Description
resource_labels identify a GKE cluster's purpose, environment and responsible team. Missing labels can hinder resource tracking and make cost analysis or asset management inconsistent.
Cluster resource labels differ from Kubernetes Pod labels. Labels do not themselves restrict IAM permissions or network access.
Potential impact
- Identifying a cluster's purpose and responsible team can become harder.
- Cost analysis and asset automation can lack necessary information.
Remediation
- Set
resource_labelsas a key-value map in thegoogle.cloud.gcp_container_clustertask. - Standardize environment, system and responsible-team labels, and update them when those details change. Do not include secrets in labels.
Examples
These are task excerpts. Replace the project, cluster names and service-account JSON file path for your environment. Check networking and other cluster requirements separately.
Before
yaml
- name: GKE 클러스터 생성
google.cloud.gcp_container_cluster:
name: my-cluster1
initial_node_count: 2
location: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
After
yaml
- name: GKE 클러스터 생성
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
location: us-central1-a
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
resource_labels:
env: prod
owner: platform
Explanation:
- Before: No labels identify the purpose or responsible team.
- After: A map identifies the environment and responsible team. Configure access controls separately.