# How to Set Up Private Autopilot Clusters in GKE: Complete Configuration Guide

> Learn to set up private Autopilot clusters in GKE with this complete guide. Configure private networking, control plane endpoints, and authorized networks easily.

- Repository: [Google/skills](https://github.com/google/skills)
- Tags: how-to-guide
- Published: 2026-08-09

---

**To set up private Autopilot clusters in GKE, enable Autopilot mode and configure private node networking, a private control plane endpoint, and master authorized networks using gcloud flags or the GKE MCP `create_cluster` tool.**

Google Kubernetes Engine (GKE) Autopilot mode simplifies cluster management by automating node infrastructure, while private clusters eliminate public internet exposure for both nodes and the control plane. When you set up private Autopilot clusters in GKE, you combine these capabilities to create a secure, fully managed environment that bills based on pod resource requests rather than provisioned nodes. The `google/skills` repository documents the recommended "golden-path" configuration in the GKE Basics skill and CLI reference files.

## Understanding Private Autopilot Architecture

Autopilot is the default operational mode in GKE where Google manages the underlying node infrastructure, automatically scaling resources based on your pod specifications. According to the source code in [`skills/cloud/gke-basics/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-basics/SKILL.md) (lines 29-38), enabling Autopilot removes node-pool management and enforces mandatory resource requests for all workloads.

Private clusters extend this security model by ensuring nodes receive internal IP addresses only and the control plane (master) is inaccessible from public networks. This configuration requires specific VPC networking prerequisites, including sufficient IP address space for both node and pod ranges.

## Required Configuration Flags

### Enable Private Nodes

The `--enable-private-nodes` flag assigns internal IP addresses to all cluster nodes, preventing direct internet egress without a NAT gateway or Cloud Router. This flag is mandatory when creating a private Autopilot cluster and ensures your workloads remain isolated from public networks.

### Secure the Control Plane Endpoint

To remove the public IP address from the Kubernetes control plane, use `--enable-private-endpoint`. As implemented in the GKE Basics skill documentation, this configuration restricts API server access to internal networks only, requiring bastion hosts or VPN connectivity for administrative operations.

### Restrict API Access with Authorized Networks

The `--enable-master-authorized-networks` flag combined with `--master-authorized-networks=CIDR_BLOCK` creates an allowlist of IP ranges that can communicate with the private control plane endpoint. You must specify the CIDR blocks of your bastion hosts, on-premises networks, or VPN endpoints to maintain administrative access.

## Implementation Methods

### Using the gcloud CLI

The standard approach uses the `gcloud container clusters create-auto` command with private cluster flags. Based on the reference implementation in [`skills/cloud/gke-basics/references/cli-reference.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-basics/references/cli-reference.md) (lines 87-91), the following command creates a production-ready private Autopilot cluster:

```bash
gcloud container clusters create-auto my-private-autopilot \
  --region=us-central1 \
  --enable-private-nodes \
  --enable-private-endpoint \
  --enable-master-authorized-networks \
  --master-authorized-networks=203.0.113.0/24 \
  --enable-dns-access \
  --enable-secret-manager \
  --scoped-rbs-bindings \
  --quiet

```

Additional optional flags include:
- `--enable-dns-access` allows private nodes to resolve Cloud DNS without public endpoints
- `--enable-secret-manager` integrates with Google Secret Manager for workload secrets
- `--scoped-rbs-bindings` enforces scoped role-based security bindings

### Using the GKE MCP Tool

For programmatic cluster creation, the GKE MCP `create_cluster` tool accepts a structured JSON payload equivalent to the gcloud flags. This method is documented in the CLI reference and supports infrastructure-as-code workflows:

```bash
create_cluster(
  parent="projects/PROJECT_ID/locations/us-central1",
  cluster='{
    "name":"my-private-autopilot",
    "autopilot":{"enabled":true},
    "privateClusterConfig":{
      "enablePrivateNodes":true,
      "enablePrivateEndpoint":true,
      "masterAuthorizedNetworksConfig":{
        "cidrBlocks":[{"cidrBlock":"203.0.113.0/24"}]
      }
    },
    "dnsConfig":{"usePrivateDnsOnly":true}
  }'
)

```

## Network and Billing Considerations

Private Autopilot clusters require a VPC network with adequate IP allocation for both node subnets and pod address ranges. Unlike standard GKE clusters, **Autopilot billing** is based on pod resource requests rounded to 250 mCPU increments, not node instance types.

After cluster creation, retrieve credentials using:

```bash
gcloud container clusters get-credentials my-private-autopilot \
  --region=us-central1 \
  --quiet

```

## Summary

- **Autopilot mode** automates node management and requires explicit CPU/memory resource requests for all pods
- **Private configuration** requires `--enable-private-nodes`, `--enable-private-endpoint`, and `--enable-master-authorized-networks` flags
- **Master authorized networks** must include CIDR blocks for all administrative access points
- **Implementation options** include both gcloud CLI commands and the GKE MCP `create_cluster` tool as documented in [`skills/cloud/gke-basics/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-basics/SKILL.md)
- **DNS and Secret Manager** integration can be enabled with additional flags for enhanced private connectivity

## Frequently Asked Questions

### What is the difference between private nodes and a private endpoint in GKE?

**Private nodes** (`--enable-private-nodes`) assign internal IP addresses only to cluster nodes, preventing direct internet access without a NAT gateway. **Private endpoint** (`--enable-private-endpoint`) removes the public IP address from the Kubernetes control plane API server, restricting access to internal networks or authorized CIDR blocks only. Both flags are required for a fully private Autopilot cluster.

### How does Autopilot billing work for private clusters?

Autopilot bills based on **pod resource requests** rather than provisioned node capacity. You must specify CPU and memory requests for every pod, and Google rounds these to the nearest 250 mCPU increment for billing purposes. This model applies regardless of whether the cluster uses private or public networking.

### Can I use Terraform to create private Autopilot clusters?

Yes. The `google/skills` repository includes Terraform examples for Autopilot cluster provisioning in [`skills/cloud/gke-basics/references/iac-usage.md`](https://github.com/google/skills/blob/main/skills/cloud/gke-basics/references/iac-usage.md). These examples support the same private cluster configuration flags as the gcloud CLI, including `enable_private_nodes`, `enable_private_endpoint`, and `master_authorized_networks_config` blocks.

### Why do I need master authorized networks with a private endpoint?

Even with a private control plane endpoint, you must specify **master authorized networks** to define which internal CIDR blocks can communicate with the API server. This provides defense-in-depth by restricting access to specific bastion hosts, VPN endpoints, or on-premises network ranges that require administrative access to the cluster.