Stay organized with collections
Save and categorize content based on your preferences.
Prepare for fleet-level setup
A fleet in Google Cloud is a logical group of Kubernetes clusters and other resources that can be managed together, created by registering clusters to Google Cloud. Fleet-level setup for GKE Identity Service builds on the power of fleets to let administrators set up authentication with their preferred identity providers for one or more GKE clusters at once, with their authentication configuration maintained by GKE Enterprise and stored in Google Cloud.
This document is for cluster administrators or application operators who want to set up GKE Identity Service for a fleet.
Supported cluster types
The following cluster types and environments are supported for fleet-level setup:
Other GKE Identity Service supported cluster types and environments still require individual cluster setup. You may also want to use per-cluster setup if you are using an earlier version of GKE clusters, or if you require GKE Identity Service features that aren't yet supported with fleet-level lifecycle management.
Supported identity provider protocols
If you configure fleet-level GKE Identity Service, you can use identity providers that support the OIDC, SAML or LDAP protocols.
Before you begin
Ensure that your platform administrator has given you all the necessary details, including the client ID and secret for GKE Identity Service.
Ensure that you have the following command line tools installed:
The latest version of the Google Cloud CLI, which includes gcloud, the command line tool for interacting with Google Cloud. If you need to install the Google Cloud CLI, see the installation guide.
kubectl for running commands against Kubernetes clusters. If you need to install kubectl, see the installation guide.
If you are using Cloud Shell as your shell environment for interacting with Google Cloud, these tools are installed for you.
Ensure that you have initialized the gcloud CLI for use with the project where the clusters are registered.
If you are not the project owner, you need the GKE Hub Admin role in the project where the clusters are registered to complete the configuration steps.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-28 UTC."],[],[],null,["# Prepare for fleet-level setup\n=============================\n\nA fleet in Google Cloud is a logical group of Kubernetes clusters and other resources that can be managed together, created by registering clusters to Google Cloud. Fleet-level setup for GKE Identity Service builds on the power of fleets to let administrators set up authentication with their preferred identity providers for one or more GKE clusters at once, with their authentication configuration maintained by GKE Enterprise and stored in Google Cloud.\nThis document is for cluster administrators or application operators who want to set up GKE Identity Service for a fleet.\n\nSupported cluster types\n-----------------------\n\nThe following cluster types and environments are supported for fleet-level setup:\n\n- [Google Distributed Cloud (software-only) on VMware](/anthos/clusters/docs/on-prem/overview), version 1.8.2 or higher\n- [Google Distributed Cloud (software-only) on bare metal](/anthos/clusters/docs/bare-metal/concepts/about-bare-metal), version 1.8.3 or higher\n- [GKE on Azure](/anthos/clusters/docs/azure/concepts/architecture)\n- [GKE on AWS](/anthos/clusters/docs/aws/concepts/architecture) running Kubernetes 1.21 or higher,\n- [GKE](/kubernetes-engine/docs) clusters on Google Cloud with Identity Service for GKE enabled. Follow the instructions in [Identity Service for GKE](/kubernetes-engine/docs/how-to/oidc) to enable the feature before [configuring authentication for the cluster](/kubernetes-engine/enterprise/identity/setup/fleet-cluster).\n\nThe following cluster type and environment is supported for fleet-level setup that is in *Pre-GA*:\n\n- Amazon Elastic Kubernetes Service (Amazon EKS) attached clusters\n\n| **Note:** This feature is covered by the [Pre-GA Offerings](https://cloud.google.com/terms/service-terms#1) Terms of the Google Cloud Terms of Service. Pre-GA features might have limited support, and changes to pre-GA features might not be compatible with other pre-GA versions. For more information, see the [launch stage descriptions](https://cloud.google.com/products#product-launch-stages).\n\nFor more information about attached clusters, see [GKE attached clusters](/kubernetes-engine/multi-cloud/docs/attached).\n\nOther GKE Identity Service supported cluster types and environments still require [individual cluster setup](/kubernetes-engine/enterprise/identity/setup/per-cluster). You may also want to use per-cluster setup if you are using an earlier version of GKE clusters, or if you require GKE Identity Service features that aren't yet supported with fleet-level lifecycle management.\n\nSupported identity provider protocols\n-------------------------------------\n\nIf you configure fleet-level GKE Identity Service, you can use identity providers that support the [OIDC](https://openid.net/connect/), [SAML](https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html) or [LDAP](https://ldap.com/) protocols.\n\nBefore you begin\n----------------\n\n- Ensure that your platform administrator has given you all the necessary details, including the client ID and secret for GKE Identity Service.\n- Ensure that you have the following command line tools installed:\n - The latest version of the Google Cloud CLI, which includes `gcloud`, the command line tool for interacting with Google Cloud. If you need to install the Google Cloud CLI, see the [installation guide](/sdk/docs/install).\n - `kubectl` for running commands against Kubernetes clusters. If you need to install `kubectl`, see the [installation guide](/kubernetes-engine/docs/how-to/cluster-access-for-kubectl). If you are using Cloud Shell as your shell environment for interacting with Google Cloud, these tools are installed for you.\n- Ensure that you have [initialized](/sdk/docs/install-sdk#initializing_the) the gcloud CLI for use with the project where the clusters are registered.\n- If you are not the project owner, you need the [GKE Hub Admin](/iam/docs/understanding-roles#gke-hub-roles) role in the project where the clusters are registered to complete the configuration steps.\n\nSet up your fleet\n-----------------\n\nAfter you have all necessary information and components installed, you can start to [set up clusters at fleet level](/kubernetes-engine/enterprise/identity/setup/fleet-cluster)."]]