Review GKE Cloud Logging integration

Enable required GKE log collection and verify delivery and retention.

Description

Disabling GKE Cloud Logging integration can reduce the system and workload logs collected through this path. Logs are important evidence when investigating Pod failures and abnormal activity.

Omitting loggingService does not imply that logging is disabled. GKE can apply default logging settings, and automatic Admin Activity audit logs are separate from this integration. Enabling it does not automatically select every control-plane or application log.

Potential impact

  • Identifying the cause of failures or abnormal behavior and restoring service can take longer.
  • Failing to collect and retain required logs can leave insufficient incident-response evidence.

Remediation

  • Enable the required components through the supported loggingService: logging.googleapis.com/kubernetes value or current logging settings.
  • Verify collection permissions, exclusion filters and actual log receipt. Select required control-plane logs and application output, and manage retention and access permissions.

Examples

With Deployment Manager support ended, these excerpts show only the relevant GKE cluster request-body fields. They are not complete creation requests. Supply required location, network and node settings separately through a supported tool.

Before

yaml
name: my-cluster

After

yaml
name: my-cluster
loggingService: logging.googleapis.com/kubernetes

Explanation:

  • Before: The logging service is omitted. Check the applied default and effective collection state.
  • After: GKE Cloud Logging integration is explicit. Verify the required log coverage and actual delivery separately.

References