New recommendations of NODE_SA_MISSING_PERMISSIONS subtype are added to the portfolio of GKE Recommendations
Share
Services
## Feature
New recommendations of `NODE_SA_MISSING_PERMISSIONS` subtype are added to the portfolio of [GKE Recommendations](https://cloud.google.com/kubernetes-engine/docs/how-to/optimize-with-recommenders). Use the new recommendations to [identify clusters](https://cloud.google.com/kubernetes-engine/docs/troubleshooting/logging#identify-fix-permissions-logs-in-all-clusters) with node service accounts missing IAM permissions that are critical for normal cluster operations.
If your organization has a policy to [disable automatic role grants to default service accounts](https://cloud.google.com/resource-manager/docs/organization-policy/restricting-service-accounts#disable%5Fservice%5Faccount%5Fdefault%5Fgrants), the created [default GKE node service account](https://cloud.google.com/kubernetes-engine/docs/how-to/service-accounts#default-gke-service-agent) will not get the necessary permissions. Missing critical permissions can degrade your essential cluster operations, such as logging and monitoring.
What else is happening at Google Cloud Platform?
App Hub application labels are now attached to your log entries
about 20 hours ago
Services
Share
Google Distributed Cloud (software only) for VMware 1.30.700-gke.56 is now available for download
about 21 hours ago
Services
Share
Anywhere Cache for Cloud Storage is now generally available (GA)
about 22 hours ago
Services
Share