Description
GKE legacyAbac.enabled controls the legacy ABAC authorization mechanism. It can grant broad cluster API permissions, making an RBAC-only review insufficient to establish effective access.
Before disabling it, verify that required users and workloads can operate with their RBAC permissions.
Potential impact
- Users or workloads may receive permission for cluster operations beyond their needs.
- Exposed credentials with excessive permissions can increase damage to cluster resources.
Remediation
- Prepare required roles and bindings and test least-privilege operation.
- Set
legacyAbac.enabledtofalseand apply the change to the actual cluster. - Remove unnecessary administrative permissions and recheck access for existing clients and automation.
Examples
Deployment Manager support has ended. These settings are excerpts from a cluster request body. Prepare the actual location, node, network and update configuration using a supported management tool.
Before
yaml
name: my-cluster
legacyAbac:
enabled: true
Legacy ABAC authorization is enabled.
After
yaml
name: my-cluster
legacyAbac:
enabled: false
Legacy ABAC authorization is disabled. Prepare required RBAC permissions first to avoid interrupting access.