Gke Platform Security

Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for workload-level security (Workload Identity, SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security instead).

is-bo 5d486ba 9.6 KB Updated

File contents

is-bo/fullstack-forge-skill/tree/main/third_party/agent-skills/google-skills/content/skills/cloud/gke-platform-security commit 5d486ba23c

Frequently asked questions

npx skillmds@latest add is-bo/gke-platform-security