Skip to main content

💼 6.2.1 Ensure GKE clusters are not running using the Compute Engine default service account (Scored)

  • ID: /frameworks/cis-gke-v1.0.0/06/02/01

Description​

Create and use minimally privileged Service accounts to run GKE cluster nodes instead of using the Compute Engine default Service account. Unnecessary permissions could be abused in the case of a node compromise.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS GKE v1.8.0 → 💼 5.2.1 Ensure GKE clusters are not running using the Compute Engine default service account (Automated)1no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance