Review legacy GKE Kubernetes Dashboard use

Remove unnecessary management UIs and manage the cluster through supported authentication and authorization controls.

Description

Kubernetes Dashboard provides powerful cluster-management functions. Unnecessary exposure can combine with stolen credentials or excessive permissions to allow resource manipulation. The legacy addons_config.kubernetes_dashboard field was removed in Google Provider 3.0; do not add it to modern configurations.

Potential impact

  • An unnecessary management UI can increase the attack surface.
  • Compromise of the Dashboard service account or authentication path can allow changes within its granted permissions.

Remediation

  • Disable or remove unnecessary Dashboard installations. In environments that support the legacy add-on, the relevant setting is kubernetes_dashboard.disabled = true.
  • Migrate to supported GKE and provider versions and remove obsolete fields. Review authentication, network access and least privilege for separately installed management UIs as well.

Examples

These historical examples use GKE 1.9.7 and an older provider. Do not deploy them as current configurations; migrate to supported versions.

Before

hcl
resource "google_container_cluster" "legacy" {
  name               = "legacy-cluster"
  location           = "asia-northeast3"
  min_master_version = "1.9.7"

  addons_config {
    kubernetes_dashboard {
      disabled = false
    }
  }
}

After

hcl
resource "google_container_cluster" "legacy" {
  name               = "legacy-cluster"
  location           = "asia-northeast3"
  min_master_version = "1.9.7"

  addons_config {
    kubernetes_dashboard {
      disabled = true
    }
  }
}

Explanation:

  • Before: Dashboard is enabled through the legacy GKE add-on.
  • After: Dashboard is disabled in the same legacy add-on. This does not resolve the unsupported GKE version.

References