Description
A GKE version that lacks security fixes or has reached end of support can leave known vulnerabilities and operational risks. Check actual control-plane and node versions and keep them on supported versions available for the location and release channel. min_master_version is a minimum, not a permanent pin of the running version.
Potential impact
- Known Kubernetes vulnerabilities can remain exposed for longer.
- Unsupported versions can increase operational risk.
- Compatibility issues between control-plane and node versions can affect operations.
Remediation
- Check supported versions and security fixes available for the location and release channel, and plan upgrades.
- Review automatic upgrades and maintenance schedules. Test application compatibility before upgrading, then verify the actual control-plane and node versions.
Examples
The before example’s 1.24 is historical and unsupported. Supply var.gke_version with a currently available version compatible with the location, channel, control plane and nodes. Declare this input separately; it is not an instruction to always choose the newest version.
Before
hcl
resource "google_container_cluster" "example" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
min_master_version = "1.24"
}
After
hcl
resource "google_container_cluster" "example" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
min_master_version = var.gke_version
node_version = var.gke_version
}
Explanation:
- Before: An old minimum control-plane version is specified. Check the actual running version and its support status separately.
- After: The reviewed version is used for the control-plane minimum and node version. Verify the upgrade procedure and the effective result.