logo

Improving Your Kubernetes Authorization: Don’t Use system:masters

ID: 272570fb-8b4a-5bbb-b9d4-a75168e6e7bb

STIX ID: report--272570fb-8b4a-5bbb-b9d4-a75168e6e7bb

Feed Name: Aqua Security Blog

Date Published: 2021-05-20

Date Updated: 2026-04-26

...
...

This note explains that the Kubernetes built-in group system:masters is hardcoded to provide unrestricted cluster-admin privileges, making any credentials associated with it effectively long-lived backdoors (notably client certificate credentials like admin.conf). It recommends avoiding granting users membership in system:masters, using clusterrolebindings to grant revocable admin rights when needed, and tightly controlling bootstrap/admin credentials to reduce the risk of unauthorized cluster access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.