Review GKE Cloud Monitoring integration

Collect required cluster and workload metrics and verify their receipt.

Description

When GKE Cloud Monitoring integration is disabled, required cluster-health and resource-usage metrics may be unavailable. Components and metrics are selected separately; enabling integration does not automatically configure every application metric or alarm.

Potential impact

  • Resource shortages or performance degradation may be noticed late.
  • Troubleshooting and capacity planning may lack necessary evidence.

Remediation

  • Enable required metrics with the supported monitoring_service = "monitoring.googleapis.com/kubernetes" setting or current monitoring configuration. Use supported settings instead of the retired legacy integration.
  • Verify actual metric receipt and collection permissions, and configure required alarms. Review collection scope and cost.

Examples

These excerpts show part of a Standard cluster configuration. Supply the omitted network and node settings for your environment.

Before

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  monitoring_service = "none"
}

After

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  monitoring_service = "monitoring.googleapis.com/kubernetes"
}

Explanation:

  • Before: Monitoring integration is disabled. Check whether another monitoring system meets requirements.
  • After: The current GKE Monitoring integration is selected. Verify required metrics and alarms separately.

References