Cheat Sheets / Cloud — OpenStack, AWS, EKS & GKE

Production GKE Platform cheat sheet

107 commands from every lesson of Production GKE Platform — From Zero to Production, on one page.

01 · Google Cloud & GKE services and terms

Find your way around

gcloud config listActive account, project and default region/zone
gcloud config set project my-prod-projectSwitch the project every later command uses
gcloud projects listProjects you can see
gcloud services list --enabledAPIs enabled in the project (container.googleapis.com for GKE)
gcloud services enable container.googleapis.com artifactregistry.googleapis.comEnable the GKE and Artifact Registry APIs

GKE at a glance

gcloud container clusters listClusters in the project, with location, version and status
gcloud container get-server-config --region europe-west1Versions available per release channel in a region
gcloud container clusters get-credentials prod --region europe-west1Write a kubeconfig entry (uses gke-gcloud-auth-plugin)
gcloud container node-pools list --cluster prod --region europe-west1Node pools of a Standard cluster

02 · GKE architecture: Autopilot, Standard, regional and release channels

Create (lab)

gcloud container clusters create-auto lab --region europe-west1An Autopilot cluster: regional, release channel Regular by default
gcloud container clusters create lab --region europe-west1 --release-channel regular --num-nodes 1A Standard regional cluster: 1 node per zone (3 in total)
gcloud container clusters create lab-z --zone europe-west1-b --num-nodes 2A zonal Standard cluster (cheaper, no control-plane redundancy)

Inspect

gcloud container clusters describe lab --region europe-west1 --format='value(autopilot.enabled,releaseChannel.channel,currentMasterVersion)'Mode, channel and control-plane version
gcloud container get-server-config --region europe-west1 --flatten=channels --format='table(channels.channel,channels.defaultVersion)'Default version per release channel
kubectl get nodes -L topology.kubernetes.io/zoneNodes and the zones they run in

03 · Organisation, projects & Shared VPC

Shared VPC

gcloud compute shared-vpc enable net-host-prodMake a project a Shared VPC host
gcloud compute shared-vpc associated-projects add gke-prod --host-project net-host-prodAttach a service project to the host
gcloud compute networks create prod-vpc --subnet-mode custom --project net-host-prodA custom-mode VPC (no automatic subnets)
gcloud compute networks subnets create gke-prod-ew1 --network prod-vpc --region europe-west1 --range 10.10.0.0/22 --secondary-range pods=10.20.0.0/16,services=10.30.0.0/20 --enable-private-ip-google-accessSubnet with Pod and Service secondary ranges, Private Google Access on

Egress

gcloud compute routers create nat-router --network prod-vpc --region europe-west1Cloud Router for Cloud NAT
gcloud compute routers nats create nat-ew1 --router nat-router --region europe-west1 --auto-allocate-nat-external-ips --nat-all-subnet-ip-rangesCloud NAT for every range in the region (nodes and Pods)
gcloud compute firewall-rules list --filter='network:prod-vpc'Firewall rules on the VPC, including the ones GKE created

04 · VPC-native networking & IP planning

Plan and check

gcloud container clusters describe prod --region europe-west1 --format='value(ipAllocationPolicy.clusterIpv4CidrBlock,ipAllocationPolicy.servicesIpv4CidrBlock)'The cluster's Pod and Service ranges
kubectl get nodes -o custom-columns=NODE:.metadata.name,PODCIDR:.spec.podCIDRThe Pod block each node received
gcloud compute networks subnets describe gke-prod-ew1 --region europe-west1 --format='yaml(secondaryIpRanges)'Secondary ranges on the subnet

Grow

gcloud compute networks subnets update gke-prod-ew1 --region europe-west1 --add-secondary-ranges pods-2=10.21.0.0/16Add another secondary range to the subnet
gcloud container node-pools create pool-2 --cluster prod --region europe-west1 --pod-ipv4-range pods-2 --max-pods-per-node 64A node pool that takes Pod IPs from the new range
gcloud container clusters update prod --region europe-west1 --additional-pod-ipv4-ranges pods-2Make an extra Pod range available cluster-wide (newer versions)

05 · The cluster: control plane access, node pools & compute

Cluster

gcloud container clusters create prod --region europe-west1 --release-channel regular --network projects/net-host-prod/global/networks/prod-vpc --subnetwork projects/net-host-prod/regions/europe-west1/subnetworks/gke-prod-ew1 --cluster-secondary-range-name pods --services-secondary-range-name services --enable-private-nodes --enable-dns-access --workload-pool my-prod-project.svc.id.goog --enable-dataplane-v2 --service-account gke-nodes@my-prod-project.iam.gserviceaccount.com --num-nodes 1A private, VPC-native, Workload-Identity-enabled Standard cluster on a Shared VPC
gcloud container clusters get-credentials prod --region europe-west1 --dns-endpointkubeconfig that uses the DNS-based control-plane endpoint
gcloud container clusters update prod --region europe-west1 --enable-master-authorized-networks --master-authorized-networks 10.0.0.0/8Restrict the IP-based endpoint to listed ranges

Node pools

gcloud container node-pools create apps --cluster prod --region europe-west1 --machine-type n2-standard-8 --num-nodes 1 --enable-autoscaling --min-nodes 1 --max-nodes 10 --node-labels pool=appsAn autoscaled application pool (counts are per zone)
gcloud container node-pools create spot --cluster prod --region europe-west1 --spot --machine-type e2-standard-4 --node-taints cloud.google.com/gke-spot=true:NoScheduleA Spot pool, tainted so only tolerant workloads land there
gcloud container node-pools delete default-pool --cluster prod --region europe-west1Remove the default pool once your own pools exist

06 · Identity & access: IAM, RBAC and Workload Identity Federation

People and CI

gcloud projects add-iam-policy-binding my-prod-project --member group:sre@example.com --role roles/container.adminFull GKE admin for the SRE group on the project
gcloud projects add-iam-policy-binding my-prod-project --member group:shop-devs@example.com --role roles/container.clusterViewerLets the group get credentials; RBAC then decides what they may do
kubectl auth can-i --list --as alice@example.com -n shopWhat a user may do in a namespace (RBAC view)

Workload Identity

gcloud projects add-iam-policy-binding my-prod-project --member principal://iam.googleapis.com/projects/123456789/locations/global/workloadIdentityPools/my-prod-project.svc.id.goog/subject/ns/shop/sa/orders --role roles/pubsub.publisherGrant an IAM role directly to Kubernetes ServiceAccount shop/orders
kubectl -n shop run wi-test --rm -it --image google/cloud-sdk:slim --overrides='{"spec":{"serviceAccountName":"orders"}}' -- gcloud auth listCheck which identity a pod gets
gcloud container node-pools update apps --cluster prod --region europe-west1 --workload-metadata GKE_METADATAMake a pool use the GKE metadata server (hides node credentials)

07 · Load balancing: Services, Ingress & Gateway API

See what was created

kubectl get svc,ingress,gateway,httproute -AEvery exposed object and its address
kubectl get gatewayclassGatewayClasses the GKE Gateway controller offers
kubectl describe gateway web -n infraGateway status, addresses and events (errors from the controller show here)
gcloud compute forwarding-rules listLoad balancer front ends in the project
gcloud compute backend-services get-health <backend> --globalHealth of a load balancer's backends (Pods behind NEGs)

Enable

gcloud container clusters update prod --region europe-west1 --gateway-api standardTurn on the Gateway API CRDs and controller
gcloud compute ssl-policies create modern-tls --profile MODERN --min-tls-version 1.2A TLS policy for external load balancers

08 · Artifact Registry & application delivery

Artifact Registry

gcloud artifacts repositories create apps --repository-format docker --location europe-west1 --description 'App images'A Docker repository in a region
gcloud auth configure-docker europe-west1-docker.pkg.devLet local Docker push and pull with your gcloud credentials
docker push europe-west1-docker.pkg.dev/platform-shared/apps/shop:1.4.2Push an image
gcloud artifacts docker images list europe-west1-docker.pkg.dev/platform-shared/apps --include-tagsImages and tags in a repository
gcloud artifacts repositories add-iam-policy-binding apps --location europe-west1 --member serviceAccount:gke-nodes@my-prod-project.iam.gserviceaccount.com --role roles/artifactregistry.readerLet a cluster's nodes pull from the repository

Deploy and roll out

kubectl set image deploy/shop shop=europe-west1-docker.pkg.dev/platform-shared/apps/shop:1.4.3 -n shopChange the image (better: change it in Git)
kubectl rollout status deploy/shop -n shopWait for the rollout
kubectl rollout undo deploy/shop -n shopRoll back to the previous ReplicaSet

09 · Storage: Persistent Disk, Hyperdisk, Filestore & Cloud Storage

Inspect

kubectl get storageclassStorageClasses GKE provides (standard-rwo, premium-rwo…) and your own
kubectl get pvc,pv -AClaims and the volumes bound to them
kubectl get volumesnapshotclass,volumesnapshot -ASnapshot classes and snapshots
gcloud compute disks list --filter='name~pvc-'Disks created for PersistentVolumes

Enable and back up

gcloud container clusters update prod --region europe-west1 --update-addons GcpFilestoreCsiDriver=ENABLEDTurn on the Filestore CSI driver
gcloud container clusters update prod --region europe-west1 --update-addons GcsFuseCsiDriver=ENABLEDTurn on the Cloud Storage FUSE CSI driver
gcloud container clusters update prod --region europe-west1 --update-addons BackupRestore=ENABLEDTurn on the Backup for GKE agent
gcloud beta container backup-restore backup-plans list --location europe-west1Backup plans in a region

10 · Autoscaling: Pods, nodes and compute classes

Pods

kubectl autoscale deploy shop -n shop --cpu-percent 70 --min 3 --max 30A CPU-based HPA
kubectl get hpa -ACurrent versus target metrics and replica counts
gcloud container clusters update prod --region europe-west1 --enable-vertical-pod-autoscalingEnable the VPA on a Standard cluster

Nodes

gcloud container node-pools update apps --cluster prod --region europe-west1 --enable-autoscaling --min-nodes 1 --max-nodes 20 --location-policy BALANCEDAutoscale a pool (per zone), spreading across zones
gcloud container clusters update prod --region europe-west1 --autoscaling-profile optimize-utilizationScale down more aggressively to save cost
gcloud container clusters update prod --region europe-west1 --enable-autoprovisioning --max-cpu 400 --max-memory 1600Node auto-provisioning with cluster-wide limits
kubectl get events -A --field-selector reason=TriggeredScaleUpWhy and when the autoscaler added nodes

11 · Observability: Cloud Logging, Cloud Monitoring & Managed Prometheus

Configure

gcloud container clusters update prod --region europe-west1 --logging SYSTEM,WORKLOADWhich logs GKE collects (system components and containers)
gcloud container clusters update prod --region europe-west1 --monitoring SYSTEM,API_SERVER,SCHEDULER,CONTROLLER_MANAGER,POD,DEPLOYMENTSystem, control-plane and kube-state metric packages
gcloud container clusters update prod --region europe-west1 --enable-managed-prometheusManaged collection for Managed Service for Prometheus

Look

gcloud logging read 'resource.type="k8s_container" AND resource.labels.namespace_name="shop" AND severity>=ERROR' --limit 20Recent errors from one namespace
kubectl get podmonitoring,clusterpodmonitoring -AWhat Managed Prometheus scrapes
gcloud logging sinks listWhere logs are routed besides the default bucket
gcloud logging buckets list --location globalLog buckets and their retention

12 · Security: nodes, secrets, policy and supply chain

Harden the cluster

gcloud container clusters update prod --region europe-west1 --database-encryption-key projects/sec-prod/locations/europe-west1/keyRings/gke/cryptoKeys/secretsEncrypt Kubernetes Secrets with your Cloud KMS key
gcloud container clusters update prod --region europe-west1 --enable-shielded-nodesShielded nodes (secure boot and integrity checks available per pool)
gcloud container clusters update prod --region europe-west1 --binauthz-evaluation-mode PROJECT_SINGLETON_POLICY_ENFORCEEnforce the project's Binary Authorization policy
gcloud container clusters update prod --region europe-west1 --enable-secret-managerSecret Manager add-on: mount secrets as files in Pods

Check

kubectl label ns shop pod-security.kubernetes.io/enforce=restrictedEnforce the restricted Pod Security standard in a namespace
kubectl get pods -A -o jsonpath='{range .items[?(@.spec.containers[*].securityContext.privileged==true)]}{.metadata.namespace}/{.metadata.name}{"\n"}{end}'List privileged Pods
gcloud container clusters describe prod --region europe-west1 --format='value(databaseEncryption.state,shieldedNodes.enabled)'Is secrets encryption on? Are nodes shielded?

13 · Upgrades: release channels, maintenance windows & node upgrade strategies

When

gcloud container clusters update prod --region europe-west1 --maintenance-window-start 2026-01-06T02:00:00Z --maintenance-window-end 2026-01-06T06:00:00Z --maintenance-window-recurrence 'FREQ=WEEKLY;BYDAY=TU,WE,TH'Allow automatic maintenance only in this weekly window
gcloud container clusters update prod --region europe-west1 --add-maintenance-exclusion-name peak --add-maintenance-exclusion-start 2026-11-20T00:00:00Z --add-maintenance-exclusion-end 2026-12-05T00:00:00Z --add-maintenance-exclusion-scope no_minor_or_node_upgradesNo minor or node upgrades during a peak period
gcloud container clusters describe prod --region europe-west1 --format='yaml(maintenancePolicy,releaseChannel,currentMasterVersion,currentNodeVersion)'Window, exclusions, channel and versions

How

gcloud container clusters upgrade prod --region europe-west1 --master --cluster-version 1.34Upgrade the control plane by hand (ahead of auto-upgrade)
gcloud container node-pools update apps --cluster prod --region europe-west1 --max-surge-upgrade 2 --max-unavailable-upgrade 0Surge settings: 2 extra nodes, none unavailable
gcloud container node-pools update apps --cluster prod --region europe-west1 --enable-blue-green-upgrade --node-pool-soak-duration 3600sBlue-green node upgrades with a one-hour soak
gcloud container clusters upgrade prod --region europe-west1 --node-pool appsUpgrade a node pool to the control plane's version now

14 · Terraform, GitOps & fleets across cloud and on-prem

Terraform

terraform init -backend-config='bucket=tf-state-platform'Initialise with remote state in a Cloud Storage bucket
terraform plan -out plan.tfplan && terraform apply plan.tfplanReview, then apply exactly what was reviewed
terraform import google_container_node_pool.apps projects/my-prod-project/locations/europe-west1/clusters/prod/nodePools/appsBring an existing node pool under Terraform

Fleets

gcloud container fleet memberships listClusters registered to the project's fleet
gcloud container clusters update prod --region europe-west1 --fleet-project platform-fleetRegister a GKE cluster to a fleet
gcloud container fleet memberships get-credentials prod-onpremkubeconfig through Connect gateway (works for on-prem and attached clusters)
gcloud container fleet multi-cluster-services enableMulti-cluster Services across fleet clusters

15 · Disaster recovery & reliability

Backup for GKE

gcloud beta container backup-restore backup-plans create prod-daily --project my-prod-project --location europe-west4 --cluster projects/my-prod-project/locations/europe-west1/clusters/prod --all-namespaces --include-secrets --include-volume-data --cron-schedule '0 2 * * *' --backup-retain-days 14Daily backup of all namespaces with volumes, stored in another region
gcloud beta container backup-restore backups list --backup-plan prod-daily --location europe-west4Backups taken by a plan
gcloud beta container backup-restore restore-plans list --location europe-west4Restore plans

Check readiness

kubectl get pdb -ABudgets that keep enough replicas during disruptions
kubectl get pods -A -o wide | awk '{print $8}' | sort | uniq -cHow Pods spread over nodes (map nodes to zones for zone spread)

16 · Architecture & design review

Quick checks before go-live

gcloud container clusters describe prod --region europe-west1 --format='yaml(releaseChannel,maintenancePolicy,privateClusterConfig,workloadIdentityConfig,databaseEncryption,networkConfig.datapathProvider)'Channel, windows, privacy, Workload Identity, secrets encryption, data plane
kubectl get ns -L pod-security.kubernetes.io/enforcePod Security level of every namespace
kubectl get resourcequota,limitrange -AQuotas and default limits per namespace
kubectl get networkpolicy -ANamespaces with (and without) network policies