Hands-on Lab·Certified Kubernetes Security Specialist
Restricting Node External Network Access
The node's listening ports are only a finding once you prove what answers on them. This guide probes two of them from another machine, finds one that authenticates and one that does not, closes the second with a single scoped rule, and puts it back.
System Hardening Guide 16 of 40 Advanced
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. The demonstration adds one nftables rule in a table of its own so kube-proxy's and Cilium's chains are untouched, and deletes that table afterwards. `ufw` is installed and inactive on these nodes.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA7001 | 192.168.0.51 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA7001-NODE01 | 192.168.0.52 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 14 - where these ports came from.
-
The surface, and what is guarding it
-
Prove the exposure from another machine
-
Close it at the host, and measure again
-
Put it back, and say what the real fix is