GKE Golden Path Configuration
The golden path is the recommended Autopilot configuration for production
clusters. It defines sensible defaults — when the user requests different
settings, apply them and note relevant trade-offs.
MCP Tools: get_cluster, create_cluster, update_cluster
Rules
- Default to the golden path. Use golden path values unless the user
requests otherwise. When deviating, note trade-offs but respect the user's
choice.
- Day-0 vs Day-1. Flag Day-0 decisions (networking, private nodes,
subnets, IP allocation) prominently — they are hard/impossible to change
after creation.
- Tool preference: MCP > gcloud > kubectl. MCP is preferred as it directly
interfaces with GKE APIs with structured data, reducing shell syntax errors
and parsing ambiguities. See the
gke-basics skill's CLI reference for full
coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.
- Document decisions and rationale, especially for Day-0 choices and
golden path deviations.
Required Inputs
If the user is unsure, use golden path defaults.
- Project ID (required)
- Region (required, e.g.,
us-central1)
- Cluster name (required)
- Environment type: dev/test or production (defaults to production)
- Networking: bring-your-own VPC/subnet or auto-create (default:
auto-create)
- Scale expectations: expected node/pod count, workload types
- Cost constraints: Spot VM tolerance, budget considerations
Always-Apply Defaults
Recommended best practices applied by default. If the user requests a different
setting, apply it and briefly note the security or operational trade-off.
| Setting |
Golden Path Value |
autopilot.enabled |
true |
privateClusterConfig.enablePrivateNodes |
true |
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled |
true |
secretManagerConfig.enabled + rotationInterval: 120s |
true |
rbacBindingConfig.enableInsecureBinding* |
false (both) |
workloadIdentityConfig.workloadPool |
enabled |
networkConfig.datapathProvider |
ADVANCED_DATAPATH |
networkConfig.dnsConfig.clusterDns |
CLOUD_DNS |
autoscaling.autoscalingProfile |
OPTIMIZE_UTILIZATION |
verticalPodAutoscaling.enabled |
true |
monitoringConfig components |
SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER |
loggingConfig components |
SYSTEM_COMPONENTS, WORKLOADS (enabled by default) |
advancedDatapathObservabilityConfig.enableMetrics |
true |
nodeConfig.shieldedInstanceConfig.enableSecureBoot |
true |
nodeConfig.workloadMetadataConfig.mode |
GKE_METADATA |
nodeConfig.gcfsConfig.enabled / gvnic.enabled |
true / true |
addonsConfig.statefulHaConfig.enabled |
true |
| Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) |
enabled |
| Pod Security Standards |
restricted on production namespaces |
Customer-Configurable Settings
These have golden path defaults but customers may deviate with valid
justification. Ask before changing.
| Setting |
Default |
Why Deviate |
dnsEndpointConfig.allowExternalTraffic |
true |
Restrict if cluster only accessed from within VPC |
autoIpamConfig / createSubnetwork |
true / true |
Customer has pre-existing VPC/subnets |
maxPodsPerNode |
48 |
110 for high pod-density (costs more CIDR space) |
subnetwork |
auto-created |
Customer brings existing subnets |
| Maintenance exclusion windows |
configured (NO_MINOR_UPGRADES, 1yr) |
Customer-specific scheduling |
nodeConfig.bootDisk.diskType |
pd-balanced |
pd-ssd for I/O-intensive, pd-standard for cost |
nodeConfig.machineType |
ek-standard-8 (Autopilot) |
Varies by workload; use ComputeClasses |
Guardrails
- Do not request or output secrets (tokens, keys, service account JSON).
- Discover project/cluster context via MCP tools or
gcloud config get-value project — don't ask users to paste project IDs.
- For Day-0 decisions, always ask clarifying questions before proceeding.
- For Day-1 features, propose golden path defaults with trade-offs and let the
customer confirm.
- Do not promise zero downtime; advise PDBs, health probes, replicas, and
staged upgrades.
- When auditing existing clusters, compare against golden path and report
deviations with severity and remediation.
Golden Path Config
See golden-path-autopilot.yaml for the
full cluster-level policy settings.
1---2name: gke-golden-path3description: Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up workload autoscaling specifically (use gke-workload-scaling instead).4---5# GKE Golden Path Configuration67The golden path is the recommended Autopilot configuration for production8clusters. It defines sensible defaults — when the user requests different9settings, apply them and note relevant trade-offs.1011> **MCP Tools:** `get_cluster`, `create_cluster`, `update_cluster`1213## Rules14151. **Default to the golden path.** Use golden path values unless the user16 requests otherwise. When deviating, note trade-offs but respect the user's17 choice.182. **Day-0 vs Day-1.** Flag Day-0 decisions (networking, private nodes,19 subnets, IP allocation) prominently — they are hard/impossible to change20 after creation.213. **Tool preference: MCP > gcloud > kubectl.** MCP is preferred as it directly22 interfaces with GKE APIs with structured data, reducing shell syntax errors23 and parsing ambiguities. See the `gke-basics` skill's CLI reference for full24 coverage matrix and override options. If the user25 says "use gcloud" or "use kubectl", respect that for the session.264. **Document decisions and rationale**, especially for Day-0 choices and27 golden path deviations.2829## Required Inputs3031If the user is unsure, use golden path defaults.3233- **Project ID** (required)34- **Region** (required, e.g., `us-central1`)35- **Cluster name** (required)36- **Environment type**: dev/test or production (defaults to production)37- **Networking**: bring-your-own VPC/subnet or auto-create (default:38 auto-create)39- **Scale expectations**: expected node/pod count, workload types40- **Cost constraints**: Spot VM tolerance, budget considerations4142## Always-Apply Defaults4344Recommended best practices applied by default. If the user requests a different45setting, apply it and briefly note the security or operational trade-off.4647Setting | Golden Path Value48------------------------------------------------------------------ | -----------------49`autopilot.enabled` | `true`50`privateClusterConfig.enablePrivateNodes` | `true`51`masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled` | `true`52`secretManagerConfig.enabled` + `rotationInterval: 120s` | `true`53`rbacBindingConfig.enableInsecureBinding*` | `false` (both)54`workloadIdentityConfig.workloadPool` | enabled55`networkConfig.datapathProvider` | `ADVANCED_DATAPATH`56`networkConfig.dnsConfig.clusterDns` | `CLOUD_DNS`57`autoscaling.autoscalingProfile` | `OPTIMIZE_UTILIZATION`58`verticalPodAutoscaling.enabled` | `true`59`monitoringConfig` components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER60`loggingConfig` components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default)61`advancedDatapathObservabilityConfig.enableMetrics` | `true`62`nodeConfig.shieldedInstanceConfig.enableSecureBoot` | `true`63`nodeConfig.workloadMetadataConfig.mode` | `GKE_METADATA`64`nodeConfig.gcfsConfig.enabled` / `gvnic.enabled` | `true` / `true`65`addonsConfig.statefulHaConfig.enabled` | `true`66Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled67Pod Security Standards | `restricted` on production namespaces6869## Customer-Configurable Settings7071These have golden path defaults but customers may deviate with valid72justification. **Ask before changing.**7374Setting | Default | Why Deviate75---------------------------------------- | ----------------------------------- | -----------76`dnsEndpointConfig.allowExternalTraffic` | `true` | Restrict if cluster only accessed from within VPC77`autoIpamConfig` / `createSubnetwork` | `true` / `true` | Customer has pre-existing VPC/subnets78`maxPodsPerNode` | `48` | `110` for high pod-density (costs more CIDR space)79`subnetwork` | auto-created | Customer brings existing subnets80Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling81`nodeConfig.bootDisk.diskType` | `pd-balanced` | `pd-ssd` for I/O-intensive, `pd-standard` for cost82`nodeConfig.machineType` | `ek-standard-8` (Autopilot) | Varies by workload; use ComputeClasses8384## Guardrails8586- Do not request or output secrets (tokens, keys, service account JSON).87- Discover project/cluster context via MCP tools or `gcloud config get-value88 project` — don't ask users to paste project IDs.89- For Day-0 decisions, always ask clarifying questions before proceeding.90- For Day-1 features, propose golden path defaults with trade-offs and let the91 customer confirm.92- Do not promise zero downtime; advise PDBs, health probes, replicas, and93 staged upgrades.94- When auditing existing clusters, compare against golden path and report95 deviations with severity and remediation.9697## Golden Path Config9899See [golden-path-autopilot.yaml](./assets/golden-path-autopilot.yaml) for the100full cluster-level policy settings.