Insight konektivitas GKE on-premise ke bidang kontrol
Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Halaman ini menjelaskan insight Network Analyzer untuk Google Kubernetes Engine (GKE)
on-premise untuk mengontrol konektivitas bidang kontrol. Untuk mengetahui informasi tentang semua
jenis insight, lihat Grup dan jenis insight.
Melihat insight di Recommender API
Untuk melihat insight ini di Google Cloud CLI atau Recommender API, gunakan jenis insight berikut:
Untuk informasi selengkapnya tentang penggunaan Recommender API untuk insight Penganalisis Jaringan, lihat Menggunakan Recommender CLI dan API.
Konektivitas GKE on-premise ke control plane tidak memiliki rute kembali
Penganalisis ini memverifikasi konektivitas antara jaringan lokal Anda
dan bidang kontrol GKE.
Jika penganalisis ini menyimpulkan bahwa ada rute di jaringan lokal Anda yang mengirim traffic ke bidang kontrol, penganalisis juga akan memverifikasi bahwa rute kembali ada di jaringan VPC bidang kontrol. Insight
ini dihasilkan saat Cloud Router mengiklankan rentang CIDR
bidang kontrol ke jaringan lokal, tetapi rute kustom ke jaringan lokal
tidak diekspor ke Peering Jaringan VPC
cluster GKE. Jika hal ini terjadi, penganalisis akan menyimpulkan bahwa jaringan lokal Anda memiliki rute ke jaringan VPC bidang kontrol. Namun, bidang kontrol GKE tidak memiliki rute
kembali ke jaringan lokal Anda. Jika ini adalah konfigurasi jaringan yang Anda inginkan, Anda dapat menutup insight ini.
Insight ini mencakup informasi berikut:
Cluster GKE: Nama cluster GKE.
Jaringan: Nama jaringan tempat cluster GKE dikonfigurasi.
VPC Network Peering: Nama konfigurasi peering VPC yang menghubungkan
cluster GKE Anda ke bidang kontrol.
Cloud Router Terkait: Daftar Cloud Router yang mengiklankan
rentang alamat bidang kontrol.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-04 UTC."],[],[],null,["# GKE on-premises to control plane connectivity insights\n\nThis page describes the Network Analyzer insights for Google Kubernetes Engine (GKE)\non-premises to control plane connectivity. For information about all the\ninsight types, see [Insight groups and types](/network-intelligence-center/docs/network-analyzer/insight-groups-types).\n\nView insights in the Recommender API\n------------------------------------\n\nTo view these insights in the Google Cloud CLI or the Recommender API, use\nthe following insight type:\n\n- `google.networkanalyzer.container.connectivityInsight`\n\nYou need the following permissions:\n\n- `recommender.networkAnalyzerGkeConnectivityInsights.list`\n- `recommender.networkAnalyzerGkeConnectivityInsights.get`\n\nFor more information about using the Recommender API for\nNetwork Analyzer insights, see [Use the Recommender CLI and API](/network-intelligence-center/docs/network-analyzer/use-cli-recommender-api).\n\nGKE on-premises to control plane connectivity missing return route\n------------------------------------------------------------------\n\nThis analyzer verifies connectivity between your on-premises network\nand the GKE control plane.\n\nIf this analyzer infers that there is a route in your on-premises network that\ndelivers traffic to the control plane, the analyzer also verifies that the\nreturn route exists in the control plane's VPC network. This\ninsight is generated when a Cloud Router advertises the control plane's\nCIDR range to the on-premises network, but the custom route to the on-premises\nnetwork is not exported to the GKE cluster's\nVPC Network Peering. When this happens, the analyzer infers that your\non-premises network has a route to the control plane's VPC\nnetwork. However, the GKE control plane does not have a return\nroute to your on-premises network. If this is your intended network\nconfiguration, you can dismiss this insight.\n\nThis insight includes the following information:\n\n- **GKE cluster:** Name of the GKE cluster.\n- **Network:** Name of the network where the GKE cluster is configured.\n- **VPC Network Peering:** The name of the VPC peering configuration that connects your GKE cluster to the control plane.\n- **Associated Cloud Routers:** The list of Cloud Routers that are advertising the control plane's address range.\n\n### Related topics\n\nFor more information, see\n[Connecting to the control plane's private endpoint from on-premises networks](/kubernetes-engine/docs/how-to/private-clusters#cp-on-prem-routing).\n\n### Recommendations\n\n- Configure your VPC network to export its custom routes in the peering relationship to the control plane's VPC network."]]