More Info:

Ensures all Kubernetes clusters have the web dashboard disabled. It is recommended to disable the web dashboard because it is backed by a highly privileged service account.

Risk Level

High

Address

Security

Compliance Standards

CISGKE

Triage and Remediation

Remediation

To remediate the “Web Dashboard Should Be Disabled” misconfiguration in GCP using the GCP console, follow these steps:

  1. Log in to the GCP Console.

  2. Navigate to the GCP project that has the misconfiguration.

  3. In the left-hand menu, select “IAM & Admin” and then click on “Dashboard.”

  4. In the “Dashboard” page, you will see the “Web Dashboard” option. Click on the three dots on the right-hand side of the “Web Dashboard” option and select “Disable.”

  5. A confirmation message will appear. Click on “Disable” to confirm.

  6. Once the “Web Dashboard” has been disabled, you will no longer be able to access it from the GCP Console.

  7. Verify that the “Web Dashboard” has been disabled by going back to the “Dashboard” page and confirming that the “Web Dashboard” option is no longer available.

By following these steps, you have successfully remediated the “Web Dashboard Should Be Disabled” misconfiguration in GCP using the GCP console.

Additional Reading: