Part 3 — Operate · wrap-up
Cheat sheet & self-check
📋 Cheat sheet✅ Check yourself 15
Every command from this section on one page. Print / save as PDF
Configure gcloud container clusters update prod --region europe-west1 --logging SYSTEM,WORKLOADWhich logs GKE collects (system components and containers) gcloud container clusters update prod --region europe-west1 --monitoring SYSTEM,API_SERVER,SCHEDULER,CONTROLLER_MANAGER,POD,DEPLOYMENTSystem, control-plane and kube-state metric packages gcloud container clusters update prod --region europe-west1 --enable-managed-prometheusManaged collection for Managed Service for Prometheus
Look gcloud logging read 'resource.type="k8s_container" AND resource.labels.namespace_name="shop" AND severity>=ERROR' --limit 20Recent errors from one namespace kubectl get podmonitoring,clusterpodmonitoring -AWhat Managed Prometheus scrapes gcloud logging sinks listWhere logs are routed besides the default bucket gcloud logging buckets list --location globalLog buckets and their retention
Harden the cluster gcloud container clusters update prod --region europe-west1 --database-encryption-key projects/sec-prod/locations/europe-west1/keyRings/gke/cryptoKeys/secretsEncrypt Kubernetes Secrets with your Cloud KMS key gcloud container clusters update prod --region europe-west1 --enable-shielded-nodesShielded nodes (secure boot and integrity checks available per pool) gcloud container clusters update prod --region europe-west1 --binauthz-evaluation-mode PROJECT_SINGLETON_POLICY_ENFORCEEnforce the project's Binary Authorization policy gcloud container clusters update prod --region europe-west1 --enable-secret-managerSecret Manager add-on: mount secrets as files in Pods
Check kubectl label ns shop pod-security.kubernetes.io/enforce=restrictedEnforce the restricted Pod Security standard in a namespace kubectl get pods -A -o jsonpath='{range .items[?(@.spec.containers[*].securityContext.privileged==true)]}{.metadata.namespace}/{.metadata.name}{"\n"}{end}'List privileged Pods gcloud container clusters describe prod --region europe-west1 --format='value(databaseEncryption.state,shieldedNodes.enabled)'Is secrets encryption on? Are nodes shielded?
When gcloud container clusters update prod --region europe-west1 --maintenance-window-start 2026-01-06T02:00:00Z --maintenance-window-end 2026-01-06T06:00:00Z --maintenance-window-recurrence 'FREQ=WEEKLY;BYDAY=TU,WE,TH'Allow automatic maintenance only in this weekly window gcloud container clusters update prod --region europe-west1 --add-maintenance-exclusion-name peak --add-maintenance-exclusion-start 2026-11-20T00:00:00Z --add-maintenance-exclusion-end 2026-12-05T00:00:00Z --add-maintenance-exclusion-scope no_minor_or_node_upgradesNo minor or node upgrades during a peak period gcloud container clusters describe prod --region europe-west1 --format='yaml(maintenancePolicy,releaseChannel,currentMasterVersion,currentNodeVersion)'Window, exclusions, channel and versions
How gcloud container clusters upgrade prod --region europe-west1 --master --cluster-version 1.34Upgrade the control plane by hand (ahead of auto-upgrade) gcloud container node-pools update apps --cluster prod --region europe-west1 --max-surge-upgrade 2 --max-unavailable-upgrade 0Surge settings: 2 extra nodes, none unavailable gcloud container node-pools update apps --cluster prod --region europe-west1 --enable-blue-green-upgrade --node-pool-soak-duration 3600sBlue-green node upgrades with a one-hour soak gcloud container clusters upgrade prod --region europe-west1 --node-pool appsUpgrade a node pool to the control plane's version now
Terraform terraform init -backend-config='bucket=tf-state-platform'Initialise with remote state in a Cloud Storage bucket terraform plan -out plan.tfplan && terraform apply plan.tfplanReview, then apply exactly what was reviewed terraform import google_container_node_pool.apps projects/my-prod-project/locations/europe-west1/clusters/prod/nodePools/appsBring an existing node pool under Terraform
Fleets gcloud container fleet memberships listClusters registered to the project's fleet gcloud container clusters update prod --region europe-west1 --fleet-project platform-fleetRegister a GKE cluster to a fleet gcloud container fleet memberships get-credentials prod-onpremkubeconfig through Connect gateway (works for on-prem and attached clusters) gcloud container fleet multi-cluster-services enableMulti-cluster Services across fleet clusters
Backup for GKE gcloud beta container backup-restore backup-plans create prod-daily --project my-prod-project --location europe-west4 --cluster projects/my-prod-project/locations/europe-west1/clusters/prod --all-namespaces --include-secrets --include-volume-data --cron-schedule '0 2 * * *' --backup-retain-days 14Daily backup of all namespaces with volumes, stored in another region gcloud beta container backup-restore backups list --backup-plan prod-daily --location europe-west4Backups taken by a plan gcloud beta container backup-restore restore-plans list --location europe-west4Restore plans
Check readiness kubectl get pdb -ABudgets that keep enough replicas during disruptions kubectl get pods -A -o wide | awk '{print $8}' | sort | uniq -cHow Pods spread over nodes (map nodes to zones for zone spread)