Review GKE node image selection

Choose node images that meet workload OS requirements and support policies.

Description

Container-Optimized OS (COS) provides a minimal, hardened node environment for containers. GKE offers other supported images, so not using COS does not alone establish a vulnerability. Windows workloads require Windows nodes.

Review support periods, patch status and required OS features together. Unnecessary host packages and inconsistent updates can increase risk.

Potential impact

  • Missing updates can leave operating-system vulnerabilities unresolved.
  • An incompatible image can prevent workloads from running or cause disruption.

Remediation

  • Set config.image_type to an image supported by the workload and GKE version. Consider COS_CONTAINERD for Linux workloads that need no additional OS features.
  • Test compatibility before changing images and plan capacity and disruption during node replacement. Continue maintaining node updates.

Examples

These excerpts target different operating systems. A Windows workload cannot simply move unchanged to Linux nodes. Supply the actual cluster result object, project and service-account JSON file for your environment.

Before

yaml
- name: 노드 풀 생성
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    config:
      image_type: WINDOWS_LTSC_CONTAINERD

After

yaml
- name: 노드 풀 생성
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    config:
      image_type: COS_CONTAINERD

Explanation:

  • Before: Windows with containerd is selected and can be appropriate for Windows workloads.
  • After: COS with containerd is selected for Linux. This is not a replacement to apply without checking workload compatibility.

References