Review GKE control-plane authorized networks

Limit IP access to the GKE control plane to the management networks that need it.

Description

GKE authorized networks restrict the source ranges that can reach control-plane IP endpoints. Allowing only approved CIDRs can reduce unnecessary connection attempts where management networks are known.

Review the actual IP and DNS endpoints and other access controls together. Network access does not replace authentication or IAM and RBAC authorization.

Potential impact

  • Networks beyond the required management scope may be able to attempt control-plane connections.
  • An incorrect restriction can disconnect operators or automation.

Remediation

  • When using IP endpoints, configure approved management CIDRs in masterAuthorizedNetworksConfig.
  • Select ranges based on actual connection paths and source addresses, such as VPNs, bastions or fixed office IPs.
  • Review enforcement on private endpoints and access controls for DNS paths. Test required management connections and intended restrictions after changes.

Examples

Deployment Manager is no longer supported. These are partial cluster request bodies; location, node and network settings are omitted. Prepare the actual configuration with a supported management tool.

Before

yaml
name: my-cluster
description: cluster

After

yaml
name: my-cluster
description: cluster
masterAuthorizedNetworksConfig:
  enabled: true

Explanation:

  • Before: Authorized networks are not specified in this excerpt. Review the actual endpoints and access policies.
  • After: Authorized networks are enabled, but no management CIDRs are added. Confirm the required ranges and working management connections before applying the configuration.

References