The gcp auth plugin has been removed. Please use the "gke-gcloud-auth-plugin" credential plugin instead.
Routes GKE legacy gcp auth-provider failures in kubectl and k9s. Use when commands fail with The gcp auth plugin has been removed. Not for missing gke-gcloud-auth-plugin binary errors or expired tokens.
GKE removed the built-in gcp auth provider from kubectl and client-go, so any kubeconfig still using auth-provider gcp fails - inside k9s too. Install gke-gcloud-auth-plugin with gcloud components install, then regenerate the kubeconfig entry using gcloud container clusters get-credentials. k9s picks up the new exec-based auth and connects.
The error
error: The gcp auth plugin has been removed. Please use the "gke-gcloud-auth-plugin" kubectl/client-go credential plugin instead.
See https://cloud.google.com/blog/products/containers-kubernetes/kubectl-auth-changes-in-gke for further details.What to do
- Install the plugin:
gcloud components install gke-gcloud-auth-pluginExpected: Plugin installs.
- Regenerate the kubeconfig entry:
gcloud container clusters get-credentials [cluster] --region [region] --project [project]Expected: Kubeconfig rewritten with the exec plugin entry.
- Verify with kubectl:
kubectl get podsExpected: Works, no gcp plugin error.
- Restart k9s.
Expected: Connects to the GKE cluster.
When this applies
- the exact gcp auth plugin has been removed message
- GKE kubeconfigs created before the auth change
- kubectl 1.26+ and k9s against GKE
When it does NOT apply
- gke-gcloud-auth-plugin executable not found (install the plugin first)
- non-GKE clusters
Works with
kubectl 1.26+, k9s, gke-gcloud-auth-plugin, Google Cloud SDK
WARNING: the gcp auth plugin is deprecated
Earlier warning for the same change. Migrate the same way before it becomes the error.
Why it happens
Google moved GKE kubectl auth from an in-tree gcp provider to the external gke-gcloud-auth-plugin exec plugin. Old kubeconfig entries reference the removed provider, and newer clients refuse them.
Edge cases
- Setting USEGKEGCLOUDAUTHPLUGIN=True was the transitional workaround; the durable fix is regenerating the config entry.
- Delete the stale config (or back it up) before regenerating if kubectl keeps reading the old entry.
Resolved from
dev.to GKE kubectl auth guide - https://dev.to/meddlesome/kubectl-authentication-error-on-gke-v126-58ba