Description
Container-Optimized OS (COS) provides a minimal, hardened node environment for containers. GKE offers other supported images, so not using COS does not alone establish a vulnerability. Windows workloads require Windows nodes.
Review support periods, patch status and required OS features together. Unnecessary host packages and inconsistent updates can increase risk.
Potential impact
- Missing updates can leave operating-system vulnerabilities unresolved.
- An incompatible image can prevent workloads from running or cause disruption.
Remediation
- Set
config.image_typeto an image supported by the workload and GKE version. ConsiderCOS_CONTAINERDfor Linux workloads that need no additional OS features. - Test compatibility before changing images and plan capacity and disruption during node replacement. Continue maintaining node updates.
Examples
These excerpts target different operating systems. A Windows workload cannot simply move unchanged to Linux nodes. Supply the actual cluster result object, project and service-account JSON file for your environment.
Before
yaml
- name: 노드 풀 생성
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
config:
image_type: WINDOWS_LTSC_CONTAINERD
After
yaml
- name: 노드 풀 생성
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
config:
image_type: COS_CONTAINERD
Explanation:
- Before: Windows with containerd is selected and can be appropriate for Windows workloads.
- After: COS with containerd is selected for Linux. This is not a replacement to apply without checking workload compatibility.