GKE Golden Path Configuration
SkillDev toolsProvides GKE golden path configuration defaults, production readiness checklists, and cluster default patterns. Use when designing GKE clusters, verifying GKE production readiness, or checking configurations against GKE defaults. Don't use for setting up node autoscaling specifically (use gke-scaling instead).
Use GKE Golden Path Configuration in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add GKE Golden Path Configuration and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the GKE Golden Path Configuration skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by hermesonehq/hermes-registry in skills/devops/gke-golden-path/SKILL.md and read by ahel’s review.
The golden path is the recommended Autopilot configuration for production clusters. It defines sensible defaults — when the user requests different settings, apply them and note relevant trade-offs.
MCP Tools:
get_cluster,create_cluster,update_cluster
Rules
- Default to the golden path. Use golden path values unless the user requests otherwise. When deviating, note trade-offs but respect the user's choice.
- Day-0 vs Day-1. Flag Day-0 decisions (networking, private nodes, subnets, IP allocation) prominently — they are hard/impossible to change after creation.
- Tool preference: MCP > gcloud > kubectl. See the
gke-basicsskill's CLI reference for full coverage matrix and override options. If the user says "use gcloud" or "use kubectl", respect that for the session. - Document decisions and rationale, especially for Day-0 choices and golden path deviations.
Required Inputs
If the user is unsure, use golden path defaults.
- Project ID (required)
- Region (required, e.g.,
us-central1) - Cluster name (required)
- Environment type: dev/test or production (defaults to production)
- Networking: bring-your-own VPC/subnet or auto-create (default: auto-create)
- Scale expectations: expected node/pod count, workload types
- Cost constraints: Spot VM tolerance, budget considerations
Always-Apply Defaults
Recommended best practices applied by default. If the user requests a different setting, apply it and briefly note the security or operational trade-off.
| Setting | Golden Path Value |
|---|---|
autopilot.enabled | true |
privateClusterConfig.enablePrivateNodes | true |
masterAuthorizedNetworksConfig.privateEndpointEnforcementEnabled | true |
secretManagerConfig.enabled + rotationInterval: 120s | true |
rbacBindingConfig.enableInsecureBinding* | false (both) |
workloadIdentityConfig.workloadPool | enabled |
networkConfig.datapathProvider | ADVANCED_DATAPATH |
networkConfig.dnsConfig.clusterDns | CLOUD_DNS |
autoscaling.autoscalingProfile | OPTIMIZE_UTILIZATION |
verticalPodAutoscaling.enabled | true |
monitoringConfig components | SYSTEM_COMPONENTS, STORAGE, POD, DEPLOYMENT, STATEFULSET, DAEMONSET, HPA, JOBSET, CADVISOR, KUBELET, DCGM, APISERVER, SCHEDULER, CONTROLLER_MANAGER |
advancedDatapathObservabilityConfig.enableMetrics | true |
nodeConfig.shieldedInstanceConfig.enableSecureBoot | true |
nodeConfig.workloadMetadataConfig.mode | GKE_METADATA |
nodeConfig.gcfsConfig.enabled / gvnic.enabled | true / true |
addonsConfig.statefulHaConfig.enabled | true |
| Storage CSI drivers (Filestore, GCS FUSE, Parallelstore) | enabled |
| Pod Security Standards | restricted on production namespaces |
Customer-Configurable Settings
These have golden path defaults but customers may deviate with valid justification. Ask before changing.
| Setting | Default | Why Deviate |
|---|---|---|
dnsEndpointConfig.allowExternalTraffic | true | Restrict if cluster only accessed from within VPC |
autoIpamConfig / createSubnetwork | true / true | Customer has pre-existing VPC/subnets |
maxPodsPerNode | 48 | 110 for high pod-density (costs more CIDR space) |
subnetwork | auto-created | Customer brings existing subnets |
| Maintenance exclusion windows | configured (NO_MINOR_UPGRADES, 1yr) | Customer-specific scheduling |
nodeConfig.bootDisk.diskType | pd-balanced | pd-ssd for I/O-intensive, pd-standard for cost |
nodeConfig.machineType | ek-standard-8 (Autopilot) | Varies by workload; use ComputeClasses |
Guardrails
- Do not request or output secrets (tokens, keys, service account JSON).
- Discover project/cluster context via MCP tools or
gcloud config get-value project— don't ask users to paste project IDs. - For Day-0 decisions, always ask clarifying questions before proceeding.
- For Day-1 features, propose golden path defaults with trade-offs and let the customer confirm.
- Do not promise zero downtime; advise PDBs, health probes, replicas, and staged upgrades.
- When auditing existing clusters, compare against golden path and report deviations with severity and remediation.
Golden Path Config
See golden-path-autopilot.yaml for the full cluster-level policy settings.
Signals
- GitHub stars
- 91
- Forks
- 17
- Last commit
- Jul 2026
Advanced
- Item type
- skill
- Key
gke-golden-path-hermesonehq- Source
- github.com/hermesonehq/hermes-registry
github.com/hermesonehq/hermes-registry
Related picks
Skill · microsoft
The pick for Kubernetesinfra-containers-kubernetes
Skill · agents-inc
The pick for Kubernetesgcp-security-scanner
Skill · a5c-ai
The pick for GCPgcp-config-connector
Skill · gke-labs
The pick for GCPgenerate-sandbox-policy
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infra