Review Kubernetes control plane profiling settings

Disable unnecessary profiling and restrict access to diagnostic endpoints that are needed.

Description

The --profiling flag controls performance profiling in components such as kube-apiserver and kube-controller-manager. Profiling is useful for diagnosis, but unnecessary profiling combined with excessive access can expose operational information. Check the running version’s defaults and effective configuration rather than assuming omission means it is disabled.

Potential impact

  • Principals with access to diagnostic endpoints may obtain internal execution information.
  • Unnecessary diagnostics add access paths that operators must manage.

Remediation

  • When profiling is not needed, set --profiling=false for kube-apiserver and kube-controller-manager. With KubeSchedulerConfiguration, apply the version’s enableProfiling: false setting.
  • Protect needed diagnostics with authentication, authorization and network restrictions. After temporary analysis, restore the previous setting and verify the effective configuration.

Examples

These existing v1.30.0 excerpts compare the profiling argument only. Other API server authentication, storage and networking settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --profiling=true

Profiling is enabled. Actual exposure depends on access controls for the diagnostic endpoints.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: kube-apiserver
spec:
  containers:
    - name: kube-apiserver
      image: registry.k8s.io/kube-apiserver:v1.30.0
      command:
        - kube-apiserver
      args:
        - --profiling=false

Profiling is disabled. This does not replace protection of other API server access paths.

References