Description
Tiller is the server component of Helm 2 and manages Kubernetes resources using its own service account permissions. If a reachable endpoint lacks appropriate authentication, other workloads can request operations using those permissions.
Helm 2 has received no security updates since November 2020. Migrate to a supported Helm version without Tiller.
Potential impact
- Unauthorized requests can change deployments or other resources, within the permissions granted to Tiller.
- A compromised Pod may affect other workloads through a reachable management endpoint.
Remediation
- Validate release information and deployment procedures, migrate to an approach without Tiller, and then remove Tiller.
- If removal must wait, restrict access with loopback binding or authenticated TLS connections and minimize service account permissions.
- Review containers in the same Pod and permission to use port forwarding. Loopback binding alone does not block every management access path.
Examples
These excerpts compare listening addresses in a historical Tiller Deployment. The actual image, selector and service account settings are required separately; this is not a recommendation to install Tiller.
Before
apiVersion: apps/v1
kind: Deployment
metadata:
name: tiller-bad-args
labels:
app: helm
name: tiller
spec:
template:
metadata:
labels:
app: helm
name: tiller
spec:
containers:
- name: tiller-v2
image: tiller-image
args:
- "--listen=10.7.2.8:44134"
If the configured address is assigned to the Pod, Tiller can accept requests through that non-loopback interface. Review actual reachability together with TLS authentication.
After
apiVersion: apps/v1
kind: Deployment
metadata:
name: tiller-deploy
labels:
app: helm
name: tiller
spec:
template:
metadata:
labels:
app: helm
name: tiller
spec:
containers:
- name: tiller
image: tiller-image
args:
- "--listen=127.0.0.1:44134"
The listening address is limited to 127.0.0.1. Processes in the same Pod and authorized port-forwarding paths can still reach it, so permissions must remain restricted while migration proceeds.