Upgrade Announcement for CCE Cluster Audit Component kube-external-auditor
Updated at:2025-10-27
kube-external-auditor is an auditing component of Cloud Container Engine (CCE). CCE standalone cluster auditing component (kube-external-auditor) versions prior to V1.1.2 have the risks of performance latency and memory OOM, causing APIServer interruption and unavailability when auditing is enabled or disabled. You are recommended to upgrade the standalone cluster auditing component to ensure stable business operation.
Scope of impact
Clusters to be upgraded:
- Standalone clusters created before 00:00:00 on August 15, 2025
Clusters not requiring action:
- Clusters created after 00:00:00 on August 15, 2025
- Standalone clusters with auditing component upgraded
Upgrade benefits
Standalone clusters may encounter stability issues when the cluster auditing function is enabled/disabled. Upgrading the auditing component kube-external-auditor to V1.1.2 will benefit you as follows:
- Performance optimization: Significantly improve the processing ability of sending audit events concurrently
- Stability enhancement: Optimize APIServer restart logic, reducing service interruption time
- Issue fixes: Solve the problems of memory leakage and concurrent competition
Upgrade path
- Method I: Submit a ticket
- Method II: Contact your dedicated account manager
Risk tips
- Operation impact: APIServer will restart in the upgrading process
- Evaluation recommendation: Recommend execution during off-peak service hours and evaluate the impact on your operations in advance
