Description
--etcd-cafile supplies the CA file kube-apiserver uses to verify the etcd server certificate. It is separate from the API server's own client certificate.
If etcd uses a certificate issued by a private CA, configure the API server to trust that CA. Check the actual HTTPS endpoint and server certificate trust as well as the CA file path.
Potential impact
A missing trusted CA or an incorrect file can cause TLS connection failures. Bypassing certificate verification to resolve those failures creates a risk of connecting to an impostor server.
Remediation
- Set
--etcd-cafileto a trusted CA file and mount it where the API server can read it. - Use the correct HTTPS addresses in
--etcd-servers, and verify that the server certificate matches those addresses and the trusted CA. - If etcd requires client certificates, configure
--etcd-certfileand--etcd-keyfileseparately and verify the actual connection.
Examples
These argument excerpts use a historical kube-apiserver version. Actual deployments also need a supported version, etcd endpoints, mounted certificate files and the remaining settings.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args: []
No etcd CA file is specified. Check that the actual endpoint and certificate trust are configured appropriately.
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args: ["--etcd-cafile=/path/to/ca/file.pem"]
This specifies a CA file. Replace the example path with the real file and check HTTPS connections and any required client authentication.