4.6.4 Avoid deploying workloads in the default namespace

Information

Avoid deploying GKE Autopilot workloads in the default namespace. Use dedicated namespaces to separate applications, environments, or tenants so namespace level controls can be applied consistently.

The default namespace exists for objects created without an explicit namespace, but using it for normal workloads weakens ownership, access separation, and resource governance. Dedicated namespaces make it easier to apply namespace based RBAC, ResourceQuotas, NetworkPolicies, Pod Security labels, observability controls, and cost attribution.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Create dedicated namespaces for GKE Autopilot workloads based on application, environment, or tenant boundaries, then migrate application resources out of the default namespace. Make updates so all workload resources explicitly specify the new target namespace. After migration, apply appropriate namespace level governance, including RBAC, ResourceQuotas, NetworkPolicies, Pod Security labels, and ownership labels.

Impact:

Teams must specify the correct namespace in manifests, deployment pipelines, and operational commands. Existing workloads in the default namespace may need to be migrated to dedicated namespaces, with related updates to service discovery, RBAC bindings, quotas, NetworkPolicies, Pod Security labels, monitoring, and CI/CD configuration.

See Also

https://workbench.cisecurity.org/benchmarks/24958

Item Details

Category: CONFIGURATION MANAGEMENT, CONTINGENCY PLANNING, PLANNING, PROGRAM MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-7, 800-53|CP-6, 800-53|CP-7, 800-53|PL-8, 800-53|PM-7, 800-53|SA-8, 800-53|SC-7, CSCv7|2.10

Plugin: GCP

Control ID: 0caeeb4c7f6d5805da488ca4bb7cae98d531e6c09ae708ac899268a4320bd02f