gcloud alpha container hub policycontroller deployment set Stay organized with collections Save and categorize content based on your preferences.
- NAME
- gcloud alpha container hub policycontroller deployment set - sets configuration of the Policy Controller components
- SYNOPSIS
gcloud alpha container hub policycontroller deployment setDEPLOYMENTPROPERTYVALUE[--effect=EFFECT][--all-memberships| [--memberships=[MEMBERSHIPS,…] :--location=LOCATION]][GCLOUD_WIDE_FLAG …]
- DESCRIPTION
(ALPHA)Customizes on-cluster components of Policy Controller.Supported properties may be set with this command, or removed with 'remove'.These components are managed as individual kubernetes deployments (e.g.'admission') in the gatekeeper-system namespace.When setting cpu or memory limits and requests, Kubernetes-standard resourceunits are used.
All properties set using this command will overwrite previous properties, withthe exception of tolerations which can only be added, and any number may beadded. To edit a toleration, use 'remove' to first delete it, and then 'set' thedesired toleration.
- EXAMPLES
- To set the replica count for a component:
gcloudalphacontainerhubpolicycontrollerdeploymentsetadmissionreplica-count3To set the replica count for a component across all fleet memberships:
gcloudalphacontainerhubpolicycontrollerdeploymentsetadmissionreplica-count3--all-membershipsTo set a toleration with key 'my-key' on a component (which is an 'Exists'operator):
gcloudalphacontainerhubpolicycontrollerdeploymentsetadmissiontolerationmy-keyTo set a toleration with key 'my-key' and 'my-value' on a component (which is an'Equal' operator):
gcloudalphacontainerhubpolicycontrollerdeploymentsetadmissiontolerationmy-key=my-valueTo set a toleration with key 'my-key' and 'my-value' on a component, along withthe effect 'NoSchedule' (which is an 'Equal' operator):
gcloudalphacontainerhubpolicycontrollerdeploymentsetadmissiontolerationmy-key=my-value--effect=NoScheduleTo set a memory limit:
gcloudalphacontainerhubpolicycontrollerdeploymentsetauditmemory-limit4GiTo set a memory request:
gcloudalphacontainerhubpolicycontrollerdeploymentsetmutationmemory-request2GiTo set a cpu limit:
gcloudalphacontainerhubpolicycontrollerdeploymentsetadmissioncpu-limit500mTo set a cpu request:
gcloudalphacontainerhubpolicycontrollerdeploymentsetauditcpu-request250mTo set anti-affinity to achieve high availability on the mutation deployment:
gcloudalphacontainerhubpolicycontrollerdeploymentsetmutationpod-affinityanti - POSITIONAL ARGUMENTS
DEPLOYMENT- The PolicyController deployment component (e.g. "admission", "audit" or"mutation") upon which to set configuration.
PROPERTY- Property to be set.
VALUE- The value to set the property to. Valid input varies based on the property beingset.
- FLAGS
--effect=EFFECT- Applies only to "toleration" property.
EFFECTmust beone of:NoSchedule,PreferNoSchedule,NoExecute. - Membership flags.
At most one of these can be specified:
--all-memberships- If supplied, apply to all Policy Controllers memberships in the fleet.
- Membership resource - The group of arguments defining one or more memberships.The arguments in this group can be used to specify the attributes of thisresource. (NOTE) Some attributes are not given arguments in this group but canbe set in other ways.
To set the
projectattribute:- provide the argument
--membershipson the command line with a fullyspecified name; - provide the argument
--projecton the command line; - set the property
core/project.
--memberships=[MEMBERSHIPS,…]- IDs of the memberships or fully qualified identifiers for the memberships.
To set the
membershipsattribute:- provide the argument
--membershipson the command line.
This flag argument must be specified if any of the other arguments in this groupare specified.
- provide the argument
--location=LOCATION- Location for the memberships.
To set the
locationattribute:- provide the argument
--membershipson the command line with a fullyspecified name; - provide the argument
--locationon the command line; - set the property
gkehub/location.
- provide the argument
- provide the argument
- GCLOUD WIDE FLAGS
- These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$gcloud helpfor details. - NOTES
- This command is currently in alpha and might change without notice. If thiscommand fails with API permission errors despite specifying the correct project,you might be trying to access an API with an invitation-only early accessallowlist. These variants are also available:
gcloudcontainerhubpolicycontrollerdeploymentsetgcloudbetacontainerhubpolicycontrollerdeploymentset
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-05-07 UTC.