Kubernetes security fundamentals: API Security
ID: 40b68f05-e203-5a13-9c04-caf446afec38
STIX ID: report--40b68f05-e203-5a13-9c04-caf446afec38
Feed Name: Datadog Security Labs
The report examines Kubernetes component API exposure in unmanaged and managed environments, detailing default ports, interface bindings, and authentication behaviors for etcd, kube-apiserver, kubelet, kube-proxy, and managed offerings (EKS, AKS, GKE). It highlights risks of internet-exposed control plane endpoints—especially kube-apiserver—and unauthenticated metrics/health ports, noting differences like GKE’s read-only kubelet port and AKS/EKS kube-proxy exposure. The piece recommends minimizing network exposure, enforcing encryption, restricting access to trusted ranges or private endpoints, and using firewalls to limit access to sensitive components, with a focus on hardening kube-apiserver while allowing necessary monitoring and logging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
