Review GKE private cluster settings

Review the actual network paths to GKE nodes and the control plane, and allow only required access.

Description

Private nodes and a private control-plane endpoint are separate GKE network settings. Private nodes operate without external IP addresses, while a private endpoint helps restrict IP access to the control plane. Review the actual node pools, IP and DNS endpoints, and access policies together.

A public endpoint does not provide unauthenticated access to the cluster. Prepare the required management paths before reducing public exposure.

Potential impact

  • Nodes or the control plane may receive connection attempts from a broader range than needed.
  • Disabling public access without a working management path can interrupt operators and automation.

Remediation

  • Use private nodes for internal workloads and provide their required outbound connectivity.
  • Review the control plane’s actual IP and DNS access settings and authorized networks. Test an approved management connection, such as a VPN, before relying on private IP access.
  • Apply least-privilege IAM and RBAC permissions and firewall controls. Verify required access and intended restrictions after the change.

Examples

Deployment Manager is no longer supported. These are cluster request-body excerpts; location, nodes and VPC network settings are omitted. Prepare the actual configuration with a supported management tool.

Before

yaml
name: mycluster

After

yaml
name: mycluster
privateClusterConfig:
  enablePrivateEndpoint: true
  enablePrivateNodes: true

Explanation:

  • Before: Private networking settings are not specified in this excerpt. Check the actual cluster access paths separately.
  • After: Private nodes and a private IP endpoint are requested. Management access and required node egress need separate configuration.

References