Review GKE node pool auto-repair settings

Review GKE node auto-repair together with failure monitoring.

Description

When node auto-repair is disabled, persistent unhealthy nodes can require operator intervention, prolonging an outage. Auto-repair is enabled by default for new Standard node pools and is always enabled in Autopilot.

Potential impact

Prolonged node failures reduce availability and increase manual recovery work. Auto-repair does not resolve every failure immediately or replace data backups.

Remediation

Set management.auto_repair: true on Standard node pools. Maintain failure alerts and manual response procedures, and configure workloads to tolerate node replacement. Manage auto-upgrades for security patches separately.

Examples

These excerpts show node-pool management settings. cluster is a prepared cluster resource; supply the project and the path to a protected service-account JSON file separately.

Before

yaml
- name: create a node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    management:
      auto_repair: no

- name: create a node pool3
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

The first task disables auto-repair. The omission in the second does not mean auto-repair is disabled; check the actual node-pool state.

After

yaml
- name: create a node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    management:
      auto_repair: true

Auto-repair is explicitly enabled. Repairs follow the service’s health-check criteria.

References