logo

Kubernetes security fundamentals: API Security

ID: 40b68f05-e203-5a13-9c04-caf446afec38

STIX ID: report--40b68f05-e203-5a13-9c04-caf446afec38

Feed Name: Datadog Security Labs

Date Published: 2023-12-07

Date Updated: 2026-04-27

...
...

The report examines Kubernetes component API exposure in unmanaged and managed environments, detailing default ports, interface bindings, and authentication behaviors for etcd, kube-apiserver, kubelet, kube-proxy, and managed offerings (EKS, AKS, GKE). It highlights risks of internet-exposed control plane endpoints—especially kube-apiserver—and unauthenticated metrics/health ports, noting differences like GKE’s read-only kubelet port and AKS/EKS kube-proxy exposure. The piece recommends minimizing network exposure, enforcing encryption, restricting access to trusted ranges or private endpoints, and using firewalls to limit access to sensitive components, with a focus on hardening kube-apiserver while allowing necessary monitoring and logging.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.