Gke Workload Security

作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running security audits (`audit_cluster.sh`), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling) and pod securityContext, and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing workload security posture, isolating namespaces, applying pod security standards, or configuring network policies and secret volume mounts. Don't use for Workload Identity (use gke-workload-identity), cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

精選包含腳本SecurityDevOps & Cloud
AI 產生的概覽

稽核並強化 GKE 工作負載安全:網路政策、沙箱隔離、Pod 安全標準與密鑰掛載。

功能
提供用於保護 Google Kubernetes Engine 工作負載的工作流程與資訊清單,包括一支叢集稽核指令碼,用來檢查 Workload Identity、網路政策、Shielded Nodes、Binary Authorization 與私有叢集設定。內容也涵蓋套用預設拒絕網路政策、在 GKE Sandbox(gVisor)中執行 Pod、強制套用 Pod Security Standards 標籤、透過 CSI 驅動程式掛載 Secret Manager 密鑰,以及啟用 Dataplane V2 網路記錄。此技能附有一支稽核 shell 指令碼,以及網路政策與工作負載身分 Pod 的範例 YAML 資源。
適用情境
適用於稽核或強化 GKE 中工作負載層級的安全態勢、以網路政策隔離命名空間、套用 Pod 安全標準、將不受信任的 Pod 放入沙箱,或設定密鑰磁碟區掛載。不適用於 Workload Identity 繫結、叢集控制平面安全、RBAC 強化、Binary Authorization 或平台層級外掛。
執行需求
需要已驗證並指向 GKE 專案的 gcloud CLI,以及供稽核指令碼使用的 jq JSON 處理器;套用資訊清單需要 kubectl。Secret Manager CSI 驅動程式與 Dataplane V2 等叢集端功能必須已啟用。附有一支可執行稽核指令碼與 YAML 資源。

GKE Workload Security

Routing Note: For Workload Identity KSA/GSA bindings, open gke-workload-identity/SKILL.md. For cluster-level security flags (--database-encryption-key, --security-posture, RBAC, Shielded Nodes, Binary Authorization), open gke-platform-security/SKILL.md.

This skill provides workflows and best practices for securing GKE workloads. It covers security auditing, Identity and Access Management (Workload Identity), Network Security (Network Policies), and Node Security.

Workflows

1. Security Audit

Assess the current security posture of your cluster using the provided audit script.

Prerequisites:

  • gcloud CLI authenticated.
  • jq command-line JSON processor installed.

Capabilities:

  • Checks for Workload Identity.
  • Verifies Network Policy is enabled.
  • Checks if Shielded Nodes are enabled.
  • Checks if Binary Authorization is enabled.
  • Checks for Private Cluster configuration.

Command:

bash
scripts/audit_cluster.sh <cluster-name> <region> <project-id>

2. Configure Workload Identity

Workload Identity allows Kubernetes Service Accounts (KSAs) to impersonate Google Service Accounts (GSAs). This is the recommended method for workloads to access Google Cloud APIs.

Steps:

  1. Create Namespace and KSA:

    bash
    kubectl create namespace workload-identity-test-nskubectl create serviceaccount <ksa-name> \    --namespace workload-identity-test-ns
  2. Bind KSA to GSA:

    bash
    gcloud iam service-accounts add-iam-policy-binding <gsa-name>@<project-id>.iam.gserviceaccount.com \    --role roles/iam.workloadIdentityUser \    --member "serviceAccount:<project-id>.svc.id.goog[workload-identity-test-ns/<ksa-name>]"
  3. Annotate KSA:

    bash
    kubectl annotate serviceaccount <ksa-name> \    --namespace workload-identity-test-ns \    iam.gke.io/gcp-service-account=<gsa-name>@<project-id>.iam.gserviceaccount.com
  4. Verify Example Pod: Use existing asset assets/workload-identity-pod.yaml to test the configuration. Update the <ksa-name> in the file first.

    bash
    kubectl apply -f assets/workload-identity-pod.yaml -n workload-identity-test-ns

3. Implement Network Policies

Control traffic flow between Pods using Network Policies. By default, all traffic is allowed.

Enable Network Policy Enforcement:

bash
gcloud container clusters update <cluster-name> \    --update-addons=NetworkPolicy=ENABLED \    --region <region>

[!NOTE] If your cluster uses Dataplane V2 (--enable-dataplane-v2), Network Policy enforcement is built-in and this step is not required (and may fail).

Apply Default Deny Policy: Isolate namespaces by denying all ingress and egress traffic by default.

Replace <target-namespace> with the namespace you want to isolate.

bash
kubectl apply -f assets/default-deny-netpol.yaml -n <target-namespace>

4. GKE Sandbox (gVisor) Pod Isolation

Run untrusted workloads in a sandbox for extra kernel isolation. (Note: Enabling Shielded Nodes (--enable-shielded-nodes) and GKE Sandbox (--enable-gke-sandbox) at the cluster control plane level are platform-level actions covered in the gke-platform-security skill.)

Run a Sandboxed Pod: Add runtimeClassName: gvisor to your Pod spec:

yaml
apiVersion: v1kind: Podmetadata:  name: sandboxed-podspec:  runtimeClassName: gvisor  containers:  - name: app    image: nginx

5. Pod Security Standards

Enforce security policies on namespaces using labels.

Enforce Restricted Profile:

bash
kubectl label --overwrite ns <namespace> \    pod-security.kubernetes.io/enforce=restricted \    pod-security.kubernetes.io/enforce-version=latest

[!NOTE] Using latest ensures you use the policies corresponding to the cluster's current version. You can pin it to a specific version (e.g., v1.30) to lock down the namespace to policies of a specific release.

6. Secret Manager Integration (CSI Driver)

Mount secrets from Google Cloud Secret Manager directly as volumes in your pods.

Prerequisites: Secret Manager CSI driver must be enabled on the cluster.

Example SecretProviderClass:

yaml
apiVersion: secrets-store.csi.x-k8s.io/v1kind: SecretProviderClassmetadata:  name: my-secret-providerspec:  provider: gcp  parameters:    secrets: |      - resourceName: "projects/<project-id>/secrets/my-secret/versions/latest"        fileName: "my-secret-file"

Example Pod Spec excerpt:

yaml
spec:  containers:    - name: my-app      volumeMounts:        - name: secrets-store-inline          mountPath: "/mnt/secrets"          readOnly: true  volumes:    - name: secrets-store-inline      csi:        driver: secrets-store.csi.k8s.io        readOnly: true        volumeAttributes:          secretProviderClass: "my-secret-provider"

7. Enable Network Policy Logging

If using GKE Dataplane V2, you can log allowed and denied connections.

Steps:

  1. Configure the NetworkLogging custom resource.

Example NetworkLogging Manifest:

yaml
apiVersion: networking.gke.io/v1alpha1kind: NetworkLoggingmetadata:  name: defaultspec:  cluster:    allow:      log: true      delegate: true    deny:      log: true      delegate: true

This will log connection details to Cloud Logging.

Best Practices

  1. Least Privilege: Always use Workload Identity with minimal IAM roles. Avoid using Node default service accounts.
  2. Network Isolation: Use Network Policies to restrict Pod-to-Pod communication. Enable Network Policy Logging for visibility.
  3. Image Security: Use Binary Authorization to ensure only trusted images are deployed.
  4. Secret Management: Use Secret Manager CSI driver instead of default Kubernetes secrets for sensitive data.
  5. Pod Security: Enforce baseline or restricted Pod Security Standards on all non-system namespaces.
  6. Policy Enforcement: Consider using Policy Controller (Gatekeeper) to enforce custom security and compliance policies across the cluster.

Resources

來源與署名

來源:google/skills位於skills/cloud/gke-workload-security提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Security21K今天更新

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類21K今天更新

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics21K今天更新

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security21K今天更新

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security21K今天更新

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security21K今天更新