GKE logging is disabled

Verify collection of the system and workload logs needed for GKE.

Description

Disabling GKE log collection reduces the records available for centralized investigation of failures and unusual behavior. Select the log types you need separately; omitting a logging setting does not itself disable collection.

Potential impact

Records needed to establish a failure’s cause and impact can be missing.

Remediation

Enable Cloud Logging collection and configure the required component logs and retention. Ansible creation settings can use logging_service: logging.googleapis.com/kubernetes.

Examples

For a Standard cluster, the first excerpt uses defaults and the second disables collection with none. The revised excerpt explicitly selects the current logging service. Other cluster settings remain partial.

Before

yaml
- name: create a cluster1
  google.cloud.gcp_container_cluster:
    name: my-cluster1
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present

- name: create a cluster2
  google.cloud.gcp_container_cluster:
    name: my-cluster2
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present
    logging_service: none

After

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_credentials_file }}"
    state: present
    logging_service: logging.googleapis.com/kubernetes

References