Review GKE node service-account permissions

Grant a dedicated node service account only the IAM roles the nodes require.

Description

A default service account may be shared across purposes or hold excessive permissions. A default account is not inherently an administrator, so inspect its actual IAM grants.

Prefer a dedicated, least-privilege account for GKE nodes. Separate application access to Google Cloud from node permissions using mechanisms such as Workload Identity Federation for GKE.

Potential impact

  • Leaked node credentials can expose other Google Cloud resources allowed by the account.
  • A shared account can make permission separation and attribution harder.

Remediation

  • Set node_config.service_account on the actual operating node pools to a dedicated account.
  • Prepare the required node-operation IAM roles first and remove unnecessary roles.
  • Assess node replacement and service disruption when changing accounts, and manage workload cloud permissions separately.

Examples

These excerpts create and then remove the default node pool. Define google_service_account.myserviceaccount and its IAM roles separately, and set node_config.service_account on the separate node pools that will actually run workloads.

Before

hcl
resource "google_container_cluster" "example" {
  name                     = "my-gke-cluster"
  location                 = "us-central1"
  remove_default_node_pool = true
  initial_node_count       = 1

  node_config {
    oauth_scopes = [
      "https://www.googleapis.com/auth/cloud-platform"
    ]
  }
}

After

hcl
resource "google_container_cluster" "example" {
  name                     = "my-gke-cluster"
  location                 = "us-central1"
  remove_default_node_pool = true
  initial_node_count       = 1

  node_config {
    service_account = google_service_account.myserviceaccount.email
    oauth_scopes = [
      "https://www.googleapis.com/auth/cloud-platform"
    ]
  }
}

Explanation:

  • Before: No account is specified for the temporary default node pool. The account used by separate pools after its removal is not determined by this excerpt.
  • After: An account is selected for the temporary default pool. Apply it to the operating pools too, and minimize IAM roles separately from the cloud-platform scope.

References