Legacy ABAC authorization enabled in GKE

Disable legacy ABAC and use fine-grained access control in GKE

Description

GKE’s legacy ABAC authorization can grant broad access, making granular permission management difficult. Manage cluster access through Kubernetes RBAC and IAM with legacy ABAC disabled.

Potential impact

Permissions broader than the intended RBAC restrictions may allow users or service accounts to access resources they do not need.

Remediation

Configure and verify the required RBAC permissions before setting enable_legacy_abac = false. Grant users and service accounts only the permissions their work requires.

Examples

These examples disable legacy ABAC for the cluster. Configure the required RBAC bindings separately.

Before

hcl
resource "google_container_cluster" "primary_cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  enable_legacy_abac = true
}

After

hcl
resource "google_container_cluster" "primary_cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3
  enable_legacy_abac = false
}

References