npx skills add ...
npx skills add google/skills --skill gke-golden-path
Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up workload autoscaling specifically (use gke-workload-scaling instead).
npx skills add google/skills --skill gke-golden-path
The golden path is the recommended Autopilot configuration for production clusters. It defines sensible defaults — when the user requests different settings, apply them and note relevant trade-offs.
MCP Tools:
get_cluster,create_cluster,update_cluster
gke-basics skill's CLI reference for full
coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.If the user is unsure, use golden path defaults.
us-central1)Recommended best practices applied by default. If the user requests a different setting, apply it and briefly note the security or operational trade-off.
| Setting | Golden Path Value |
|---|---|
autopilot.enabled | true |
privateClusterConfig.enablePrivateNodes | true |
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true |
secretManagerConfig.enabled + rotationInterval: 120s | true |
rbacBindingConfig.enableInsecureBinding* | false (both) |
workloadIdentityConfig.workloadPool | enabled |
networkConfig.datapathProvider | ADVANCED_DATAPATH |
networkConfig.dnsConfig.clusterDns | CLOUD_DNS |
autoscaling.autoscalingProfile | OPTIMIZE_UTILIZATION |
verticalPodAutoscaling.enabled | true |
monitoringConfig components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER |
loggingConfig components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default) |
advancedDatapathObservabilityConfig.enableMetrics | true |
nodeConfig.shieldedInstanceConfig.enableSecureBoot | true |
nodeConfig.workloadMetadataConfig.mode | GKE_METADATA |
nodeConfig.gcfsConfig.enabled / gvnic.enabled | true / true |
addonsConfig.statefulHaConfig.enabled | true |
| Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled |
| Pod Security Standards | restricted on production namespaces |
These have golden path defaults but customers may deviate with valid justification. Ask before changing.
| Setting | Default | Why Deviate |
|---|---|---|
dnsEndpointConfig.allowExternalTraffic | true | Restrict if cluster only accessed from within VPC |
autoIpamConfig / createSubnetwork | true / true | Customer has pre-existing VPC/subnets |
maxPodsPerNode | 48 | 110 for high pod-density (costs more CIDR space) |
subnetwork | auto-created | Customer brings existing subnets |
| Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling |
nodeConfig.bootDisk.diskType | pd-balanced | pd-ssd for I/O-intensive, pd-standard for cost |
nodeConfig.machineType | ek-standard-8 (Autopilot) | Varies by workload; use ComputeClasses |
gcloud config get-value project — don't ask users to paste project IDs.See golden-path-autopilot.yaml for the full cluster-level policy settings.