Gke Platform Security

by google55b4e13eba6dNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, Secrets Encryption (--database-encryption-key), Security Posture (--security-posture), enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for Workload Identity (use gke-workload-identity) or workload-level security (SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security).

FeaturedInstructions onlySecurityDevOps & Cloud
AI-generated overview

Hardens platform-level Google Kubernetes Engine cluster security, covering RBAC, Secret Manager, Shielded Nodes, Sandbox and IAM.

What it does
Provides reference guidance and gcloud commands for hardening platform-level GKE cluster security. It covers cluster add-ons such as Secret Manager enablement and rotation, RBAC hardening against insecure legacy bindings, Binary Authorization, Secrets Encryption, Security Posture, Shielded Nodes, GKE Sandbox enablement, and GKE IAM roles. It also lists golden-path security defaults and cross-service IAM binding patterns for backend service accounts.
When to use it
Use when securing GKE cluster control planes, hardening cluster RBAC, enabling Shielded Nodes or the GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. It is not intended for Workload Identity or workload-level controls such as SecretProviderClass, Pod Security Standards, Network Policies or gVisor pod runtime classes.
Requirements
Instructions only, with no bundled scripts. Running the documented commands requires the gcloud CLI and access to a GKE cluster, plus optional Kubernetes tooling and the listed MCP tools for cluster and RBAC inspection.

GKE Platform Security

This reference covers platform-level security hardening and cluster configuration for Google Kubernetes Engine (GKE). For workload-level security controls (such as Workload Identity Service Account bindings, SecretProviderClass volume mounts, Network Policies, and Pod Security Standards), refer to the gke-workload-security skill.

MCP Tools: gke:get_cluster, k8s:check_k8s_auth, k8s:get_k8s_resource, k8s:apply_k8s_manifest, gke:update_cluster

Golden Path Security Defaults

SettingGolden Path ValueDay-0/1Notes
workloadIdentityConfig.workloadPool<PROJECT>.svc.id.googDay-0Workload Identity Federation for cluster pods
secretManagerConfig.enabledtrueDay-1Google Secret Manager cluster add-on integration
secretManagerConfig.rotationConfigenabled: true, rotationInterval: 120sDay-1Automatic secret rotation at the cluster level
rbacBindingConfig.enableInsecureBindingSystemAuthenticatedfalseDay-0Blocks legacy system:authenticated bindings
rbacBindingConfig.enableInsecureBindingSystemUnauthenticatedfalseDay-0Blocks legacy system:unauthenticated bindings
nodeConfig.shieldedInstanceConfig.enableSecureBoottrueDay-0Verifiable boot integrity
nodeConfig.shieldedInstanceConfig.enableIntegrityMonitoringtrueDay-0Runtime integrity checks
nodeConfig.workloadMetadataConfig.modeGKE_METADATADay-0Blocks legacy metadata API, enforces Workload Identity
Private cluster + Dataplane V2 settingsSee the gke-networking skillDay-0Private nodes, private endpoint enforcement, ADVANCED_DATAPATH

Secret Manager Add-on Enablement

The golden path enables Secret Manager at the cluster level with automatic secret rotation.

bash
# Verify Secret Manager is enabled on clustergcloud container clusters describe <CLUSTER_NAME> --region <REGION> \  --format="value(secretManagerConfig.enabled)" \  --quiet
# Enable if not already (Day-1 change)gcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-secret-manager \  --secret-manager-rotation-interval=120s \  --quiet

Note: For configuring SecretProviderClass manifests and mounting secrets as volumes inside application deployments, see the gke-workload-security skill.

RBAC Hardening

The golden path disables insecure legacy RBAC bindings that grant broad access to system:authenticated and system:unauthenticated groups.

bash
# Verify insecure bindings are disabledgcloud container clusters describe <CLUSTER_NAME> --region <REGION> \  --format="yaml(rbacBindingConfig)" \  --quiet

Best practices for RBAC:

  • Use namespace-scoped Roles over cluster-wide ClusterRoles.
  • Bind to specific Groups or ServiceAccounts, never to system:authenticated or system:unauthenticated.
  • Audit permissions via MCP: k8s:check_k8s_auth(parent="...", verb="list", resourceType="pods", namespace="...") (or kubectl auth can-i --list --as=<user>).
  • Review bindings via MCP: k8s:get_k8s_resource(parent="...", resourceType="clusterrolebinding") (or kubectl get clusterrolebindings,rolebindings --all-namespaces).

See the gke-multitenancy skill for enterprise RBAC planning and https://docs.cloud.google.com/kubernetes-engine/docs/best-practices/rbac.md.txt

Binary Authorization

Not enabled in golden path by default but recommended for enforcing production image provenance across the cluster:

bash
# Enable Binary Authorizationgcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --binauthz-evaluation-mode=PROJECT_SINGLETON_POLICY_ENFORCE \  --quiet

Shielded Nodes & GKE Sandbox Enablement

Enabling verifiable node boot integrity and kernel isolation features at the cluster level:

bash
# Enable Shielded Nodes on an existing clustergcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-shielded-nodes \  --quiet
# Enable GKE Sandbox (gVisor) runtime on an existing clustergcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-gke-sandbox \  --quiet

Note: To run workloads inside the gVisor sandbox, specify runtimeClassName: gvisor in your Pod specs as detailed in the gke-workload-security skill.

Common IAM Roles

The five most common predefined IAM roles for GKE platform and cluster access:

RolePurposeWhen to Use
roles/container.adminFull control overPlatform team admins
: : clusters and : managing cluster :
: : Kubernetes : lifecycle :
: : resources : :
roles/container.clusterAdminManage clusters butCluster operators
: : not project-level : who create/delete :
: : IAM : clusters :
roles/container.developerDeploy workloadsApplication
: : (pods, services, : developers deploying :
: : deployments) : to existing clusters :
roles/container.viewerRead-only access toMonitoring,
: : clusters and : auditing, or :
: : Kubernetes : read-only dashboards :
: : resources : :
roles/container.clusterViewerList and getCI/CD pipelines that
: : cluster details : need cluster :
: : only : metadata :

Principle of least privilege: Start with roles/container.viewer or roles/container.developer and escalate only as needed. Avoid granting roles/container.admin broadly across teams.

Service Accounts & Agents

  • GKE Service Agent (service-<PROJECT_NUMBER>@container-engine-robot.iam.gserviceaccount.com): Automatically created. Manages nodes, networking, and cluster operations on your behalf. Do not remove or modify its permissions.
  • Node Service Account: By default, nodes use the Compute Engine default service account. For production platforms, create a dedicated Google Service Account with minimal required permissions (roles/monitoring.metricWriter, roles/logging.logWriter) and assign it at node pool creation time.
  • Workload Identity: For binding Google Service Accounts to Kubernetes Service Accounts (roles/iam.workloadIdentityUser), refer to the gke-workload-security skill.

Cross-Service Authentication Patterns

Common project-level IAM policy binding patterns for granting backend Google Service Accounts (GSAs) access to external Google Cloud services before linking via Workload Identity:

bash
# Grant a GSA access to Cloud Storage objectsgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/storage.objectViewer" \  --quiet
# Grant a GSA access to Cloud SQL databasesgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/cloudsql.client" \  --quiet
# Grant a GSA access to Pub/Sub subscriptionsgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/pubsub.subscriber" \  --quiet
## Resources
- [GKE Cluster Hardening Guide](https://cloud.google.com/kubernetes-engine/docs/how-to/hardening-your-cluster)- [GKE RBAC Best Practices](https://cloud.google.com/kubernetes-engine/docs/best-practices/rbac)- [Secret Manager Add-on for GKE](https://cloud.google.com/secret-manager/docs/secret-manager-managed-csi-component)- [Binary Authorization on GKE](https://cloud.google.com/binary-authorization/docs/setting-up)- [Shielded GKE Nodes](https://cloud.google.com/kubernetes-engine/docs/how-to/shielded-gke-nodes)- [GKE Sandbox (gVisor)](https://cloud.google.com/kubernetes-engine/docs/how-to/sandbox-pods)

Source and attribution

Source:google/skillsinskills/cloud/gke-platform-securityat commit55b4e13

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from google/skills

Google Cloud Solution N Tier Serverless Web App

google

Featured

Guides design and Terraform implementation of secure n-tier serverless web apps on Google Cloud.

DevOps & CloudOct 8, 2026

Google Cloud Solution Hybrid Search Alloydb

google

Featured

Discovers requirements and generates architectural, design, and deployment guidance for dynamic hybrid search systems by combining semantic search and keyword search. Optimized for AlloyDB hybrid search use cases in Google Cloud. Use when users need vector search combined with structured SQL filtering, faceted attributes, semantic reranking, in-database AI validation, or serverless hosting across transactional relational databases, analytical data warehouses, or managed database engines. DON'T use this skill for simple keyword-only search, or when a standalone non-relational vector database is required.

Awaiting classificationOct 8, 2026

Google Cloud Solution Architecture

google

Featured

Interactively discovers requirements and designs holistic, multi-product system architectures, solution blueprints, and deployment recommendations for complex workloads on Google Cloud. Use when designing end-to-end cloud solutions, selecting and integrating Google Cloud services, generating architecture diagrams, or conducting requirements discovery for new cloud workloads or migrations. Don't use for single-product tasks (use product-specific skills), initial onboarding or authentication (use google-cloud-recipe-*), Well-Architected Framework reviews or audits (use google-cloud-waf-*), or workloads covered by specialized solution skills.

Awaiting classificationOct 8, 2026

Google Cloud Solution Agentic Ai Data Science Workflow

google

Featured

Designs a tailored multi-product agentic data science architecture on Google Cloud that incorporates opinionated best practices. Use when architecting multi-product solutions for agent-based data analytics or ML workloads. Don't use for simple queries, non-agentic pipelines, general cloud reviews, or writing agent code.

Awaiting classificationOct 8, 2026

Google Cloud Solution Agentic Ai Borderless Data Lakehouse

google

Featured

Discovers requirements and designs a borderless open data lakehouse using Lakehouse for Apache Iceberg and BigQuery data agents. Use when architecting multi-cloud storage infrastructure (Cloud Storage, AWS S3, Azure Blob), establishing ingestion and AI serving subsystems, configuring Cross-Cloud Interconnect, or deploying Gemini Enterprise Agent Platform and BigQuery data agents. Don't use for single-cloud data warehouses, or when the focus is on Knowledge Catalog metadata governance and Spark-driven IDE analytics workflows (use google-cloud-solution-agentic-analytics-spark-knowledge-catalog instead).

Awaiting classificationOct 8, 2026

Google Cloud Solution Agentic Ai Bidirectional Streaming

google

Featured

Guides agents to interactively discover customer requirements for live, bidirectional multi-agent AI systems that process continuous streams of multimodal data for real-time technical guidance and safety monitoring. Generates a custom Google Cloud solution that uses opinionated best practices and architecture guidance. Use when users need agentic assistance to design and create a multi-product solution in the cloud for live bidirectional multimodal streaming workloads. Don't use for simple text-based chat applications or workloads without real-time streaming requirements.

Awaiting classificationOct 8, 2026