API server etcd CA file configuration needs review

Configure kube-apiserver to verify the etcd server certificate against a trusted CA.

Description

--etcd-cafile supplies the CA file kube-apiserver uses to verify the etcd server certificate. It is separate from the API server's own client certificate.

If etcd uses a certificate issued by a private CA, configure the API server to trust that CA. Check the actual HTTPS endpoint and server certificate trust as well as the CA file path.

Potential impact

A missing trusted CA or an incorrect file can cause TLS connection failures. Bypassing certificate verification to resolve those failures creates a risk of connecting to an impostor server.

Remediation

  • Set --etcd-cafile to a trusted CA file and mount it where the API server can read it.
  • Use the correct HTTPS addresses in --etcd-servers, and verify that the server certificate matches those addresses and the trusted CA.
  • If etcd requires client certificates, configure --etcd-certfile and --etcd-keyfile separately and verify the actual connection.

Examples

These argument excerpts use a historical kube-apiserver version. Actual deployments also need a supported version, etcd endpoints, mounted certificate files and the remaining settings.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args: []

No etcd CA file is specified. Check that the actual endpoint and certificate trust are configured appropriately.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args: ["--etcd-cafile=/path/to/ca/file.pem"]

This specifies a CA file. Replace the example path with the real file and check HTTPS connections and any required client authentication.

References