Managed Kubernetes platform on Google Cloud. Defaults to Autopilot mode unless Standard is explicitly required.
-
Private Autopilot Clusters:
- Use
--enable-private-nodes for private node IP addresses.
- Use
--enable-private-endpoint to disable public IP access to the control plane.
- Restrict control plane access with
--enable-master-authorized-networks and --master-authorized-networks=CIDR_BLOCK:
gcloud container clusters create-auto CLUSTER_NAME --region=REGION \
--enable-private-nodes \
--enable-private-endpoint \
--enable-master-authorized-networks \
--master-authorized-networks=CIDR_BLOCK
-
Workload Identity (IAM Binding):
- Never mount raw GCP Service Account JSON keys in Pods.
- Annotate the Kubernetes ServiceAccount (
KSA) to bind to the Google Service Account (GSA):
metadata:
annotations:
iam.gke.io/gcp-service-account: GSA_NAME@PROJECT_ID.iam.gserviceaccount.com
-
Autopilot Resource Requests:
- In Autopilot, CPU requests must be specified in increments of 250m (0.25 vCPU). If an unaligned CPU request (e.g., 300m) is requested, round up to the nearest 250m increment (500m / 0.5 vCPU).
- Resource requests equal limits automatically. Omit
limits to allow Autopilot to set defaults matching requests.
-
Cluster Credentials:
- Always explicitly specify
--region (for regional clusters) or --zone (for zonal clusters) when fetching credentials:
gcloud container clusters get-credentials CLUSTER_NAME --region=REGION --quiet
-
Core Concepts [blocked]: Architecture, cluster modes (Autopilot vs Standard), networking, scaling, and security model.
-
CLI Usage & Tool Reference [blocked]: Tool preference hierarchy (MCP vs gcloud vs kubectl), gcloud container commands, and user preference overrides.
-
Client Libraries [blocked]: Official Kubernetes and Google Cloud Container client libraries in Python, Go, Node.js, and Java.
-
MCP Usage [blocked]: Connecting to and using the 23 structured GKE MCP tools for cluster management, K8s resources, and diagnostics.
-
Infrastructure as Code [blocked]: Terraform examples for google_container_cluster (Autopilot), Kubernetes provider resources, and YAML samples.