如何在Google Cloud Composer工作节点上更新gcloud?2020年末可行方案咨询
Great question—by late 2020, GCP had rolled out several far more scalable solutions to avoid the manual headaches you dealt with back in 2018. Let’s walk through the most practical approaches:
1. Custom Image Families for Pre-Configured Nodes
Instead of modifying a one-off base image, create a custom image family that includes all your pre-updated packages and configurations. This works seamlessly with auto-scaling:
- Build your updated base image with commands like
apt-get update && apt-get upgrade -y(plus any custom tools you need), then save it as part of an image family using:gcloud compute images create my-gke-node-v2 \ --source-disk my-updated-source-disk \ --source-disk-zone us-central1-a \ --family my-custom-gke-nodes - When setting up or updating a node pool, reference the image family instead of a specific image version:
gcloud container node-pools create my-scaling-pool \ --cluster my-production-cluster \ --image-family my-custom-gke-nodes \ --image-project my-gcp-project
Any new nodes spun up via auto-scaling will automatically pull the latest image from your family, no manual intervention needed.
2. GKE Node Auto-Upgrades (Fully Managed)
By late 2020, GKE’s node auto-upgrade feature was mature enough to handle OS and Kubernetes version updates automatically, with built-in downtime protection:
- Enable auto-upgrades on an existing node pool with:
gcloud container node-pools update my-scaling-pool \ --cluster my-production-cluster \ --enable-autoupgrade - GKE will roll out updates incrementally: it cordons and drains nodes to move workloads safely, updates the node, and brings it back online. This applies to both existing nodes and any new auto-scaled nodes.
- You can also set maintenance windows to schedule updates during off-peak hours, so they don’t disrupt your services.
3. DaemonSets for Post-Provisioning Updates
If you need to run specific updates or configurations after nodes are deployed (like installing niche tools), a DaemonSet is the way to go:
- Create a DaemonSet that runs a pod on every node in the cluster, executing your required update commands. New nodes will automatically get this pod when they join.
- Example manifest snippet for an upgrade DaemonSet:
apiVersion: apps/v1 kind: DaemonSet metadata: name: node-post-updater spec: selector: matchLabels: app: node-updater template: metadata: labels: app: node-updater spec: containers: - name: updater image: debian:10 command: ["sh", "-c", "apt-get update && apt-get upgrade -y && sleep infinity"] securityContext: privileged: true volumeMounts: - name: host-filesystem mountPath: /host volumes: - name: host-filesystem hostPath: path: /
This ensures every node—including auto-scaled ones—gets the post-deployment updates without you having to SSH into each one.
Why These Beat 2018’s Methods
- No manual SSH: All solutions work automatically for new nodes from auto-scaling
- Scalable: Image families and DaemonSets grow with your cluster
- Managed options: Node auto-upgrades offload the work entirely to GCP
内容的提问来源于stack exchange,提问作者rodrigo-silveira

