Encryption provider configuration is not specified

Protect the API server encryption configuration and keys, and verify existing data is covered.

Description

Without --encryption-provider-config, kube-apiserver may not encrypt sensitive resources stored in etcd. Data such as Secrets can remain unencrypted at the API storage layer.

This API-level encryption is separate from disk encryption on etcd servers. Configure the target resources, first encryption provider and key management as well as the file path. Separately restrict permission to read Secrets through the API.

Potential impact

  • Sensitive resources such as Secrets may lack encryption at rest.
  • Exposure of etcd data can reveal sensitive information.
  • Stored-data protection requirements may not be met.

Remediation

  • Specify the kube-apiserver --encryption-provider-config path.
  • Distribute the configuration securely and coordinate encryption and decryption settings across API servers. Do not commit files containing keys to ordinary repositories; control access and retain recovery keys securely.
  • Verify stored data and rewrite existing resources through a safe procedure to apply encryption. A new configuration does not automatically convert existing data.

Examples

These are API server argument excerpts. Match the image to the actual cluster version and mount a valid EncryptionConfiguration read-only at the example path. Keys, volumes and other settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: []

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--encryption-provider-config=/path/to/config/file.yaml"]

Explanation:

  • Before: No encryption configuration file is specified, so API-level storage encryption may not be applied.
  • After: The encryption provider file is specified. Its resource scope and provider order determine whether encryption is applied.

References