# GKE Deployments on Google Cloud | ZopNight

> Every check ZopNight runs on your GKE Deployments on Google Cloud: 17 in total, across orphaned resources, reliability, rightsizing and security.

Source: https://zop.dev/zopnight/rules/gcp/gke-deployment

---

_Google Cloud · 17 checks_

## GKE Deployments on Google Cloud, checked for you.

ZopNight runs 17 checks on your GKE Deployments in Google Cloud, covering reliability, security, rightsizing and orphaned resources. 1 of them it can fix after a guided review. Workloads are scheduled by namespace.

- 17 — checks
- 4 — categories
- 1 — check fixable in the product
- Yes — scheduled with its namespace

Free to start. No card. The playground just needs your work email.

## Every check, grouped by what it protects.

Each one opens with why it matters and exactly what to change.

### Orphaned resources

Resources no longer attached to anything that needs them, such as unattached volumes and unassigned IPs.

- [Stopped Deployment](https://zop.dev/zopnight/rules/stopped-deployment)

### Rightsizing

Resources sized for headroom they never use. A smaller size runs the same workload for less.

- [CPU Over-Provisioned](https://zop.dev/zopnight/rules/cpu-over-provisioned)
- [Memory Over-Provisioned](https://zop.dev/zopnight/rules/memory-over-provisioned)

### Reliability

Production-shape issues that cause incidents and rework: single replicas, missing requests and limits, missing probes.

- [Container Image Tag Latest or Missing](https://zop.dev/zopnight/rules/container-image-tag-latest-or-missing)
- [Deployment Not Fully Ready](https://zop.dev/zopnight/rules/deployment-not-fully-ready)
- [Deployment Uses Recreate Strategy](https://zop.dev/zopnight/rules/deployment-uses-recreate-strategy)
- [Liveness and Readiness Share One Handler](https://zop.dev/zopnight/rules/liveness-and-readiness-share-one-handler)
- [Missing CPU/Memory Limits](https://zop.dev/zopnight/rules/missing-cpu-memory-limits)
- [Missing CPU/Memory Requests](https://zop.dev/zopnight/rules/missing-cpu-memory-requests)
- [Missing Liveness Probe](https://zop.dev/zopnight/rules/missing-liveness-probe)
- [Missing Readiness Probe](https://zop.dev/zopnight/rules/missing-readiness-probe)
- [Missing Startup Probe](https://zop.dev/zopnight/rules/missing-startup-probe)
- [Single Replica Deployment](https://zop.dev/zopnight/rules/single-replica-deployment)
- [Workload Missing Topology Spread](https://zop.dev/zopnight/rules/workload-missing-topology-spread)

### Security

Risky configurations: privileged containers, containers running as root, host networking, ingress without TLS.

- [Container Running as Root](https://zop.dev/zopnight/rules/container-running-as-root)
- [Container with Host Network](https://zop.dev/zopnight/rules/container-with-host-network)
- [Privileged Container](https://zop.dev/zopnight/rules/privileged-container)

## Find these on your own GKE Deployments.

Connect a read-only role and ZopNight inventories the GKE Deployments you run, then runs all 17 checks against them.

[object Object]
