Cluster là một quyết định vận hành
GKE managed control plane giúp giảm phần việc quản trị Kubernetes, nhưng người vận hành vẫn phải quyết định project, location, node/workload model, identity, network, upgrade và cost. Hãy vẽ boundary trước khi chọn command create.
Autopilot, Standard và failure domain
Autopilot giảm node management và tính phí theo workload model; Standard cho phép kiểm soát node pool, machine, taint/label và một số tuning nhưng tăng trách nhiệm patch/scale/capacity. Zonal và regional khác nhau ở control-plane/node distribution, quota, latency và cost.
Identity và lifecycle
Google IAM cấp quyền thao tác cluster/project; Kubernetes RBAC cấp quyền API resource; workload identity cho phép pod gọi Google APIs mà không nhét key vào image. Khi nâng cấp, cần release channel, compatibility check, maintenance window và rollback/mitigation. Cluster lab phải có TTL/owner và cleanup proof, không để node/IP/log chạy vô hạn.
Bài tập
Thiết kế cluster cho production API và lab training, chọn Autopilot/Standard + zonal/regional, ghi rationale, quota, failure mode, IAM/RBAC/workload identity, upgrade và cost. Dùng describe để tạo evidence; nếu có sandbox, tạo nhỏ và dọn sạch sau verify.