Description
If GKE nodes share the default service account or hold excessive IAM roles, a compromised node can affect other Google Cloud resources. The default account is not inherently an administrator; review its actual role grants.
Potential impact
Misused node credentials can allow reading or modifying resources permitted by the account. Sharing an account also makes permission separation and attribution harder.
Remediation
Set node_config.service_account to the email of a dedicated account with only the roles required for node operations. Prepare the account and roles before changing it and assess disruption. Manage application access to Google Cloud separately with Workload Identity Federation for GKE.
Examples
These excerpts select a node service account. Supply the email of an existing account in node_service_account_email and grant required node roles separately. Also provide the project and Ansible’s JSON credential file path.
Before
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
With no node account specified, nodes use the default service account. The actual risk depends on the roles granted to that account.
After
- name: create a cluster
google.cloud.gcp_container_cluster:
name: my-cluster
initial_node_count: 2
node_config:
machine_type: n1-standard-4
disk_size_gb: 500
service_account: "{{ node_service_account_email }}"
location: us-central1-a
project: "{{ gcp_project }}"
auth_kind: serviceaccount
service_account_file: "{{ gcp_service_account_file }}"
state: present
A separate account is assigned to the nodes. A distinct name alone does not establish least privilege, so review its IAM roles.