Skip to main content
Google Cloud Documentation
Documentation
  • Get Started
  • Get Started with Google Cloud
  • Product List
  • Cloud Customer Care
  • Featured Products
  • Agent Platform
  • Apigee API Management
  • BigQuery
  • Compute Engine
  • Cloud CDN
  • Cloud Run
  • Cloud Storage
  • Cloud SQL
  • Gemini Enterprise
  • Google Kubernetes Engine
  • Looker
  • Cross-product Tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
  • Technology Areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • Google Kubernetes Engine (GKE)
  • GKE security
Start free
Overview Guides
Google Cloud Documentation
  • Documentation
    • More
    • Overview
    • Guides
  • Console
  • Discover
  • GKE security overview
  • Explore GKE documentation
    • Overview
    • Main GKE documentation
    • GKE AI/ML documentation
    • GKE networking documentation
    • GKE security documentation
    • GKE fleet management documentation
  • Security measures in GKE Autopilot
  • About cluster trust
  • Shared security responsibilities
  • CIS Benchmarks
  • Control access
  • Authenticate
    • Authenticate to the GKE API
    • Authenticate to the Kubernetes API server
    • Use external identity providers to authenticate to GKE clusters
    • About service accounts in GKE
    • Configure GKE node service accounts
  • Authorize
    • About RBAC and IAM
    • Best practices for RBAC
    • Authorize access to Google Cloud resources using IAM policies
    • Authorize actions in clusters using GKE RBAC
    • Manage permissions for groups using Google Groups with RBAC
    • Enable access and view cluster resources by namespace
    • Access scopes in GKE
  • Access resources from workloads
    • About Workload Identity Federation for GKE
    • Authenticate to Google Cloud APIs from GKE
    • Access secrets stored outside GKE clusters using client libraries
    • Access private registries with private CA certificates
  • Manage cluster security
  • Best practices for hardening your clusters
  • Best practices for AI workload security
  • Security patching
  • Mitigate security incidents
  • Manage node security
    • Verify node identity and integrity with GKE Shielded Nodes
    • Prevent node self-registration in GKE clusters
    • Disable the insecure kubelet read-only port
    • Run VM agents on every GKE node
    • Manage node SSH access without using SSH keys
    • Securely load modules on nodes running COS
  • Isolate workloads
    • About GKE Sandbox
    • Isolate your workloads using GKE Sandbox
    • Isolate your workloads in dedicated node pools
    • About seccomp in GKE
    • Isolate your workloads using sole-tenant nodes
    • Configure workload separation in GKE
  • Manage credentials
    • Rotate your cluster's credentials
    • Rotate your control plane IP addresses
  • Encrypt sensitive data
    • About FIPS-validated encryption in GKE
    • Encrypt your data in-use with GKE Confidential Nodes
    • Encrypt your data in-transit in GKE with user-managed encryption keys
    • Encrypt data at rest with keys that you manage
    • Encrypt Secrets at the application layer
    • Access vTPMs and attestation reports in Confidential GKE Nodes
  • Enforce security policies
    • Apply predefined Pod-level security policies using PodSecurity
    • Apply custom Pod-level security policies using Gatekeeper
    • Restrict actions on GKE resources using custom organization policies
    • Enforce Autopilot security policies in Standard clusters
    • Restrict access to modify and select ComputeClasses
  • Manage network security
  • Enforce firewall rules and policies
    • Selectively enforce firewall policies in GKE
    • Use network tags to apply firewall rules to nodes
  • Manage control plane security
  • About control plane security
  • About cluster trust
  • Configure control plane security features
    • About control plane authority
    • Run your own certificate authorities and keys in GKE
    • Encrypt etcd and control plane boot disks
    • Rotate customer-managed control plane CAs and keys
    • Rotate etcd and control plane boot disk encryption keys
  • Verify control plane security status
    • Verify Google connections to the GKE control plane
    • Verify identity issuance and usage
    • Verify GKE control plane VM integrity
  • Monitor cluster security
  • Manage audit logs
    • Audit logging for Kubernetes
    • Audit logging for Kubernetes Engine
    • Audit logging for Container Security API
    • About audit policy
    • Enable Linux auditd logging in Standard clusters
  • Monitor cluster security
    • About the security posture dashboard
    • About Kubernetes security posture scanning
    • Scan workloads for configuration issues
    • About workload vulnerability scanning
    • Scan containers for known vulnerabilities
  • Monitor fleet security
    • Configure GKE security posture features for fleets
  • Troubleshoot
  • Authentication
  • Service accounts
  • Application-layer secrets encryption
  • CRDs with an invalid CA bundle
  • Get Started
  • Get Started with Google Cloud
  • Product List
  • Cloud Customer Care
  • Featured Products
  • Agent Platform
  • Apigee API Management
  • BigQuery
  • Compute Engine
  • Cloud CDN
  • Cloud Run
  • Cloud Storage
  • Cloud SQL
  • Gemini Enterprise
  • Google Kubernetes Engine
  • Looker
  • Cross-product Tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
  • Technology Areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
  • Home
  • Documentation