Description
Disabling GKE log collection reduces the records available for centralized investigation of failures and unusual behavior. Select the log types you need separately; omitting a logging setting does not itself disable collection.
Potential impact
Records needed to establish a failure’s cause and impact can be missing.
Remediation
Enable Cloud Logging collection and configure the required component logs and retention. Ansible creation settings can use logging_service: logging.googleapis.com/kubernetes.
Examples
For a Standard cluster, the first excerpt uses defaults and the second disables collection with none. The revised excerpt explicitly selects the current logging service. Other cluster settings remain partial.
Before
yaml
- name: create a cluster1
google.cloud.gcp_container_cluster:
name: my-cluster1
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
- name: create a cluster2
google.cloud.gcp_container_cluster:
name: my-cluster2
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
logging_service: none
After
yaml
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
logging_service: logging.googleapis.com/kubernetes