Description
The Node authorizer controls API permissions needed for kubelet operations. It ties access to resources such as Secrets and ConfigMaps to Pods placed on that node, helping avoid unnecessary node permissions.
Production clusters commonly combine Node with RBAC. Permissive modes or incomplete combinations can weaken authorization.
Potential impact
- Node requests may receive broader permissions than intended.
- Other configuration errors can permit unnecessary resource access.
- Departures from the intended control-plane authorization model make security verification harder.
Remediation
- Enable the Node authorizer through
--authorization-modeor the AuthorizationConfiguration in use. - Commonly use
RBAC,Node, and verify that kubelet identities belong tosystem:nodeswith names in the formsystem:node:<nodeName>. Use NodeRestriction to constrain node modifications as well. - Check API server settings for permissive modes such as
AlwaysAllow.
Examples
These are API server argument excerpts. Match the image to the actual cluster version. Kubelet credentials, RBAC bindings and other API server settings are omitted.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--authorization-mode=AlwaysAllow"]
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--authorization-mode=RBAC,Node"]
Explanation:
- Before:
AlwaysAllowpermits requests without enforcing the required permission scope. - After:
RBAC,Nodeis enabled. Correct node identities and least-privilege bindings are also required.