Description
A legacy client certificate is a credential for accessing the GKE cluster API. In the Ansible google.cloud.gcp_container_cluster module, master_auth.client_certificate_config.issue_client_certificate controls whether a certificate is issued. This setting is separate from verification of the API server's TLS certificate.
Legacy authentication has been disabled by default since GKE 1.12 and is unavailable in Autopilot. Disabling client certificate issuance still allows OAuth authentication and verification of the API server's TLS certificate.
Potential impact
If a client certificate is exposed, someone else can use its permissions to access the cluster. Disabling issuance does not remove permissions from certificates that have already been issued, so existing certificates and their access permissions also need attention.
Remediation
- Disable legacy client certificate issuance for new clusters and use OAuth authentication. Grant only the necessary permissions through IAM or Kubernetes RBAC. Configure the GKE authentication plugin if you use
kubectl. - For existing clusters, review the authentication methods and granted permissions. Follow Google's procedures for configuring RBAC and removing certificate permissions, then confirm that operators and automation jobs can still access the cluster.
Examples
These older configurations illustrate the certificate issuance option. Both include basic authentication (username and password), which was removed in GKE 1.19. Do not apply them unchanged to a current environment.
Certificate issuance disabled
- name: create a cluster3
google.cloud.gcp_container_cluster:
name: my-cluster3
initial_node_count: 2
master_auth:
username: cluster_admin
password: my-secret-password
client_certificate_config:
issue_client_certificate: no
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
issue_client_certificate: no disables client certificate issuance.
Older configuration with issuance enabled
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
master_auth:
username: cluster_admin
password: my-secret-password
client_certificate_config:
issue_client_certificate: yes
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
issue_client_certificate: yes issues a legacy client certificate. Do not use it as the recommended authentication setup for a new cluster.