Skip to main content
compliance · gcp

GKE clusters whose nodes are not configured as private nodes

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

GKE clusters are flagged at high severity when the cluster-level `privateClusterConfig.enablePrivateNodes` setting is not true, so nodes can be provisioned with external IP addresses. Every node with a public address is a host on the internet that attackers can probe, whereas private nodes carry internal addresses only and reach out through Cloud NAT.

Signal and threshold

How ZopNight evaluates GKE clusters whose nodes are not configured as private nodes.
Field Value
Rule IDsRC-1222
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdprivate nodes not enabled at cluster level
SourceZopNight
Permissions usedcontainer.clusters.list · container.clusters.get

The exposure a public node adds

A GKE node is a Compute Engine VM. If it has an external IP address, it can be reached from the internet subject only to firewall rules, and a single permissive rule turns every node into an entry point. Google’s network isolation overview describes private nodes as the way to prevent external clients from reaching nodes: they are provisioned with internal IP addresses only. The same page adds the trade-off, that workloads on nodes without an external address cannot reach the internet unless NAT is enabled on the network.

Listing clusters and node pools by node visibility

Terminal window
gcloud container clusters list \
--format="table(name,location,privateClusterConfig.enablePrivateNodes)"
gcloud compute instances list --filter="name~^gke-" \
--format="table(name,zone,networkInterfaces[0].accessConfigs[0].natIP)"

The second command shows which GKE node VMs actually hold an external IP today.

What ZopNight checks on each cluster

For every fully inventoried GKE cluster, ZopNight reads whether private nodes are enabled in the cluster’s private cluster configuration. When the value is anything other than true, the rule fires. A cluster missing its basic inventory details is skipped.

Where the cluster setting is not the whole story

Private nodes can now be set per node pool, and Google states that a node pool setting overrides the cluster default. A cluster whose pools are all private at pool level can still appear here, so check the node list above before planning work. This rule does not assess the control plane endpoint; that is GKE Control Plane Master Authorized Networks Disabled.

Attack surface, not spend

There is no saving. Moving to private nodes can add a Cloud NAT gateway to the bill if workloads need outbound internet access.

Making nodes private

  1. Create a Cloud NAT gateway on the cluster’s network if workloads call external services.
  2. Set the cluster default for new node pools: gcloud container clusters update CLUSTER_NAME --location=LOCATION --enable-private-nodes.
  3. Convert each existing Standard node pool, because the cluster flag only affects new pools: gcloud container node-pools update POOL_NAME --cluster=CLUSTER_NAME --location=LOCATION --enable-private-nodes.
  4. Confirm the node VMs no longer show an external IP.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·