Review GKE node and control-plane access paths

Restrict node external IPs and control-plane access paths separately to the required scope.

Description

Private nodes operate without external IP addresses. A private control-plane IP endpoint limits management access to private network paths. These are separate settings, and a public endpoint does not itself grant anonymous access or administrative permissions.

Private IP configuration is also separate from access controls for the DNS-based endpoint. Review the actual endpoints, IAM and Kubernetes permissions, and connectivity together.

Potential impact

  • Unnecessary public access paths can expand the external attack surface.
  • Disabling a public path before preparing private connectivity can disconnect management tools or automation.

Remediation

  • Use enable_private_nodes = true where nodes do not need external IPs, and prepare required outbound connectivity.
  • To restrict IP-based management access, connect the management network before applying enable_private_endpoint = true.
  • Check DNS endpoint access controls separately, and verify connectivity and permissions for kubectl, CI/CD and management tools.

Examples

These excerpts show private_cluster_config. Supply the VPC, subnet, IP allocation and any control-plane address range required by the version separately. Both examples use private nodes; only the control-plane IP endpoint setting changes.

Before

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3

  private_cluster_config {
    enable_private_endpoint = false
    enable_private_nodes    = true
  }

  timeouts {
    create = "30m"
    update = "40m"
  }
}

After

hcl
resource "google_container_cluster" "cluster" {
  name               = "marcellus-wallace"
  location           = "us-central1-a"
  initial_node_count = 3

  private_cluster_config {
    enable_private_endpoint = true
    enable_private_nodes    = true
  }

  timeouts {
    create = "30m"
    update = "40m"
  }
}

Explanation:

  • Before: Nodes have no external IPs, but the external control-plane IP endpoint remains. Authentication and authorization still apply.
  • After: The control-plane IP endpoint is also restricted to private paths. This does not automatically restrict the DNS endpoint settings.

References