Description
VPC-native clusters use alias IP addresses from subnet secondary ranges for Pods and integrate them with VPC routing. This reduces individual route management compared with routes-based clusters. VPC-native networking is the current default for new GKE clusters; omitting the setting does not establish that alias IPs are unused.
Potential impact
Poor address-capacity and routing plans can cause scaling or connectivity problems. Alias IPs alone do not block Pod traffic or make cluster access private.
Remediation
For new clusters, use ip_allocation_policy.use_ip_aliases: yes with suitable Pod and Service address ranges. An existing cluster’s network mode cannot be changed, so plan workload migration to a new cluster if conversion is required. Configure firewalls and network policies separately.
Examples
These are network configuration excerpts. Supply the project and JSON credential path, and prepare the VPC, subnet and sufficient secondary IP ranges. These examples do not create those resources.
Before
- name: create a cluster1
google.cloud.gcp_container_cluster:
name: my-cluster1
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
- name: create a cluster3
google.cloud.gcp_container_cluster:
name: my-cluster3
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
ip_allocation_policy:
create_subnetwork: no
use_ip_aliases: no
The first task omits the allocation policy; the second requests routes-based networking with use_ip_aliases: no. Check the actual cluster value when the setting is omitted.
After
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
ip_allocation_policy:
create_subnetwork: no
use_ip_aliases: yes
VPC-native networking is explicit. With create_subnetwork: no, configure the subnet and address ranges separately.