GKE cluster labels are not configured

Maintain consistent labels identifying each cluster’s environment and responsible team.

Description

resourceLabels identify a cluster's purpose, environment, responsible organization and cost allocation. Without them, operators can struggle to identify what a cluster is for, and cost analysis or asset management can become inconsistent.

Cluster resource labels differ from Kubernetes Pod labels. They do not themselves restrict IAM permissions or network access.

Potential impact

  • Distinguishing production from test clusters or finding the responsible team can become harder.
  • Cost allocation and asset management can become inefficient.

Remediation

  • Set consistent service, environment and responsible-team identifiers in resourceLabels.
  • Update labels when ownership or use changes and verify that inventory and cost analysis use them. Do not put secrets in labels.

Examples

These partial GKE Cluster request bodies replace the historical Deployment Manager format, whose support has ended. Other settings required for a complete creation request are omitted.

Before

yaml
name: my-cluster

After

yaml
name: my-cluster
resourceLabels:
  env: prod
  owner: platform

Explanation:

  • Before: Labels identifying the environment and responsible team are absent.
  • After: Labels identify production use and the responsible team. Configure access controls separately.

References