google/gke-golden-path
>- Provides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up node autoscaling specifically (use gke-scaling instead).
npx skills add https://github.com/google/skills --skill gke-golden-path
The golden path is the recommended Autopilot configuration for production
clusters. It defines sensible defaults — when the user requests different
settings, apply them and note relevant trade-offs.
> MCP Tools: get_cluster, create_cluster, update_cluster
requests otherwise. When deviating, note trade-offs but respect the user's
choice.
subnets, IP allocation) prominently — they are hard/impossible to change
after creation.
gke-basics skill'sCLI reference for full coverage matrix and override options. If the user
says "use gcloud" or "use kubectl", respect that for the session.
golden path deviations.
If the user is unsure, use golden path defaults.
us-central1)auto-create)
Recommended best practices applied by default. If the user requests a different
setting, apply it and briefly note the security or operational trade-off.
Setting | Golden Path Value
------------------------------------------------------------------ | -----------------
autopilot.enabled | true
privateClusterConfig.enablePrivateNodes | true
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true
secretManagerConfig.enabled + rotationInterval: 120s | true
rbacBindingConfig.enableInsecureBinding* | false (both)
workloadIdentityConfig.workloadPool | enabled
networkConfig.datapathProvider | ADVANCED_DATAPATH
networkConfig.dnsConfig.clusterDns | CLOUD_DNS
autoscaling.autoscalingProfile | OPTIMIZE_UTILIZATION
verticalPodAutoscaling.enabled | true
monitoringConfig components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER
loggingConfig components | SYSTEM_COMPONENTS, WORKLOADS (enabled by default)
advancedDatapathObservabilityConfig.enableMetrics | true
nodeConfig.shieldedInstanceConfig.enableSecureBoot | true
nodeConfig.workloadMetadataConfig.mode | GKE_METADATA
nodeConfig.gcfsConfig.enabled / gvnic.enabled | true / true
addonsConfig.statefulHaConfig.enabled | true
Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled
Pod Security Standards | restricted on production namespaces
These have golden path defaults but customers may deviate with valid
justification. Ask before changing.
Setting | Default | Why Deviate
---------------------------------------- | ----------------------------------- | -----------
dnsEndpointConfig.allowExternalTraffic | true | Restrict if cluster only accessed from within VPC
autoIpamConfig / createSubnetwork | true / true | Customer has pre-existing VPC/subnets
maxPodsPerNode | 48 | 110 for high pod-density (costs more CIDR space)
subnetwork | auto-created | Customer brings existing subnets
Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling
nodeConfig.bootDisk.diskType | pd-balanced | pd-ssd for I/O-intensive, pd-standard for cost
nodeConfig.machineType | ek-standard-8 (Autopilot) | Varies by workload; use ComputeClasses
project` — don't ask users to paste project IDs.
customer confirm.
staged upgrades.
deviations with severity and remediation.
See golden-path-autopilot.yaml for the
full cluster-level policy settings.
Take google/gke-golden-path from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.