Measures

Configfiles

By default, it gives the following directories to own important information about the cluster:

 

-> /etc/kubernetes/

-> /var/lib/kubelet/

-> /etc/sysconfig/kubelet

-> ./kube/config.yaml

 

These directories are only relevant for troubleshooting. Therefore, there should be no access rights for non-admin users for these paths. Since all paths are immediately visible with "systemctl cat kubelet", "systemctl" should only be possible for admins of the cluster.

Furthermore, these directories are mounted in the corresponding pods by configmaps in the kube-system namespace. Therefore, access to the configmaps should also be restricted to the kube-system namespace.

Any Questions?

Please feel free to contact us for any question that is not answered yet. 

We are looking forward to get in contact with you!

Design Escapes

KubeOps GmbH
Hinter Stöck 17
72406 Bisingen
Germany

  • Telefon:

    +49 7433 93724 90

  • Mail:

    This email address is being protected from spambots. You need JavaScript enabled to view it.

Download Area
Certified as

KubeOps GmbH is the owner of the Union trademark KubeOps with the registration number 018305184. 

© KubeOps GmbH. All rights reserved. Subsidiary of