More Info:

GKE cluster should be proactively receive updates about GKE upgrades and GKE versions

Risk Level

Low

Address

Security, Reliability, Operational Excellence, Performance Efficiency

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “Upgrades and Updates Should Be Enabled” in GCP, follow the steps below:

  1. Open the GCP console and navigate to the project that has the misconfiguration.
  2. Click on the hamburger menu on the top left corner and select “Compute Engine”.
  3. Click on “VM instances” to view all the virtual machine instances in the project.
  4. For each virtual machine instance, click on the instance name to view its details.
  5. Click on the “Edit” button at the top of the page.
  6. Scroll down to the “Management” section and check the box next to “Automatic restart”.
  7. Check the box next to “Enable guest environment”.
  8. Under “OS patch management”, select “On” for “Enable OS patch management”.
  9. Click on “Save” to apply the changes.

Repeat steps 4-9 for each virtual machine instance in the project to ensure that all instances have the upgrades and updates enabled. This will ensure that the virtual machines receive the latest security updates and patches.