kube-apiserver secure-port is set to zero

Check the kube-apiserver HTTPS listener and its actual TLS, authentication and authorization configuration.

Description

The kube-apiserver --secure-port option selects the HTTPS API listener. Historical versions allowed 0 to disable that listener, but current API servers do not permit disabling it this way.

An unavailable protected API endpoint can interrupt control-plane communication. Selecting a port alone does not provide appropriate certificates or access permissions.

Potential impact

Failure to start the API server or use its HTTPS endpoint can disrupt cluster administration and workloads. If a legacy insecure endpoint remains as an alternative, it can also leave API access unprotected.

Remediation

  • On a supported Kubernetes version, configure a valid --secure-port, such as 6443, for your environment.
  • Configure a TLS certificate matching the API address, client trust and appropriate authentication and authorization. Restrict unnecessary network access.
  • Prepare clients and load balancers before changing ports. Verify normal connections, authentication failures and denial of unapproved operations.

Examples

These historical Kubernetes 1.6 excerpts compare a zero setting with an HTTPS port. They do not recommend the old image for current deployments.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"
      args:
        - "--secure-port=0"

This disables the HTTPS listener in the illustrated historical version. It is invalid in current versions.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: api-server
spec:
  containers:
    - name: kube-apiserver
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command:
        - "kube-apiserver"
        - "--secure-port=6443"

This selects HTTPS port 6443. Also verify certificates, access controls and actual client connections.

References