GKE Platform Security
This reference covers platform-level security hardening and cluster
configuration for Google Kubernetes Engine (GKE). For workload-level security
controls (such as Workload Identity Service Account bindings,
SecretProviderClass volume mounts, Network Policies, and Pod Security
Standards), refer to the gke-workload-security skill.
MCP Tools:
gke:get_cluster,k8s:check_k8s_auth,k8s:get_k8s_resource,k8s:apply_k8s_manifest,gke:update_cluster
Golden Path Security Defaults
Secret Manager Add-on Enablement
The golden path enables Secret Manager at the cluster level with automatic secret rotation.
Note: For configuring
SecretProviderClassmanifests and mounting secrets as volumes inside application deployments, see thegke-workload-securityskill.
RBAC Hardening
The golden path disables insecure legacy RBAC bindings that grant broad access
to system:authenticated and system:unauthenticated groups.
Best practices for RBAC:
- Use namespace-scoped Roles over cluster-wide ClusterRoles.
- Bind to specific Groups or ServiceAccounts, never to
system:authenticatedorsystem:unauthenticated. - Audit permissions via MCP:
k8s:check_k8s_auth(parent="...", verb="list", resourceType="pods", namespace="...")(orkubectl auth can-i --list --as=<user>). - Review bindings via MCP:
k8s:get_k8s_resource(parent="...", resourceType="clusterrolebinding")(orkubectl get clusterrolebindings,rolebindings --all-namespaces).
See the
gke-multitenancyskill for enterprise RBAC planning and https://docs.cloud.google.com/kubernetes-engine/docs/best-practices/rbac.md.txt
Binary Authorization
Not enabled in golden path by default but recommended for enforcing production image provenance across the cluster:
Shielded Nodes & GKE Sandbox Enablement
Enabling verifiable node boot integrity and kernel isolation features at the cluster level:
Note: To run workloads inside the gVisor sandbox, specify
runtimeClassName: gvisorin your Pod specs as detailed in thegke-workload-securityskill.
Common IAM Roles
The five most common predefined IAM roles for GKE platform and cluster access:
Principle of least privilege: Start with
roles/container.viewerorroles/container.developerand escalate only as needed. Avoid grantingroles/container.adminbroadly across teams.
Service Accounts & Agents
- GKE Service Agent
(
service-<PROJECT_NUMBER>@container-engine-robot.iam.gserviceaccount.com): Automatically created. Manages nodes, networking, and cluster operations on your behalf. Do not remove or modify its permissions. - Node Service Account: By default, nodes use the Compute Engine default
service account. For production platforms, create a dedicated Google Service
Account with minimal required permissions (
roles/monitoring.metricWriter,roles/logging.logWriter) and assign it at node pool creation time. - Workload Identity: For binding Google Service Accounts to Kubernetes
Service Accounts (
roles/iam.workloadIdentityUser), refer to thegke-workload-securityskill.
Cross-Service Authentication Patterns
Common project-level IAM policy binding patterns for granting backend Google Service Accounts (GSAs) access to external Google Cloud services before linking via Workload Identity:
