Description
GKE’s masterAuth.username and masterAuth.password are legacy HTTP basic-authentication settings. Basic authentication was removed in GKE 1.19; omitting these settings does not disable cluster authentication.
Use recommended Google Cloud OAuth authentication and the required IAM and RBAC permissions. Successful authentication and permitted operations must be managed separately.
Potential impact
- Unnecessary legacy credentials can increase the risk of exposure or misuse.
- Excessive IAM and RBAC permissions can let authenticated users act beyond their needs.
Remediation
- Configure operators and automation to use supported authentication and test required access.
- Do not add a static administrator password to the template. Move clients that depend on legacy credentials to supported methods.
- Remove unnecessary permission bindings and verify that intended access and restrictions are enforced.
Examples
Deployment Manager is no longer supported. These are authentication-related cluster request-body excerpts. Configure actual client authentication, authorization and other cluster settings separately with supported tools.
Before
yaml
name: cluster
description: cluster
After
yaml
name: cluster
masterAuth:
clientCertificateConfig:
issueClientCertificate: false
Explanation:
- Before:
masterAuthis omitted. That alone does not create a cluster with authentication disabled. - After: No static password is added and legacy client certificate issuance is not requested. This does not configure OAuth or IAM and RBAC, nor revoke already issued certificates.