Gke Platform Security

作者 google55b4e13eba6d无许可证21K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, Secrets Encryption (--database-encryption-key), Security Posture (--security-posture), enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for Workload Identity (use gke-workload-identity) or workload-level security (SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security).

精选仅含说明SecurityDevOps & Cloud
AI 生成的概览

强化 Google Kubernetes Engine 集群的平台级安全,涵盖 RBAC、Secret Manager、Shielded Nodes、Sandbox 与 IAM。

功能
提供用于强化 GKE 集群平台级安全的参考指南和 gcloud 命令。内容涵盖集群附加组件(如 Secret Manager 的启用与轮换)、针对不安全旧式绑定的 RBAC 强化、Binary Authorization、Secrets Encryption、Security Posture、Shielded Nodes、GKE Sandbox 启用以及 GKE IAM 角色。此外还列出黄金路径安全默认值和后端服务账号的跨服务 IAM 绑定模式。
适用场景
适用于保护 GKE 集群控制平面、强化集群 RBAC、启用 Shielded Nodes 或 GKE Sandbox 运行时、启用集群级安全附加组件,或管理 GKE IAM 角色的场景。不适用于 Workload Identity 或工作负载级控制,例如 SecretProviderClass、Pod 安全标准、网络策略或 gVisor Pod 运行时类。
运行要求
仅为说明性内容,不附带脚本。执行文档中的命令需要 gcloud CLI 和 GKE 集群访问权限,另外可选使用 Kubernetes 工具以及所列的 MCP 工具来检查集群和 RBAC。

GKE Platform Security

This reference covers platform-level security hardening and cluster configuration for Google Kubernetes Engine (GKE). For workload-level security controls (such as Workload Identity Service Account bindings, SecretProviderClass volume mounts, Network Policies, and Pod Security Standards), refer to the gke-workload-security skill.

MCP Tools: gke:get_cluster, k8s:check_k8s_auth, k8s:get_k8s_resource, k8s:apply_k8s_manifest, gke:update_cluster

Golden Path Security Defaults

SettingGolden Path ValueDay-0/1Notes
workloadIdentityConfig.workloadPool<PROJECT>.svc.id.googDay-0Workload Identity Federation for cluster pods
secretManagerConfig.enabledtrueDay-1Google Secret Manager cluster add-on integration
secretManagerConfig.rotationConfigenabled: true, rotationInterval: 120sDay-1Automatic secret rotation at the cluster level
rbacBindingConfig.enableInsecureBindingSystemAuthenticatedfalseDay-0Blocks legacy system:authenticated bindings
rbacBindingConfig.enableInsecureBindingSystemUnauthenticatedfalseDay-0Blocks legacy system:unauthenticated bindings
nodeConfig.shieldedInstanceConfig.enableSecureBoottrueDay-0Verifiable boot integrity
nodeConfig.shieldedInstanceConfig.enableIntegrityMonitoringtrueDay-0Runtime integrity checks
nodeConfig.workloadMetadataConfig.modeGKE_METADATADay-0Blocks legacy metadata API, enforces Workload Identity
Private cluster + Dataplane V2 settingsSee the gke-networking skillDay-0Private nodes, private endpoint enforcement, ADVANCED_DATAPATH

Secret Manager Add-on Enablement

The golden path enables Secret Manager at the cluster level with automatic secret rotation.

bash
# Verify Secret Manager is enabled on clustergcloud container clusters describe <CLUSTER_NAME> --region <REGION> \  --format="value(secretManagerConfig.enabled)" \  --quiet
# Enable if not already (Day-1 change)gcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-secret-manager \  --secret-manager-rotation-interval=120s \  --quiet

Note: For configuring SecretProviderClass manifests and mounting secrets as volumes inside application deployments, see the gke-workload-security skill.

RBAC Hardening

The golden path disables insecure legacy RBAC bindings that grant broad access to system:authenticated and system:unauthenticated groups.

bash
# Verify insecure bindings are disabledgcloud container clusters describe <CLUSTER_NAME> --region <REGION> \  --format="yaml(rbacBindingConfig)" \  --quiet

Best practices for RBAC:

  • Use namespace-scoped Roles over cluster-wide ClusterRoles.
  • Bind to specific Groups or ServiceAccounts, never to system:authenticated or system:unauthenticated.
  • Audit permissions via MCP: k8s:check_k8s_auth(parent="...", verb="list", resourceType="pods", namespace="...") (or kubectl auth can-i --list --as=<user>).
  • Review bindings via MCP: k8s:get_k8s_resource(parent="...", resourceType="clusterrolebinding") (or kubectl get clusterrolebindings,rolebindings --all-namespaces).

See the gke-multitenancy skill for enterprise RBAC planning and https://docs.cloud.google.com/kubernetes-engine/docs/best-practices/rbac.md.txt

Binary Authorization

Not enabled in golden path by default but recommended for enforcing production image provenance across the cluster:

bash
# Enable Binary Authorizationgcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --binauthz-evaluation-mode=PROJECT_SINGLETON_POLICY_ENFORCE \  --quiet

Shielded Nodes & GKE Sandbox Enablement

Enabling verifiable node boot integrity and kernel isolation features at the cluster level:

bash
# Enable Shielded Nodes on an existing clustergcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-shielded-nodes \  --quiet
# Enable GKE Sandbox (gVisor) runtime on an existing clustergcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-gke-sandbox \  --quiet

Note: To run workloads inside the gVisor sandbox, specify runtimeClassName: gvisor in your Pod specs as detailed in the gke-workload-security skill.

Common IAM Roles

The five most common predefined IAM roles for GKE platform and cluster access:

RolePurposeWhen to Use
roles/container.adminFull control overPlatform team admins
: : clusters and : managing cluster :
: : Kubernetes : lifecycle :
: : resources : :
roles/container.clusterAdminManage clusters butCluster operators
: : not project-level : who create/delete :
: : IAM : clusters :
roles/container.developerDeploy workloadsApplication
: : (pods, services, : developers deploying :
: : deployments) : to existing clusters :
roles/container.viewerRead-only access toMonitoring,
: : clusters and : auditing, or :
: : Kubernetes : read-only dashboards :
: : resources : :
roles/container.clusterViewerList and getCI/CD pipelines that
: : cluster details : need cluster :
: : only : metadata :

Principle of least privilege: Start with roles/container.viewer or roles/container.developer and escalate only as needed. Avoid granting roles/container.admin broadly across teams.

Service Accounts & Agents

  • GKE Service Agent (service-<PROJECT_NUMBER>@container-engine-robot.iam.gserviceaccount.com): Automatically created. Manages nodes, networking, and cluster operations on your behalf. Do not remove or modify its permissions.
  • Node Service Account: By default, nodes use the Compute Engine default service account. For production platforms, create a dedicated Google Service Account with minimal required permissions (roles/monitoring.metricWriter, roles/logging.logWriter) and assign it at node pool creation time.
  • Workload Identity: For binding Google Service Accounts to Kubernetes Service Accounts (roles/iam.workloadIdentityUser), refer to the gke-workload-security skill.

Cross-Service Authentication Patterns

Common project-level IAM policy binding patterns for granting backend Google Service Accounts (GSAs) access to external Google Cloud services before linking via Workload Identity:

bash
# Grant a GSA access to Cloud Storage objectsgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/storage.objectViewer" \  --quiet
# Grant a GSA access to Cloud SQL databasesgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/cloudsql.client" \  --quiet
# Grant a GSA access to Pub/Sub subscriptionsgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/pubsub.subscriber" \  --quiet
## Resources
- [GKE Cluster Hardening Guide](https://cloud.google.com/kubernetes-engine/docs/how-to/hardening-your-cluster)- [GKE RBAC Best Practices](https://cloud.google.com/kubernetes-engine/docs/best-practices/rbac)- [Secret Manager Add-on for GKE](https://cloud.google.com/secret-manager/docs/secret-manager-managed-csi-component)- [Binary Authorization on GKE](https://cloud.google.com/binary-authorization/docs/setting-up)- [Shielded GKE Nodes](https://cloud.google.com/kubernetes-engine/docs/how-to/shielded-gke-nodes)- [GKE Sandbox (gVisor)](https://cloud.google.com/kubernetes-engine/docs/how-to/sandbox-pods)

来源与署名

来源:google/skills位于skills/cloud/gke-platform-security提交55b4e13

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 google/skills 的技能