Review controller API server CA trust settings

Verify that the CA bundle distributed to workloads validates the actual API server certificate.

Description

The kube-controller-manager --root-ca-file option specifies a PEM CA bundle included in resources such as service-account token Secrets. Workloads can use this trust information to verify the API server’s TLS certificate. It is distinct from the private key used to sign tokens.

In recent versions, the CA publishing controller can use CA data from its own client configuration when this path is omitted. Check the CA actually distributed and its match to the API server certificate, rather than relying only on whether a path is present.

Potential impact

  • An incorrect or outdated CA can prevent workload TLS connections to the API server.
  • Disabling certificate verification to work around failures can introduce server-impersonation or man-in-the-middle risks.

Remediation

  • Identify the trusted CA bundle that validates the API server certificate and specify --root-ca-file where needed.
  • Make the actual PEM CA file readable by the controller, and verify the distributed CA and certificate-rotation procedure.
  • Test TLS verification from workloads and keep certificate verification enabled.

Examples

These command-argument excerpts retain the historical v1.6.0 image; that version is not a deployment recommendation. Apply the setting to a supported version and the actual control-plane configuration, with required certificate and connection settings supplied separately. Replace the sample path with the actual supplied CA certificate file.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
      command: ["kube-controller-manager"]
      args: []

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-controller-manager-amd64:v1.6.0
      command: ["kube-controller-manager"]
      args: ["--root-ca-file=/path/to/ca/file.pem"]

Explanation:

  • Before: No CA file path is specified. Review the actual version and client configuration to determine the trust information used.
  • After: A CA file path is explicit. The file must exist and contain the correct PEM CA bundle for validating the API server certificate.

References