Description
The GKE control plane manages cluster workloads and permissions, so its users and their privileges need clear controls. Omitting master_auth does not disable authentication. Basic authentication using the username and password in this block is unsupported from GKE 1.19 onward.
Potential impact
Excessive administrative permissions or exposed credentials can allow workload changes and data access. Automation that relies on an obsolete login method can also fail.
Remediation
Use current authentication with Google Cloud OAuth tokens and limit IAM and Kubernetes RBAC permissions to required operations. Remove obsolete username/password login procedures and verify access for approved operators.
Examples
These are cluster configuration excerpts. Supply the project and the path to a protected service-account JSON file. Manage Ansible deployment credentials separately from cluster operators’ permissions.
Before
- name: GKE 클러스터 생성
google.cloud.gcp_container_cluster:
name: my-cluster1
initial_node_count: 2
node_config:
machine_type: n1-standard-4
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
The absence of master_auth does not by itself permit unauthenticated access.
After
- name: GKE 클러스터 생성
google.cloud.gcp_container_cluster:
name: my-cluster1
initial_node_count: 2
master_auth:
username: ""
password: ""
node_config:
machine_type: n1-standard-4
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
Empty username and password values specify that legacy Basic credentials are not used. IAM and RBAC permissions still need separate configuration.