Description
The NodeRestriction admission plugin limits the Node and Pod objects a kubelet can modify. It allows limited changes to the kubelet’s own Node and Pods bound to that node, and prevents changes to certain protected node labels.
Nodes are important cluster identities and need tightly scoped privileges. For these restrictions to apply, kubelets must authenticate in the system:nodes group with usernames in the form system:node:<nodeName>.
Potential impact
- Restrictions on resources a node can modify may be weaker.
- Misuse of node permissions may be easier.
- Control-plane security policies may be less restrictive than intended.
Remediation
- Include
NodeRestrictionin kube-apiserver--enable-admission-plugins. - Configure the Node authorizer, RBAC and correct node identities together. NodeRestriction itself does not require a separate plugin configuration file.
- Check the active admission plugins and normal node operations, and verify that unauthorized object and label changes are rejected.
Examples
These are API server argument excerpts. Match the image to the actual cluster version. Other admission plugins and node authentication and authorization settings are omitted.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--disable-admission-plugins=NodeRestriction"]
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--enable-admission-plugins=NodeRestriction"]
Explanation:
- Before: Explicitly disabling
NodeRestrictionremoves its additional restrictions on kubelet modification requests. - After:
NodeRestrictionis enabled. Correct node identities and authorization settings are also required.