Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up workload autoscaling specifically (use gke-workload-scaling instead).
66
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/cloud/gke-golden-path/SKILL.mdThe golden path is the recommended Autopilot configuration for production clusters. It defines sensible defaults — when the user requests different settings, apply them and note relevant trade-offs.
MCP Tools:
get_cluster,create_cluster,update_cluster
gke-basics skill's CLI reference for full
coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.If the user is unsure, use golden path defaults.
us-central1)Recommended best practices applied by default. If the user requests a different setting, apply it and briefly note the security or operational trade-off.
| Setting | Golden Path Value |
|---|---|
autopilot.enabled | true |
privateClusterConfig.enablePrivateNodes | true |
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true |
secretManagerConfig.enabled + rotationInterval: 120s | true |
rbacBindingConfig.enableInsecureBinding* | false (both) |
workloadIdentityConfig.workloadPool | enabled |
networkConfig.datapathProvider | ADVANCED_DATAPATH |
networkConfig.dnsConfig.clusterDns | CLOUD_DNS |
autoscaling.autoscalingProfile | OPTIMIZE_UTILIZATION |
verticalPodAutoscaling.enabled | true |
monitoringConfig components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER |
loggingConfig components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default) |
advancedDatapathObservabilityConfig.enableMetrics | true |
nodeConfig.shieldedInstanceConfig.enableSecureBoot | true |
nodeConfig.workloadMetadataConfig.mode | GKE_METADATA |
nodeConfig.gcfsConfig.enabled / gvnic.enabled | true / true |
addonsConfig.statefulHaConfig.enabled | true |
| Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled |
| Pod Security Standards | restricted on production namespaces |
These have golden path defaults but customers may deviate with valid justification. Ask before changing.
| Setting | Default | Why Deviate |
|---|---|---|
dnsEndpointConfig.allowExternalTraffic | true | Restrict if cluster only accessed from within VPC |
autoIpamConfig / createSubnetwork | true / true | Customer has pre-existing VPC/subnets |
maxPodsPerNode | 48 | 110 for high pod-density (costs more CIDR space) |
subnetwork | auto-created | Customer brings existing subnets |
| Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling |
nodeConfig.bootDisk.diskType | pd-balanced | pd-ssd for I/O-intensive, pd-standard for cost |
nodeConfig.machineType | ek-standard-8 (Autopilot) | Varies by workload; use ComputeClasses |
gcloud config get-value project — don't ask users to paste project IDs.See golden-path-autopilot.yaml for the full cluster-level policy settings.
1776276
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.