Stay organized with collections
Save and categorize content based on your preferences.
This page provides an overview of how to set up Binary Authorization for use with
Cloud Service Mesh.
Before you begin
Before you use Binary Authorization for Cloud Service Mesh, you must first
install Cloud Service Mesh on Google Kubernetes Engine (GKE). For more information,
see the quickstart or the GKE installation guides.
Setup Steps
To set up Binary Authorization for Cloud Service Mesh, perform the following steps:
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-25 UTC."],[[["\u003cp\u003eThis guide details how to set up Binary Authorization for Cloud Service Mesh, which is only available on Google Kubernetes Engine (GKE).\u003c/p\u003e\n"],["\u003cp\u003eBefore setting up Binary Authorization, Cloud Service Mesh must be installed on GKE, referencing the quickstart or GKE installation guides for this process.\u003c/p\u003e\n"],["\u003cp\u003eThe setup involves enabling Binary Authorization, configuring its policy, and optionally using the \u003ccode\u003ebuilt-by-cloud-build\u003c/code\u003e attestor or attestations.\u003c/p\u003e\n"],["\u003cp\u003eThe policy can be configured with default rules, specific rules for the Cloud Service Mesh service identity, and exempt images.\u003c/p\u003e\n"],["\u003cp\u003eBinary Authorization for GKE with Cloud Service Mesh can be disabled by following the provided instructions, and audit logs can be viewed for GKE as well.\u003c/p\u003e\n"]]],[],null,["# Set up overview for Cloud Service Mesh\n\nThis page provides an overview of how to set up Binary Authorization for use with\nCloud Service Mesh.\n\nBefore you begin\n----------------\n\n| **Note:** Binary Authorization for Cloud Service Mesh is available only on Google Kubernetes Engine. Installation on GKE Enterprise isn't supported.\n\nBefore you use Binary Authorization for Cloud Service Mesh, you must first\ninstall Cloud Service Mesh on Google Kubernetes Engine (GKE). For more information,\nsee the [quickstart](/service-mesh/docs/quickstart-asm) or the [GKE installation guides](/service-mesh/docs/all-gke-install-guides).\n\nSetup Steps\n-----------\n\nTo set up Binary Authorization for Cloud Service Mesh, perform the following steps:\n\n1. [Enable Binary Authorization](/binary-authorization/docs/enabling).\n2. Configure your Binary Authorization policy.\n\n | **Note:** Skip this step if you want to use attestations.\n\n You can configure the following features in your policy:\n - [Default rule](/binary-authorization/docs/configuring-policy-console#default-rule).\n - [Specific rules for your Cloud Service Mesh service identity](/binary-authorization/docs/configuring-policy-console#add-specific-rules-asm).\n - [Exempt images](/binary-authorization/docs/configuring-policy-console#exempt_images). [Learn more about exempt images](/binary-authorization/docs/key-concepts#exempt_images).\n3. Optional: Use the `built-by-cloud-build` attestor to [deploy only images built by Cloud Build](/binary-authorization/docs/deploy-cloud-build).\n\n4. Optional: [Use attestations](/binary-authorization/docs/attestations).\n\n5. View audit logs by following instructions in [View audit logs for GKE](/binary-authorization/docs/viewing-audit-logs).\n\nDisable Binary Authorization for GKE with Cloud Service Mesh\n------------------------------------------------------------\n\nTo disable Binary Authorization for GKE with Cloud Service Mesh enabled,\nfollow the instructions in [Disable Binary Authorization for\nGKE](/binary-authorization/docs/disabling)."]]