Description
Node auto-upgrades help apply security fixes and reliability improvements to GKE nodes. If they are not used and manual updates are delayed, vulnerable node versions can remain in service longer.
Do not infer disabled auto-upgrades from an omitted setting; check the cluster mode and actual node pools. Required upgrades, including those associated with end of support, can still occur even when auto-upgrades are disabled.
Potential impact
- Delayed patches can prolong exposure to known vulnerabilities.
- Node upgrades can restart workloads or temporarily reduce available capacity.
Remediation
- Set
management.autoUpgradetotruefor applicable node pools, and plan maintenance windows and workload availability together. - Review node versions and upgrade results regularly. If manual management is necessary, define security-update deadlines and validation procedures and keep versions supported.
Examples
Deployment Manager support has ended; use supported management tooling. These are partial GKE cluster request bodies, not complete deployment templates. nodePools is an array; names and the remaining node-pool configuration are omitted.
Before
yaml
name: cluster
description: my-cluster
After
yaml
name: cluster
description: my-cluster
nodePools:
- initialNodeCount: 2
management:
autoUpgrade: true
Explanation:
- Before: Auto-upgrade settings are omitted. Check effective defaults and node-pool state.
- After: Auto-upgrades are requested for the node pool. Verify the actual schedule and results.