Review legacy client certificates in GKE

Prefer the default OAuth authentication and remove unnecessary client certificates and permissions.

Description

Legacy GKE client certificates provide an access path in addition to the default OAuth authentication. Distributing and managing the certificate and private key adds operational work; disclosure can allow access within that identity’s permissions. This is separate from TLS certificate verification for the API server.

Potential impact

  • Old authentication methods can make tracking and retirement harder.
  • A disclosed client certificate and private key can let an unauthorized party authenticate.

Remediation

  • Set issue_client_certificate = false to stop unnecessary legacy certificate issuance and use the default OAuth authentication. Minimize IAM and Kubernetes RBAC permissions as well.
  • Migrate procedures that use existing certificates and remove their associated permissions through supported procedures. Do not assume that changing the issuance setting revokes certificates already issued.

Examples

These excerpts compare client-certificate issuance. The setting does not disable server TLS verification; removing existing certificate permissions is a separate task.

Before

hcl
resource "google_container_cluster" "example" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3

  master_auth {
    client_certificate_config {
      issue_client_certificate = true
    }
  }
}

After

hcl
resource "google_container_cluster" "example" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3

  master_auth {
    client_certificate_config {
      issue_client_certificate = false
    }
  }
}

Explanation:

  • Before: Legacy client-certificate issuance is requested.
  • After: Legacy certificate issuance is disabled. Check existing certificates’ access separately.

References