Review kubelet hostname override settings

Keep the node identity consistent with authentication and operational configuration.

Description

The kubelet --hostname-override flag uses the supplied string to identify the node instead of its hostname. This is valid when needed, but an incorrect value can create inconsistencies between the node name, certificates and asset records.

Potential impact

  • Node registration or authentication can fail, or operators can misidentify the node.
  • Removing an existing override without planning can change the node identity and disrupt workload operations.

Remediation

  • Check why the override is needed and compare the actual Node name, certificates and asset records. Use the default name when an override is unnecessary.
  • If an existing node name will change, plan workload migration and node replacement or registration, and verify successful registration under the new name.

Examples

foo/bar is an example image, and these excerpts compare kubelet arguments only. They do not represent a complete kubelet deployment or authentication configuration.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kubelet
spec:
  containers:
    - name: kubelet
      image: foo/bar
      command:
        - kubelet
      args:
        - --hostname-override=node-a

The override uses node-a to identify the node. It must agree with the actual authentication and operational configuration.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kubelet
spec:
  containers:
    - name: kubelet
      image: foo/bar
      command:
        - kubelet
      args: []

The override argument is removed. Plan the node transition first if the existing identity will change.

References