PROFESSIONAL-CLOUD-DEVELOPER · Question #226
You are trying to connect to your Google Kubernetes Engine (GKE) cluster using kubectl from Cloud Shell. You have deployed your GKE cluster with a public endpoint. From Cloud Shell, you run the…
The correct answer is B. Your Cloud Shell external IP address is not part of the authorized networks of the cluster. GKE clusters with public endpoints support an authorized networks feature - an IP allowlist that restricts which source IPs can reach the Kubernetes API server. Cloud Shell sessions receive dynamic external IP addresses that are typically not pre-added to this allowlist. A…
Question
You are trying to connect to your Google Kubernetes Engine (GKE) cluster using kubectl from Cloud Shell. You have deployed your GKE cluster with a public endpoint. From Cloud Shell, you run the following command:
You notice that the kubectl commands time out without returning an error message. What is the most likely cause of this issue?
Options
- AYour user account does not have privileges to interact with the cluster using kubectl.
- BYour Cloud Shell external IP address is not part of the authorized networks of the cluster.
- CThe Cloud Shell is not part of the same VPC as the GKE cluster.
- DA VPC firewall is blocking access to the cluster's endpoint.
How the community answered
(61 responses)- A7% (4)
- B77% (47)
- C3% (2)
- D13% (8)
Explanation
GKE clusters with public endpoints support an authorized networks feature - an IP allowlist that restricts which source IPs can reach the Kubernetes API server. Cloud Shell sessions receive dynamic external IP addresses that are typically not pre-added to this allowlist. A blocked IP at this layer results in a TCP timeout (the connection is silently dropped), which explains the timeout with no error message. An authentication/authorization failure (A) would return an HTTP 401/403 error immediately, not a timeout. VPC membership (C) is irrelevant for a public endpoint - the API server is reachable over the internet. A VPC firewall (D) is possible in theory but less likely than the authorized networks restriction for a public-endpoint cluster accessed from Cloud Shell.
Topics
Community Discussion
No community discussion yet for this question.