Description
Private nodes and a private control-plane endpoint are separate GKE network settings. Private nodes operate without external IP addresses, while a private endpoint helps restrict IP access to the control plane. Review the actual node pools, IP and DNS endpoints, and access policies together.
A public endpoint does not provide unauthenticated access to the cluster. Prepare the required management paths before reducing public exposure.
Potential impact
- Nodes or the control plane may receive connection attempts from a broader range than needed.
- Disabling public access without a working management path can interrupt operators and automation.
Remediation
- Use private nodes for internal workloads and provide their required outbound connectivity.
- Review the control plane’s actual IP and DNS access settings and authorized networks. Test an approved management connection, such as a VPN, before relying on private IP access.
- Apply least-privilege IAM and RBAC permissions and firewall controls. Verify required access and intended restrictions after the change.
Examples
Deployment Manager is no longer supported. These are cluster request-body excerpts; location, nodes and VPC network settings are omitted. Prepare the actual configuration with a supported management tool.
Before
name: mycluster
After
name: mycluster
privateClusterConfig:
enablePrivateEndpoint: true
enablePrivateNodes: true
Explanation:
- Before: Private networking settings are not specified in this excerpt. Check the actual cluster access paths separately.
- After: Private nodes and a private IP endpoint are requested. Management access and required node egress need separate configuration.