Description
VPC-native GKE clusters use alias IP addresses to allocate Pod addresses from secondary ranges in VPC subnets. This helps integrate address management and VPC connectivity. New clusters currently default to VPC_NATIVE, so an omitted setting alone does not establish routes-based networking.
Alias IP addresses do not block unnecessary traffic by themselves. Manage firewall rules, network policies and permissions separately.
Potential impact
- Poor address planning can cause IP exhaustion or connectivity conflicts.
- A routes-based cluster may not support required networking features or scaling needs.
Remediation
- For new clusters, configure
networking_mode = "VPC_NATIVE"with an appropriateip_allocation_policy. - Calculate Pod and Service address capacity and prepare ranges that do not overlap existing networks.
- For an existing routes-based cluster, plan migration to a new cluster instead of changing the mode in place, and verify connectivity.
Examples
These excerpts compare networking modes. Supply the project, VPC and subnet separately. An empty ip_allocation_policy does not select explicit ranges; verify the actual allocations and available capacity.
Before
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
networking_mode = "ROUTES"
ip_allocation_policy {}
timeouts {
create = "30m"
update = "40m"
}
}
After
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
networking_mode = "VPC_NATIVE"
ip_allocation_policy {}
timeouts {
create = "30m"
update = "40m"
}
}
Explanation:
- Before: ROUTES selects routes-based networking.
- After: VPC_NATIVE selects alias IP networking. This setting alone does not restrict traffic access.