GKE nodes use the default service account

Use a dedicated GKE node service account with only the roles the nodes require.

Description

If GKE nodes share the default service account or hold excessive IAM roles, a compromised node can affect other Google Cloud resources. The default account is not inherently an administrator; review its actual role grants.

Potential impact

Misused node credentials can allow reading or modifying resources permitted by the account. Sharing an account also makes permission separation and attribution harder.

Remediation

Set node_config.service_account to the email of a dedicated account with only the roles required for node operations. Prepare the account and roles before changing it and assess disruption. Manage application access to Google Cloud separately with Workload Identity Federation for GKE.

Examples

These excerpts select a node service account. Supply the email of an existing account in node_service_account_email and grant required node roles separately. Also provide the project and Ansible’s JSON credential file path.

Before

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

With no node account specified, nodes use the default service account. The actual risk depends on the roles granted to that account.

After

yaml
- name: create a cluster
  google.cloud.gcp_container_cluster:
    name: my-cluster
    initial_node_count: 2
    node_config:
      machine_type: n1-standard-4
      disk_size_gb: 500
      service_account: "{{ node_service_account_email }}"
    location: us-central1-a
    project: "{{ gcp_project }}"
    auth_kind: serviceaccount
    service_account_file: "{{ gcp_service_account_file }}"
    state: present

A separate account is assigned to the nodes. A distinct name alone does not establish least privilege, so review its IAM roles.

References