Description
Private nodes operate without external IP addresses. A private control-plane IP endpoint limits management access to private network paths. These are separate settings, and a public endpoint does not itself grant anonymous access or administrative permissions.
Private IP configuration is also separate from access controls for the DNS-based endpoint. Review the actual endpoints, IAM and Kubernetes permissions, and connectivity together.
Potential impact
- Unnecessary public access paths can expand the external attack surface.
- Disabling a public path before preparing private connectivity can disconnect management tools or automation.
Remediation
- Use
enable_private_nodes = truewhere nodes do not need external IPs, and prepare required outbound connectivity. - To restrict IP-based management access, connect the management network before applying
enable_private_endpoint = true. - Check DNS endpoint access controls separately, and verify connectivity and permissions for kubectl, CI/CD and management tools.
Examples
These excerpts show private_cluster_config. Supply the VPC, subnet, IP allocation and any control-plane address range required by the version separately. Both examples use private nodes; only the control-plane IP endpoint setting changes.
Before
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
private_cluster_config {
enable_private_endpoint = false
enable_private_nodes = true
}
timeouts {
create = "30m"
update = "40m"
}
}
After
resource "google_container_cluster" "cluster" {
name = "marcellus-wallace"
location = "us-central1-a"
initial_node_count = 3
private_cluster_config {
enable_private_endpoint = true
enable_private_nodes = true
}
timeouts {
create = "30m"
update = "40m"
}
}
Explanation:
- Before: Nodes have no external IPs, but the external control-plane IP endpoint remains. Authentication and authorization still apply.
- After: The control-plane IP endpoint is also restricted to private paths. This does not automatically restrict the DNS endpoint settings.