Best practices

K8s etcd is not using peer certificate access

Risk Level

Informational (4)

Platform(s)
  • N/A

Description

etcd is a highly-available key value store used by Kubernetes deployments for persistent storage of all of its REST API objects. These objects are sensitive in nature and should be accessible only by authenticated etcd peers in the etcd cluster. Orca has detected that etcd is not configured to authenticate peers using a valid client certificate, which could result an unauthenticated peer to join the etcd cluster.
  • Recommended Mitigation

    It is recommended to edit the etcd pod specification file to include the ""--client-cert-auth"" parameter.