gke-golden-path
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- GKE Security Best Practices: The skill defaults to highly secure configurations, including
privateClusterConfig.enablePrivateNodesandworkloadIdentityConfig.workloadPool, which reduce the cluster's attack surface. - Secret Management: It explicitly enables
secretManagerConfigwith a short rotation interval, facilitating secure handling of sensitive credentials. - RBAC Hardening: The configuration explicitly disables insecure RBAC bindings (
enableInsecureBindingSystemAuthenticatedandenableInsecureBindingSystemUnauthenticated), adhering to the principle of least privilege. - Infrastructure Integrity: It enables Shielded Nodes and Secure Boot (
enableSecureBoot), protecting the underlying node infrastructure from tampering.
Audit Metadata