Unauthenticated kubelet read-only port enabled

Disable the unauthenticated kubelet read-only port and move required monitoring to a protected path.

Description

A nonzero --read-only-port can enable a kubelet read-only endpoint without authentication or authorization. Clients that can reach it may obtain node and workload information unnecessarily.

Read-only access can still provide useful reconnaissance information. Disable this endpoint in production and move required monitoring to a TLS endpoint with authentication and authorization.

Potential impact

  • Node information may be exposed without authentication.
  • Attackers may use it to learn about nodes and workloads.
  • The kubelet’s exposed management surface can be unnecessarily enlarged.

Remediation

  • Set readOnlyPort: 0 or the legacy --read-only-port=0.
  • Migrate dependent monitoring collectors to a TLS endpoint with authentication and authorization.
  • Check effective node settings and startup arguments, and verify that the read-only port is no longer listening.

Examples

These excerpts compare command arguments. foo/bar is a placeholder image; deploying this Pod does not reconfigure the node’s kubelet. Apply the setting through the supported configuration method for the actual node version.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: foo/bar
      command: ["kubelet"]
      args: ["--read-only-port=1"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kubelet-demo
spec:
  containers:
    - name: kubelet-demo-container
      image: foo/bar
      command: ["kubelet"]
      args: ["--read-only-port=0"]

Explanation:

  • Before: The read-only port is set to 1. Reachable clients may obtain information without authentication.
  • After: Setting the port to 0 disables the read-only service. Verify the required monitoring path as well.

References