Hands-on Lab·Kubernetes and Cloud Native Security Associate
kube-apiserver Security Flags
The apiserver is the only way into the cluster, so its flags are the cluster's security posture. This guide reads them off the manifest and then tests one of them from outside with no credential at all - which reveals a default that is not in the file.
Cluster Component Security Guide 10 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 16 min
- Reviewed25 August 2026
Written against the versions above. kubeadm's defaults for v1.36. `--authorization-mode=Node,RBAC` and `--enable-admission-plugins=NodeRestriction` are what kubeadm sets; a flag absent from the manifest means the apiserver's own default applies, and that is the trap this page is about.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 9 - where these flags live.
-
What the manifest says
-
The flag that is not there