Notes / Kubernetes / 07 Kubernetes Security / 10 Protecting The Control Plane

10 — Protecting the Control Plane

Because etcd stores every cluster secret unencrypted by default, encryption at rest, mutual TLS between control plane components, and tightly scoped RBAC on kube-system are the highest-leverage hardening steps, not just API server firewalling.

· §202607201139-63 ·
Chapter Navigation
On This Page

10 — Protecting the Control Plane

Purpose

[stub: protecting-the-control-plane]

Metadata

AuthorAmit Singh
Scopekubernetes

Local graph

Full graph →