Shielded GKE Nodes should be enabled

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Description

Shielded GKE Nodes provide verifiable node integrity through secure boot, virtual Trusted Platform Module (vTPM)-enabled measured boot, and integrity monitoring, protecting clusters against boot- or kernel-level malware and rootkits that persist beyond an infected OS.

Remediation

Enable Shielded GKE Nodes on the cluster under the Security settings, or run gcloud container clusters update. See Using Shielded GKE Nodes for the full procedure.

References