GKE 노드 자동 업그레이드 설정 점검

GKE 노드의 자동 업그레이드와 보안 업데이트 일정을 확인하세요.

설명

GKE 노드 자동 업그레이드를 끄면 적시에 버전을 갱신하는 운영자의 책임이 커집니다. 수동 업그레이드가 지연되면 알려진 취약점이 포함된 노드 버전이 오래 남을 수 있습니다.

잠재적 영향

패치 지연과 노드 풀 간 버전 차이로 보안 위험과 운영 부담이 커질 수 있습니다. 자동 업그레이드를 꺼도 제어 플레인 업데이트나 모든 유지보수가 중단되는 것은 아니며, 지원이 끝난 노드 버전은 서비스가 업그레이드할 수 있습니다.

해결 방법

management.auto_upgrade: yes를 설정하고 유지보수 시간과 워크로드 중단 허용 범위를 계획하세요. 수동 관리를 선택했다면 지원 기간 내 정기 업그레이드 일정과 검증 절차를 유지하세요. 자동 복구는 별도 기능입니다.

예시

노드 풀 업그레이드 설정 발췌입니다. 준비된 cluster 리소스와 프로젝트, 보호된 서비스 계정 JSON 파일 경로를 제공하세요.

변경 전

yaml
- name: create a node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

- name: create a third node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    management:
      auto_repair: yes
      auto_upgrade: no

첫 작업은 관리 설정을 생략하므로 실제 자동 업그레이드 상태를 확인해야 합니다. 두 번째는 자동 복구를 켜지만 자동 업그레이드는 끕니다.

변경 후

yaml
- name: create a node pool
  google.cloud.gcp_container_node_pool:
    name: my-pool
    initial_node_count: 4
    cluster: "{{ cluster }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present
    management:
      auto_upgrade: yes

자동 업그레이드를 활성화합니다. 적용 일정과 노드 교체 영향은 클러스터 정책 및 유지보수 설정과 함께 관리하세요.

참조