Review GKE node image selection

Choose a supported GKE node image for the workload and maintain node updates.

Description

Container-Optimized OS (COS) provides a minimal, hardened node environment for containers. GKE Standard also supports Ubuntu with containerd, so using a different image does not alone establish that a node is insecure.

Choose an image that meets the workload's filesystem and package requirements. Unnecessary host packages or unsupported images can increase maintenance and security risks.

Potential impact

  • Missed updates can leave operating-system vulnerabilities unresolved.
  • Changing images without compatibility testing can disrupt workloads.

Remediation

  • Select a supported image that meets your requirements. Consider COS_CONTAINERD when additional OS features are unnecessary.
  • Test compatibility before changing images and plan capacity and disruption during node replacement. Continue managing node updates afterward.

Examples

These partial NodePool request bodies replace the historical Deployment Manager format, whose support has ended. The old Docker-based image values are replaced with containerd variants; settings required for a complete creation request are omitted.

Before

yaml
name: my-node
config:
  imageType: UBUNTU_CONTAINERD

After

yaml
name: my-node
config:
  imageType: COS_CONTAINERD

Explanation:

  • Before: Ubuntu with containerd is selected. Its features can make it appropriate for the workload.
  • After: COS with containerd is selected. Image selection does not itself restrict application permissions or network access.

References