Review Alpha features in a production GKE cluster

Test Alpha features only in short-lived clusters separated from production.

Description

Alpha clusters are intended for testing experimental Kubernetes features and have no GKE SLA. They cannot be upgraded, receive no security updates and are automatically deleted after 30 days, so they should not run stable production workloads.

Potential impact

  • Experimental features can change or disappear, unexpectedly disrupting workloads.
  • Security fixes are unavailable, and automatic cluster deletion can cause service and data loss.

Remediation

  • Configure new production clusters with enable_kubernetes_alpha = false. Migrate production workloads from existing Alpha clusters to supported standard clusters.
  • Test Alpha features in short-lived clusters isolated from production, and preserve required data before they expire. Check Alpha creation requirements, including disabling node auto-upgrade and auto-repair.

Examples

These excerpts select features for a new cluster. Alpha creation has separate node-management requirements; changing the value to false does not convert an existing Alpha cluster into a standard cluster.

Before

hcl
resource "google_container_cluster" "example" {
  name                    = "example-cluster"
  location                = "asia-northeast3"
  enable_kubernetes_alpha = true
}

After

hcl
resource "google_container_cluster" "example" {
  name                    = "example-cluster"
  location                = "asia-northeast3"
  enable_kubernetes_alpha = false
}

Explanation:

  • Before: An experimental Alpha cluster without an SLA or upgrade support is selected.
  • After: A standard cluster without Alpha features is selected. Other features and operational security settings still need review.

References