Description
The kube-apiserver --secure-port option selects the HTTPS API listener. Historical versions allowed 0 to disable that listener, but current API servers do not permit disabling it this way.
An unavailable protected API endpoint can interrupt control-plane communication. Selecting a port alone does not provide appropriate certificates or access permissions.
Potential impact
Failure to start the API server or use its HTTPS endpoint can disrupt cluster administration and workloads. If a legacy insecure endpoint remains as an alternative, it can also leave API access unprotected.
Remediation
- On a supported Kubernetes version, configure a valid
--secure-port, such as 6443, for your environment. - Configure a TLS certificate matching the API address, client trust and appropriate authentication and authorization. Restrict unnecessary network access.
- Prepare clients and load balancers before changing ports. Verify normal connections, authentication failures and denial of unapproved operations.
Examples
These historical Kubernetes 1.6 excerpts compare a zero setting with an HTTPS port. They do not recommend the old image for current deployments.
Before
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command:
- "kube-apiserver"
args:
- "--secure-port=0"
This disables the HTTPS listener in the illustrated historical version. It is invalid in current versions.
After
apiVersion: v1
kind: Pod
metadata:
name: api-server
spec:
containers:
- name: kube-apiserver
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command:
- "kube-apiserver"
- "--secure-port=6443"
This selects HTTPS port 6443. Also verify certificates, access controls and actual client connections.