GKE Golden Path Configuration
The golden path is the recommended Autopilot configuration for production
clusters. It defines sensible defaults — when the user requests different
settings, apply them and note relevant trade-offs.
MCP Tools: get_cluster, create_cluster, update_cluster
Rules
- Default to the golden path. Use golden path values unless the user
requests otherwise. When deviating, note trade-offs but respect the user's
choice.
- Day-0 vs Day-1. Flag Day-0 decisions (networking, private nodes,
subnets, IP allocation) prominently — they are hard/impossible to change
after creation.
- Tool preference: MCP > gcloud > kubectl. See the
gke-basics skill's
CLI reference for full coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.
- Document decisions and rationale, especially for Day-0 choices and
golden path deviations.
Required Inputs
If the user is unsure, use golden path defaults.
- Project ID (required)
- Region (required, e.g.,
us-central1)
- Cluster name (required)
- Environment type: dev/test or production (defaults to production)
- Networking: bring-your-own VPC/subnet or auto-create (default:
auto-create)
- Scale expectations: expected node/pod count, workload types
- Cost constraints: Spot VM tolerance, budget considerations
Always-Apply Defaults
Recommended best practices applied by default. If the user requests a different
setting, apply it and briefly note the security or operational trade-off.
| Setting |
Golden Path Value |
autopilot.enabled |
true |
privateClusterConfig.enablePrivateNodes |
true |
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled |
true |
secretManagerConfig.enabled + rotationInterval: 120s |
true |
rbacBindingConfig.enableInsecureBinding* |
false (both) |
workloadIdentityConfig.workloadPool |
enabled |
networkConfig.datapathProvider |
ADVANCED_DATAPATH |
networkConfig.dnsConfig.clusterDns |
CLOUD_DNS |
autoscaling.autoscalingProfile |
OPTIMIZE_UTILIZATION |
verticalPodAutoscaling.enabled |
true |
monitoringConfig components |
SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER |
advancedDatapathObservabilityConfig.enableMetrics |
true |
nodeConfig.shieldedInstanceConfig.enableSecureBoot |
true |
nodeConfig.workloadMetadataConfig.mode |
GKE_METADATA |
nodeConfig.gcfsConfig.enabled / gvnic.enabled |
true / true |
addonsConfig.statefulHaConfig.enabled |
true |
| Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) |
enabled |
| Pod Security Standards |
restricted on production namespaces |
Customer-Configurable Settings
These have golden path defaults but customers may deviate with valid
justification. Ask before changing.
| Setting |
Default |
Why Deviate |
dnsEndpointConfig.allowExternalTraffic |
true |
Restrict if cluster only accessed from within VPC |
autoIpamConfig / createSubnetwork |
true / true |
Customer has pre-existing VPC/subnets |
maxPodsPerNode |
48 |
110 for high pod-density (costs more CIDR space) |
subnetwork |
auto-created |
Customer brings existing subnets |
| Maintenance exclusion windows |
configured (NO_MINOR_UPGRADES, 1yr) |
Customer-specific scheduling |
nodeConfig.bootDisk.diskType |
pd-balanced |
pd-ssd for I/O-intensive, pd-standard for cost |
nodeConfig.machineType |
ek-standard-8 (Autopilot) |
Varies by workload; use ComputeClasses |
Guardrails
- Do not request or output secrets (tokens, keys, service account JSON).
- Discover project/cluster context via MCP tools or
gcloud config get-value project — don't ask users to paste project IDs.
- For Day-0 decisions, always ask clarifying questions before proceeding.
- For Day-1 features, propose golden path defaults with trade-offs and let the
customer confirm.
- Do not promise zero downtime; advise PDBs, health probes, replicas, and
staged upgrades.
- When auditing existing clusters, compare against golden path and report
deviations with severity and remediation.
Golden Path Config
See golden-path-autopilot.yaml for the
full cluster-level policy settings.
1---2name: gke-golden-path3description: Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns for designing and verifying GKE clusters.4---56# GKE Golden Path Configuration78The golden path is the recommended Autopilot configuration for production9clusters. It defines sensible defaults — when the user requests different10settings, apply them and note relevant trade-offs.1112> **MCP Tools:** `get_cluster`, `create_cluster`, `update_cluster`1314## Rules15161. **Default to the golden path.** Use golden path values unless the user17 requests otherwise. When deviating, note trade-offs but respect the user's18 choice.192. **Day-0 vs Day-1.** Flag Day-0 decisions (networking, private nodes,20 subnets, IP allocation) prominently — they are hard/impossible to change21 after creation.223. **Tool preference: MCP > gcloud > kubectl.** See the `gke-basics` skill's23 CLI reference for full coverage matrix and override options. If the user24 says "use gcloud" or "use kubectl", respect that for the session.254. **Document decisions and rationale**, especially for Day-0 choices and26 golden path deviations.2728## Required Inputs2930If the user is unsure, use golden path defaults.3132- **Project ID** (required)33- **Region** (required, e.g., `us-central1`)34- **Cluster name** (required)35- **Environment type**: dev/test or production (defaults to production)36- **Networking**: bring-your-own VPC/subnet or auto-create (default:37 auto-create)38- **Scale expectations**: expected node/pod count, workload types39- **Cost constraints**: Spot VM tolerance, budget considerations4041## Always-Apply Defaults4243Recommended best practices applied by default. If the user requests a different44setting, apply it and briefly note the security or operational trade-off.4546Setting | Golden Path Value47------------------------------------------------------------------ | -----------------48`autopilot.enabled` | `true`49`privateClusterConfig.enablePrivateNodes` | `true`50`masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled` | `true`51`secretManagerConfig.enabled` + `rotationInterval: 120s` | `true`52`rbacBindingConfig.enableInsecureBinding*` | `false` (both)53`workloadIdentityConfig.workloadPool` | enabled54`networkConfig.datapathProvider` | `ADVANCED_DATAPATH`55`networkConfig.dnsConfig.clusterDns` | `CLOUD_DNS`56`autoscaling.autoscalingProfile` | `OPTIMIZE_UTILIZATION`57`verticalPodAutoscaling.enabled` | `true`58`monitoringConfig` components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER59`advancedDatapathObservabilityConfig.enableMetrics` | `true`60`nodeConfig.shieldedInstanceConfig.enableSecureBoot` | `true`61`nodeConfig.workloadMetadataConfig.mode` | `GKE_METADATA`62`nodeConfig.gcfsConfig.enabled` / `gvnic.enabled` | `true` / `true`63`addonsConfig.statefulHaConfig.enabled` | `true`64Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled65Pod Security Standards | `restricted` on production namespaces6667## Customer-Configurable Settings6869These have golden path defaults but customers may deviate with valid70justification. **Ask before changing.**7172Setting | Default | Why Deviate73---------------------------------------- | ----------------------------------- | -----------74`dnsEndpointConfig.allowExternalTraffic` | `true` | Restrict if cluster only accessed from within VPC75`autoIpamConfig` / `createSubnetwork` | `true` / `true` | Customer has pre-existing VPC/subnets76`maxPodsPerNode` | `48` | `110` for high pod-density (costs more CIDR space)77`subnetwork` | auto-created | Customer brings existing subnets78Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling79`nodeConfig.bootDisk.diskType` | `pd-balanced` | `pd-ssd` for I/O-intensive, `pd-standard` for cost80`nodeConfig.machineType` | `ek-standard-8` (Autopilot) | Varies by workload; use ComputeClasses8182## Guardrails8384- Do not request or output secrets (tokens, keys, service account JSON).85- Discover project/cluster context via MCP tools or `gcloud config get-value86 project` — don't ask users to paste project IDs.87- For Day-0 decisions, always ask clarifying questions before proceeding.88- For Day-1 features, propose golden path defaults with trade-offs and let the89 customer confirm.90- Do not promise zero downtime; advise PDBs, health probes, replicas, and91 staged upgrades.92- When auditing existing clusters, compare against golden path and report93 deviations with severity and remediation.9495## Golden Path Config9697See [golden-path-autopilot.yaml](./assets/golden-path-autopilot.yaml) for the98full cluster-level policy settings.