kube-apiserver uses a basic authentication file

Replace legacy password-file authentication with a supported authentication method.

Description

--basic-auth-file is a legacy kube-apiserver option that authenticates users with names and passwords from a local file. Long-lived passwords and file permissions require careful management, and leaked credentials can be misused for API access. Kubernetes removed this authentication method in 1.19.

Potential impact

  • Disclosure of the password file or client credentials can grant API access with the affected user’s permissions.
  • Legacy authentication can complicate credential revocation, rotation and migration to supported Kubernetes releases.

Remediation

  • Configure a supported authentication method, such as OIDC, and required user permissions; test actual sign-in first.
  • Migrate existing clients before removing --basic-auth-file, then securely retire passwords and files that are no longer needed.
  • Move to a supported Kubernetes release and verify TLS, least-privilege authorization and auditing.

Examples

These historical Kubernetes 1.6 excerpts explain an old startup option and are not current deployment examples. Certificates, replacement authentication and the remaining control-plane configuration are required separately.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"
        - "--basic-auth-file=/path/to/auth.csv"

The API server uses the specified static password file. Protect the file and credentials against disclosure.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"

This stops use of the basic-authentication file. Removing the flag does not configure replacement authentication, so migrate existing clients first.

References