Best practices

K8s etcd is using –peer-auto-tls argument

Risk Level

Informational (4)

Compliance Frameworks


etcd is a highly-available key value store used by Kubernetes deployments for persistent storage of all of its REST API objects. These objects are sensitive in nature and should be accessible only by authenticated etcd peers in the etcd cluster. Hence, do not use self- signed certificates for authentication. Using the --peer-auto-tls option, allows peers to use a self-signed certificate. Orca has detected that etcd is configured to accept self-signed client certificates as authentication method for etcd cluster peers.
  • Recommended Mitigation

    It is recommended to edit the etcd pod specification file to remove the ""--peer-auto-tls=true"" parameter.