Review Shielded GKE node protection

Enable node identity protection and check separate boot-protection settings.

Description

Shielded GKE Nodes use verifiable node identity and attestation to protect how nodes join a cluster. This helps reduce the risk of another system impersonating a legitimate node after bootstrap credentials are compromised.

It is currently enabled by default in Standard and always used in Autopilot. enable_shielded_nodes concerns worker-node protection; it is not a switch that enables every separate Secure Boot or integrity monitoring setting.

Potential impact

  • The cluster can lose additional identity protection during node admission.
  • Defenses against node impersonation can be weaker if bootstrap credentials are compromised.

Remediation

  • Verify enable_shielded_nodes = true and actual node state on Standard clusters.
  • Prepare availability and spare capacity for control-plane and node recreation when changing existing clusters.
  • Check Secure Boot and integrity monitoring separately, including workload compatibility and alert operations.

Examples

These excerpts show the cluster’s Shielded setting. Supply the project, networking, node count and remaining operational settings separately.

Before

hcl
resource "google_container_cluster" "cluster" {
  name                  = "my-gke-cluster"
  location              = "us-central1"
  enable_shielded_nodes = false
}

After

hcl
resource "google_container_cluster" "cluster" {
  name                  = "my-gke-cluster"
  location              = "us-central1"
  enable_shielded_nodes = true
}

Explanation:

  • Before: Shielded GKE protection is disabled for worker nodes. This does not disable Shielded protection of the control plane.
  • After: Shielded GKE Nodes is enabled to strengthen node identity protection. Verify the actual Secure Boot and integrity monitoring settings separately.

References