๐ก๏ธ Google GKE Cluster Monitoring is not enabled๐ข
- Contextual name: ๐ก๏ธ Cluster Monitoring is not enabled๐ข
- ID:
/ce/ca/google/gke/cluster-monitoring - Tags:
- ๐ข Policy with categories
- ๐ข Policy with type
- ๐ข Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY,RELIABILITY
Logicโ
- ๐ง prod.logic.yaml๐ข
Descriptionโ
Descriptionโ
This policy ensures that Cloud Monitoring is enabled for all Google Kubernetes Engine (GKE) clusters. Cloud Monitoring collects metrics, events, and metadata from your clusters, providing visibility into cluster performance, uptime, and overall health.
Rationaleโ
Enabling Cloud Monitoring allows you to track resource utilization, troubleshoot issues, and set up alerts for abnormal behavior. Without monitoring, you lack the necessary visibility to diagnose problems, optimize performance, or respond effectively to security incidents.
Auditโ
This policy marks a Google GKE Cluster as
INCOMPLIANTifMonitoring Serviceis not set to monitoring.googleapis.com/kubernetes.Default Valueโ
Cloud Monitoring is enabled by default starting in GKE version 1.14; Legacy Logging and Monitoring support is enabled by default for earlier versions.
Referencesโ
- https://cloud.google.com/stackdriver/docs/solutions/gke/observing
- https://cloud.google.com/stackdriver/docs/solutions/gke/managing-logs
- https://cloud.google.com/stackdriver/docs/solutions/gke/installing
... see more
Remediationโ
Remediationโ
To ensure visibility into cluster performance, uptime, and overall health, Cloud Monitoring should be enabled for GKE clusters.
Enable Cloud Monitoring on an Existing Clusterโ
From gcloud CLIโ
```sh
gcloud container clusters update {{cluster-name}} \
--location {{location}} \
--monitoring=SYSTEM,API_SERVER,POD
```
policy.yamlโ
Linked Framework Sectionsโ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| ๐ผ CIS GKE v1.8.0 โ ๐ผ 5.7.1 Ensure Logging and Cloud Monitoring is Enabled (Automated) | 2 | no data | |||
| ๐ผ Cloudaware Framework โ ๐ผ Logging and Monitoring Configuration | 65 | no data | |||
| ๐ผ PCI DSS v3.2.1 โ ๐ผ 10.1 Implement audit trails to link all access to system components to each individual user. | 4 | 7 | no data | ||
| ๐ผ PCI DSS v3.2.1 โ ๐ผ 10.2 Implement automated audit trails for all system components. | 7 | 6 | 28 | no data | |
| ๐ผ PCI DSS v4.0.1 โ ๐ผ 10.2.1 Audit logs are enabled and active for all system components and cardholder data. | 7 | 27 | no data | ||
| ๐ผ PCI DSS v4.0 โ ๐ผ 10.2.1 Audit logs are enabled and active for all system components and cardholder data. | 7 | 1 | 27 | no data |