Ensure GKE cluster uses Container-Optimized OS
Nodes should use Container-Optimized OS for enhanced security.
Security Impact
Non-COS images may have unnecessary packages and larger attack surface.
How to Remediate
Configure node pools to use Container-Optimized OS (cos_containerd).
Affected Resources
Compliance Frameworks
How TigerGate Helps
TigerGate continuously monitors your GCP environment to detect and alert on this misconfiguration. Here's what our platform does for this specific check:
- Continuous Scanning
Automatically scans all Google Kubernetes Engine resources across your GCP projects every hour
- Instant Alerts
Get notified via Slack, email, or webhooks when this misconfiguration is detected
- One-Click Remediation
Fix this issue directly from the TigerGate dashboard with our guided remediation
- Compliance Evidence
Automatically collect audit evidence for CIS GCP v1.3.0, SOC 2 compliance
- Drift Detection
Get alerted if this configuration drifts back to an insecure state after remediation
Check Details
- Check ID
- gcp-gke-7
- Service
- Google Kubernetes Engine
- Category
- Instance Security
- Severity
- MEDIUM
- CIS Benchmark
- 5.5.1
Automate This Check
TigerGate automatically scans your GCP environment for this and 79+ other security checks.
Start Free Trial