Description
Disabling GKE node auto-upgrades can delay vulnerability fixes and recommended versions, leaving older nodes in service. The current Google provider enables management.auto_upgrade by default.
Control-plane and node upgrades are managed separately. Disabling node auto-upgrades does not stop control-plane updates or all mandatory upgrades for versions reaching end of support.
Potential impact
- Nodes can remain on older Kubernetes versions or patch levels.
- Delayed fixes or version differences from the control plane can create security and operational problems.
Remediation
- Check
management.auto_upgrade = trueand the actual upgrade policy for each node pool. - Prepare maintenance windows, workload compatibility and availability during node replacement.
- Assign an owner and manual patch schedule to exceptions, and update before support ends.
Examples
These excerpts show node-pool upgrade settings. Define the referenced cluster and remaining operational settings separately.
Before
hcl
resource "google_container_node_pool" "node_pool" {
name = "my-node-pool"
location = "us-central1-a"
cluster = google_container_cluster.primary.name
node_count = 3
management {
auto_upgrade = false
}
timeouts {
create = "30m"
update = "20m"
}
}
After
hcl
resource "google_container_node_pool" "node_pool" {
name = "my-node-pool"
location = "us-central1-a"
cluster = google_container_cluster.primary.name
node_count = 3
management {
auto_upgrade = true
}
timeouts {
create = "30m"
update = "20m"
}
}
Explanation:
- Before: Routine node auto-upgrades are disabled. This does not disable all service maintenance.
- After: Node auto-upgrades are enabled. Actual timing and supported versions depend on GKE policies.