Skip to main content

💼 5.2.1 Ensure GKE clusters are not running using the Compute Engine default service account (Automated)

  • ID: /frameworks/cis-gke-v1.8.0/05/02/01

Description

Create and use minimally privileged Service accounts to run GKE cluster nodes instead of using the Compute Engine default Service account. Unnecessary permissions could be abused in the case of a node compromise.

Similar

  • Sections
    • /frameworks/cis-gke-v1.0.0/06/02/01

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS GKE v1.0.0 → 💼 6.2.1 Ensure GKE clusters are not running using the Compute Engine default service account (Scored)no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ Google GKE Cluster Node Pool uses default Service account🟢1🟢 x6no data