers nats create confident-prod-nat \
--router=confident-prod-router --region=$REGION \
--nat-all-subnet-ip-ranges --auto-allocate-nat-external-ips
코드 샌드박스 이미지 미러링 (필수)
코드 기반 및 트랜스포머 지표는 confident-code-sandbox-gcp 이미지를 실행하는 샌드박스형 Cloud Run 서비스에서 실행돼요. Terraform이 서비스를 만들기 전에 반드시 여러분의 Artifact Registry에 있어야 하므로, 공개 이미지를 미러링해요.
Artifact Registry 리포지토리를 만들고 Docker가 인증하게 해요:
gcloud artifacts repositories create confident \
--repository-format=docker --location=$REGION
gcloud auth configure-docker $REGION-docker.pkg.dev --quiet
공개 이미지를 가져와 리포지토리로 푸시해요:
docker pull confidentai/confident-code-sandbox-gcp:latest
docker tag confidentai/confident-code-sandbox-gcp:latest \
$REGION-docker.pkg.dev/$PROJECT/confident/confident-code-sandbox-gcp:latest
docker push $REGION-docker.pkg.dev/$PROJECT/confident/confident-code-sandbox-gcp:latest
Terraform 설정 작성
공개 모듈을 참조하는 main.tf를 만들고, 프로젝트와 앞선 단계들의 네트워크 이름을 채워요. 각 변수의 역할:
- 프로젝트와 네트워크:
confident_gcp_project_id,confident_gcp_region, 그리고 네트워크 단계의 네트워크 이름. - 네이밍:
confident_environment와confident_environment_code가prod네이밍 컨벤션을 모든 리소스에 적용해요. - 접근:
confident_public_gke는 클러스터 API를 머신에 노출해요. 비공개 전용 엔드포인트를 원하면false로. - 데이터베이스:
confident_psql_password는 자체 PostgreSQL 비밀번호를 설정해요. 생략하면 자동 생성해요. - 관리형 서비스:
confident_create_secret_manager와confident_managed_redis_enabled가 권장 시크릿 스토어와 Redis를 켜요. - 코드 실행기:
confident_ar_repository_name은 방금 미러링한 이미지를 담은 Artifact Registry 리포지토리.
provider "google" {
project = "my-gcp-project"
region = "us-central1"
}
module "confident_ai" {
source = "confident-ai/confident-ai/google"
version = "~> 0.1"
confident_gcp_project_id = "my-gcp-project"
confident_gcp_region = "us-central1"
confident_network_name = "confident-prod-vpc"
confident_network_id = "projects/my-gcp-project/global/networks/confident-prod-vpc"
confident_subnetwork_name = "confident-prod-subnet"
confident_ip_range_pods = "confident-pods"
confident_ip_range_services = "confident-services"
confident_environment = "prod"
confident_environment_code = "p"
confident_public_gke = true
confident_psql_password = "choose-a-strong-password"
confident_create_secret_manager = true
confident_managed_redis_enabled = true
confident_code_executor_enabled = true
confident_ar_repository_name = "confident"
}
output "helm_values" {
value = module.confident_ai.helm_values
sensitive = true
}
리포지토리 안에서 작업하고 싶다면
terraform-google-confident-ai를 클론해module블록 대신terraform.tfvars파일에 같은 변수를 넣으세요.
원격 상태 구성 (선택)
이걸 건너뛰면 로컬 상태를 사용해요. 팀이나 실제 환경이라면 상태를 GCS 버킷에 두세요.
backend.tf를 만들어요:
terraform {
backend "gcs" {
bucket = "confident-tfstate"
prefix = "confident-ai/gcp"
}
}
적용(Apply)
terraform init
terraform plan
terraform apply
GKE 클러스터와 Cloud SQL을 만드는 데는 대략 15-20분이 걸려요.
클러스터 연결
eval "$(terraform output -raw configure_kubectl)"
kubectl get nodes
GKE에는 기본 스토리지 클래스(standard-rwo)가 있어서, 클러스터 내부 ClickHouse와 Redis 디스크가 바로 동작해요.
출력값 읽기
다음 페이지의 Helm 차트가 이 값들을 필요로 해요. terraform output helm_values가 바로 붙여 넣을 수 있는 스니펫을 출력하거나, 개별로 읽어요. 각 줄의 주석은 그것이 넣어줄 Helm 값을 나타내요:
terraform output -raw database_url # secrets.data.DATABASE_URL
terraform output test_cases_bucket # storage.testCasesBucket
terraform output payloads_bucket # storage.payloadsBucket
terraform output -raw app_service_account_email # serviceAccount annotation
terraform output -raw code_executor_function_url # codeExecutor.gcp.functionUrl
관리형 시크릿과 Redis (권장)
위의 모듈 블록이 둘 다 프로비저닝해요. Deploy 페이지가 External Secrets Operator를 설치하고 차트에 연결해요:
- Secret Manager + External Secrets Operator (
confident_create_secret_manager = true): Terraform이 시크릿과 ESO용 Workload Identity 바인딩 서비스 계정을 만들어요. - Memorystore for Redis (
confident_managed_redis_enabled = true): 클러스터 내부 대신 관리형 Redis.terraform output -raw redis_url이redis.externalUrl값을 줘요.
더 간단한 구성이 좋다면 둘 다
false로 두어 시크릿을 Kubernetes Secret에 담고 Redis를 클러스터에서 실행하세요. Deploy 페이지의 더 간단한 옵션을 참고하세요.
입력 참조(Inputs reference)
가장 자주 설정할 변수들이에요. 완전하고 항상 최신인 목록은 Terraform Registry의 모듈 입력을 참고하세요.
필수
| Variable | 설명 |
|---|---|
confident_gcp_project_id |
배포할 GCP 프로젝트. |
confident_network_name / confident_network_id |
기존 VPC 네트워크 이름과 self-link. |
confident_subnetwork_name |
GKE 노드용 기존 서브넷. |
confident_ip_range_pods / confident_ip_range_services |
기존 보조 범위 이름 (파드·서비스). |
자주 설정 (선택, 프로덕션 기본값 포함)
| Variable | 기본값 | 설명 |
|---|---|---|
confident_gcp_region |
us-central1 |
클러스터와 데이터 플레인 리전. |
confident_environment / confident_environment_code |
stage / s |
리소스에 적용되는 네이밍 컨벤션 (prod / p 사용). |
confident_public_gke |
false |
클러스터 API 엔드포인트 노출. |
confident_psql_password |
생성됨 | 자체 PostgreSQL 비밀번호 설정, 또는 자동 생성을 위해 비워 둠. |
confident_node_machine_type / confident_node_group_desired_size |
n2-standard-8 / 4 |
노드 풀 크기. |
confident_code_executor_enabled / confident_ar_repository_name |
true / "" |
코드 실행기 Cloud Run 서비스와 그 이미지를 담은 Artifact Registry 리포지토리. |
confident_create_secret_manager |
false |
Secret Manager 시크릿과 ESO Workload Identity. |
confident_managed_redis_enabled |
false |
클러스터 내부 대신 Memorystore. |
다음 단계
Helm으로 배포
Terraform 출력값으로 앱을 설치하고 HTTPS로 노출.