C-0305 - No Rolling Update Strategy
Framework
DevOpsBest
Severity
Low
Description of the the issue
A Deployment that explicitly sets a non-rolling update strategy (for example, Recreate) terminates all existing Pods before new ones start. This causes avoidable downtime every time the workload is updated.
Related Resources
Deployment
What does this control test
The control checks Deployments that explicitly define spec.strategy.type and fails any Deployment whose strategy type is not RollingUpdate. Deployments that don't set a strategy type pass, since Kubernetes defaults to RollingUpdate.
Remediation
Set spec.strategy.type to RollingUpdate:
apiVersion: apps/v1 kind: Deployment spec: strategy: type: RollingUpdate
If the workload can't run two versions side by side (for example, it holds an exclusive lock on a volume), keep Recreate and accept the downtime, or redesign the workload to support rolling updates.
Updated 38 minutes ago
