gke-platform-security
About
Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. Covers cluster add-ons (Secret Manager enablement), RBAC hardening (disabling insecure bindings, audit tools), Binary Authorization, enabling Shielded Nodes, GKE Sandbox cluster enablement, GKE IAM roles, and cross-service authentication IAM patterns. Use when securing cluster control planes, hardening GKE RBAC, enabling Shielded Nodes, enabling GKE Sandbox runtime, enabling cluster-wide security add-ons, or managing GKE IAM roles. Don't use for workload-level security (Workload Identity, SecretProviderClass, PSS, NetPol, gVisor pod runtimeClassName; use gke-workload-security instead).
Capabilities
The crawler did not record capability metadata for this resource. Inspect the endpoint directly to see what it exposes.
Provenance
- Discovered
- Relayed by agntcy
- Identifier
- urn:air:outshift.io:agntcy:gke-platform-security
- Catalog host
- outshift.io · via agntcy registry
- Anchor check
- Not anchored
- Last crawled
- seen 1h ago
Discovered through outshift.io's registry, not anchored by StealthStack. We relay the listing as-is; we have not checked that the URN authority matches the publishing host. How trust works →