Review GKE VPC-native networking

Plan Pod and Service address ranges and check the cluster’s actual networking mode.

Description

VPC-native GKE clusters use alias IP addresses to allocate Pod addresses from secondary ranges in VPC subnets. This helps integrate address management and VPC connectivity. New clusters currently default to VPC_NATIVE, so an omitted setting alone does not establish routes-based networking.

Alias IP addresses do not block unnecessary traffic by themselves. Manage firewall rules, network policies and permissions separately.

Potential impact

  • Poor address planning can cause IP exhaustion or connectivity conflicts.
  • A routes-based cluster may not support required networking features or scaling needs.

Remediation

  • For new clusters, configure networking_mode = "VPC_NATIVE" with an appropriate ip_allocation_policy.
  • Calculate Pod and Service address capacity and prepare ranges that do not overlap existing networks.
  • For an existing routes-based cluster, plan migration to a new cluster instead of changing the mode in place, and verify connectivity.

Examples

These excerpts compare networking modes. Supply the project, VPC and subnet separately. An empty ip_allocation_policy does not select explicit ranges; verify the actual allocations and available capacity.

Before

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  networking_mode    = "ROUTES"

  ip_allocation_policy {}

  timeouts {
    create = "30m"
    update = "40m"
  }
}

After

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  networking_mode    = "VPC_NATIVE"

  ip_allocation_policy {}

  timeouts {
    create = "30m"
    update = "40m"
  }
}

Explanation:

  • Before: ROUTES selects routes-based networking.
  • After: VPC_NATIVE selects alias IP networking. This setting alone does not restrict traffic access.

References