설명
GKE 노드 자동 업그레이드를 끄면 적시에 버전을 갱신하는 운영자의 책임이 커집니다. 수동 업그레이드가 지연되면 알려진 취약점이 포함된 노드 버전이 오래 남을 수 있습니다.
잠재적 영향
패치 지연과 노드 풀 간 버전 차이로 보안 위험과 운영 부담이 커질 수 있습니다. 자동 업그레이드를 꺼도 제어 플레인 업데이트나 모든 유지보수가 중단되는 것은 아니며, 지원이 끝난 노드 버전은 서비스가 업그레이드할 수 있습니다.
해결 방법
management.auto_upgrade: yes를 설정하고 유지보수 시간과 워크로드 중단 허용 범위를 계획하세요. 수동 관리를 선택했다면 지원 기간 내 정기 업그레이드 일정과 검증 절차를 유지하세요. 자동 복구는 별도 기능입니다.
예시
노드 풀 업그레이드 설정 발췌입니다. 준비된 cluster 리소스와 프로젝트, 보호된 서비스 계정 JSON 파일 경로를 제공하세요.
변경 전
yaml
- name: create a node pool
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
- name: create a third node pool
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
management:
auto_repair: yes
auto_upgrade: no
첫 작업은 관리 설정을 생략하므로 실제 자동 업그레이드 상태를 확인해야 합니다. 두 번째는 자동 복구를 켜지만 자동 업그레이드는 끕니다.
변경 후
yaml
- name: create a node pool
google.cloud.gcp_container_node_pool:
name: my-pool
initial_node_count: 4
cluster: "{{ cluster }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
management:
auto_upgrade: yes
자동 업그레이드를 활성화합니다. 적용 일정과 노드 교체 영향은 클러스터 정책 및 유지보수 설정과 함께 관리하세요.