GKE Cluster (Autopilot & Standard)
Private, Workload-Identity-enabled GKE cluster with managed node pools, release channels and maintenance windows, hardened to Google best practice.
Compare Managed Kubernetes across clouds →
Part of: GCP Kubernetes Platform
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-30 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o gcp-gke-cluster-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/gcp-gke-cluster/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle gcp-gke-cluster-1.0.0.sigstore.json \
gcp-gke-cluster-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "45796f37b37c3e07e78481e06cf255482579695180cff2059f6d9979199bca20 gcp-gke-cluster-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "gke_cluster" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-gke-cluster/gcp"
version = "1.0.0"
}Paid module — needs a purchase (or a subscription that covers it) plus a registry token from /account/tokens. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract — every input name, type, default and description, plus every output — is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every Free module. This one is Premium, so its contract unlocks when you buy it.
Documentation
gcp-gke-cluster
Private, Workload-Identity-enabled GKE cluster with managed node pools, release
channels and maintenance windows, hardened to Google best practice. Runs in
Autopilot or Standard mode from the same module: private nodes, Dataplane
V2, shielded nodes with secure boot, a dedicated least-privilege node service
account, and deletion protection on by default. Works with Terraform and
OpenTofu (>= 1.6), Google provider >= 7.0, < 8.0.
Secure defaults:
- Private nodes (no public node IPs), optional fully-private endpoint
- Workload Identity enabled (
PROJECT.svc.id.goog) - Dedicated node service account with only the logging/monitoring/Artifact Registry roles GKE needs (never the default compute SA)
- Shielded nodes, secure boot, integrity monitoring,
GKE_METADATAworkload metadata, legacy metadata endpoints disabled - Release-channel upgrades inside a weekend maintenance window
deletion_protection = true
Requirements
| Requirement | Version |
|---|---|
| Terraform / OpenTofu | >= 1.6 |
hashicorp/google | >= 7.0, < 8.0 |
The subnetwork must already have the two named secondary IP ranges (pods +
services). Pair with the gcp-vpc module from this catalog.
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference unlock after purchase
The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence - shown here and bundled in the download.
- Usage
- Inputs
- Outputs
Related modules
Alibaba Cloud ACK Cluster
Managed ACK Kubernetes with node pools, VPC integration, and RAM roles.
Azure Kubernetes Service Cluster
Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.
Civo Kubernetes Cluster
Fast-launch k3s cluster with node pools, firewall rules, and network.
DigitalOcean DOKS Cluster
Production DOKS with node pools, VPC, registry hookup, and maintenance windows in one apply.
EKS Cluster with Managed Node Groups
Opinionated EKS cluster with node groups, core add-ons, Pod Identity, and KMS secret encryption.
Exoscale SKS Cluster
SKS Kubernetes with node pools, security groups, and anti-affinity.