Description
GKE authorized networks restrict the source ranges that can reach control-plane IP endpoints. Allowing only approved CIDRs can reduce unnecessary connection attempts where management networks are known.
Review the actual IP and DNS endpoints and other access controls together. Network access does not replace authentication or IAM and RBAC authorization.
Potential impact
- Networks beyond the required management scope may be able to attempt control-plane connections.
- An incorrect restriction can disconnect operators or automation.
Remediation
- When using IP endpoints, configure approved management CIDRs in
masterAuthorizedNetworksConfig. - Select ranges based on actual connection paths and source addresses, such as VPNs, bastions or fixed office IPs.
- Review enforcement on private endpoints and access controls for DNS paths. Test required management connections and intended restrictions after changes.
Examples
Deployment Manager is no longer supported. These are partial cluster request bodies; location, node and network settings are omitted. Prepare the actual configuration with a supported management tool.
Before
yaml
name: my-cluster
description: cluster
After
yaml
name: my-cluster
description: cluster
masterAuthorizedNetworksConfig:
enabled: true
Explanation:
- Before: Authorized networks are not specified in this excerpt. Review the actual endpoints and access policies.
- After: Authorized networks are enabled, but no management CIDRs are added. Confirm the required ranges and working management connections before applying the configuration.