Hands-on Lab·Kubernetes and Cloud Native Security Associate
Kubelet API Access and Ports
Every node runs an API that can list Pods, read logs and exec into containers - and it is not the apiserver. This guide reads the kubelet's authentication and authorization settings, then calls it from outside with no credential.
Cluster Component Security Guide 12 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 16 min
- Reviewed25 August 2026
Written against the versions above. kubeadm's kubelet defaults for v1.36, in `/var/lib/kubelet/config.yaml`. `readOnlyPort` defaults to 0 and kubeadm does not set it, which is why port 10255 is not listening here.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 10 - the other API, for comparison.
-
Its authentication and authorization, which are its own
-
What is listening, and on which interface
-
Calling it with nothing