Review GKE VPC-native networking settings

Review VPC-native networking and Pod and Service address planning in GKE.

Description

VPC-native clusters use alias IP addresses from subnet secondary ranges for Pods and integrate them with VPC routing. This reduces individual route management compared with routes-based clusters. VPC-native networking is the current default for new GKE clusters; omitting the setting does not establish that alias IPs are unused.

Potential impact

Poor address-capacity and routing plans can cause scaling or connectivity problems. Alias IPs alone do not block Pod traffic or make cluster access private.

Remediation

For new clusters, use ip_allocation_policy.use_ip_aliases: yes with suitable Pod and Service address ranges. An existing cluster’s network mode cannot be changed, so plan workload migration to a new cluster if conversion is required. Configure firewalls and network policies separately.

Examples

These are network configuration excerpts. Supply the project and JSON credential path, and prepare the VPC, subnet and sufficient secondary IP ranges. These examples do not create those resources.

Before

yaml
- name: create a cluster1
  google.cloud.gcp_container_cluster:
    name: my-cluster1
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

- name: create a cluster3
  google.cloud.gcp_container_cluster:
    name: my-cluster3
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    ip_allocation_policy:
      create_subnetwork: no
      use_ip_aliases: no

The first task omits the allocation policy; the second requests routes-based networking with use_ip_aliases: no. Check the actual cluster value when the setting is omitted.

After

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    ip_allocation_policy:
      create_subnetwork: no
      use_ip_aliases: yes

VPC-native networking is explicit. With create_subnetwork: no, configure the subnet and address ranges separately.

References