Review legacy Basic authentication settings in GKE

Remove obsolete Basic authentication settings and login procedures from GKE configurations.

Description

GKE Basic authentication with a username and password is unsupported from GKE 1.19 onward. Retained static credentials and automation for older clusters need to move to a current authentication method.

Potential impact

Exposed shared credentials can permit cluster access with their assigned privileges. Reliance on obsolete authentication complicates individual attribution and credential replacement and can break management operations.

Remediation

Remove legacy values from master_auth.username and master_auth.password. Move to Google Cloud OAuth token access with least-privilege IAM and Kubernetes RBAC permissions. Remove the old credentials from automation and operating procedures.

Examples

These excerpts compare historical Basic authentication fields; they do not enable Basic authentication on current GKE. Supply the project and the protected service-account JSON file path for your environment.

Before

yaml
- name: create a cluster4
  google.cloud.gcp_container_cluster:
    name: my-cluster4
    initial_node_count: 2
    master_auth:
      username: cluster_admin
      password: ""
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

- name: create a cluster5
  google.cloud.gcp_container_cluster:
    name: my-cluster5
    initial_node_count: 2
    master_auth:
      username: ""
      password: my-secret-password
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

The first task specifies a username. The second is invalid because it supplies a password without a username. Neither is a recommended login method for current GKE.

After

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    master_auth:
      username: ""
      password: ""
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

Empty values leave legacy Basic credentials unused. This neither disables current authentication nor grants IAM permissions.

References