GKE clusters whose nodes are not configured as private nodes
What does ZopNight detect here?
GKE clusters are flagged at high severity when the cluster-level `privateClusterConfig.enablePrivateNodes` setting is not true, so nodes can be provisioned with external IP addresses. Every node with a public address is a host on the internet that attackers can probe, whereas private nodes carry internal addresses only and reach out through Cloud NAT.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1222 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | private nodes not enabled at cluster level |
| Source | ZopNight |
| Permissions used | container.clusters.list · container.clusters.get |
Where it applies
The exposure a public node adds
A GKE node is a Compute Engine VM. If it has an external IP address, it can be reached from the internet subject only to firewall rules, and a single permissive rule turns every node into an entry point. Google’s network isolation overview describes private nodes as the way to prevent external clients from reaching nodes: they are provisioned with internal IP addresses only. The same page adds the trade-off, that workloads on nodes without an external address cannot reach the internet unless NAT is enabled on the network.
Listing clusters and node pools by node visibility
gcloud container clusters list \ --format="table(name,location,privateClusterConfig.enablePrivateNodes)"
gcloud compute instances list --filter="name~^gke-" \ --format="table(name,zone,networkInterfaces[0].accessConfigs[0].natIP)"The second command shows which GKE node VMs actually hold an external IP today.
What ZopNight checks on each cluster
For every fully inventoried GKE cluster, ZopNight reads whether private nodes are enabled in the cluster’s private cluster configuration. When the value is anything other than true, the rule fires. A cluster missing its basic inventory details is skipped.
Where the cluster setting is not the whole story
Private nodes can now be set per node pool, and Google states that a node pool setting overrides the cluster default. A cluster whose pools are all private at pool level can still appear here, so check the node list above before planning work. This rule does not assess the control plane endpoint; that is GKE Control Plane Master Authorized Networks Disabled.
Attack surface, not spend
There is no saving. Moving to private nodes can add a Cloud NAT gateway to the bill if workloads need outbound internet access.
Making nodes private
- Create a Cloud NAT gateway on the cluster’s network if workloads call external services.
- Set the cluster default for new node pools:
gcloud container clusters update CLUSTER_NAME --location=LOCATION --enable-private-nodes. - Convert each existing Standard node pool, because the cluster flag only affects new pools:
gcloud container node-pools update POOL_NAME --cluster=CLUSTER_NAME --location=LOCATION --enable-private-nodes. - Confirm the node VMs no longer show an external IP.