Files
kube-hunter/docs/_kb/KHV032.md

756 B

vid, title, categories, severity
vid title categories severity
KHV032 Etcd Remote Read Access Event
Access Risk
CRITICAL

{{ page.vid }} - {{ page.title }}

Issue description

Etcd (Kubernetes' Database) is accessible without authentication. This exposes the entire state of your Kubernetes cluster to the reader.

Remediation

Ensure your etcd is accepting connections only from the Kubernetes API, using the --trusted-ca-file etcd flag. This is usually done by the installer, or cloud platform.

References