Enabling the Policy Center
When you use the policy center function for the first time, you need to enable it. You can choose to enable this function for a fleet or only for clusters that have not joined a fleet. After the policy center function is enabled, the system automatically installs the Gatekeeper add-on for the fleet or cluster you select.
Constraints
- Only Huawei Cloud accounts or users with the UCS FullAccess permission can enable the policy center function.
- Before enabling the policy center function for a non-Huawei Cloud cluster, ensure that the cluster can pull public network images.
- After the policy center function is enabled, the system installs the Gatekeeper add-on on the fleet or cluster. Note that the add-on occupies some cluster resources (as shown in Table 1). Therefore, ensure the cluster has sufficient resources. This will help ensure the smooth deployment of the policy center function while avoiding negative impacts on the performance of existing workloads.
Table 1 Resource usage of the Gatekeeper add-on CPU
Mem
Requests: 100m * 3
Limits: 1000m * 3
Requests: 256Mi * 3
Limits: 512Mi * 3
* 3 indicates that there are three pods.
- When a fleet or cluster is being enabled, avoid performing any operations on the fleet or cluster. Performing operations during the enabling process may affect the enabling success.
Procedure
- Log in to the UCS console. In the navigation pane, choose Policy Center.
- Click Enable. The Enable Policy Management dialog box is displayed.
- Select a fleet or cluster from the drop-down list and click OK to return to the policy center.
You will see that policy management is being enabled. Wait for about 3 minutes.
If The throttling threshold has been reached: policy ip over rate limit is displayed when you enable the policy management function, traffic is limited because a large number of clusters are enabled. Wait for a while and try again.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot