Description
Disabling GKE metric collection makes node health and resource usage harder to inspect centrally. Omitting a monitoring setting can use the default service.
Potential impact
Resource shortages or unhealthy states can go unnoticed for longer, making performance problems harder to diagnose.
Remediation
Enable Cloud Monitoring collection and configure the required metrics and alerts. Ansible creation settings can use monitoring_service: monitoring.googleapis.com/kubernetes.
Examples
For a Standard cluster, the first excerpt uses defaults and the second disables collection with none. The revised excerpt selects the current monitoring service; alert policies need separate configuration.
Before
yaml
- name: create a cluster1
google.cloud.gcp_container_cluster:
name: my-cluster1
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
- name: create a cluster2
google.cloud.gcp_container_cluster:
name: my-cluster2
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
monitoring_service: none
After
yaml
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project_id }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_credentials_file }}"
state: present
monitoring_service: monitoring.googleapis.com/kubernetes