Review GKE authentication and access permissions

Review supported GKE authentication and least privilege without re-enabling removed basic authentication.

Description

GKE’s masterAuth.username and masterAuth.password are legacy HTTP basic-authentication settings. Basic authentication was removed in GKE 1.19; omitting these settings does not disable cluster authentication.

Use recommended Google Cloud OAuth authentication and the required IAM and RBAC permissions. Successful authentication and permitted operations must be managed separately.

Potential impact

  • Unnecessary legacy credentials can increase the risk of exposure or misuse.
  • Excessive IAM and RBAC permissions can let authenticated users act beyond their needs.

Remediation

  • Configure operators and automation to use supported authentication and test required access.
  • Do not add a static administrator password to the template. Move clients that depend on legacy credentials to supported methods.
  • Remove unnecessary permission bindings and verify that intended access and restrictions are enforced.

Examples

Deployment Manager is no longer supported. These are authentication-related cluster request-body excerpts. Configure actual client authentication, authorization and other cluster settings separately with supported tools.

Before

yaml
name: cluster
description: cluster

After

yaml
name: cluster
masterAuth:
  clientCertificateConfig:
    issueClientCertificate: false

Explanation:

  • Before: masterAuth is omitted. That alone does not create a cluster with authentication disabled.
  • After: No static password is added and legacy client certificate issuance is not requested. This does not configure OAuth or IAM and RBAC, nor revoke already issued certificates.

References