Legacy ABAC authorization is enabled in GKE

Migrate required access to RBAC before disabling legacy GKE ABAC authorization.

Description

GKE legacyAbac.enabled controls the legacy ABAC authorization mechanism. It can grant broad cluster API permissions, making an RBAC-only review insufficient to establish effective access.

Before disabling it, verify that required users and workloads can operate with their RBAC permissions.

Potential impact

  • Users or workloads may receive permission for cluster operations beyond their needs.
  • Exposed credentials with excessive permissions can increase damage to cluster resources.

Remediation

  • Prepare required roles and bindings and test least-privilege operation.
  • Set legacyAbac.enabled to false and apply the change to the actual cluster.
  • Remove unnecessary administrative permissions and recheck access for existing clients and automation.

Examples

Deployment Manager support has ended. These settings are excerpts from a cluster request body. Prepare the actual location, node, network and update configuration using a supported management tool.

Before

yaml
name: my-cluster
legacyAbac:
  enabled: true

Legacy ABAC authorization is enabled.

After

yaml
name: my-cluster
legacyAbac:
  enabled: false

Legacy ABAC authorization is disabled. Prepare required RBAC permissions first to avoid interrupting access.

References