Gke Basics

by google55b4e13eba6dNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment. Use when creating GKE clusters, fetching kubectl credentials, or deciding between Autopilot and Standard modes. Don't use for Workload Identity (use gke-workload-identity), GKE networking (use gke-networking), security hardening (use gke-platform-security or gke-workload-security), or cluster upgrades (use gke-upgrades).

FeaturedInstructions onlyDevOps & Cloud
AI-generated overview

Guides GKE cluster provisioning, Autopilot versus Standard selection, credentials, and workload deployment.

What it does
Provides instructions for creating and managing Google Kubernetes Engine clusters, including choosing between Autopilot and Standard modes, configuring private clusters, and fetching kubectl credentials. It also covers Autopilot resource request rules and routes related topics such as Workload Identity, networking, security, and upgrades to other skills. Reference files cover core concepts, CLI usage, client libraries, MCP tools, and Terraform infrastructure as code.
When to use it
Use when creating GKE clusters, retrieving kubectl credentials, or deciding between Autopilot and Standard modes. It is not intended for Workload Identity, GKE networking, security hardening, or cluster upgrades, which are handled by other skills.
Requirements
Requires Google Cloud access with gcloud and kubectl for the documented commands; reference material also covers MCP tools, client libraries, and Terraform. Ships no scripts; instructions and reference documents only.

GKE Basics & Critical Gotchas

Routing Note: For Workload Identity KSA/GSA setup, open gke-workload-identity/SKILL.md. For cluster security flags (--database-encryption-key, --security-posture, RBAC, Shielded Nodes, Binary Authorization), open gke-platform-security/SKILL.md. For cluster upgrades or maintenance windows, open gke-upgrades/SKILL.md. For generating Kubernetes YAML manifests (Deployment, StatefulSet, Service, HTTPRoute, PodDisruptionBudget), open gke-manifest-generation/SKILL.md.

Managed Kubernetes platform on Google Cloud. Defaults to Autopilot mode unless Standard is explicitly required.

Key Selection Rules: Autopilot vs. Standard

  • Default to Autopilot for almost all workloads.
  • Use Standard ONLY if:
    • Custom node OS kernel parameters (sysctl) are required.
    • Custom node taints or specific hardware node pools are required.
    • DaemonSets require raw hostPath mounts to the host OS filesystem.
  • When explaining why Standard is required over Autopilot, explicitly cite all matching restrictions (e.g., custom sysctls and custom node taints).
  • For advanced cluster architecture or complex node pool creation planning, refer to gke-cluster-creation.

Critical Gotchas & Best Practices

  1. Private Autopilot Clusters:

    • Use --enable-private-nodes for private node IP addresses.
    • Use --enable-private-endpoint to disable public IP access to the control plane.
    • Restrict control plane access with --enable-master-authorized-networks and --master-authorized-networks=CIDR_BLOCK:
      bash
      gcloud container clusters create-auto CLUSTER_NAME --region=REGION \  --enable-private-nodes \  --enable-private-endpoint \  --enable-master-authorized-networks \  --master-authorized-networks=CIDR_BLOCK
  2. Workload Identity (IAM Binding):

    • Never mount raw GCP Service Account JSON keys in Pods; open gke-workload-identity/SKILL.md for KSA/GSA setup.
  3. Autopilot Resource Requests:

    • In Autopilot, CPU requests must be specified in increments of 250m (0.25 vCPU). If an unaligned CPU request (e.g., 300m) is requested, round up to the nearest 250m increment (500m / 0.5 vCPU).
    • Resource requests equal limits automatically. Omit limits to allow Autopilot to set defaults matching requests.
  4. Cluster Credentials:

    • Always explicitly specify --region (for regional clusters) or --zone (for zonal clusters) when fetching credentials:
      bash
      gcloud container clusters get-credentials CLUSTER_NAME --region=REGION --quiet

Reference Directory

  • Core Concepts [blocked]: Architecture, cluster modes (Autopilot vs Standard), networking, scaling, and security model.

  • CLI Usage & Tool Reference [blocked]: Tool preference hierarchy (MCP vs gcloud vs kubectl), gcloud container commands, and user preference overrides.

  • Client Libraries [blocked]: Official Kubernetes and Google Cloud Container client libraries in Python, Go, Node.js, and Java.

  • MCP Usage [blocked]: Connecting to and using the 23 structured GKE MCP tools for cluster management, K8s resources, and diagnostics.

  • Infrastructure as Code [blocked]: Terraform examples for google_container_cluster (Autopilot), Kubernetes provider resources, and YAML samples.

Source and attribution

Source:google/skillsinskills/cloud/gke-basicsat commit55b4e13

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from google/skills

Dpop Adoption

google

Featured

Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

SecurityOct 8, 2026

Finding Google Skills

google

Featured

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

Awaiting classificationOct 8, 2026

Spanner Basics

google

Featured

Guides Google Cloud Spanner administration, schema design, querying and performance diagnosis.

Data & AnalyticsOct 8, 2026

Secops Triage

google

Featured

Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

SecurityOct 8, 2026

Secops Investigate

google

Featured

Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.

SecurityOct 8, 2026

Secops Hunt

google

Featured

Guides proactive threat hunting in Google SecOps using UDM queries, IoC lookback, prevalence and outlier analysis.

SecurityOct 8, 2026