Description
Disabling GKE Cloud Logging integration can leave gaps in the system and workload logs collected through that path. Automatically recorded Admin Activity audit logs are separate, and enabling integration does not automatically select every control-plane and application log.
Potential impact
- Evidence needed to investigate container failures or unusual activity may be missing.
- Finding the cause of an outage and restoring service can take longer.
Remediation
- Enable logging for required components with the supported
logging_service = "logging.googleapis.com/kubernetes"setting or current logging configuration. - Check collection permissions, exclusion filters and actual receipt. Select required control-plane logs and application output, and manage retention and access permissions.
Examples
These excerpts show part of a Standard cluster configuration. Supply the omitted network and node settings for your environment.
Before
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
logging_service = "none"
}
After
hcl
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
logging_service = "logging.googleapis.com/kubernetes"
}
Explanation:
- Before: Cluster Logging integration is disabled. This does not disable every kind of Google Cloud audit log.
- After: GKE Logging integration is selected. Verify required log scope and actual delivery separately.