Aqua CSPM

Automatic Node Upgrades Enabled

Quick Info

Plugin TitleAutomatic Node Upgrades Enabled
CloudGOOGLE
CategoryKubernetes
DescriptionEnsures all Kubernetes cluster nodes have automatic upgrades enabled
More InfoEnabling automatic upgrades on nodes ensures that each node stays current with the latest version of the master branch, also ensuring that the latest security patches are installed to provide the most secure environment.
GOOGLE Linkhttps://cloud.google.com/kubernetes-engine/docs/how-to/node-auto-upgrades
Recommended ActionEnsure that automatic node upgrades are enabled on all node pools in Kubernetes clusters

Detailed Remediation Steps

  1. Log into the Google Cloud Platform Console.
  2. Scroll down the left navigation panel and choose the “Kubernetes Engine” option under the “Compute” and select the “Clusters.”
  3. On the “Kubernetes clusters” page , click on the “Name” as a link option to select the cluster.
  4. On the selected “Clusters” page, scroll down and select the “Node pools” by clicking on the “Name” as a link.
  5. On the “Node pool details” page, scroll down the page, check “Auto-upgrade” option under the “Management” and if it’s showing “Disabled” then it doesn’t ensures that each node stays current with the latest version of the master branch.
  6. Repeat steps number 2 - 5 to verify other clusters in the account.
  7. Navigate to the “Kubernetes Engine” option under the “Compute”, choose the “Clusters” and select the “Node pools” option.
  8. On the “Node pool details” page, click on the “Edit” button at the top.
  9. On the “Edit node pool” page, scroll down and click on the checkbox next to the “Enable auto-upgrade” under the “Management."
  10. Click on the “Save” button to make the changes.
  11. Repeat steps number 7 - 10 to ensure automatic node upgrades are enabled on all node pools in Kubernetes clusters.