gke-golden-path
>-
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
GKE Golden Path Configuration
The golden path is the recommended Autopilot configuration for production
clusters. It defines sensible defaults — when the user requests different
settings, apply them and note relevant trade-offs.
> MCP Tools: get_cluster, create_cluster, update_cluster
Rules
- Default to the golden path. Use golden path values unless the user
requests otherwise. When deviating, note trade-offs but respect the user's
choice.
- Day-0 vs Day-1. Flag Day-0 decisions (networking, private nodes,
subnets, IP allocation) prominently — they are hard/impossible to change
after creation.
- Tool preference: MCP > gcloud > kubectl. MCP is preferred as it directly
interfaces with GKE APIs with structured data, reducing shell syntax errors
and parsing ambiguities. See the gke-basics skill's CLI reference for full
coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.
- Document decisions and rationale, especially for Day-0 choices and
golden path deviations.
Required Inputs
If the user is unsure, use golden path defaults.
- Project ID (required)
- Region (required, e.g.,
us-central1) - Cluster name (required)
- Environment type: dev/test or production (defaults to production)
- Networking: bring-your-own VPC/subnet or auto-create (default:
auto-create)
- Scale expectations: expected node/pod count, workload types
- Cost constraints: Spot VM tolerance, budget considerations
Always-Apply Defaults
Recommended best practices applied by default. If the user requests a different
setting, apply it and briefly note the security or operational trade-off.
Setting | Golden Path Value
------------------------------------------------------------------ | -----------------
autopilot.enabled | true
privateClusterConfig.enablePrivateNodes | true
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true
secretManagerConfig.enabled + rotationInterval: 120s | true
rbacBindingConfig.enableInsecureBinding* | false (both)
workloadIdentityConfig.workloadPool | enabled
networkConfig.datapathProvider | ADVANCED_DATAPATH
networkConfig.dnsConfig.clusterDns | CLOUD_DNS
autoscaling.autoscalingProfile | OPTIMIZE_UTILIZATION
verticalPodAutoscaling.enabled | true
monitoringConfig components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER
loggingConfig components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default)
advancedDatapathObservabilityConfig.enableMetrics | true
nodeConfig.shieldedInstanceConfig.enableSecureBoot | true
nodeConfig.workloadMetadataConfig.mode | GKE_METADATA
nodeConfig.gcfsConfig.enabled / gvnic.enabled | true / true
addonsConfig.statefulHaConfig.enabled | true
Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled
Pod Security Standards | restricted on production namespaces
Customer-Configurable Settings
These have golden path defaults but customers may deviate with valid
justification. Ask before changing.
Setting | Default | Why Deviate
---------------------------------------- | ----------------------------------- | -----------
dnsEndpointConfig.allowExternalTraffic | true | Restrict if cluster only accessed from within VPC
autoIpamConfig / createSubnetwork | true / true | Customer has pre-existing VPC/subnets
maxPodsPerNode | 48 | 110 for high pod-density (costs more CIDR space)
subnetwork | auto-created | Customer brings existing subnets
Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling
nodeConfig.bootDisk.diskType | pd-balanced | pd-ssd for I/O-intensive, pd-standard for cost
nodeConfig.machineType | ek-standard-8 (Autopilot) | Varies by workload; use ComputeClasses
Guardrails
- Do not request or output secrets (tokens, keys, service account JSON).
- Discover project/cluster context via MCP tools or `gcloud config get-value
project` — don't ask users to paste project IDs.
- For Day-0 decisions, always ask clarifying questions before proceeding.
- For Day-1 features, propose golden path defaults with trade-offs and let the
customer confirm.
- Do not promise zero downtime; advise PDBs, health probes, replicas, and
staged upgrades.
- When auditing existing clusters, compare against golden path and report
deviations with severity and remediation.
Golden Path Config
See [golden-path-autopilot.yaml](./assets/golden-path-autopilot.yaml) for the
full cluster-level policy settings.
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。