跳到主要内容
知仓学习社ZHICANG

gke-basics

>-

读凭据严重 1 · 高危 0google/skills

它会碰到什么

扫了多少6 个文本文件,29 KB
它会碰到什么读凭据
命中总数1 处
命中统计严重 1 · 高 0 · 中 0 · 低 0
逐条看命中(1 条严重或高危)
  • 严重 references/client-library-usage.md:27cred-paths
    config.load_kube_config() # Loads from ~/.kube/config

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

GKE Basics & Critical Gotchas

Managed Kubernetes platform on Google Cloud. Defaults to Autopilot mode unless Standard is explicitly required.

Key Selection Rules: Autopilot vs. Standard

  • Default to Autopilot for almost all workloads.
  • Use Standard ONLY if:
  • Custom node OS kernel parameters (sysctl) are required.
  • Custom node taints or specific hardware node pools are required.
  • DaemonSets require raw hostPath mounts to the host OS filesystem.
  • When explaining why Standard is required over Autopilot, explicitly cite all matching restrictions (e.g., custom sysctls and custom node taints).
  • For advanced cluster architecture or complex node pool creation planning, refer to gke-cluster-creation.

Critical Gotchas & Best Practices

  1. Private Autopilot Clusters:
  • Use --enable-private-nodes for private node IP addresses.
  • Use --enable-private-endpoint to disable public IP access to the control plane.
  • Restrict control plane access with --enable-master-authorized-networks and --master-authorized-networks=CIDR_BLOCK:
     gcloud container clusters create-auto CLUSTER_NAME --region=REGION \
       --enable-private-nodes \
       --enable-private-endpoint \
       --enable-master-authorized-networks \
       --master-authorized-networks=CIDR_BLOCK
  1. Workload Identity (IAM Binding):
  • Never mount raw GCP Service Account JSON keys in Pods.
  • Annotate the Kubernetes ServiceAccount (KSA) to bind to the Google Service Account (GSA):
     metadata:
       annotations:
         iam.gke.io/gcp-service-account: GSA_NAME@PROJECT_ID.iam.gserviceaccount.com
  1. Autopilot Resource Requests:
  • In Autopilot, CPU requests must be specified in increments of 250m (0.25 vCPU). If an unaligned CPU request (e.g., 300m) is requested, round up to the nearest 250m increment (500m / 0.5 vCPU).
  • Resource requests equal limits automatically. Omit limits to allow Autopilot to set defaults matching requests.
  1. Cluster Credentials:
  • Always explicitly specify --region (for regional clusters) or --zone (for zonal clusters) when fetching credentials:
     gcloud container clusters get-credentials CLUSTER_NAME --region=REGION --quiet

Reference Directory

  • [Core Concepts](references/core-concepts.md): Architecture, cluster modes (Autopilot vs Standard), networking, scaling, and security model.
  • [CLI Usage & Tool Reference](references/cli-reference.md): Tool preference hierarchy (MCP vs gcloud vs kubectl), gcloud container commands, and user preference overrides.
  • [Client Libraries](references/client-library-usage.md): Official Kubernetes and Google Cloud Container client libraries in Python, Go, Node.js, and Java.
  • [MCP Usage](references/mcp-usage.md): Connecting to and using the 23 structured GKE MCP tools for cluster management, K8s resources, and diagnostics.
  • [Infrastructure as Code](references/iac-usage.md): Terraform examples for google_container_cluster (Autopilot), Kubernetes provider resources, and YAML samples.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。