Anonymous authentication is not disabled

Restrict unnecessary anonymous authentication and permissions to protect API and node access.

Description

Without --anonymous-auth=false, requests without credentials may be treated as anonymous. If permissions are too broad, those requests may be allowed unexpectedly.

Disable anonymous authentication unless it is needed. If paths such as health checks require anonymous requests, limit the exception to those paths and permissions. Treating a caller as anonymous is separate from authorizing the request.

Potential impact

  • Unauthenticated users may attempt to access API or node configuration information.
  • Combined with other configuration errors, this can expose information or permit misuse of privileges.
  • Control-plane access policies may become less restrictive than intended.

Remediation

  • For a kube-apiserver configured through flags, set --anonymous-auth=false. Disable kubelet anonymous authentication through its active configuration mechanism, such as authentication.anonymous.enabled: false.
  • Check the settings in static Pods, manifests and startup scripts.
  • Keep anonymous authentication disabled unless a documented exception is required.

Examples

These existing examples compare API server arguments. Do not use the old image version in production; match the actual cluster version. Credentials, networking and authorization settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver", "--anonymous-auth=true"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver", "--anonymous-auth=false"]

Explanation:

  • Before: Anonymous authentication leaves requests without credentials eligible for further processing.
  • After: Disabling anonymous authentication restricts processing to authenticated requests.

References