跳到主要内容
知仓学习社ZHICANG

gke-golden-path

>-

不碰外部(只输出文字)无严重或高危命中google/skills

它会碰到什么

扫了多少2 个文本文件,10 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

GKE Golden Path Configuration

The golden path is the recommended Autopilot configuration for production

clusters. It defines sensible defaults — when the user requests different

settings, apply them and note relevant trade-offs.

> MCP Tools: get_cluster, create_cluster, update_cluster

Rules

  1. Default to the golden path. Use golden path values unless the user

requests otherwise. When deviating, note trade-offs but respect the user's

choice.

  1. Day-0 vs Day-1. Flag Day-0 decisions (networking, private nodes,

subnets, IP allocation) prominently — they are hard/impossible to change

after creation.

  1. Tool preference: MCP > gcloud > kubectl. MCP is preferred as it directly

interfaces with GKE APIs with structured data, reducing shell syntax errors

and parsing ambiguities. See the gke-basics skill's CLI reference for full

coverage matrix and override options. If the user

says "use gcloud" or "use kubectl", respect that for the session.

  1. Document decisions and rationale, especially for Day-0 choices and

golden path deviations.

Required Inputs

If the user is unsure, use golden path defaults.

  • Project ID (required)
  • Region (required, e.g., us-central1)
  • Cluster name (required)
  • Environment type: dev/test or production (defaults to production)
  • Networking: bring-your-own VPC/subnet or auto-create (default:

auto-create)

  • Scale expectations: expected node/pod count, workload types
  • Cost constraints: Spot VM tolerance, budget considerations

Always-Apply Defaults

Recommended best practices applied by default. If the user requests a different

setting, apply it and briefly note the security or operational trade-off.

Setting | Golden Path Value

------------------------------------------------------------------ | -----------------

autopilot.enabled | true

privateClusterConfig.enablePrivateNodes | true

masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true

secretManagerConfig.enabled + rotationInterval: 120s | true

rbacBindingConfig.enableInsecureBinding* | false (both)

workloadIdentityConfig.workloadPool | enabled

networkConfig.datapathProvider | ADVANCED_DATAPATH

networkConfig.dnsConfig.clusterDns | CLOUD_DNS

autoscaling.autoscalingProfile | OPTIMIZE_UTILIZATION

verticalPodAutoscaling.enabled | true

monitoringConfig components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER

loggingConfig components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default)

advancedDatapathObservabilityConfig.enableMetrics | true

nodeConfig.shieldedInstanceConfig.enableSecureBoot | true

nodeConfig.workloadMetadataConfig.mode | GKE_METADATA

nodeConfig.gcfsConfig.enabled / gvnic.enabled | true / true

addonsConfig.statefulHaConfig.enabled | true

Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled

Pod Security Standards | restricted on production namespaces

Customer-Configurable Settings

These have golden path defaults but customers may deviate with valid

justification. Ask before changing.

Setting | Default | Why Deviate

---------------------------------------- | ----------------------------------- | -----------

dnsEndpointConfig.allowExternalTraffic | true | Restrict if cluster only accessed from within VPC

autoIpamConfig / createSubnetwork | true / true | Customer has pre-existing VPC/subnets

maxPodsPerNode | 48 | 110 for high pod-density (costs more CIDR space)

subnetwork | auto-created | Customer brings existing subnets

Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling

nodeConfig.bootDisk.diskType | pd-balanced | pd-ssd for I/O-intensive, pd-standard for cost

nodeConfig.machineType | ek-standard-8 (Autopilot) | Varies by workload; use ComputeClasses

Guardrails

  • Do not request or output secrets (tokens, keys, service account JSON).
  • Discover project/cluster context via MCP tools or `gcloud config get-value

project` — don't ask users to paste project IDs.

  • For Day-0 decisions, always ask clarifying questions before proceeding.
  • For Day-1 features, propose golden path defaults with trade-offs and let the

customer confirm.

  • Do not promise zero downtime; advise PDBs, health probes, replicas, and

staged upgrades.

  • When auditing existing clusters, compare against golden path and report

deviations with severity and remediation.

Golden Path Config

See [golden-path-autopilot.yaml](./assets/golden-path-autopilot.yaml) for the

full cluster-level policy settings.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。