Description
A default service account may be shared across purposes or hold excessive permissions. A default account is not inherently an administrator, so inspect its actual IAM grants.
Prefer a dedicated, least-privilege account for GKE nodes. Separate application access to Google Cloud from node permissions using mechanisms such as Workload Identity Federation for GKE.
Potential impact
- Leaked node credentials can expose other Google Cloud resources allowed by the account.
- A shared account can make permission separation and attribution harder.
Remediation
- Set
node_config.service_accounton the actual operating node pools to a dedicated account. - Prepare the required node-operation IAM roles first and remove unnecessary roles.
- Assess node replacement and service disruption when changing accounts, and manage workload cloud permissions separately.
Examples
These excerpts create and then remove the default node pool. Define google_service_account.myserviceaccount and its IAM roles separately, and set node_config.service_account on the separate node pools that will actually run workloads.
Before
hcl
resource "google_container_cluster" "example" {
name = "my-gke-cluster"
location = "us-central1"
remove_default_node_pool = true
initial_node_count = 1
node_config {
oauth_scopes = [
"https://www.googleapis.com/auth/cloud-platform"
]
}
}
After
hcl
resource "google_container_cluster" "example" {
name = "my-gke-cluster"
location = "us-central1"
remove_default_node_pool = true
initial_node_count = 1
node_config {
service_account = google_service_account.myserviceaccount.email
oauth_scopes = [
"https://www.googleapis.com/auth/cloud-platform"
]
}
}
Explanation:
- Before: No account is specified for the temporary default node pool. The account used by separate pools after its removal is not determined by this excerpt.
- After: An account is selected for the temporary default pool. Apply it to the operating pools too, and minimize IAM roles separately from the cloud-platform scope.