More Info:

Running the GKE Metadata Server prevents workloads from accessing sensitive instance metadata and facilitates Workload Identity

Risk Level

Low

Address

Security, Reliability, Operational Excellence, Performance Efficiency

Compliance Standards

CISGKE

Triage and Remediation

Remediation

To remediate the misconfiguration “Ensure The GKE Metadata Server Is Enabled” for GCP using GCP console, follow the below steps:

  1. Go to the Google Kubernetes Engine (GKE) cluster in the GCP console.
  2. Click on “Edit” button at the top of the page.
  3. Scroll down to the “Security” section.
  4. Ensure that “Enable metadata concealment” is unchecked.
  5. Click on “Save” button at the bottom of the page.

By following these steps, you will remediate the misconfiguration “Ensure The GKE Metadata Server Is Enabled” for GCP using GCP console.

Additional Reading: