finding-google-skills
Locates and loads the right Google product skill on demand from a remote catalog index, instead of preloading every skill. Use at the START of any request…
Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster
$ npx -y skills add google/skills --skill gke-platform-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/gke-platform-securityContext preview
The summary Claude sees to decide when to auto-load this skill.
Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster
name: gke-platform-security description: >- Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for workload-level security (Workload Identity, SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security instead). metadata: category: Security
This reference covers platform-level security hardening and cluster configuration for Google Kubernetes Engine (GKE). For workload-level security controls (such as Workload Identity Service Account bindings, SecretProviderClass volume mounts, Network Policies, and Pod Security Standards), refer to the `gke-workload-security` skill.
> **MCP Tools:** `gke:get_cluster`, `k8s:check_k8s_auth`, > `k8s:get_k8s_resource`, `k8s:apply_k8s_manifest`, `gke:update_cluster`
Setting | Golden Path Value | Day-0/1 | Notes -------------------------------------------------------------- | --------------------------------------- | ------- | ----- `workloadIdentityConfig.workloadPool` | `<PROJECT>.svc.id.goog` | Day-0 | Workload Identity Federation for cluster pods `secretManagerConfig.enabled` | `true` | Day-1 | Google Secret Manager cluster add-on integration `secretManagerConfig.rotationConfig` | `enabled: true, rotationInterval: 120s` | Day-1 | Automatic secret rotation at the cluster level `rbacBindingConfig.enableInsecureBindingSystemAuthenticated` | `false` | Day-0 | Blocks legacy `system:authenticated` bindings `rbacBindingConfig.enableInsecureBindingSystemUnauthenticated` | `false` | Day-0 | Blocks legacy `system:unauthenticated` bindings `nodeConfig.shieldedInstanceConfig.enableSecureBoot` | `true` | Day-0 | Verifiable boot integrity `nodeConfig.shieldedInstanceConfig.enableIntegrityMonitoring` | `true` | Day-0 | Runtime integrity checks `nodeConfig.workloadMetadataConfig.mode` | `GKE_METADATA` | Day-0 | Blocks legacy metadata API, enforces Workload Identity Private cluster + Dataplane V2 settings | See the `gke-networking` skill | Day-0 | Private nodes, private endpoint enforcement, ADVANCED_DATAPATH
The golden path enables Secret Manager at the cluster level with automatic secret rotation.
# Verify Secret Manager is enabled on cluster gcloud container clusters describe <CLUSTER_NAME> --region <REGION> \ --format="value(secretManagerConfig.enabled)" \ --quiet # Enable if not already (Day-1 change) gcloud container clusters update <CLUSTER_NAME> --region <REGION> \ --enable-secret-manager \ --secret-manager-rotation-interval=120s \ --quiet
> **Note:** For configuring `SecretProviderClass` manifests and mounting secrets > as volumes inside application deployments, see the `gke-workload-security` > skill.
The golden path disables insecure legacy RBAC bindings that grant broad access to `system:authenticated` and `system:unauthenticated` groups.
# Verify insecure bindings are disabled gcloud container clusters describe <CLUSTER_NAME> --region <REGION> \ --format="yaml(rbacBindingConfig)" \ --quiet
**Best practices for RBAC:**
or `system:unauthenticated`.
resourceType="pods", namespace="...")` (or `kubectl auth can-i --list --as=<user>`).
resourceType="clusterrolebinding")` (or `kubectl get clusterrolebindings,rolebindings --all-namespaces`).
> See the `gke-multitenancy` skill for enterprise RBAC planning and > https://docs.cloud.google.com/kubernetes-engine/docs/best-practices/rbac.md.txt
Not enabled in golden path by default but recommended for enforcing production image provenance across the cluster:
# Enable Binary Authorization gcloud container clusters update <CLUSTER_NAME> --region <REGION> \ --binauthz-evaluation-mode=PROJECT_SINGLETON_POLICY_ENFORCE \ --quiet
Enabling verifiable node boot integrity and kernel isolation features at the cluster level:
# Enable Shielded Nodes on an existing cluster gcloud container clusters update <CLUSTER_NAME> --region <REGION> \ --enable-shielded-nodes \ --quiet # Enable GKE Sandbox (gVisor) runtime on an existing cluster gcloud container clusters update <CLUSTER_NAME> --region <REGION> \ --enable-gke-sandbox \ --quiet
> **Note:** To run workloads inside the gVisor sandbox, specify > `runtimeClassName: gvisor` in your Pod specs as detailed in the > `gke-workload-security` skill.
The five most common predefined IAM roles for GKE platform and cluster access:
| Role | Purpose | When to Use | | ------------------------------- | ------------------- | -------------------- | | `roles/container.admin` | Fu
This repository contains Agent Skills for Google products and technologies, including Google Cloud.
Repo: google/skills
Locates and loads the right Google product skill on demand from a remote catalog index, instead of preloading every skill. Use at the START of any request…
Provides safety-critical validation, guardrails, and data reduction for gcloud CLI operations across Google Cloud Platform (GCP) services and infrastructure.…
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default…
Guides a developer's first steps on Google Cloud, covering account creation, billing setup, project management, and deploying a first resource. Use when a new…
Searches, retrieves, and synthesizes official Google developer documentation across Google Cloud, AI/Gemini, Android, Chrome, Web, Flutter, Go, Firebase, and…
Guides developers through managing (adding, removing, and clearing) audience members for Google products using the Data Manager API and its associated client…