Gke Platform Security

作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, Secrets Encryption (--database-encryption-key), Security Posture (--security-posture), enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for Workload Identity (use gke-workload-identity) or workload-level security (SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security).

精選僅含說明SecurityDevOps & Cloud
AI 產生的概覽

強化 Google Kubernetes Engine 叢集的平台層級安全,涵蓋 RBAC、Secret Manager、Shielded Nodes、Sandbox 與 IAM。

功能
提供用於強化 GKE 叢集平台層級安全的參考指引與 gcloud 指令。內容涵蓋叢集附加元件(例如 Secret Manager 的啟用與輪替)、針對不安全舊式繫結的 RBAC 強化、Binary Authorization、Secrets Encryption、Security Posture、Shielded Nodes、GKE Sandbox 啟用,以及 GKE IAM 角色。此外也列出黃金路徑安全預設值,以及後端服務帳戶的跨服務 IAM 繫結模式。
適用情境
適用於保護 GKE 叢集控制平面、強化叢集 RBAC、啟用 Shielded Nodes 或 GKE Sandbox 執行環境、啟用叢集層級安全附加元件,或管理 GKE IAM 角色的情境。不適用於 Workload Identity 或工作負載層級控制,例如 SecretProviderClass、Pod 安全標準、網路政策或 gVisor Pod 執行環境類別。
執行需求
僅為說明性內容,不附帶指令碼。執行文件中的指令需要 gcloud CLI 與 GKE 叢集存取權,另外可選用 Kubernetes 工具以及所列的 MCP 工具來檢查叢集與 RBAC。

GKE Platform Security

This reference covers platform-level security hardening and cluster configuration for Google Kubernetes Engine (GKE). For workload-level security controls (such as Workload Identity Service Account bindings, SecretProviderClass volume mounts, Network Policies, and Pod Security Standards), refer to the gke-workload-security skill.

MCP Tools: gke:get_cluster, k8s:check_k8s_auth, k8s:get_k8s_resource, k8s:apply_k8s_manifest, gke:update_cluster

Golden Path Security Defaults

SettingGolden Path ValueDay-0/1Notes
workloadIdentityConfig.workloadPool<PROJECT>.svc.id.googDay-0Workload Identity Federation for cluster pods
secretManagerConfig.enabledtrueDay-1Google Secret Manager cluster add-on integration
secretManagerConfig.rotationConfigenabled: true, rotationInterval: 120sDay-1Automatic secret rotation at the cluster level
rbacBindingConfig.enableInsecureBindingSystemAuthenticatedfalseDay-0Blocks legacy system:authenticated bindings
rbacBindingConfig.enableInsecureBindingSystemUnauthenticatedfalseDay-0Blocks legacy system:unauthenticated bindings
nodeConfig.shieldedInstanceConfig.enableSecureBoottrueDay-0Verifiable boot integrity
nodeConfig.shieldedInstanceConfig.enableIntegrityMonitoringtrueDay-0Runtime integrity checks
nodeConfig.workloadMetadataConfig.modeGKE_METADATADay-0Blocks legacy metadata API, enforces Workload Identity
Private cluster + Dataplane V2 settingsSee the gke-networking skillDay-0Private nodes, private endpoint enforcement, ADVANCED_DATAPATH

Secret Manager Add-on Enablement

The golden path enables Secret Manager at the cluster level with automatic secret rotation.

bash
# Verify Secret Manager is enabled on clustergcloud container clusters describe <CLUSTER_NAME> --region <REGION> \  --format="value(secretManagerConfig.enabled)" \  --quiet
# Enable if not already (Day-1 change)gcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-secret-manager \  --secret-manager-rotation-interval=120s \  --quiet

Note: For configuring SecretProviderClass manifests and mounting secrets as volumes inside application deployments, see the gke-workload-security skill.

RBAC Hardening

The golden path disables insecure legacy RBAC bindings that grant broad access to system:authenticated and system:unauthenticated groups.

bash
# Verify insecure bindings are disabledgcloud container clusters describe <CLUSTER_NAME> --region <REGION> \  --format="yaml(rbacBindingConfig)" \  --quiet

Best practices for RBAC:

  • Use namespace-scoped Roles over cluster-wide ClusterRoles.
  • Bind to specific Groups or ServiceAccounts, never to system:authenticated or system:unauthenticated.
  • Audit permissions via MCP: k8s:check_k8s_auth(parent="...", verb="list", resourceType="pods", namespace="...") (or kubectl auth can-i --list --as=<user>).
  • Review bindings via MCP: k8s:get_k8s_resource(parent="...", resourceType="clusterrolebinding") (or kubectl get clusterrolebindings,rolebindings --all-namespaces).

See the gke-multitenancy skill for enterprise RBAC planning and https://docs.cloud.google.com/kubernetes-engine/docs/best-practices/rbac.md.txt

Binary Authorization

Not enabled in golden path by default but recommended for enforcing production image provenance across the cluster:

bash
# Enable Binary Authorizationgcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --binauthz-evaluation-mode=PROJECT_SINGLETON_POLICY_ENFORCE \  --quiet

Shielded Nodes & GKE Sandbox Enablement

Enabling verifiable node boot integrity and kernel isolation features at the cluster level:

bash
# Enable Shielded Nodes on an existing clustergcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-shielded-nodes \  --quiet
# Enable GKE Sandbox (gVisor) runtime on an existing clustergcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-gke-sandbox \  --quiet

Note: To run workloads inside the gVisor sandbox, specify runtimeClassName: gvisor in your Pod specs as detailed in the gke-workload-security skill.

Common IAM Roles

The five most common predefined IAM roles for GKE platform and cluster access:

RolePurposeWhen to Use
roles/container.adminFull control overPlatform team admins
: : clusters and : managing cluster :
: : Kubernetes : lifecycle :
: : resources : :
roles/container.clusterAdminManage clusters butCluster operators
: : not project-level : who create/delete :
: : IAM : clusters :
roles/container.developerDeploy workloadsApplication
: : (pods, services, : developers deploying :
: : deployments) : to existing clusters :
roles/container.viewerRead-only access toMonitoring,
: : clusters and : auditing, or :
: : Kubernetes : read-only dashboards :
: : resources : :
roles/container.clusterViewerList and getCI/CD pipelines that
: : cluster details : need cluster :
: : only : metadata :

Principle of least privilege: Start with roles/container.viewer or roles/container.developer and escalate only as needed. Avoid granting roles/container.admin broadly across teams.

Service Accounts & Agents

  • GKE Service Agent (service-<PROJECT_NUMBER>@container-engine-robot.iam.gserviceaccount.com): Automatically created. Manages nodes, networking, and cluster operations on your behalf. Do not remove or modify its permissions.
  • Node Service Account: By default, nodes use the Compute Engine default service account. For production platforms, create a dedicated Google Service Account with minimal required permissions (roles/monitoring.metricWriter, roles/logging.logWriter) and assign it at node pool creation time.
  • Workload Identity: For binding Google Service Accounts to Kubernetes Service Accounts (roles/iam.workloadIdentityUser), refer to the gke-workload-security skill.

Cross-Service Authentication Patterns

Common project-level IAM policy binding patterns for granting backend Google Service Accounts (GSAs) access to external Google Cloud services before linking via Workload Identity:

bash
# Grant a GSA access to Cloud Storage objectsgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/storage.objectViewer" \  --quiet
# Grant a GSA access to Cloud SQL databasesgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/cloudsql.client" \  --quiet
# Grant a GSA access to Pub/Sub subscriptionsgcloud projects add-iam-policy-binding <PROJECT_ID> \  --member "serviceAccount:<GSA_NAME>@<PROJECT_ID>.iam.gserviceaccount.com" \  --role "roles/pubsub.subscriber" \  --quiet
## Resources
- [GKE Cluster Hardening Guide](https://cloud.google.com/kubernetes-engine/docs/how-to/hardening-your-cluster)- [GKE RBAC Best Practices](https://cloud.google.com/kubernetes-engine/docs/best-practices/rbac)- [Secret Manager Add-on for GKE](https://cloud.google.com/secret-manager/docs/secret-manager-managed-csi-component)- [Binary Authorization on GKE](https://cloud.google.com/binary-authorization/docs/setting-up)- [Shielded GKE Nodes](https://cloud.google.com/kubernetes-engine/docs/how-to/shielded-gke-nodes)- [GKE Sandbox (gVisor)](https://cloud.google.com/kubernetes-engine/docs/how-to/sandbox-pods)

來源與署名

來源:google/skills位於skills/cloud/gke-platform-security提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Security21K今天更新

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類21K今天更新

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics21K今天更新

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security21K今天更新

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security21K今天更新

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security21K今天更新