GKE Golden Path Configuration
The golden path is the recommended Autopilot configuration for production
clusters. It defines sensible defaults — when the user requests different
settings, apply them and note relevant trade-offs.
MCP Tools: get_cluster, create_cluster, update_cluster
Rules
- Default to the golden path. Use golden path values unless the user
requests otherwise. When deviating, note trade-offs but respect the user's
choice.
- Day-0 vs Day-1. Flag Day-0 decisions (networking, private nodes,
subnets, IP allocation) prominently — they are hard/impossible to change
after creation.
- Tool preference: MCP > gcloud > kubectl. See the
gke-basics skill's
CLI reference for full coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.
- Document decisions and rationale, especially for Day-0 choices and
golden path deviations.
Required Inputs
If the user is unsure, use golden path defaults.
- Project ID (required)
- Region (required, e.g.,
us-central1)
- Cluster name (required)
- Environment type: dev/test or production (defaults to production)
- Networking: bring-your-own VPC/subnet or auto-create (default:
auto-create)
- Scale expectations: expected node/pod count, workload types
- Cost constraints: Spot VM tolerance, budget considerations
Always-Apply Defaults
Recommended best practices applied by default. If the user requests a different
setting, apply it and briefly note the security or operational trade-off.
| Setting |
Golden Path Value |
autopilot.enabled |
true |
privateClusterConfig.enablePrivateNodes |
true |
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled |
true |
secretManagerConfig.enabled + rotationInterval: 120s |
true |
rbacBindingConfig.enableInsecureBinding* |
false (both) |
workloadIdentityConfig.workloadPool |
enabled |
networkConfig.datapathProvider |
ADVANCED_DATAPATH |
networkConfig.dnsConfig.clusterDns |
CLOUD_DNS |
autoscaling.autoscalingProfile |
OPTIMIZE_UTILIZATION |
verticalPodAutoscaling.enabled |
true |
monitoringConfig components |
SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER |
loggingConfig components |
SYSTEM_COMPONENTS, WORKLOADS (enabled by default) |
advancedDatapathObservabilityConfig.enableMetrics |
true |
nodeConfig.shieldedInstanceConfig.enableSecureBoot |
true |
nodeConfig.workloadMetadataConfig.mode |
GKE_METADATA |
nodeConfig.gcfsConfig.enabled / gvnic.enabled |
true / true |
addonsConfig.statefulHaConfig.enabled |
true |
| Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) |
enabled |
| Pod Security Standards |
restricted on production namespaces |
Customer-Configurable Settings
These have golden path defaults but customers may deviate with valid
justification. Ask before changing.
| Setting |
Default |
Why Deviate |
dnsEndpointConfig.allowExternalTraffic |
true |
Restrict if cluster only accessed from within VPC |
autoIpamConfig / createSubnetwork |
true / true |
Customer has pre-existing VPC/subnets |
maxPodsPerNode |
48 |
110 for high pod-density (costs more CIDR space) |
subnetwork |
auto-created |
Customer brings existing subnets |
| Maintenance exclusion windows |
configured (NO_MINOR_UPGRADES, 1yr) |
Customer-specific scheduling |
nodeConfig.bootDisk.diskType |
pd-balanced |
pd-ssd for I/O-intensive, pd-standard for cost |
nodeConfig.machineType |
ek-standard-8 (Autopilot) |
Varies by workload; use ComputeClasses |
Guardrails
- Do not request or output secrets (tokens, keys, service account JSON).
- Discover project/cluster context via MCP tools or
gcloud config get-value project — don't ask users to paste project IDs.
- For Day-0 decisions, always ask clarifying questions before proceeding.
- For Day-1 features, propose golden path defaults with trade-offs and let the
customer confirm.
- Do not promise zero downtime; advise PDBs, health probes, replicas, and
staged upgrades.
- When auditing existing clusters, compare against golden path and report
deviations with severity and remediation.
Golden Path Config
See golden-path-autopilot.yaml for the
full cluster-level policy settings.
Source: google/skills → skills/cloud/gke-golden-path/SKILL.md
1---2name: gke-golden-path3description: >- Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up node autoscaling specifically (use gke-scaling instead).4---5
6
7# GKE Golden Path Configuration
8
9The golden path is the recommended Autopilot configuration for production
10clusters. It defines sensible defaults — when the user requests different
11settings, apply them and note relevant trade-offs.
12
13> **MCP Tools:** `get_cluster`, `create_cluster`, `update_cluster`
14
15## Rules
16
171. **Default to the golden path.** Use golden path values unless the user
18 requests otherwise. When deviating, note trade-offs but respect the user's
19 choice.
202. **Day-0 vs Day-1.** Flag Day-0 decisions (networking, private nodes,
21 subnets, IP allocation) prominently — they are hard/impossible to change
22 after creation.
233. **Tool preference: MCP > gcloud > kubectl.** See the `gke-basics` skill's
24 CLI reference for full coverage matrix and override options. If the user
25 says "use gcloud" or "use kubectl", respect that for the session.
264. **Document decisions and rationale**, especially for Day-0 choices and
27 golden path deviations.
28
29## Required Inputs
30
31If the user is unsure, use golden path defaults.
32
33- **Project ID** (required)
34- **Region** (required, e.g., `us-central1`)
35- **Cluster name** (required)
36- **Environment type**: dev/test or production (defaults to production)
37- **Networking**: bring-your-own VPC/subnet or auto-create (default:
38 auto-create)
39- **Scale expectations**: expected node/pod count, workload types
40- **Cost constraints**: Spot VM tolerance, budget considerations
41
42## Always-Apply Defaults
43
44Recommended best practices applied by default. If the user requests a different
45setting, apply it and briefly note the security or operational trade-off.
46
47Setting | Golden Path Value
48------------------------------------------------------------------ | -----------------
49`autopilot.enabled` | `true`
50`privateClusterConfig.enablePrivateNodes` | `true`
51`masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled` | `true`
52`secretManagerConfig.enabled` + `rotationInterval: 120s` | `true`
53`rbacBindingConfig.enableInsecureBinding*` | `false` (both)
54`workloadIdentityConfig.workloadPool` | enabled
55`networkConfig.datapathProvider` | `ADVANCED_DATAPATH`
56`networkConfig.dnsConfig.clusterDns` | `CLOUD_DNS`
57`autoscaling.autoscalingProfile` | `OPTIMIZE_UTILIZATION`
58`verticalPodAutoscaling.enabled` | `true`
59`monitoringConfig` components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER
60`loggingConfig` components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default)
61`advancedDatapathObservabilityConfig.enableMetrics` | `true`
62`nodeConfig.shieldedInstanceConfig.enableSecureBoot` | `true`
63`nodeConfig.workloadMetadataConfig.mode` | `GKE_METADATA`
64`nodeConfig.gcfsConfig.enabled` / `gvnic.enabled` | `true` / `true`
65`addonsConfig.statefulHaConfig.enabled` | `true`
66Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled
67Pod Security Standards | `restricted` on production namespaces
68
69## Customer-Configurable Settings
70
71These have golden path defaults but customers may deviate with valid
72justification. **Ask before changing.**
73
74Setting | Default | Why Deviate
75---------------------------------------- | ----------------------------------- | -----------
76`dnsEndpointConfig.allowExternalTraffic` | `true` | Restrict if cluster only accessed from within VPC
77`autoIpamConfig` / `createSubnetwork` | `true` / `true` | Customer has pre-existing VPC/subnets
78`maxPodsPerNode` | `48` | `110` for high pod-density (costs more CIDR space)
79`subnetwork` | auto-created | Customer brings existing subnets
80Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling
81`nodeConfig.bootDisk.diskType` | `pd-balanced` | `pd-ssd` for I/O-intensive, `pd-standard` for cost
82`nodeConfig.machineType` | `ek-standard-8` (Autopilot) | Varies by workload; use ComputeClasses
83
84## Guardrails
85
86- Do not request or output secrets (tokens, keys, service account JSON).
87- Discover project/cluster context via MCP tools or `gcloud config get-value
88 project` — don't ask users to paste project IDs.
89- For Day-0 decisions, always ask clarifying questions before proceeding.
90- For Day-1 features, propose golden path defaults with trade-offs and let the
91 customer confirm.
92- Do not promise zero downtime; advise PDBs, health probes, replicas, and
93 staged upgrades.
94- When auditing existing clusters, compare against golden path and report
95 deviations with severity and remediation.
96
97## Golden Path Config
98
99See [golden-path-autopilot.yaml](./assets/golden-path-autopilot.yaml) for the
100full cluster-level policy settings.
101
102---
103
104**Source:** [`google/skills`](https://github.com/google/skills) → `skills/cloud/gke-golden-path/SKILL.md`