Review authorized networks for the GKE control plane

Limit access to GKE control plane IP endpoints to required management networks.

Description

Master Authorized Networks restricts source addresses that can reach GKE control plane IP endpoints. Allowing networks that do not need administrative access increases opportunities for API access attempts. Review IAM access to the DNS endpoint separately.

Potential impact

With a public endpoint and a network path, scans and authentication attempts from external clients can reach the API server. Connectivity alone does not bypass authentication or authorization.

Remediation

For IP endpoints, set master_authorized_networks_config.enabled: yes and limit cidr_blocks to approved management sources. Verify the separate enforcement setting for the internal IP endpoint. Confirm required VPN or jump-host paths before the change and remove temporary exceptions. Restrict IAM and RBAC permissions separately.

Examples

These excerpts show access restrictions. Replace the documentation range 192.0.2.0/24 with the approved source range actually used by management clients.

Before

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    location: us-central1-a
    auth_kind: serviceaccount
    master_authorized_networks_config:
      cidr_blocks:
        - cidr_block: 192.0.2.0/24
      enabled: no
    state: present

- name: create a third cluster
  google.cloud.gcp_container_cluster:
    name: my-third-cluster
    location: us-central1-a
    auth_kind: serviceaccount
    state: present

The first task lists a range but disables the feature. Omitting the setting in the second task does not by itself establish whether the actual endpoint is public.

After

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    location: us-central1-a
    auth_kind: serviceaccount
    master_authorized_networks_config:
      cidr_blocks:
        - cidr_block: 192.0.2.0/24
      enabled: yes
    state: present

This enables the management CIDR allow-list. Verify internal IP endpoint enforcement and required operational access separately.

References