For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-46l.md. A documentation index is available at /llms.txt.

Control plane authorized networks should be enabled

Description

Master authorized networks should be enabled to restrict access to the cluster’s control plane by using an allowlist of IPs.

Remediation

Using the command line

  1. Enable master authorized networks with the following command:
    gcloud container clusters update <cluster_name> --zone <compute_zone> --enable-master-authorized-networks