Description
The --profiling flag controls performance profiling in components such as kube-apiserver and kube-controller-manager. Profiling is useful for diagnosis, but unnecessary profiling combined with excessive access can expose operational information. Check the running version’s defaults and effective configuration rather than assuming omission means it is disabled.
Potential impact
- Principals with access to diagnostic endpoints may obtain internal execution information.
- Unnecessary diagnostics add access paths that operators must manage.
Remediation
- When profiling is not needed, set --profiling=false for kube-apiserver and kube-controller-manager. With KubeSchedulerConfiguration, apply the version’s enableProfiling: false setting.
- Protect needed diagnostics with authentication, authorization and network restrictions. After temporary analysis, restore the previous setting and verify the effective configuration.
Examples
These existing v1.30.0 excerpts compare the profiling argument only. Other API server authentication, storage and networking settings are omitted.
Before
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --profiling=true
Profiling is enabled. Actual exposure depends on access controls for the diagnostic endpoints.
After
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --profiling=false
Profiling is disabled. This does not replace protection of other API server access paths.