Gke Networking

by google55b4e13eba6dNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Plans, configures, and manages core GKE cluster networking. Covers private clusters, VPC-native configurations, DNS, node egress, Dataplane V2, and IP planning. Use when designing GKE networking layouts, configuring private clusters, setting up Dataplane V2, planning GKE IP ranges, or managing VPC- native cluster modes. Don't use for application ingress, load balancing, or service networking (use gke-service-networking instead).

FeaturedInstructions only

GKE Networking

This reference covers networking configuration for GKE clusters. The golden path enforces private, VPC-native clusters with Dataplane V2.

MCP Tools: get_cluster, update_cluster, apply_k8s_manifest, get_k8s_resource

Golden Path Networking Defaults

SettingGolden Path ValueDay-0/1Notes
privateClusterConfig.enablePrivateNodestrueDay-0Nodes have no public IPs
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabledtrueDay-0Control plane only reachable via private endpoint or DNS
controlPlaneEndpointsConfig.dnsEndpointConfig.allowExternalTraffictrueDay-0Allows DNS-based access from outside VPC
networkConfig.datapathProviderADVANCED_DATAPATH (Dataplane V2)Day-0eBPF-based, built-in Network Policy
networkConfig.dnsConfig.clusterDnsCLOUD_DNSDay-0Managed DNS, more reliable than kube-dns
networkConfig.enableIntraNodeVisibilitytrueDay-1VPC Flow Logs for intra-node traffic
ipAllocationPolicy.autoIpamConfig.enabledtrueDay-0Automatic IP range management
ipAllocationPolicy.createSubnetworktrueDay-0Auto-create dedicated subnet
defaultMaxPodsConstraint.maxPodsPerNode48Day-0Conservative default; 110 for high density

Private Cluster Access Patterns

The golden path creates a private cluster. Users access it via:

  1. DNS endpoint (default): allowExternalTraffic: true enables access via the cluster's DNS endpoint from outside the VPC. No VPN required.
  2. Private endpoint: Direct access from within the VPC or via Cloud VPN/Interconnect.
  3. Authorized networks: Add specific CIDRs to masterAuthorizedNetworksConfig for IP-based access control.
bash
# Access private cluster via DNS endpoint (golden path default)gcloud container clusters get-credentials {cluster_name} \  --region {region} --dns-endpoint \  --quiet
# Access via private endpoint (from within VPC)gcloud container clusters get-credentials {cluster_name} \  --region {region} --internal-ip \  --quiet

Bring-Your-Own VPC/Subnet

If the customer has existing network infrastructure:

bash
gcloud container clusters create-auto {cluster_name} \  --region {region} \  --network {vpc_name} \  --subnetwork {subnet_name} \  --cluster-secondary-range-name {pod_range} \  --services-secondary-range-name {svc_range} \  --enable-private-nodes \  --enable-master-authorized-networks \  --quiet

Day-0 Warning: VPC, subnet, and IP ranges cannot be changed after cluster creation.

VPC-Native Mode Benefits

VPC-native clusters route traffic natively using GCP Alias IP ranges. Key benefits to cover:

  1. Scalability: Traffic routes natively inside the VPC, bypassing the need for custom routes and avoiding custom route limit bottlenecks.
  2. Direct VPC Integration: Direct resource integration across GCP networks without complex bridging or routing tunnels.
  3. Avoiding IP Exhaustion: Supports discontiguous IP ranges and optimizes allocation, reducing the risk of exhausting subnet IP ranges.

IP Planning

ResourceGolden PathNotes
Pod CIDR/17 (auto)~32K pod IPs; size based on maxPodsPerNode
Service CIDR/20 (auto)~4K service IPs
Node subnetauto-created/20 recommended for growth
Max pods/node48Each node gets a /25 pod range; set to 110
: : : for /24 per node :

Pod CIDR sizing rule of thumb:

  • maxPodsPerNode=48 -> each node uses a /25 (128 IPs) from pod CIDR
  • maxPodsPerNode=110 -> each node uses a /24 (256 IPs) from pod CIDR
  • Larger maxPodsPerNode = fewer nodes fit in a given CIDR

Egress

  • Default: nodes use Cloud NAT for outbound internet access (private nodes have no public IPs) to allow private nodes to reach the internet without public IP exposure.
  • For static egress IPs: configure Cloud NAT with manual IP allocation to maintain a consistent source IP for external allowlists or partner firewalls.
  • For restricted egress: route through a firewall appliance via custom routes to inspect and filter outbound traffic according to organization security policies.

Network Policy

Dataplane V2 (golden path) provides built-in Network Policy enforcement — no additional addon needed. Apply default-deny per namespace, then allow specific flows.

See the gke-workload-security skill for default-deny policy and the gke-multitenancy skill for per-team allow policies.

Source and attribution

Source:google/skillsinskills/cloud/gke-networkingat commit55b4e13

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from google/skills

Dpop Adoption

google

Featured

Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

SecurityOct 8, 2026

Finding Google Skills

google

Featured

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

Awaiting classificationOct 8, 2026

Spanner Basics

google

Featured

Guides Google Cloud Spanner administration, schema design, querying and performance diagnosis.

Data & AnalyticsOct 8, 2026

Secops Triage

google

Featured

Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

SecurityOct 8, 2026

Secops Investigate

google

Featured

Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.

SecurityOct 8, 2026

Secops Hunt

google

Featured

Guides proactive threat hunting in Google SecOps using UDM queries, IoC lookback, prevalence and outlier analysis.

SecurityOct 8, 2026