More Info:

Ensures all Kubernetes clusters have alias IP ranges enabled. Alias IP ranges allow users to assign ranges of internal IP addresses as alias to a network interface.

Risk Level

Low

Address

Security

Compliance Standards

CISGKE

Triage and Remediation

Remediation

To remediate the “Alias IP Ranges Should Be Enabled” misconfiguration for GCP using the GCP console, follow these steps:

  1. Open the GCP console and navigate to the VPC network that you want to remediate.

  2. Click on the “Edit” button next to the VPC network.

  3. Scroll down to the “Subnet” section and click on the subnet that you want to remediate.

  4. Click on the “Edit” button next to the subnet.

  5. In the “Secondary IP ranges” section, click on the “Add secondary IP range” button.

  6. Enter a name for the secondary IP range and specify the IP address range that you want to use.

  7. Click on the “Save” button to save the changes.

  8. Repeat steps 5-7 for any additional secondary IP ranges that you want to add.

  9. Click on the “Save” button to save the changes to the subnet.

  10. Repeat steps 3-9 for any additional subnets that you want to remediate.

By following these steps, you have enabled the “Alias IP Ranges” feature for the selected subnets in your GCP VPC network.

Additional Reading: