Description
GKE’s legacy ABAC authorization can grant broad access, making granular permission management difficult. Manage cluster access through Kubernetes RBAC and IAM with legacy ABAC disabled.
Potential impact
Permissions broader than the intended RBAC restrictions may allow users or service accounts to access resources they do not need.
Remediation
Configure and verify the required RBAC permissions before setting enable_legacy_abac = false. Grant users and service accounts only the permissions their work requires.
Examples
These examples disable legacy ABAC for the cluster. Configure the required RBAC bindings separately.
Before
hcl
resource "google_container_cluster" "primary_cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
enable_legacy_abac = true
}
After
hcl
resource "google_container_cluster" "primary_cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
enable_legacy_abac = false
}