Hands-on Lab·Kubernetes and Cloud Native Security Associate
etcd Security and Access Control
Every object in the cluster is a row in etcd, so etcd access is cluster access - and on a default kubeadm cluster the Secrets in it are not encrypted. This guide proves both halves of that sentence.
Cluster Component Security Guide 11 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. etcd 3.6.8 with `--client-cert-auth=true`, as kubeadm configures it. The encryption-at-rest gap is also kubeadm's default: no `--encryption-provider-config` is set.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 10 - the component that normally stands between you and etcd.
-
How etcd is protected, and where it listens
-
The handshake refusal, which `-s` hid
-
A distroless component, which is the hardening working
-
The Secret, three ways
-
The flag that would have stopped it