Kube-Proxy Kubeconfig File Ownership Is Set To root:root
More Info:
The kube-proxy kubeconfig file should be owned by root:root to ensure that only the root user can read or modify it. Incorrect ownership could allow unauthorized users to tamper with proxy configuration.
Risk Level
Medium
Address
Security
Compliance Standards
- CIS GKE
Triage and Remediation
- Remediation
Remediation
Manual Steps
-
On every worker node, confirm the kubelet kubeconfig file exists and check its current ownership:
ls -l /var/lib/kubelet/kubeconfigstat -c %U:%G /var/lib/kubelet/kubeconfig -
On every worker node, change the ownership of the kubeconfig file to root:root:
sudo chown root:root /var/lib/kubelet/kubeconfig -
(Optional, for hardening) On every worker node, restrict permissions to read/write for root only:
sudo chmod 600 /var/lib/kubelet/kubeconfig -
On every worker node, verify the ownership (and optionally permissions) are correct:
stat -c %U:%G /var/lib/kubelet/kubeconfigstat -c '%a %n' /var/lib/kubelet/kubeconfigExpected ownership:
root:root(and permissions such as600if you applied step 3).
Using kubectl
kubectl cannot modify host-level file ownership, so it cannot be used to fix the ownership of /var/lib/kubelet/kubeconfig on worker nodes. This remediation must be performed directly on each node’s filesystem (over SSH or your node management tooling); see the Manual Steps section for the exact commands.
Automation
#!/usr/bin/env bash
#
# Fix CIS GKE 3.1.2: Ensure kubelet kubeconfig file ownership is set to root:root
# Scope: run on every worker node (as root). Safe to re-run.
set -euo pipefail
KUBECONFIG_PATH="/var/lib/kubelet/kubeconfig"
DESIRED_OWNER="root"
DESIRED_GROUP="root"
echo "=== CIS GKE 3.1.2: kubelet kubeconfig ownership ==="
if [ ! -e "$KUBECONFIG_PATH" ]; then
echo "INFO: $KUBECONFIG_PATH does not exist on this node; nothing to do."
exit 0
fi
current_owner="$(stat -c '%U' "$KUBECONFIG_PATH")"
current_group="$(stat -c '%G' "$KUBECONFIG_PATH")"
if [ "$current_owner" = "$DESIRED_OWNER" ] && [ "$current_group" = "$DESIRED_GROUP" ]; then
echo "OK: $KUBECONFIG_PATH already owned by ${DESIRED_OWNER}:${DESIRED_GROUP}."
else
echo "FIX: Setting ownership of $KUBECONFIG_PATH to ${DESIRED_OWNER}:${DESIRED_GROUP}..."
chown "${DESIRED_OWNER}:${DESIRED_GROUP}" "$KUBECONFIG_PATH"
fi
echo "=== Verifying ownership ==="
/bin/sh -c "if test -e $KUBECONFIG_PATH; then stat -c %U:%G $KUBECONFIG_PATH; fi"
final_owner_group="$(stat -c '%U:%G' "$KUBECONFIG_PATH")"
if [ "$final_owner_group" != "${DESIRED_OWNER}:${DESIRED_GROUP}" ]; then
echo "ERROR: Ownership verification failed; expected ${DESIRED_OWNER}:${DESIRED_GROUP}, got $final_owner_group" >&2
exit 1
fi
echo "SUCCESS: $KUBECONFIG_PATH ownership is ${DESIRED_OWNER}:${DESIRED_GROUP}."