Description
Disabling GKE node auto-upgrades increases the operator’s responsibility to keep versions current. Delayed manual upgrades can leave nodes running versions with known vulnerabilities.
Potential impact
Delayed patches and version differences between node pools increase security risk and operational work. Disabling auto-upgrades does not stop control-plane updates or all maintenance; the service can upgrade node versions that are no longer supported.
Remediation
Set management.auto_upgrade: yes and plan maintenance windows and acceptable workload disruption. If managing upgrades manually, maintain a tested schedule within the version’s support period. Auto-repair is a separate feature.
Examples
These excerpts show node-pool upgrade settings. Supply the prepared cluster resource, project and protected service-account JSON file path.
Before
- name: create a node pool
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
- name: create a third node pool
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
management:
auto_repair: yes
auto_upgrade: no
The first task omits management settings, so check the actual auto-upgrade state. The second enables auto-repair but disables auto-upgrades.
After
- name: create a node pool
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
management:
auto_upgrade: yes
Auto-upgrades are enabled. Manage rollout timing and node-replacement effects together with cluster policies and maintenance settings.