Review GKE version support and updates

Older GKE versions can increase exposure to known vulnerabilities and end-of-support risks.

Description

A GKE version that lacks security fixes or has reached end of support can leave known vulnerabilities and operational risks. Check actual control-plane and node versions and keep them on supported versions available for the location and release channel. min_master_version is a minimum, not a permanent pin of the running version.

Potential impact

  • Known Kubernetes vulnerabilities can remain exposed for longer.
  • Unsupported versions can increase operational risk.
  • Compatibility issues between control-plane and node versions can affect operations.

Remediation

  • Check supported versions and security fixes available for the location and release channel, and plan upgrades.
  • Review automatic upgrades and maintenance schedules. Test application compatibility before upgrading, then verify the actual control-plane and node versions.

Examples

The before example’s 1.24 is historical and unsupported. Supply var.gke_version with a currently available version compatible with the location, channel, control plane and nodes. Declare this input separately; it is not an instruction to always choose the newest version.

Before

hcl
resource "google_container_cluster" "example" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  min_master_version = "1.24"
}

After

hcl
resource "google_container_cluster" "example" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  min_master_version = var.gke_version
  node_version       = var.gke_version
}

Explanation:

  • Before: An old minimum control-plane version is specified. Check the actual running version and its support status separately.
  • After: The reviewed version is used for the control-plane minimum and node version. Verify the upgrade procedure and the effective result.

References