Review GKE node auto-upgrade settings

Review GKE node auto-upgrades and the schedule for security updates.

Description

Disabling GKE node auto-upgrades increases the operator’s responsibility to keep versions current. Delayed manual upgrades can leave nodes running versions with known vulnerabilities.

Potential impact

Delayed patches and version differences between node pools increase security risk and operational work. Disabling auto-upgrades does not stop control-plane updates or all maintenance; the service can upgrade node versions that are no longer supported.

Remediation

Set management.auto_upgrade: yes and plan maintenance windows and acceptable workload disruption. If managing upgrades manually, maintain a tested schedule within the version’s support period. Auto-repair is a separate feature.

Examples

These excerpts show node-pool upgrade settings. Supply the prepared cluster resource, project and protected service-account JSON file path.

Before

yaml
- name: create a node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

- name: create a third node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    management:
      auto_repair: yes
      auto_upgrade: no

The first task omits management settings, so check the actual auto-upgrade state. The second enables auto-repair but disables auto-upgrades.

After

yaml
- name: create a node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    management:
      auto_upgrade: yes

Auto-upgrades are enabled. Manage rollout timing and node-replacement effects together with cluster policies and maintenance settings.

References