Description
Master Authorized Networks restricts source addresses that can reach GKE control plane IP endpoints. Allowing networks that do not need administrative access increases opportunities for API access attempts. Review IAM access to the DNS endpoint separately.
Potential impact
With a public endpoint and a network path, scans and authentication attempts from external clients can reach the API server. Connectivity alone does not bypass authentication or authorization.
Remediation
For IP endpoints, set master_authorized_networks_config.enabled: yes and limit cidr_blocks to approved management sources. Verify the separate enforcement setting for the internal IP endpoint. Confirm required VPN or jump-host paths before the change and remove temporary exceptions. Restrict IAM and RBAC permissions separately.
Examples
These excerpts show access restrictions. Replace the documentation range 192.0.2.0/24 with the approved source range actually used by management clients.
Before
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
location: us-central1-a
auth_kind: serviceaccount
master_authorized_networks_config:
cidr_blocks:
- cidr_block: 192.0.2.0/24
enabled: no
state: present
- name: create a third cluster
google.cloud.gcp_container_cluster:
name: my-third-cluster
location: us-central1-a
auth_kind: serviceaccount
state: present
The first task lists a range but disables the feature. Omitting the setting in the second task does not by itself establish whether the actual endpoint is public.
After
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
location: us-central1-a
auth_kind: serviceaccount
master_authorized_networks_config:
cidr_blocks:
- cidr_block: 192.0.2.0/24
enabled: yes
state: present
This enables the management CIDR allow-list. Verify internal IP endpoint enforcement and required operational access separately.