Description
A VPC-native GKE cluster uses Alias IP ranges to allocate pod addresses from secondary subnet ranges. This supports VPC integration and address management, but does not replace firewalls or NetworkPolicy controls that restrict workload communication.
An omitted setting can inherit defaults from the creation method. Check how the actual cluster allocates addresses.
Potential impact
- Overlapping or undersized address ranges can cause connectivity or scaling problems.
- The networking mode can affect available features and operating procedures.
Remediation
- For a new VPC-native cluster, use
ipAllocationPolicy.useIpAliases: trueand plan the subnet and address ranges. Check expected node and pod capacity and overlap with other networks. - An existing routes-based cluster cannot be converted to VPC-native in place. If needed, migrate workloads to a new cluster and test access policies and connectivity.
Examples
Deployment Manager support has ended; use supported management tooling. These are partial GKE cluster request bodies, not complete deployment templates. Network, subnet and address-range planning are still required.
Before
yaml
name: cluster
description: my-cluster
After
yaml
name: cluster
description: my-cluster
ipAllocationPolicy:
useIpAliases: true
Explanation:
- Before: Address allocation is not explicit. Check effective defaults and the cluster configuration.
- After: Alias IP use is explicit. This setting alone does not isolate workload traffic.