Self-Service Allowlisting of Privileged Apps on GKE Autopilot

Google Cloud TechAbout 4 min readJul 16, 2025Watch original
THE SUMMARYAI-generated

GKE Autopilot Self-Service Allow Listing: Detailed Summary

Key Concepts:

  • GKE Autopilot: Fully managed Kubernetes service by Google, recommended since 2023.
  • Allow Listing: Mechanism to permit applications requiring elevated privileges (e.g., root access) to run on GKE Autopilot.
  • Self-Service Allow Listing: A new process enabling partner organizations to independently create, test, and manage allow lists for their applications, minimizing GKE intervention.
  • Image Digest (SHA256): Cryptographic hash of a container image used to verify its integrity and allow usage of private image mirrors.
  • Allow List Synchronizer Object: The custom resource created by the Helm chart that encapsulates the allow list configuration.
  • Private Image Mirrors: Private registries of container images maintained by security-conscious customers.

1. Introduction: GKE Autopilot and the Need for Allow Listing

  • GKE (Google Kubernetes Engine) offers two modes: Standard and Autopilot. Autopilot, being fully managed, is the recommended mode since 2023.
  • Autopilot simplifies Kubernetes management by handling node provisioning, scaling, and configuration, reducing operational overhead. It also enforces security best practices by default, blocking applications requiring elevated privileges.
  • Certain applications (e.g., logging, monitoring, security tools) require these elevated privileges and are therefore blocked by default on Autopilot. These applications need to be allow listed.
  • The previous allow listing process was cumbersome, requiring close collaboration between partner organizations and GKE engineering/product teams. Partners couldn't independently create, test, or manage their allow lists.

2. Self-Service Allow Listing: Empowering Partners

  • The video introduces Self-Service Allow Listing, a new process designed to empower partner organizations.
  • It allows partners to create and deploy allow lists for their applications with minimal GKE intervention, streamlining the onboarding process.

3. Customer Use Case: Wiz Sensor Application

  • A user wants to run the Wiz sensor application (for security monitoring) on their Autopilot cluster. This application needs root access and is blocked by default.
  • The video demonstrates installing the Wiz sensor application using Helm, where the Helm chart includes a flag to install the allow list along with the application.
  • Passing this flag allows the application to be installed successfully.
  • The Helm chart installs a new allow list synchronizer object on the cluster.

4. Private Image Mirrors: Supporting Security-Conscious Customers

  • Some customers, like banks, maintain private container image registries for security reasons.
  • By default, allow listed workloads using private images are rejected because the image path doesn't match the publicly hosted image specified in the allow list.
  • Self-Service Allow Listing addresses this by allowing partners to specify the SHA256 image digest in their allow list file.
  • This way, any customer workload with an image matching the allow listed digest will be accepted, even if the image path is different.

5. Partner Onboarding Process: Privileged App Example

  • The video shifts to the perspective of a partner organization developing an application called "Privileged App," which requires privileged pods.
  • Each partner is assigned a Git repository for uploading their allow lists for review.
  • The partner creates an allow list file that closely matches the pod specification created by their DaemonSet. This file specifies the exact exemptions required by the privileged application.
  • The partner includes the image digest (SHA256) for their container to enable customers to use private image mirrors.
  • After security review and approvals, the allow list is submitted. It is then gradually rolled out to all GKE regions over the following week.
  • After the rollout, customers can install and run the partner's application on Autopilot clusters.

6. Key Arguments and Perspectives:

  • Reduced Operational Overhead: Autopilot simplifies cluster management, but requires allow listing for certain applications.
  • Enhanced Partner Empowerment: Self-Service Allow Listing reduces dependence on Google and enables partners to independently manage their allow lists.
  • Improved Security: Allow listing ensures that only necessary privileges are granted, minimizing the attack surface.
  • Flexibility for Security-Conscious Customers: Supporting private image mirrors allows customers to maintain their security policies while using allow listed applications.

7. Notable Quotes:

  • "Autopilot... reduces the complexity and operation overhead for our customers."
  • "Self-Service Allow Listing... allows partners to create and roll out allow lists for their own applications with minimal intervention from GK engineers or the product team."

8. Logical Connections:

  • The video starts by explaining the challenges of running privileged applications on GKE Autopilot.
  • It then introduces Self-Service Allow Listing as the solution to these challenges.
  • The customer use case demonstrates how customers can benefit from allow listing.
  • The partner onboarding process shows how partner organizations can create and deploy allow lists.
  • Finally, the video highlights the benefits of Self-Service Allow Listing for both customers and partners.

9. Conclusion:

Self-Service Allow Listing significantly improves the GKE Autopilot experience by simplifying the process of enabling privileged applications. It empowers partner organizations to independently manage their allow lists, reduces operational overhead, and provides flexibility for security-conscious customers using private image mirrors. The onboarding of major partner organizations like Wiz, Datadog, and CrowdStrike highlights the value and adoption of this new feature.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.