如何检查Kubernetes集群(含GKE集群)中Server-Side Apply是否已启用?
Great question! Let's walk through how to check if Server-Side Apply (SSA) is enabled, starting with general Kubernetes clusters and then covering GKE specifically.
There are two reliable ways to verify SSA's status—one checks the API server configuration, the other tests the functionality directly:
1. Inspect the API Server's Feature Gates
Server-Side Apply became generally available (GA) in Kubernetes 1.19, so it's enabled by default in all clusters running that version or newer. For older clusters (1.16–1.18, where it was beta), it might be disabled via feature gates.
To check the API server's feature gate settings:
- Run this command to get the kube-apiserver pod configurations:
kubectl get pods -n kube-system -l component=kube-apiserver -o yaml - Look for the
commandsection in the output. If you see--feature-gates=ServerSideApply=false, SSA is disabled. If the feature gate isn't listed at all (or showsServerSideApply=true), it's enabled.
2. Test Server-Side Apply Directly
The most definitive way is to run a server-side apply operation (with a dry run to avoid changing resources):
- Create a simple test manifest (e.g.,
test-ssa.yaml) with a basic resource like a ConfigMap:apiVersion: v1 kind: ConfigMap metadata: name: test-ssa-config data: key: value - Run the dry-run server-side apply:
kubectl apply --server-side --dry-run=client -f test-ssa.yaml- If the command succeeds (outputs something like
configmap/test-ssa-config serverside-applied (dry run)), SSA is enabled. - If you get an error like
server-side apply is disabled, then it's turned off.
- If the command succeeds (outputs something like
GKE follows Kubernetes' GA timeline for SSA: it's enabled by default on all clusters running Kubernetes 1.19 or later. For older GKE versions (1.16–1.18), you might need to confirm, but here's how to check:
1. Verify Cluster Version
First, check your GKE cluster's version with:
gcloud container clusters describe CLUSTER_NAME --zone ZONE | grep -E "currentMasterVersion|currentNodeVersion"
If the version is 1.19.x or higher, SSA is almost certainly enabled (GKE doesn't disable GA features by default).
2. Test the Functionality
Just like with general clusters, run a dry-run server-side apply to confirm:
kubectl apply --server-side --dry-run=client -f test-ssa.yaml
If it runs without errors, SSA is active. Since GKE manages the API server, you won't need to inspect feature gates directly (Google controls those for managed clusters).
One quick note: Even if SSA is enabled, resources will only show managedFields in their metadata if they've been modified using server-side apply. That field isn't a reliable indicator of whether SSA is enabled overall—testing the apply command is better.
内容的提问来源于stack exchange,提问作者David Wesby

