gke-golden-path
Pass
Audited by Gen Agent Trust Hub on Aug 7, 2026
Risk Level: SAFE
Full Analysis
- [Security-First Defaults]: The skill emphasizes 'golden path' configurations that enable high-security features by default, including private nodes, Master Authorized Networks, and Workload Identity, which help reduce the cluster's attack surface.
- [Credential Protection Guardrails]: It includes explicit instructions to avoid requesting or displaying sensitive information such as service account keys, tokens, or private secrets, which is an important safeguard against accidental data exposure.
- [Hardened Infrastructure Guidelines]: The instructions encourage the use of Shielded GKE Nodes and Secret Manager integration. These are standard security hardening measures that protect against firmware-level threats and improve secret management lifecycle.
- [Standardized Configuration Reference]: The skill utilizes a structured YAML configuration file (golden-path-autopilot.yaml) to provide consistent and verifiable defaults, ensuring that recommendations are based on established architectural standards.
Audit Metadata