Description
GKE Basic authentication with a username and password is unsupported from GKE 1.19 onward. Retained static credentials and automation for older clusters need to move to a current authentication method.
Potential impact
Exposed shared credentials can permit cluster access with their assigned privileges. Reliance on obsolete authentication complicates individual attribution and credential replacement and can break management operations.
Remediation
Remove legacy values from master_auth.username and master_auth.password. Move to Google Cloud OAuth token access with least-privilege IAM and Kubernetes RBAC permissions. Remove the old credentials from automation and operating procedures.
Examples
These excerpts compare historical Basic authentication fields; they do not enable Basic authentication on current GKE. Supply the project and the protected service-account JSON file path for your environment.
Before
- name: create a cluster4
google.cloud.gcp_container_cluster:
name: my-cluster4
initial_node_count: 2
master_auth:
username: cluster_admin
password: ""
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
- name: create a cluster5
google.cloud.gcp_container_cluster:
name: my-cluster5
initial_node_count: 2
master_auth:
username: ""
password: my-secret-password
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
The first task specifies a username. The second is invalid because it supplies a password without a username. Neither is a recommended login method for current GKE.
After
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
master_auth:
username: ""
password: ""
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
Empty values leave legacy Basic credentials unused. This neither disables current authentication nor grants IAM permissions.