Severity

0.0
low
0
10
Severity Framework
Snyk CCSS
Rule category
Containers/ Best Practices

Is your environment affected by this misconfiguration?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
Frameworks
CIS-Controls
  • Snyk IDSNYK-CC-00423
  • creditSnyk Research Team

Description

Node verification will be disabled which increases the attacker's ability to impersonate a node in the cluster.

How to fix?

Set enable_shielded_nodes attribute to true or set enable_autopilot attribute to true.

Example configuration:

resource "google_container_cluster" "allowed" {
  name                  = "my-gke-cluster423a"
  location              = "us-central1-b"
  enable_shielded_nodes = true
  initial_node_count       = 1
  node_config{
    disk_size_gb = 10
  }
}