Skip to content

adding new scripting module gke-backend-fetcher under community folder.#5593

Merged
arpit974 merged 3 commits into
GoogleCloudPlatform:developfrom
arpit974:community/modules/scripts/gke-backend-fetcher-module
May 15, 2026
Merged

adding new scripting module gke-backend-fetcher under community folder.#5593
arpit974 merged 3 commits into
GoogleCloudPlatform:developfrom
arpit974:community/modules/scripts/gke-backend-fetcher-module

Conversation

@arpit974

@arpit974 arpit974 commented May 4, 2026

Copy link
Copy Markdown
Contributor

Adding a new module to dynamically discover GCP Backend Service IDs from GKE Ingress.

When a GKE Ingress controller creates a Global Load Balancer, it generates Backend Services with dynamic, non-deterministic names. This makes it difficult to reference these backends in declarative Terraform code (e.g., for applying Identity-Aware Proxy policies).

This module introduces a Python-based utility that queries the GKE cluster's ingress annotations to resolve the mapping between a Kubernetes Service/Port and the corresponding Google Cloud Backend Service ID.

Key Changes:

External Data Provider: Utilizes the Terraform external provider to execute a specialized Python discovery script.
Python Logic: Implements a robust polling loop with a configurable timeout to wait for the GKE Ingress controller to successfully provision the cloud resources and update the ingress annotations.
Credential Handling: The script automatically handles gcloud container clusters get-credentials to ensure kubectl context is available for the lookup.
Output: Provides the backend_service_id and backend_service_name as standard Terraform outputs for consumption by downstream IAM/IAP modules.

Submission Checklist

NOTE: Community submissions can take up to 2 weeks to be reviewed.

Please take the following actions before submitting this pull request.

  • Fork your PR branch from the Toolkit "develop" branch (not main)
  • Test all changes with pre-commit in a local branch #
  • Confirm that "make tests" passes all tests
  • Add or modify unit tests to cover code changes
  • Ensure that unit test coverage remains above 80%
  • Update all applicable documentation
  • Follow Cluster Toolkit Contribution guidelines #

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request adds a new utility module to the community folder designed to bridge the gap between GKE Ingress and Google Cloud Load Balancer resources. By dynamically resolving non-deterministic backend service names, it allows for more robust and declarative infrastructure management, particularly for downstream configurations like Identity-Aware Proxy policies.

Highlights

  • New GKE Backend Fetcher Module: Introduced a new community module that dynamically discovers GCP Backend Service IDs from GKE Ingress resources.
  • Python-based Discovery Logic: Implemented a Python utility that polls GKE Ingress annotations to resolve mappings between Kubernetes services and Google Cloud backend services.
  • Terraform Integration: Utilized the Terraform external provider to execute the discovery script, enabling the consumption of backend service IDs and names as outputs.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@arpit974 arpit974 added the release-new-modules Added to release notes under the "New Modules" heading. label May 4, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces the gke-backend-fetcher community module, which utilizes a Python script to retrieve the GCP Backend Service ID and name associated with a GKE Ingress. The review feedback identifies several necessary improvements: the module must be added to the repository's module index to comply with the style guide, and the Python script's naming pattern for backends should be updated to support standard GKE Ingress conventions. Additionally, feedback was provided to remove an unused import, synchronize default timeout values, improve error handling in subprocess calls, ensure the total timeout is respected across polling loops, and relax the Terraform version constraint to a minimum version rather than an exact pin.

Comment thread community/modules/scripts/gke-backend-fetcher/README.md
Comment thread community/modules/scripts/gke-backend-fetcher/fetch_backend.py
Comment thread community/modules/scripts/gke-backend-fetcher/fetch_backend.py Outdated
Comment thread community/modules/scripts/gke-backend-fetcher/fetch_backend.py Outdated
Comment thread community/modules/scripts/gke-backend-fetcher/fetch_backend.py Outdated
Comment thread community/modules/scripts/gke-backend-fetcher/fetch_backend.py Outdated
Comment thread community/modules/scripts/gke-backend-fetcher/versions.tf
@arpit974 arpit974 marked this pull request as ready for review May 4, 2026 08:00
@arpit974 arpit974 requested a review from a team as a code owner May 4, 2026 08:00

@kvenkatachala333 kvenkatachala333 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Just a minor nit: please handle the gemini suggestion of ensuring new module is added to the index in the root modules/README.md file as required by the repository style guide

Comment thread community/modules/scripts/gke-backend-fetcher/fetch_backend.py Outdated
@arpit974 arpit974 merged commit 7ec5391 into GoogleCloudPlatform:develop May 15, 2026
14 of 80 checks passed
Thibaut-Nurit pushed a commit to Thibaut-Nurit/cluster-toolkit that referenced this pull request May 20, 2026
…r. (GoogleCloudPlatform#5593)

adding new scripting module gke-backend-fetcher under community folder.
kadupoornima pushed a commit to kadupoornima/cluster-toolkit that referenced this pull request May 25, 2026
…r. (GoogleCloudPlatform#5593)

adding new scripting module gke-backend-fetcher under community folder.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release-new-modules Added to release notes under the "New Modules" heading.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants