All skills
google avatar

/gke-basics

@9ad3d2b
by googlegoogle/skills21k stars
1,698

Manages core GKE cluster provisioning, credentials, Autopilot vs Standard selection, and workload deployment. Use when creating GKE clusters, fetching kubectl credentials, or deciding between Autopilot and Standard modes. Don't use for Workload Identity (use gke-workload-identity), GKE networking (use gke-networking), security hardening (use gke-platform-security or gke-workload-security), or cluster upgrades (use gke-upgrades).

Use this Skill: https://skilld.dev/gh/google/skills/gke-basics

This session only. Nothing lands on disk.

referencescore-concepts.md

≈823 tokens on demand. Your agent reads this file only when SKILL.md points to it.

GKE Core Concepts

Google Kubernetes Engine (GKE) is a managed Kubernetes platform for deploying, managing, and scaling containerized applications on Google Cloud infrastructure. It handles cluster provisioning, upgrades, and node management, letting teams focus on workloads rather than infrastructure.

MCP Tools: list_clusters, get_cluster

Cluster Modes

Mode Who Manages Nodes Best For
Autopilot Google — fully managed Most workloads. No node-level
: (recommended) : nodes, scaling, and security : ops. Pay per pod resource :
: : : request. :
Standard You — full control over node Workloads requiring kernel
: : pools, OS, machine types : customization, specific node :
: : : OS, or DaemonSets not :
: : : supported by Autopilot :

Default: Autopilot. Use Standard only when Autopilot has a documented limitation for your workload.

Cluster Architecture

  • Regional clusters (recommended): Control plane replicated across 3 zones. Higher availability, no single-zone failure risk.
  • Zonal clusters: Single control plane zone. Lower cost, acceptable for dev/test.
  • Private clusters (golden path default): Nodes have no public IPs. Control plane accessible via private endpoint or DNS endpoint.

Networking Model

GKE uses VPC-native clusters with alias IP ranges:

  • Each pod gets a routable IP from the pod CIDR
  • Dataplane V2 (eBPF-based) is the golden path default — provides built-in Network Policy enforcement
  • Cloud DNS for in-cluster DNS resolution
  • Gateway API for ingress/load balancing

Scaling Model

  • Horizontal Pod Autoscaler (HPA): Scales pod replicas based on CPU, memory, or custom metrics
  • Vertical Pod Autoscaler (VPA): Recommends or auto-adjusts pod resource requests
  • Cluster Autoscaler / NAP: Scales nodes to match pod demand (Autopilot handles this automatically)
  • ComputeClasses: Declarative node selection — machine family, Spot VMs, GPU targeting

Identity & Security Model

  • Workload Identity Federation: Pods assume Google Cloud IAM identities without static keys
  • Secret Manager integration: Secrets synced to Kubernetes with automatic rotation
  • Pod Security Standards: restricted profile enforced on production namespaces
  • Shielded Nodes: Secure Boot and integrity monitoring (Autopilot-enforced)

Regional Availability

GKE is available in all Google Cloud regions. Autopilot clusters are regional by default. See https://cloud.google.com/about/locations for the full region list.

Pricing

GKE pricing depends on the cluster mode:

  • Autopilot: Pay for pod resource requests (vCPU, memory, ephemeral storage). No cluster management fee.
  • Standard: Pay for underlying Compute Engine VMs plus a per-cluster management fee.

For current pricing, see https://cloud.google.com/kubernetes-engine/pricing.

Source: SKILL.md on GitHub

1 warning1d3 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    This skill provides a comprehensive guide for managing Google Kubernetes Engine (GKE) clusters, following Google Cloud's established best practices for security and provisioning. It includes potential considerations regarding the handling of Kubernetes manifests and external libraries, which are standard for cloud infrastructure management tools.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: MEDIUM · 1 issue

Signed by skilld at 9ad3d2b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
metadata
{
  "version": "1.1.1",
  "category": "Containers"
}

README badge

README badge for google/skills/gke-basics