Some comments from @peterhassall below:
- All node pools have legacy oauth scopes enabled, meaning all pods have full read/write access to the GCE API - need to create new node pools to change
- Both clusters have legacy and basic auth enabled - should be disabled
- Both clusters have the Kubernetes Dashboard enabled - no longer supported and is considered a security risk
- dev-new has SD monitoring disabled - it's handy to track resource utilisation
We probably should have a look to see if we fix those when deploying to production next time.