Review Node authorizer settings

Constrain kubelet permissions with the Node authorizer and correct node identities.

Description

The Node authorizer controls API permissions needed for kubelet operations. It ties access to resources such as Secrets and ConfigMaps to Pods placed on that node, helping avoid unnecessary node permissions.

Production clusters commonly combine Node with RBAC. Permissive modes or incomplete combinations can weaken authorization.

Potential impact

  • Node requests may receive broader permissions than intended.
  • Other configuration errors can permit unnecessary resource access.
  • Departures from the intended control-plane authorization model make security verification harder.

Remediation

  • Enable the Node authorizer through --authorization-mode or the AuthorizationConfiguration in use.
  • Commonly use RBAC,Node, and verify that kubelet identities belong to system:nodes with names in the form system:node:<nodeName>. Use NodeRestriction to constrain node modifications as well.
  • Check API server settings for permissive modes such as AlwaysAllow.

Examples

These are API server argument excerpts. Match the image to the actual cluster version. Kubelet credentials, RBAC bindings and other API server settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--authorization-mode=AlwaysAllow"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--authorization-mode=RBAC,Node"]

Explanation:

  • Before: AlwaysAllow permits requests without enforcing the required permission scope.
  • After: RBAC,Node is enabled. Correct node identities and least-privilege bindings are also required.

References