Kubelet client certificate or key is not configured

Certificate authentication from the API server to kubelet requires a client certificate and its private key.

Description

--kubelet-client-certificate and --kubelet-client-key form the pair kube-apiserver uses to authenticate to kubelet. When certificate authentication is required, omitting either can prevent API server access to kubelet.

This client authentication is separate from CA verification of the kubelet serving certificate. The pair alone does not establish all mutual authentication and access controls.

Potential impact

  • Operations using kubelet, such as fetching logs or attaching to running containers, can fail.
  • Allowing anonymous access to bypass connection failures can unnecessarily expose node management functions.

Remediation

  • When using certificate authentication, set both arguments to a valid client certificate and its matching private key.
  • Check file paths, mounts, permissions and expiry, along with kubelet’s trust in the client CA.
  • Configure serving-certificate verification and kubelet authorization, then test normal API server access.

Examples

These historical excerpts use Kubernetes 1.6.0 arguments. Apply the authentication method and file paths used by your deployment version.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]

No client certificate or key is specified. This configuration cannot authenticate if kubelet requires a client certificate.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        [
          "kube-apiserver",
          "--kubelet-client-certificate=/path/to/any/file.pem",
          "--kubelet-client-key=/path/to/any/file2.pem"
        ]

The certificate and key are specified together. Also verify that kubelet trusts the certificate and authorizes the required operations.

References