跳到主要内容
知仓学习社ZHICANG

gke-networking

>-

不碰外部(只输出文字)无严重或高危命中google/skills

它会碰到什么

扫了多少1 个文本文件,6 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

GKE Networking

This reference covers networking configuration for GKE clusters. The golden path

enforces private, VPC-native clusters with Dataplane V2.

> MCP Tools: get_cluster, update_cluster, apply_k8s_manifest,

> get_k8s_resource

Golden Path Networking Defaults

Setting | Golden Path Value | Day-0/1 | Notes

-------------------------------------------------------------------- | ---------------------------------- | ------- | -----

privateClusterConfig.enablePrivateNodes | true | Day-0 | Nodes have no public IPs

masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true | Day-0 | Control plane only reachable via private endpoint or DNS

controlPlaneEndpointsConfig.dnsEndpointConfig.allowExternalTraffic | true | Day-0 | Allows DNS-based access from outside VPC

networkConfig.datapathProvider | ADVANCED_DATAPATH (Dataplane V2) | Day-0 | eBPF-based, built-in Network Policy

networkConfig.dnsConfig.clusterDns | CLOUD_DNS | Day-0 | Managed DNS, more reliable than kube-dns

networkConfig.enableIntraNodeVisibility | true | Day-1 | VPC Flow Logs for intra-node traffic

ipAllocationPolicy.autoIpamConfig.enabled | true | Day-0 | Automatic IP range management

ipAllocationPolicy.createSubnetwork | true | Day-0 | Auto-create dedicated subnet

defaultMaxPodsConstraint.maxPodsPerNode | 48 | Day-0 | Conservative default; 110 for high density

Private Cluster Access Patterns

The golden path creates a private cluster. Users access it via:

  1. DNS endpoint (default): allowExternalTraffic: true enables access via

the cluster's DNS endpoint from outside the VPC. No VPN required.

  1. Private endpoint: Direct access from within the VPC or via Cloud

VPN/Interconnect.

  1. Authorized networks: Add specific CIDRs to

masterAuthorizedNetworksConfig for IP-based access control.

# Access private cluster via DNS endpoint (golden path default)
gcloud container clusters get-credentials {cluster_name} \
  --region {region} --dns-endpoint \
  --quiet

# Access via private endpoint (from within VPC)
gcloud container clusters get-credentials {cluster_name} \
  --region {region} --internal-ip \
  --quiet

Bring-Your-Own VPC/Subnet

If the customer has existing network infrastructure:

gcloud container clusters create-auto {cluster_name} \
  --region {region} \
  --network {vpc_name} \
  --subnetwork {subnet_name} \
  --cluster-secondary-range-name {pod_range} \
  --services-secondary-range-name {svc_range} \
  --enable-private-nodes \
  --enable-master-authorized-networks \
  --quiet

> Day-0 Warning: VPC, subnet, and IP ranges cannot be changed after cluster

> creation.

VPC-Native Mode Benefits

VPC-native clusters route traffic natively using GCP Alias IP ranges. Key

benefits to cover:

  1. Scalability: Traffic routes natively inside the VPC, bypassing the need

for custom routes and avoiding custom route limit bottlenecks.

  1. Direct VPC Integration: Direct resource integration across GCP networks

without complex bridging or routing tunnels.

  1. Avoiding IP Exhaustion: Supports discontiguous IP ranges and optimizes

allocation, reducing the risk of exhausting subnet IP ranges.

IP Planning

| Resource | Golden Path | Notes |

| ------------- | ------------ | ------------------------------------------ |

| Pod CIDR | /17 (auto) | ~32K pod IPs; size based on maxPodsPerNode |

| Service CIDR | /20 (auto) | ~4K service IPs |

| Node subnet | auto-created | /20 recommended for growth |

| Max pods/node | 48 | Each node gets a /25 pod range; set to 110 |

: : : for /24 per node :

Pod CIDR sizing rule of thumb:

  • maxPodsPerNode=48 -> each node uses a /25 (128 IPs) from pod CIDR
  • maxPodsPerNode=110 -> each node uses a /24 (256 IPs) from pod CIDR
  • Larger maxPodsPerNode = fewer nodes fit in a given CIDR

Egress

  • Default: nodes use Cloud NAT for outbound internet access (private nodes

have no public IPs) to allow private nodes to reach the internet without

public IP exposure.

  • For static egress IPs: configure Cloud NAT with manual IP allocation to

maintain a consistent source IP for external allowlists or partner

firewalls.

  • For restricted egress: route through a firewall appliance via custom routes

to inspect and filter outbound traffic according to organization security

policies.

Network Policy

Dataplane V2 (golden path) provides built-in Network Policy enforcement — no

additional addon needed. Apply default-deny per namespace, then allow specific

flows.

> See the gke-workload-security skill for default-deny policy and the

> gke-multitenancy skill for per-team allow policies.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。