/gke-workload-security
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup),
$ npx -y skills add google/skills --skill gke-workload-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/gke-workload-security
Context preview
The summary Claude sees to decide when to auto-load this skill.
Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup),
SKILL.md
gke-workload-security.SKILL.mdname: gke-workload-security
description: >-
Audits, configures, and hardens workload-level security controls for Google
Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security
audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation,
KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane
V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod
Security Standards (`restricted` labeling), and mounting Secret Manager secrets via
CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating
namespaces, applying pod security standards, setting up Workload Identity, or
configuring network policies and secret volume mounts. Don't use for cluster-wide
control plane security, RBAC hardening, Binary Authorization, Shielded Nodes,
or enabling platform-level GKE add-ons (use gke-platform-security instead).
metadata:
category: Security
GKE Workload Security
This skill provides workflows and best practices for securing GKE workloads. It covers security auditing, Identity and Access Management (Workload Identity), Network Security (Network Policies), and Node Security.
Workflows
1. Security Audit
Assess the current security posture of your cluster using the provided audit script.
**Prerequisites:**
- `gcloud` CLI authenticated.
- `jq` command-line JSON processor installed.
**Capabilities:**
- Checks for Workload Identity.
- Verifies Network Policy is enabled.
- Checks if Shielded Nodes are enabled.
- Checks if Binary Authorization is enabled.
- Checks for Private Cluster configuration.
**Command:**
scripts/audit_cluster.sh <cluster-name> <region> <project-id>
2. Configure Workload Identity
Workload Identity allows Kubernetes Service Accounts (KSAs) to impersonate Google Service Accounts (GSAs). This is the recommended method for workloads to access Google Cloud APIs.
**Steps:**
1. **Create Namespace and KSA:**
kubectl create namespace workload-identity-test-ns
kubectl create serviceaccount <ksa-name> \
--namespace workload-identity-test-ns2. **Bind KSA to GSA:**
gcloud iam service-accounts add-iam-policy-binding <gsa-name>@<project-id>.iam.gserviceaccount.com \
--role roles/iam.workloadIdentityUser \
--member "serviceAccount:<project-id>.svc.id.goog[workload-identity-test-ns/<ksa-name>]"3. **Annotate KSA:**
kubectl annotate serviceaccount <ksa-name> \
--namespace workload-identity-test-ns \
iam.gke.io/gcp-service-account=<gsa-name>@<project-id>.iam.gserviceaccount.com4. **Verify Example Pod:** Use existing asset `assets/workload-identity-pod.yaml` to test the configuration. Update the `<ksa-name>` in the file first.
kubectl apply -f assets/workload-identity-pod.yaml -n workload-identity-test-ns
3. Implement Network Policies
Control traffic flow between Pods using Network Policies. By default, all traffic is allowed.
**Enable Network Policy Enforcement:**
gcloud container clusters update <cluster-name> \
--update-addons=NetworkPolicy=ENABLED \
--region <region>> [!NOTE] If your cluster uses Dataplane V2 (`--enable-dataplane-v2`), Network > Policy enforcement is built-in and this step is not required (and may fail).
**Apply Default Deny Policy:** Isolate namespaces by denying all ingress and egress traffic by default.
**Replace `<target-namespace>` with the namespace you want to isolate.**
kubectl apply -f assets/default-deny-netpol.yaml -n <target-namespace>
4. GKE Sandbox (gVisor) Pod Isolation
Run untrusted workloads in a sandbox for extra kernel isolation. *(Note: Enabling Shielded Nodes (`--enable-shielded-nodes`) and GKE Sandbox (`--enable-gke-sandbox`) at the cluster control plane level are platform-level actions covered in the `gke-platform-security` skill.)*
**Run a Sandboxed Pod:** Add `runtimeClassName: gvisor` to your Pod spec:
apiVersion: v1
kind: Pod
metadata:
name: sandboxed-pod
spec:
runtimeClassName: gvisor
containers:
- name: app
image: nginx5. Pod Security Standards
Enforce security policies on namespaces using labels.
**Enforce Restricted Profile:**
kubectl label --overwrite ns <namespace> \
pod-security.kubernetes.io/enforce=restricted \
pod-security.kubernetes.io/enforce-version=latest> [!NOTE] Using `latest` ensures you use the policies corresponding to the > cluster's current version. You can pin it to a specific version (e.g., > `v1.30`) to lock down the namespace to policies of a specific release.
6. Secret Manager Integration (CSI Driver)
Mount secrets from Google Cloud Secret Manager directly as volumes in your pods.
**Prerequisites**: Secret Manager CSI driver must be enabled on the cluster.
**Example SecretProviderClass:**
apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
name: my-secret-provider
spec:
provider: gcp
parameters:
secrets: |
- resourceName: "projects/<project-id>/secrets/my-secret/versions/latest"
fileName: "my-secret-file"**Example Pod Spec excerpt:**
spec:
containers:
- name: my-app
volumeMounts:
- name: secrets-store-inline
mountPath: "/mnt/secrets"
readOnly: true
volumes:
- name: secrets-store-inline
csi:
driver: secrets-store.csi.k8s.io
readOnly: true
volumeAttributes:
secretProviderClass: "my-secret-provider"7. Enable Network Policy Logging
If using GKE Dataplane V2, you can log allowed and denied connections.
**Steps:**
1. Configure the `NetworkLogging` custom resource.
**Example NetworkLogging Manifest:**
apiVersion: networking.gke.io/v1alpha1
kind: NetworkLogging
metadata:
nam
Read more
name: gke-workload-security description: >- Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling), and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead). metadata: category: Security
GKE Workload Security
This skill provides workflows and best practices for securing GKE workloads. It covers security auditing, Identity and Access Management (Workload Identity), Network Security (Network Policies), and Node Security.
Workflows
1. Security Audit
Assess the current security posture of your cluster using the provided audit script.
**Prerequisites:**
- `gcloud` CLI authenticated.
- `jq` command-line JSON processor installed.
**Capabilities:**
- Checks for Workload Identity.
- Verifies Network Policy is enabled.
- Checks if Shielded Nodes are enabled.
- Checks if Binary Authorization is enabled.
- Checks for Private Cluster configuration.
**Command:**
scripts/audit_cluster.sh <cluster-name> <region> <project-id>
2. Configure Workload Identity
Workload Identity allows Kubernetes Service Accounts (KSAs) to impersonate Google Service Accounts (GSAs). This is the recommended method for workloads to access Google Cloud APIs.
**Steps:**
1. **Create Namespace and KSA:**
kubectl create namespace workload-identity-test-ns
kubectl create serviceaccount <ksa-name> \
--namespace workload-identity-test-ns2. **Bind KSA to GSA:**
gcloud iam service-accounts add-iam-policy-binding <gsa-name>@<project-id>.iam.gserviceaccount.com \
--role roles/iam.workloadIdentityUser \
--member "serviceAccount:<project-id>.svc.id.goog[workload-identity-test-ns/<ksa-name>]"3. **Annotate KSA:**
kubectl annotate serviceaccount <ksa-name> \
--namespace workload-identity-test-ns \
iam.gke.io/gcp-service-account=<gsa-name>@<project-id>.iam.gserviceaccount.com4. **Verify Example Pod:** Use existing asset `assets/workload-identity-pod.yaml` to test the configuration. Update the `<ksa-name>` in the file first.
kubectl apply -f assets/workload-identity-pod.yaml -n workload-identity-test-ns
3. Implement Network Policies
Control traffic flow between Pods using Network Policies. By default, all traffic is allowed.
**Enable Network Policy Enforcement:**
gcloud container clusters update <cluster-name> \
--update-addons=NetworkPolicy=ENABLED \
--region <region>> [!NOTE] If your cluster uses Dataplane V2 (`--enable-dataplane-v2`), Network > Policy enforcement is built-in and this step is not required (and may fail).
**Apply Default Deny Policy:** Isolate namespaces by denying all ingress and egress traffic by default.
**Replace `<target-namespace>` with the namespace you want to isolate.**
kubectl apply -f assets/default-deny-netpol.yaml -n <target-namespace>
4. GKE Sandbox (gVisor) Pod Isolation
Run untrusted workloads in a sandbox for extra kernel isolation. *(Note: Enabling Shielded Nodes (`--enable-shielded-nodes`) and GKE Sandbox (`--enable-gke-sandbox`) at the cluster control plane level are platform-level actions covered in the `gke-platform-security` skill.)*
**Run a Sandboxed Pod:** Add `runtimeClassName: gvisor` to your Pod spec:
apiVersion: v1
kind: Pod
metadata:
name: sandboxed-pod
spec:
runtimeClassName: gvisor
containers:
- name: app
image: nginx5. Pod Security Standards
Enforce security policies on namespaces using labels.
**Enforce Restricted Profile:**
kubectl label --overwrite ns <namespace> \
pod-security.kubernetes.io/enforce=restricted \
pod-security.kubernetes.io/enforce-version=latest> [!NOTE] Using `latest` ensures you use the policies corresponding to the > cluster's current version. You can pin it to a specific version (e.g., > `v1.30`) to lock down the namespace to policies of a specific release.
6. Secret Manager Integration (CSI Driver)
Mount secrets from Google Cloud Secret Manager directly as volumes in your pods.
**Prerequisites**: Secret Manager CSI driver must be enabled on the cluster.
**Example SecretProviderClass:**
apiVersion: secrets-store.csi.x-k8s.io/v1
kind: SecretProviderClass
metadata:
name: my-secret-provider
spec:
provider: gcp
parameters:
secrets: |
- resourceName: "projects/<project-id>/secrets/my-secret/versions/latest"
fileName: "my-secret-file"**Example Pod Spec excerpt:**
spec:
containers:
- name: my-app
volumeMounts:
- name: secrets-store-inline
mountPath: "/mnt/secrets"
readOnly: true
volumes:
- name: secrets-store-inline
csi:
driver: secrets-store.csi.k8s.io
readOnly: true
volumeAttributes:
secretProviderClass: "my-secret-provider"7. Enable Network Policy Logging
If using GKE Dataplane V2, you can log allowed and denied connections.
**Steps:**
1. Configure the `NetworkLogging` custom resource.
**Example NetworkLogging Manifest:**
apiVersion: networking.gke.io/v1alpha1 kind: NetworkLogging metadata: nam
This repository contains Agent Skills for Google products and technologies, including Google Cloud. This repository is under active development.
Repo: google/skills
Other skills on google-skills.
- /data-manager-api-audience-ingestion
Guides developers through managing (adding, removing, and clearing) audience members for Google products using the Data Manager API and its associated client libraries. Use this skill when the user wants to upload audience members, remove specific users, or clear/replace an
Open skill - /data-manager-api-event-ingestion
Guides developers through implementing event and conversion ingestion to Google products using the Data Manager API /v1/events/ingest endpoint and its associated client libraries. Use this skill when the user wants to upload offline conversions, enhanced conversions for leads,
Open skill - /data-manager-api-setup
Guides developers through client library installation and authentication setup steps for the Data Manager API. Use this skill when a user is getting started with the Data Manager API and needs to setup their local environment, install the client library, or setup access to the
Open skill - /google-ads-api-account-diagnostics
Diagnoses Google Ads account performance issues such as conversion loss (value or volume), low lead flow/volume, and lost impression share (opportunities) due to ad rank, bids, or budgets. Use when troubleshooting sudden performance drops, analyzing campaign impression share
Open skill - /google-ads-api-mcp-setup
Guides developers through downloading, configuring, and installing the official open-source Google Ads MCP Server. Use this skill when a user wants to connect their AI assistant (such as Gemini, Claude Code, or Cursor) to their Google Ads account to query campaigns or retrieve
Open skill - /google-ads-api-quickstart
Guides developers through Google Ads API quickstart: credential setup, choosing from 6 client libraries/REST, configuring environments, and running a "retrieve campaigns" script. Troubleshoots common setup errors: USER_PERMISSION_DENIED, login_customer_id issues, and
Open skill

