Review GKE Cloud Logging integration

Collect required system and workload logs and verify delivery.

Description

Disabling GKE Cloud Logging integration can leave gaps in the system and workload logs collected through that path. Automatically recorded Admin Activity audit logs are separate, and enabling integration does not automatically select every control-plane and application log.

Potential impact

  • Evidence needed to investigate container failures or unusual activity may be missing.
  • Finding the cause of an outage and restoring service can take longer.

Remediation

  • Enable logging for required components with the supported logging_service = "logging.googleapis.com/kubernetes" setting or current logging configuration.
  • Check collection permissions, exclusion filters and actual receipt. Select required control-plane logs and application output, and manage retention and access permissions.

Examples

These excerpts show part of a Standard cluster configuration. Supply the omitted network and node settings for your environment.

Before

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  logging_service    = "none"
}

After

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  logging_service    = "logging.googleapis.com/kubernetes"
}

Explanation:

  • Before: Cluster Logging integration is disabled. This does not disable every kind of Google Cloud audit log.
  • After: GKE Logging integration is selected. Verify required log scope and actual delivery separately.

References