Review GKE node auto-upgrade settings

Check node upgrade policies so security patches and supported versions are maintained.

Description

Disabling GKE node auto-upgrades can delay vulnerability fixes and recommended versions, leaving older nodes in service. The current Google provider enables management.auto_upgrade by default.

Control-plane and node upgrades are managed separately. Disabling node auto-upgrades does not stop control-plane updates or all mandatory upgrades for versions reaching end of support.

Potential impact

  • Nodes can remain on older Kubernetes versions or patch levels.
  • Delayed fixes or version differences from the control plane can create security and operational problems.

Remediation

  • Check management.auto_upgrade = true and the actual upgrade policy for each node pool.
  • Prepare maintenance windows, workload compatibility and availability during node replacement.
  • Assign an owner and manual patch schedule to exceptions, and update before support ends.

Examples

These excerpts show node-pool upgrade settings. Define the referenced cluster and remaining operational settings separately.

Before

hcl
resource "google_container_node_pool" "node_pool" {
  name       = "my-node-pool"
  location   = "us-central1-a"
  cluster    = google_container_cluster.primary.name
  node_count = 3

  management {
    auto_upgrade = false
  }

  timeouts {
    create = "30m"
    update = "20m"
  }
}

After

hcl
resource "google_container_node_pool" "node_pool" {
  name       = "my-node-pool"
  location   = "us-central1-a"
  cluster    = google_container_cluster.primary.name
  node_count = 3

  management {
    auto_upgrade = true
  }

  timeouts {
    create = "30m"
    update = "20m"
  }
}

Explanation:

  • Before: Routine node auto-upgrades are disabled. This does not disable all service maintenance.
  • After: Node auto-upgrades are enabled. Actual timing and supported versions depend on GKE policies.

References