5 ms·
I don't recall Kubernetes ever allowing unauthenticated access to the api. I could be wrong tho since I never considered trying to run it sans auth.
by uberduper 3y ago
I don't recall Kubernetes ever allowing unauthenticated access to the api. I could be wrong tho since I never considered trying to run it sans auth.
- parasubvert 3y agoKubernetes (and many popular distros) allowing anonymous access, even when authentication is enabled. The system:anonymous user is generally not authorized to view resources, but might be inadvertently. To test this, if you hit the K8s API server unauthenticated, do you get a 401 error or a 403 error? If the latter, you're at risk.
- uberduper 3y agoI didn't word my statement well. Yes, you can enable unauthenticated requests and you can grant the anonymous role access to the api. I didn't recall `--anonymous-auth` to be true by default.
- peddling-brink 3y agoIt is on certain clouds. But that isn't overtly dangerous until someone binds system:anonymous to cluster admin.
- raesene9 3y agoMost of the major cloud distros (AKS being the notable exception) do have --anonymous-auth enabled, although it's generally just /version and a couple of other endpoints exposed. Makes it easy to find out what clusters are running what versions of k8s which is interesting, but not a major security issue.
- raesene9 3y agoIt did in the old days of the "Insecure API port" which listened on 8080/TCP, but that's been gone a while now. Whilst it usually was just bound to localhost, I did encounter a distribution that, by default, bound it to the container network, meaning that anyone with access to one pod, got to be cluster admin! Generally speaking though I don't think any distributions do that now.