Description
--basic-auth-file is a legacy kube-apiserver option that authenticates users with names and passwords from a local file. Long-lived passwords and file permissions require careful management, and leaked credentials can be misused for API access. Kubernetes removed this authentication method in 1.19.
Potential impact
- Disclosure of the password file or client credentials can grant API access with the affected user’s permissions.
- Legacy authentication can complicate credential revocation, rotation and migration to supported Kubernetes releases.
Remediation
- Configure a supported authentication method, such as OIDC, and required user permissions; test actual sign-in first.
- Migrate existing clients before removing
--basic-auth-file, then securely retire passwords and files that are no longer needed. - Move to a supported Kubernetes release and verify TLS, least-privilege authorization and auditing.
Examples
These historical Kubernetes 1.6 excerpts explain an old startup option and are not current deployment examples. Certificates, replacement authentication and the remaining control-plane configuration are required separately.
Before
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command:
- "kube-apiserver"
- "--basic-auth-file=/path/to/auth.csv"
The API server uses the specified static password file. Protect the file and credentials against disclosure.
After
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command:
- "kube-apiserver"
This stops use of the basic-authentication file. Removing the flag does not configure replacement authentication, so migrate existing clients first.