Amazon EKS cluster endpoint is public by default. Why and how big is the risk?

Viewed 141

I learned that the EKS cluster endpoint public by default.

I set up a test cluster and below command and was able to successfully access my cluster.

kubectl --username="None" --password="None" --server="https://xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.yyz.<aws-region>.eks.amazonaws.com" --insecure-skip-tls-verify=true get pods -A

after reading this article: https://unit42.paloaltonetworks.com/unsecured-kubernetes-instances/ xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx is a 32 digit hexadecimal string
yyz is a string consisting of two letters and one number.

From https://docs.aws.amazon.com/eks/latest/userguide/cluster-endpoint.html

When you create a new cluster, Amazon EKS creates an endpoint for the managed Kubernetes API server that you use to communicate with your cluster (using Kubernetes management tools such as kubectl). By default, this API server endpoint is public to the internet, and access to the API server is secured using a combination of AWS Identity and Access Management (IAM) and native Kubernetes Role Based Access Control (RBAC).

Obviously AWS mentions IAM and RBAC and it might be fairly difficult, albeit not impossible, to guess the endpoint URL. But there are ways to increase the chances: sniff the network/DNS in public WIFI, hack users computer and see endpoint in kubectl config view, etc.

Anyone setting up a Kubernetes cluster should be able to set up a bastion host as well, I would argue.

I am wondering why AWS has chosen to set it to public by default?

0 Answers
Related