Review GKE control plane authentication

Review authentication and IAM and RBAC permissions for the GKE control plane.

Description

The GKE control plane manages cluster workloads and permissions, so its users and their privileges need clear controls. Omitting master_auth does not disable authentication. Basic authentication using the username and password in this block is unsupported from GKE 1.19 onward.

Potential impact

Excessive administrative permissions or exposed credentials can allow workload changes and data access. Automation that relies on an obsolete login method can also fail.

Remediation

Use current authentication with Google Cloud OAuth tokens and limit IAM and Kubernetes RBAC permissions to required operations. Remove obsolete username/password login procedures and verify access for approved operators.

Examples

These are cluster configuration excerpts. Supply the project and the path to a protected service-account JSON file. Manage Ansible deployment credentials separately from cluster operators’ permissions.

Before

yaml
- name: GKE 클러스터 생성
  google.cloud.gcp_container_cluster:
    name: my-cluster1
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

The absence of master_auth does not by itself permit unauthenticated access.

After

yaml
- name: GKE 클러스터 생성
  google.cloud.gcp_container_cluster:
    name: my-cluster1
    initial_node_count: 2
    master_auth:
      username: ""
      password: ""
    node_config:
      machine_type: n1-standard-4
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

Empty username and password values specify that legacy Basic credentials are not used. IAM and RBAC permissions still need separate configuration.

References