Production GKE Platform — From Zero to Production›Part 3 · Cheat sheet & self-check

Part 3 — Operate · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

11 · Observability: Cloud Logging, Cloud Monitoring & Managed Prometheus

Configure

gcloud container clusters update prod --region europe-west1 --logging SYSTEM,WORKLOADWhich logs GKE collects (system components and containers)
gcloud container clusters update prod --region europe-west1 --monitoring SYSTEM,API_SERVER,SCHEDULER,CONTROLLER_MANAGER,POD,DEPLOYMENTSystem, control-plane and kube-state metric packages
gcloud container clusters update prod --region europe-west1 --enable-managed-prometheusManaged collection for Managed Service for Prometheus

Look

gcloud logging read 'resource.type="k8s_container" AND resource.labels.namespace_name="shop" AND severity>=ERROR' --limit 20Recent errors from one namespace
kubectl get podmonitoring,clusterpodmonitoring -AWhat Managed Prometheus scrapes
gcloud logging sinks listWhere logs are routed besides the default bucket
gcloud logging buckets list --location globalLog buckets and their retention

12 · Security: nodes, secrets, policy and supply chain

Harden the cluster

gcloud container clusters update prod --region europe-west1 --database-encryption-key projects/sec-prod/locations/europe-west1/keyRings/gke/cryptoKeys/secretsEncrypt Kubernetes Secrets with your Cloud KMS key
gcloud container clusters update prod --region europe-west1 --enable-shielded-nodesShielded nodes (secure boot and integrity checks available per pool)
gcloud container clusters update prod --region europe-west1 --binauthz-evaluation-mode PROJECT_SINGLETON_POLICY_ENFORCEEnforce the project's Binary Authorization policy
gcloud container clusters update prod --region europe-west1 --enable-secret-managerSecret Manager add-on: mount secrets as files in Pods

Check

kubectl label ns shop pod-security.kubernetes.io/enforce=restrictedEnforce the restricted Pod Security standard in a namespace
kubectl get pods -A -o jsonpath='{range .items[?(@.spec.containers[*].securityContext.privileged==true)]}{.metadata.namespace}/{.metadata.name}{"\n"}{end}'List privileged Pods
gcloud container clusters describe prod --region europe-west1 --format='value(databaseEncryption.state,shieldedNodes.enabled)'Is secrets encryption on? Are nodes shielded?

13 · Upgrades: release channels, maintenance windows & node upgrade strategies

When

gcloud container clusters update prod --region europe-west1 --maintenance-window-start 2026-01-06T02:00:00Z --maintenance-window-end 2026-01-06T06:00:00Z --maintenance-window-recurrence 'FREQ=WEEKLY;BYDAY=TU,WE,TH'Allow automatic maintenance only in this weekly window
gcloud container clusters update prod --region europe-west1 --add-maintenance-exclusion-name peak --add-maintenance-exclusion-start 2026-11-20T00:00:00Z --add-maintenance-exclusion-end 2026-12-05T00:00:00Z --add-maintenance-exclusion-scope no_minor_or_node_upgradesNo minor or node upgrades during a peak period
gcloud container clusters describe prod --region europe-west1 --format='yaml(maintenancePolicy,releaseChannel,currentMasterVersion,currentNodeVersion)'Window, exclusions, channel and versions

How

gcloud container clusters upgrade prod --region europe-west1 --master --cluster-version 1.34Upgrade the control plane by hand (ahead of auto-upgrade)
gcloud container node-pools update apps --cluster prod --region europe-west1 --max-surge-upgrade 2 --max-unavailable-upgrade 0Surge settings: 2 extra nodes, none unavailable
gcloud container node-pools update apps --cluster prod --region europe-west1 --enable-blue-green-upgrade --node-pool-soak-duration 3600sBlue-green node upgrades with a one-hour soak
gcloud container clusters upgrade prod --region europe-west1 --node-pool appsUpgrade a node pool to the control plane's version now

14 · Terraform, GitOps & fleets across cloud and on-prem

Terraform

terraform init -backend-config='bucket=tf-state-platform'Initialise with remote state in a Cloud Storage bucket
terraform plan -out plan.tfplan && terraform apply plan.tfplanReview, then apply exactly what was reviewed
terraform import google_container_node_pool.apps projects/my-prod-project/locations/europe-west1/clusters/prod/nodePools/appsBring an existing node pool under Terraform

Fleets

gcloud container fleet memberships listClusters registered to the project's fleet
gcloud container clusters update prod --region europe-west1 --fleet-project platform-fleetRegister a GKE cluster to a fleet
gcloud container fleet memberships get-credentials prod-onpremkubeconfig through Connect gateway (works for on-prem and attached clusters)
gcloud container fleet multi-cluster-services enableMulti-cluster Services across fleet clusters

15 · Disaster recovery & reliability

Backup for GKE

gcloud beta container backup-restore backup-plans create prod-daily --project my-prod-project --location europe-west4 --cluster projects/my-prod-project/locations/europe-west1/clusters/prod --all-namespaces --include-secrets --include-volume-data --cron-schedule '0 2 * * *' --backup-retain-days 14Daily backup of all namespaces with volumes, stored in another region
gcloud beta container backup-restore backups list --backup-plan prod-daily --location europe-west4Backups taken by a plan
gcloud beta container backup-restore restore-plans list --location europe-west4Restore plans

Check readiness

kubectl get pdb -ABudgets that keep enough replicas during disruptions
kubectl get pods -A -o wide | awk '{print $8}' | sort | uniq -cHow Pods spread over nodes (map nodes to zones for zone spread)