Description
Container-Optimized OS is the recommended default image for Linux containers on GKE. Workloads that need Ubuntu features or Windows containers can legitimately use those supported images; an image is not unsafe simply because it is not COS.
Potential impact
- Unsupported or unmanaged images can miss security fixes and create operational inconsistencies.
- Changing to an operating system that does not support the workload can prevent containers from running.
Remediation
- Consider
COS_CONTAINERDfor typical Linux workloads, and choose a supported containerd image when Ubuntu or Windows is required. - Test node upgrades and application compatibility. When changing operating systems, migrate to a compatible new node pool; do not move Windows containers directly to Linux nodes.
Examples
These excerpts compare image choices. Supply var.project_id and the actual cluster location, and configure required node settings such as a machine type supported by the image. The examples target different operating systems, not a simple update of an existing Windows pool.
Before
hcl
resource "google_container_node_pool" "example" {
project = var.project_id
name = "primary-pool"
location = "us-west1"
cluster = google_container_cluster.example.name
node_config {
image_type = "WINDOWS_LTSC_CONTAINERD"
}
}
After
hcl
resource "google_container_node_pool" "example" {
project = var.project_id
name = "primary-pool"
location = "us-west1"
cluster = google_container_cluster.example.name
node_config {
image_type = "COS_CONTAINERD"
}
}
Explanation:
- Before: A supported image for Windows containers is selected. This is appropriate for workloads that require Windows.
- After: Container-Optimized OS is selected for Linux containers. Workloads must be compatible with Linux.