Review GKE client certificate settings

Use recommended authentication and least-privilege authorization for GKE access.

Description

masterAuth.clientCertificateConfig.issueClientCertificate controls issuance of a legacy GKE client certificate. Google discourages this authentication method. Setting it to false does not disable cluster authentication or server TLS.

Use recommended Google Cloud authentication with the required IAM and RBAC permissions. Possessing a certificate and being authorized to perform an operation are separate matters.

Potential impact

  • Unneeded legacy credentials can add access paths that may be misused if exposed.
  • Excessive IAM or RBAC permissions can let authenticated users perform operations they do not need.

Remediation

  • Avoid issuing unnecessary client certificates in new configurations and use supported authentication methods.
  • Identify clients using existing certificates and migrate them to replacement authentication. Changing this option alone cannot remove certificates already issued.
  • Remove unnecessary permission bindings and verify that required access works and unwanted access is denied.

Examples

Deployment Manager support has ended. These are authentication excerpts from a GKE Standard cluster request body. Supply the actual location, node and network configuration separately and use a supported management tool.

Before

yaml
name: my-cluster
masterAuth:
  clientCertificateConfig:
    issueClientCertificate: true

This requests issuance of a legacy client certificate.

After

yaml
name: my-cluster
masterAuth:
  clientCertificateConfig:
    issueClientCertificate: false

This does not request a client certificate. Actual client authentication and IAM/RBAC permissions still require separate configuration.

References