> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Ensure Auto Tls Argument Is Disabled

### More Info:

Do not use self-signed certificates for TLS.

### Risk Level

High

### Address

Security

### Compliance Standards

* CIS Kubernetes

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. On every etcd (control plane) node, back up the current etcd static pod manifest:

           ```bash theme={null}
           sudo cp -a /etc/kubernetes/manifests/etcd.yaml /etc/kubernetes/manifests/etcd.yaml.backup.$(date +%F-%H%M%S)
           ```

        2. Open `/etc/kubernetes/manifests/etcd.yaml` for editing:

           ```bash theme={null}
           sudo vi /etc/kubernetes/manifests/etcd.yaml
           ```

        3. In the container `command`/`args` list for etcd, locate any `--auto-tls` flag and either:
           * remove the entire `--auto-tls=...` entry, or
           * change it explicitly to false, for example:
             ```yaml theme={null}
             - --auto-tls=false
             ```

        4. Save the file and exit the editor. The kubelet will automatically restart the etcd static pod when it detects the manifest change (this temporarily restarts etcd on this node).

        5. After 30–60 seconds, verify on the same node that etcd is running without `--auto-tls=true`:

           ```bash theme={null}
           /bin/ps -ef | /bin/grep etcd | /bin/grep -v grep
           ```

        6. Inspect the output and confirm there is no `--auto-tls=true` argument present in the etcd process command line (and, if present, it is `--auto-tls=false` or absent entirely). Repeat these steps on every etcd node.
      </Accordion>

      <Accordion title="Using kubectl">
        kubectl cannot change the etcd process flags or the static pod manifest at `/etc/kubernetes/manifests/etcd.yaml` on the control plane node. To remediate this finding, you must edit that file directly on every etcd node; see the Manual Steps section.
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        #
        # Remediation: Disable etcd --auto-tls on all control plane nodes
        # Scope: Run on every control plane node that has /etc/kubernetes/manifests/etcd.yaml
        # Impact: Editing /etc/kubernetes/manifests/etcd.yaml will trigger a restart
        #         of the etcd static pod via the kubelet on that node.

        set -euo pipefail

        ETCD_MANIFEST="/etc/kubernetes/manifests/etcd.yaml"
        BACKUP_DIR="/etc/kubernetes/manifests/backup-etcd-auto-tls-$(date +%Y%m%d-%H%M%S)"

        echo "[*] Checking for etcd manifest at ${ETCD_MANIFEST}..."
        if [[ ! -f "${ETCD_MANIFEST}" ]]; then
          echo "[!] etcd manifest not found at ${ETCD_MANIFEST}. Nothing to do on this node."
          exit 0
        fi

        echo "[*] Creating backup directory ${BACKUP_DIR}..."
        mkdir -p "${BACKUP_DIR}"
        cp -p "${ETCD_MANIFEST}" "${BACKUP_DIR}/"

        echo "[*] Ensuring --auto-tls is disabled in ${ETCD_MANIFEST}..."

        # 1. Remove any existing --auto-tls flag lines to avoid duplicates or conflicting values.
        #    This is done conservatively: only lines containing '--auto-tls' are removed.
        tmpfile="$(mktemp)"
        grep -v -- '--auto-tls' "${ETCD_MANIFEST}" > "${tmpfile}"

        # 2. Insert --auto-tls=false into the etcd command args if not present.
        #    We look for an existing 'etcd' container command/args section and add it.
        #    If the manifest does not have a suitable place, we leave the file as-is
        #    (very unlikely for standard kubeadm-style manifests).
        if ! grep -q -- '--auto-tls=false' "${tmpfile}"; then
          # Try to inject into an existing args list for the etcd container.
          # This awk script:
          #  - Tracks when we are inside the etcd container definition.
          #  - When we see a line with '- --client-cert-auth' or similar args lines,
          #    we append a new arg line '- --auto-tls=false' once.
          awk '
            /name: etcd/ { in_etcd=1 }
            in_etcd && $1 == "name:" && $2 != "etcd" { in_etcd=0 }
            {
              print $0
              if (in_etcd && $1 == "-" && $2 ~ /^--/ && inserted == 0) {
                # Heuristic: insert right after the first arg line encountered.
                print "        - --auto-tls=false"
                inserted=1
              }
            }
            END {
              if (in_etcd && inserted == 0) {
                # Fallback: if we never saw an args line, append one at the end of the etcd container
                # This is best-effort and assumes standard indentation.
                # No-op in most kubeadm-generated manifests where we will have inserted earlier.
              }
            }
          ' "${tmpfile}" > "${tmpfile}.patched" || {
            echo "[!] Failed to patch manifest; restoring original."
            cp -p "${BACKUP_DIR}/etcd.yaml" "${ETCD_MANIFEST}"
            rm -f "${tmpfile}" "${tmpfile}.patched"
            exit 1
          }
          mv "${tmpfile}.patched" "${tmpfile}"
        fi

        # 3. Move patched file into place (atomic replace).
        cp -p "${tmpfile}" "${ETCD_MANIFEST}"
        rm -f "${tmpfile}"

        echo "[*] Updated ${ETCD_MANIFEST}. kubelet will restart the etcd static pod automatically."

        # Wait briefly for etcd to restart (tunable).
        sleep 10

        echo "[*] Verifying that etcd is not running with --auto-tls=true..."

        # Verification: use the same style as the audit command and ensure no etcd process has --auto-tls=true
        if /bin/ps -ef | /bin/grep etcd | /bin/grep -v grep | /bin/grep -q -- "--auto-tls=true"; then
          echo "[!] Verification FAILED: etcd is still running with --auto-tls=true on this node."
          echo "    Check the manifest and kubelet status manually."
          exit 2
        fi

        if /bin/ps -ef | /bin/grep etcd | /bin/grep -v grep | /bin/grep -q -- "--auto-tls=false"; then
          echo "[*] Verification PASSED: etcd is running with --auto-tls=false (or not set) on this node."
        else
          echo "[*] Verification PASSED: etcd is running without --auto-tls flag (default is disabled)."
        fi

        exit 0
        ```
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>

### Additional Reading:

* [https://coreos.com/etcd/docs/latest/op-guide/security.html](https://coreos.com/etcd/docs/latest/op-guide/security.html)
