GKE clusters with Cloud Logging switched off for system and workload logs
What does ZopNight detect here?
GKE clusters are flagged at high severity when ZopNight records cluster logging as disabled, for example after `gcloud container clusters update --logging=NONE`. Without Cloud Logging, container logs disappear when their Pod is removed and cluster events after one hour, so a crash from last night is no longer there to debug.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1221 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | cluster logging recorded as disabled |
| Source | ZopNight |
| Permissions used | container.clusters.list · container.clusters.get |
Where it applies
Where GKE logs go when Cloud Logging is off
GKE keeps logs on the node only briefly. Google’s GKE logging overview states that container logs are removed when their Pod is removed, when the node disk runs out of space or when newer logs replace them, that system logs are periodically cleared, and that cluster events are removed after one hour. Cloud Logging is the persistent copy.
By default a new cluster runs a managed per-node logging agent that ships container stdout and stderr, kubelet and container runtime logs, and system component logs. Turning it off removes all of that. GKE audit logs are the exception: Google states they cannot be disabled.
Checking which log components a cluster sends
gcloud container clusters describe CLUSTER_NAME --location=LOCATION \ --format="value(loggingConfig.componentConfig.enableComponents)"SYSTEM_COMPONENTS and WORKLOADS in the output mean system and application logs are flowing.
An empty result means nothing is collected.
The value ZopNight acts on
ZopNight records a logging status for every GKE cluster it inventories. The rule fires only when that status is explicitly disabled, and the severity is high because the loss is invisible until the day you need the logs.
When no finding appears
Clusters with no recorded logging status are not flagged, so a partial scan never produces a finding. The rule is a yes or no on cluster logging; it does not grade which components are sent or how long logs are retained. The companion check for metrics is GKE Cluster Monitoring Disabled.
Log volume is the real cost question
There is no saving for turning logging back on; it adds cost. Cloud Logging charges $0.50 per GiB ingested after the first 50 GiB per project per month, per Google Cloud Observability pricing. If cost was the reason logging was disabled, exclusion filters are the better lever than switching it off.
Turning cluster logging back on
- Enable system and workload logs:
gcloud container clusters update CLUSTER_NAME --location=LOCATION --logging=SYSTEM,WORKLOAD. - Add
API_SERVERto the list if you need control plane logs for investigations. - Confirm entries arrive in Logs Explorer for the cluster.
- Add exclusion filters for noisy namespaces rather than dropping whole components.