Gke Cost Optimization

作者 google55b4e13eba6d無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Optimizes GKE costs, rightsizes workloads, and configures Spot VMs, CUDs, cost allocation, and resource quotas. Use when optimizing GKE cluster or workload costs, configuring GKE cost allocation or quotas, rightsizing CPU/memory requests, or selecting Spot VMs and machine types. Don't use for general compute class provisioning or GPU Selection (use gke-compute-classes instead).

AI 產生的概覽

指導透過資源調校、Spot VM、配額、機型與承諾使用折扣來降低 GKE 成本。

功能
這份參考型技能說明如何在維持工作負載可靠性的前提下降低 Google Kubernetes Engine 成本。內容涵蓋多租戶叢集的資源配額、以 VPA 建議模式與 MPA 進行 Pod 資源調校、透過 nodeSelector 選用 Spot VM、機型比較、承諾使用折扣的規模估算,以及將節點集區縮減至零等叢集管理做法。技能附有配額、VPA 建議模式與 Spot 部署的範例 YAML 資產,並指向成本分析與 ComputeClass 設定的搭配技能。
適用情境
適用於最佳化 GKE 叢集或工作負載成本、設定 GKE 成本分配或配額、調整 CPU 與記憶體請求,以及選擇 Spot VM 和機型。不適用於一般運算類別佈建或 GPU 選擇。
執行需求
僅為說明文件,不含指令碼。假定可存取 GKE 叢集並具備 kubectl、gcloud 等工具,同時涉及 BigQuery 帳單查詢與 Google Cloud 主控台;隨附的 YAML 資產為可直接套用的範本。

GKE Cost Optimization

This reference covers strategies and workflows for reducing Google Kubernetes Engine (GKE) costs while maintaining a secure and reliable posture.

Workflows & Optimization Strategies

1. Prerequisite: Cost Allocation & Monitoring

To enable GKE cost allocation (--enable-cost-allocation) for billing tracking across namespaces and labels, inspect live cluster utilization (kubectl top), or run historical cost breakdown queries in BigQuery (bq), use the gke-cost-analysis skill. Once tracking is active and waste is diagnosed, apply the optimization workflows below.

2. Configure Resource Quotas

Resource quotas restrict total resource consumption across tenants in multi-tenant clusters, preventing runaway costs. Template: assets/resource-quota-example.yaml [blocked] (set namespace + hard limits, then kubectl apply -f).

3. Pod Rightsizing (VPA & MPA)

Adjust pod resource requests to match actual utilization. Over-provisioned requests are one of the largest sources of waste.

  • Use VPA in Recommendation Mode (updateMode: "Off" — recommends without evicting):
bash
# 1. Deploy VPA in recommendation mode (template: assets/vpa-recommendation-mode.yaml)kubectl apply -f assets/vpa-recommendation-mode.yaml# 2. Wait 24+ hours for data collection, then read recommendationskubectl get vpa {deployment_name}-vpa -o jsonpath='{.status.recommendation}'
  • Optimization Rules:
ConditionActionSavings
CPU request >5x P95 actualReduce to P95 * 1.2High
Memory request >3x P95 actualReduce to P95 * 1.2High
CPU request >2x P95 actualReduce to P95 * 1.2Medium
No resource requests setAdd requests (enables bin-packing)Medium
  • Use MPA: Reconcile HPA and VPA recommendations when scaling both horizontally and vertically to avoid conflicting scale events.
  • Review Cost Recommendations: Check Google Cloud Console (Cost Management > GKE Cost Optimization) for built-in rightsizing suggestions.

4. Spot VMs via ComputeClasses & NodeSelector

Use Spot VMs for fault-tolerant workloads to achieve 60-90% cost reduction.

4.1 ComputeClass Configuration

For a Spot-first ComputeClass with On-Demand fallback (priority ordering, activeMigration, machine family selection), use the gke-compute-classes skill — ComputeClass YAML generation and priority configuration are its domain, not this skill's.

4.2 Direct Workload Spot Selection (nodeSelector)

For stateless or batch workloads in GKE Autopilot, target Spot capacity directly using nodeSelector:

[!WARNING] Preemption Warning: Spot VMs are interruptible and can be preempted at any time with a 30-second notice. Workloads must be fault-tolerant and run with at least 2 replicas for high availability. Always explicitly warn users about this preemption risk when recommending Spot VMs.

The exact Pod-level selector is:

yaml
nodeSelector:  cloud.google.com/gke-spot: "true"

Full worked Deployment (replicas >= 2, terminationGracePeriodSeconds: 25, preStop hook): assets/spot-deployment-example.yaml [blocked].

Spot-Suitable Workloads:

WorkloadSpot-Suitable?
Batch / data processingYes
Dev / test environmentsYes
Stateless web/API (replicas >= 2)Yes (with PDBs)
Jobs with checkpointingYes
Stateful workloads (databases)No
Single-replica critical servicesNo

5. Machine Type Selection

When choosing node shapes or configuring ComputeClasses:

FamilyUse CaseRelative Cost
e2General purpose, burstableLowest
t2a / t2dScale-out (Arm/AMD), price-performance optimizedLow
n4aAxion Arm-based, general-purpose price-performanceLow
n4 / n4dGeneral purpose (Intel/AMD), flexible shapesLow-Medium
c4aAxion Arm-based, general-purpose, high efficiencyMedium
c3 / c4Compute-optimized (Intel)Medium-High
c3d / c4dCompute-optimized (AMD), high throughputMedium-High
ek-standardAutopilot enhancedMedium
m3 / x4Memory-optimized, SAP HANA, large databasesHigh
g2 (L4 GPU)AI inferenceHigh
a3 (H100 GPU)AI trainingHighest
a4 / a4xUltra-scale AI (Blackwell GPUs)Highest

6. Committed Use Discounts (CUDs)

For steady-state workloads with predictable baseline usage, purchase 1-year or 3-year CUDs:

  • Resource-based CUDs (committed to a machine family/region): roughly high-30s% discount for 1-year, ~55% for 3-year (varies by machine family).
  • Flexible CUDs (spend-based, portable across families/regions): lower discounts (~28% 1-year, ~46% 3-year) in exchange for flexibility.
  • Autopilot: Autopilot-specific CUDs were retired in January 2026 — new commitments covering Autopilot usage are spend-based Compute Flexible CUDs (existing Autopilot CUD commitments run out their term).
  • Applied automatically to matching usage across the region.
  • Purchase via Google Cloud Console > Billing > Committed use discounts.

Size the commitment to the steady-state baseline only. A commitment bills for the full term whether or not you use it, so over-committing to peak usage converts a discount into waste. Measure the floor of actual usage over a representative period, commit to that, and cover everything above it with the elastic options already in this skill:

  • Baseline (always running) → resource-based CUDs.
  • Variable / bursty → autoscaling on on-demand capacity.
  • Interruption-tolerant (batch, CI, stateless workers) → Spot VMs, which stack with autoscaling and need no commitment.

When recommending CUDs, state the split explicitly rather than implying the whole footprint should be committed.

7. Cluster Management & Multi-Tenancy

  • Idle dev clusters: GKE has no stop/start operation, and the cluster management fee accrues as long as the cluster exists. To cut idle costs, scale node pools to zero (gcloud container clusters resize {cluster_name} --node-pool {pool_name} --num-nodes 0) or delete and recreate the cluster via IaC (Terraform/Config Connector).
  • Right-size node pools (Standard): Use Cluster Autoscaler with appropriate min/max limits.
  • Cheap warm headroom instead of overprovisioned nodes: Standby capacity buffers (Preview, GKE 1.36.0-gke.2253000+) keep pre-initialized nodes suspended — you pay only disk + IP instead of full node price, with ~30s resume. See the gke-cluster-autoscaler skill.
  • Multi-tenant consolidation: Share a single cluster across multiple engineering teams instead of maintaining per-team clusters, using Namespaces and ResourceQuotas to isolate workloads.

Cost & Utilization Monitoring

To inspect live node/pod utilization (kubectl top nodes/pods), view cluster cost budgets (gcloud billing budgets list), or query detailed billing reports in BigQuery (bq query), refer to the gke-cost-analysis skill.

來源與署名

來源:google/skills位於skills/cloud/gke-cost-optimization提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform. Use when configuring non-extractable asymmetric key pairs (P-256), generating DPoP Proof JWTs for authorization code exchange and token refresh, or handling 400 use_dpop_nonce challenge retry loops at oauth2.googleapis.com/token. Don't use for unconstrained OAuth 2.0 flows (where refresh tokens are not bound to a client key pair), or for Google Cloud IAM / service account authentication.

待分類2026年10月8日

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類2026年10月8日

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics2026年10月8日

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security2026年10月8日

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security2026年10月8日

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security2026年10月8日