Review kubelet streaming connection timeouts

Verify effective streaming idle timeouts so unnecessary sessions do not remain open.

Description

Without an effective idle timeout, streaming connections such as exec, attach and port-forward may remain open longer than needed. Idle limits support resource protection and session management.

--streaming-connection-idle-timeout=0 disabled the idle limit in older versions where the setting was effective. The current streamingConnectionIdleTimeout field is deprecated and has no effect. Check the supported limits of the container runtime and components that actually handle the connection.

Potential impact

  • Uncollected idle connections can continue consuming resources.
  • Unnecessary sessions can remain accessible and complicate operations.

Remediation

  • Check the effective streaming timeouts for the actual Kubernetes version and container runtime.
  • Apply an operationally appropriate idle limit through supported component settings. Changing an ineffective kubelet option alone does not resolve the issue.
  • Verify that required debugging works and idle connections close at the configured time.

Examples

These excerpts compare command arguments. foo/bar is a placeholder image; deploying this Pod does not reconfigure the node’s kubelet. Apply the setting through the supported configuration method for the actual node version.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: foo/bar
      command: ["kubelet"]
      args: ["--streaming-connection-idle-timeout=0"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: foo/bar
      command: ["kubelet"]
      args: []

Explanation:

  • Before: The legacy kubelet idle limit is explicitly set to zero. This value alone does not establish the actual connection lifetime in current versions.
  • After: An empty argument list replaces the empty-string argument and omits the legacy option. Verify the effective timeout separately in the runtime or other responsible component.

References