Description
With --protect-kernel-defaults=false, kubelet attempts to adjust certain kernel settings that differ from its expected values. With true, it returns an error on a mismatch instead of changing them. This does not protect every kernel setting or control all workload sysctl changes.
Kernel parameters can affect the whole node and should follow an approved baseline. To prevent automatic adjustment, prepare the required values before enabling protection.
Potential impact
- Automatic adjustment can conflict with operator-managed node settings.
- Enabling protection without preparation can prevent kubelet startup when settings differ.
Remediation
- Check the kernel values required by the node’s kubelet version and apply them through approved configuration management.
- If automatic adjustment must be prevented, set
protectKernelDefaults: trueor the legacy--protect-kernel-defaults=true. - Verify kubelet startup and node health after the change, and restrict workload sysctl permissions separately.
Examples
These excerpts compare command arguments. foo/bar is a placeholder image; deploying this Pod does not reconfigure the node’s kubelet. Apply the setting through the supported configuration method for the actual node version.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--protect-kernel-defaults=false"]
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--protect-kernel-defaults=true"]
Explanation:
- Before: Kubelet attempts to adjust settings that differ from its expectations. This does not by itself grant workloads arbitrary kernel-setting access.
- After: Kubelet returns an error on a mismatch. The required kernel values must already be configured.