Review terminated Pod cleanup thresholds

Choose cleanup thresholds that balance terminated Pod retention with control-plane resource use.

Description

--terminated-pod-gc-threshold controls the terminated Pod count above which cleanup starts. A value of 0 or less disables this cleanup. A very low positive value can delete Pod objects needed for investigation too soon, while an excessive or disabled threshold can let old objects accumulate.

Terminated Pod cleanup affects cluster availability and operations. It is a count threshold, not a log-retention period, so manage log and audit retention separately.

Potential impact

  • Accumulated terminated Pod objects can increase control-plane load.
  • An excessively low threshold can remove Pod information needed for investigation too quickly.

Remediation

  • Set --terminated-pod-gc-threshold to a positive value appropriate to Pod turnover and investigation needs.
  • Consider the current default of 12500 and the cluster’s scale without applying one value indiscriminately.
  • Configure central log and audit retention separately and verify that required investigation data survives cleanup.

Examples

These command-argument excerpts retain the historical v1.6.0 image; that version is not a deployment recommendation. Apply the setting to a supported version and the actual control-plane configuration, with required certificate and connection settings supplied separately.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
      command: ["kube-controller-manager", "--terminated-pod-gc-threshold=0"]
      args: []

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
      command: ["kube-controller-manager"]
      args: ["--terminated-pod-gc-threshold=10"]

Explanation:

  • Before: 0 disables terminated Pod cleanup, allowing completed objects to accumulate.
  • After: 10 is a small illustrative count. It enables cleanup, but review whether information needed for investigation would disappear too soon.

References