NodeRestriction admission plugin is not enabled

Limit kubelet object modifications with NodeRestriction and correct node authentication.

Description

The NodeRestriction admission plugin limits the Node and Pod objects a kubelet can modify. It allows limited changes to the kubelet’s own Node and Pods bound to that node, and prevents changes to certain protected node labels.

Nodes are important cluster identities and need tightly scoped privileges. For these restrictions to apply, kubelets must authenticate in the system:nodes group with usernames in the form system:node:<nodeName>.

Potential impact

  • Restrictions on resources a node can modify may be weaker.
  • Misuse of node permissions may be easier.
  • Control-plane security policies may be less restrictive than intended.

Remediation

  • Include NodeRestriction in kube-apiserver --enable-admission-plugins.
  • Configure the Node authorizer, RBAC and correct node identities together. NodeRestriction itself does not require a separate plugin configuration file.
  • Check the active admission plugins and normal node operations, and verify that unauthorized object and label changes are rejected.

Examples

These are API server argument excerpts. Match the image to the actual cluster version. Other admission plugins and node authentication and authorization settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--disable-admission-plugins=NodeRestriction"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--enable-admission-plugins=NodeRestriction"]

Explanation:

  • Before: Explicitly disabling NodeRestriction removes its additional restrictions on kubelet modification requests.
  • After: NodeRestriction is enabled. Correct node identities and authorization settings are also required.

References