Review GKE node image selection

Choose a supported image for the workload and manage node operating-system updates.

Description

Container-Optimized OS is the recommended default image for Linux containers on GKE. Workloads that need Ubuntu features or Windows containers can legitimately use those supported images; an image is not unsafe simply because it is not COS.

Potential impact

  • Unsupported or unmanaged images can miss security fixes and create operational inconsistencies.
  • Changing to an operating system that does not support the workload can prevent containers from running.

Remediation

  • Consider COS_CONTAINERD for typical Linux workloads, and choose a supported containerd image when Ubuntu or Windows is required.
  • Test node upgrades and application compatibility. When changing operating systems, migrate to a compatible new node pool; do not move Windows containers directly to Linux nodes.

Examples

These excerpts compare image choices. Supply var.project_id and the actual cluster location, and configure required node settings such as a machine type supported by the image. The examples target different operating systems, not a simple update of an existing Windows pool.

Before

hcl
resource "google_container_node_pool" "example" {
  project = var.project_id
  name    = "primary-pool"
  location = "us-west1"
  cluster = google_container_cluster.example.name

  node_config {
    image_type = "WINDOWS_LTSC_CONTAINERD"
  }
}

After

hcl
resource "google_container_node_pool" "example" {
  project = var.project_id
  name    = "primary-pool"
  location = "us-west1"
  cluster = google_container_cluster.example.name

  node_config {
    image_type = "COS_CONTAINERD"
  }
}

Explanation:

  • Before: A supported image for Windows containers is selected. This is appropriate for workloads that require Windows.
  • After: Container-Optimized OS is selected for Linux containers. Workloads must be compatible with Linux.

References