Review control plane bind-address access scope

Restrict management listening addresses to the access paths that are needed.

Description

Control plane components such as kube-controller-manager and kube-scheduler expose management interfaces. With --bind-address=0.0.0.0, they can listen on all IPv4 interfaces in their network namespace. Actual external access depends on Pod and node networking, firewalls, authentication and authorization.

Use 127.0.0.1 when only local access is required. If health checks or monitoring run elsewhere, verify their connection requirements before choosing the listening address and allowed networks.

Potential impact

  • Clients on unnecessary networks may attempt connections to management ports.
  • Switching to loopback without checking connectivity requirements can interrupt health checks or monitoring.

Remediation

  • Set --bind-address=127.0.0.1 for kube-controller-manager or kube-scheduler when only local access is needed. Check which network namespace contains the container’s loopback interface.
  • If remote monitoring is needed, configure an approved listening address and firewall rules, retaining authentication and authorization. Test health checks and actual access scope after the change.

Examples

These existing v1.30.0 excerpts compare only the listening-address argument. Actual credentials and other runtime settings are omitted. Without hostNetwork, this Pod’s loopback belongs to its Pod network namespace.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-controller-manager
spec:
  containers:
    - name: kube-controller-manager
      image: registry.k8s.io/kube-controller-manager:v1.30.0
      command:
        - kube-controller-manager
        - --bind-address=0.0.0.0

Management requests can be received on all IPv4 interfaces. This alone does not grant Internet or anonymous access.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-controller-manager
spec:
  containers:
    - name: kube-controller-manager
      image: registry.k8s.io/kube-controller-manager:v1.30.0
      command:
        - kube-controller-manager
        - --bind-address=127.0.0.1

The component listens only on loopback in the same network namespace. Verify that required health checks and monitoring can still connect.

References