Description
Without --encryption-provider-config, kube-apiserver may not encrypt sensitive resources stored in etcd. Data such as Secrets can remain unencrypted at the API storage layer.
This API-level encryption is separate from disk encryption on etcd servers. Configure the target resources, first encryption provider and key management as well as the file path. Separately restrict permission to read Secrets through the API.
Potential impact
- Sensitive resources such as Secrets may lack encryption at rest.
- Exposure of etcd data can reveal sensitive information.
- Stored-data protection requirements may not be met.
Remediation
- Specify the kube-apiserver
--encryption-provider-configpath. - Distribute the configuration securely and coordinate encryption and decryption settings across API servers. Do not commit files containing keys to ordinary repositories; control access and retain recovery keys securely.
- Verify stored data and rewrite existing resources through a safe procedure to apply encryption. A new configuration does not automatically convert existing data.
Examples
These are API server argument excerpts. Match the image to the actual cluster version and mount a valid EncryptionConfiguration read-only at the example path. Keys, volumes and other settings are omitted.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: []
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--encryption-provider-config=/path/to/config/file.yaml"]
Explanation:
- Before: No encryption configuration file is specified, so API-level storage encryption may not be applied.
- After: The encryption provider file is specified. Its resource scope and provider order determine whether encryption is applied.