> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-67.md).

# GCP Kubernetes Engine Clusters have legacy compute engine metadata endpoints enabled misconfiguratio

## Rule Details

|                        |                                           |
| ---------------------- | ----------------------------------------- |
| Cortex AppSec Rule ID  | APPSEC\_GCP\_67                           |
| Category - Subcategory | Kubernetes - Management Services Exposure |
| Provider               | GCP                                       |
| Severity               | LOW                                       |
| Framework              | Terraform, Terraform Plan                 |
| Mapped CSPM/KSPM Rule  | ea1503e1-6927-4416-ac45-b975571d96cb      |

## Impact

Disable the legacy GCE instance metadata APIs for GKE nodes. Under some circumstances, these can be used from within a pod to extract the node's credentials. The legacy GCE metadata endpoint allows simple HTTP requests to be made returning sensitive information. To prevent the enumeration of metadata endpoints and data exfiltration, the legacy metadata endpoint must be disabled. Without requiring a custom HTTP header when accessing the legacy GCE metadata endpoint, a flaw in an application that allows an attacker to trick the code into retrieving the contents of an attacker-specified web URL could provide a simple method for enumeration and potential credential exfiltration. By requiring a custom HTTP header, the attacker needs to exploit an application flaw that allows them to control the URL and also add custom headers in order to carry out this attack successfully.

## How to Fix

*Resource:* google\_container\_cluster

* *Arguments:* min\_master\_version \[source,go]

***

resource "google\_container\_cluster" "example" { name = var.name location = var.location initial\_node\_count = 1 project = data.google\_project.project.name

* min\_master\_version = 1.12 // (or higher) }

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-67.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
