Description
A nonzero --read-only-port can enable a kubelet read-only endpoint without authentication or authorization. Clients that can reach it may obtain node and workload information unnecessarily.
Read-only access can still provide useful reconnaissance information. Disable this endpoint in production and move required monitoring to a TLS endpoint with authentication and authorization.
Potential impact
- Node information may be exposed without authentication.
- Attackers may use it to learn about nodes and workloads.
- The kubelet’s exposed management surface can be unnecessarily enlarged.
Remediation
- Set
readOnlyPort: 0or the legacy--read-only-port=0. - Migrate dependent monitoring collectors to a TLS endpoint with authentication and authorization.
- Check effective node settings and startup arguments, and verify that the read-only port is no longer listening.
Examples
These excerpts compare command arguments. foo/bar is a placeholder image; deploying this Pod does not reconfigure the node’s kubelet. Apply the setting through the supported configuration method for the actual node version.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--read-only-port=1"]
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: kubelet-demo
spec:
containers:
- name: kubelet-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--read-only-port=0"]
Explanation:
- Before: The read-only port is set to 1. Reachable clients may obtain information without authentication.
- After: Setting the port to
0disables the read-only service. Verify the required monitoring path as well.