finding-google-skills
Locates and loads the right Google product skill on demand from a remote catalog index, instead of preloading every skill. Use at the START of any request…
Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up workload autoscaling
$ npx -y skills add google/skills --skill gke-golden-path --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/gke-golden-pathContext preview
The summary Claude sees to decide when to auto-load this skill.
Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up workload autoscaling
name: gke-golden-path description: >- Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up workload autoscaling specifically (use gke-workload-scaling instead). metadata: category: Containers
The golden path is the recommended Autopilot configuration for production clusters. It defines sensible defaults — when the user requests different settings, apply them and note relevant trade-offs.
> **MCP Tools:** `get_cluster`, `create_cluster`, `update_cluster`
1. **Default to the golden path.** Use golden path values unless the user requests otherwise. When deviating, note trade-offs but respect the user's choice. 2. **Day-0 vs Day-1.** Flag Day-0 decisions (networking, private nodes, subnets, IP allocation) prominently — they are hard/impossible to change after creation. 3. **Tool preference: MCP > gcloud > kubectl.** MCP is preferred as it directly interfaces with GKE APIs with structured data, reducing shell syntax errors and parsing ambiguities. See the `gke-basics` skill's CLI reference for full coverage matrix and override options. If the user says "use gcloud" or "use kubectl", respect that for the session. 4. **Document decisions and rationale**, especially for Day-0 choices and golden path deviations.
If the user is unsure, use golden path defaults.
auto-create)
Recommended best practices applied by default. If the user requests a different setting, apply it and briefly note the security or operational trade-off.
Setting | Golden Path Value ------------------------------------------------------------------ | ----------------- `autopilot.enabled` | `true` `privateClusterConfig.enablePrivateNodes` | `true` `masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled` | `true` `secretManagerConfig.enabled` + `rotationInterval: 120s` | `true` `rbacBindingConfig.enableInsecureBinding*` | `false` (both) `workloadIdentityConfig.workloadPool` | enabled `networkConfig.datapathProvider` | `ADVANCED_DATAPATH` `networkConfig.dnsConfig.clusterDns` | `CLOUD_DNS` `autoscaling.autoscalingProfile` | `OPTIMIZE_UTILIZATION` `verticalPodAutoscaling.enabled` | `true` `monitoringConfig` components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER `loggingConfig` components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default) `advancedDatapathObservabilityConfig.enableMetrics` | `true` `nodeConfig.shieldedInstanceConfig.enableSecureBoot` | `true` `nodeConfig.workloadMetadataConfig.mode` | `GKE_METADATA` `nodeConfig.gcfsConfig.enabled` / `gvnic.enabled` | `true` / `true` `addonsConfig.statefulHaConfig.enabled` | `true` Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled Pod Security Standards | `restricted` on production namespaces
These have golden path defaults but customers may deviate with valid justification. **Ask before changing.**
Setting | Default | Why Deviate ---------------------------------------- | ----------------------------------- | ----------- `dnsEndpointConfig.allowExternalTraffic` | `true` | Restrict if cluster only accessed from within VPC `autoIpamConfig` / `createSubnetwork` | `true` / `true` | Customer has pre-existing VPC/subnets `maxPodsPerNode` | `48` | `110` for high pod-density (costs more CIDR space) `subnetwork` | auto-created | Customer brings existing subnets Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling `nodeConfig.bootDisk.diskType` | `pd-balanced` | `pd-ssd` for I/O-intensive, `pd-standard` for cost `nodeConfig.machineType` | `ek-standard-8` (Autopilot) | Varies by workload; use ComputeClasses
project` — don't ask users to paste project IDs.
customer confirm.
staged upgrades.
deviations with severity and remediation.
See [golden-path-autopilot.yaml](./assets/golden-path-autopilot.yaml) for the ful
This repository contains Agent Skills for Google products and technologies, including Google Cloud.
Repo: google/skills
Locates and loads the right Google product skill on demand from a remote catalog index, instead of preloading every skill. Use at the START of any request…
Provides safety-critical validation, guardrails, and data reduction for gcloud CLI operations across Google Cloud Platform (GCP) services and infrastructure.…
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default…
Guides a developer's first steps on Google Cloud, covering account creation, billing setup, project management, and deploying a first resource. Use when a new…
Searches, retrieves, and synthesizes official Google developer documentation across Google Cloud, AI/Gemini, Android, Chrome, Web, Flutter, Go, Firebase, and…
Guides developers through managing (adding, removing, and clearing) audience members for Google products using the Data Manager API and its associated client…