Legacy client certificate authentication in GKE

Use recommended GKE authentication and manage access granted to existing legacy client certificates.

Description

A legacy client certificate is a credential for accessing the GKE cluster API. In the Ansible google.cloud.gcp_container_cluster module, master_auth.client_certificate_config.issue_client_certificate controls whether a certificate is issued. This setting is separate from verification of the API server's TLS certificate.

Legacy authentication has been disabled by default since GKE 1.12 and is unavailable in Autopilot. Disabling client certificate issuance still allows OAuth authentication and verification of the API server's TLS certificate.

Potential impact

If a client certificate is exposed, someone else can use its permissions to access the cluster. Disabling issuance does not remove permissions from certificates that have already been issued, so existing certificates and their access permissions also need attention.

Remediation

  • Disable legacy client certificate issuance for new clusters and use OAuth authentication. Grant only the necessary permissions through IAM or Kubernetes RBAC. Configure the GKE authentication plugin if you use kubectl.
  • For existing clusters, review the authentication methods and granted permissions. Follow Google's procedures for configuring RBAC and removing certificate permissions, then confirm that operators and automation jobs can still access the cluster.

Examples

These older configurations illustrate the certificate issuance option. Both include basic authentication (username and password), which was removed in GKE 1.19. Do not apply them unchanged to a current environment.

Certificate issuance disabled

yaml
- name: create a cluster3
  google.cloud.gcp_container_cluster:
    name: my-cluster3
    initial_node_count: 2
    master_auth:
      username: cluster_admin
      password: my-secret-password
      client_certificate_config:
        issue_client_certificate: no
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present

issue_client_certificate: no disables client certificate issuance.

Older configuration with issuance enabled

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    master_auth:
      username: cluster_admin
      password: my-secret-password
      client_certificate_config:
        issue_client_certificate: yes
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

issue_client_certificate: yes issues a legacy client certificate. Do not use it as the recommended authentication setup for a new cluster.

References