Etcd集群

简要概述

etcd 集群安全相关。

etcd

确保客户端通过 tls 通讯

spec:
  containers:
  - command:
    - etcd
    - --cert-file=/etc/kubernetes/pki/etcd/server.crt
    - --key-file=/etc/kubernetes/pki/etcd/server.key

确保客户端通过 tls 认证

spec:
  containers:
  - command:
    - etcd
    - --client-cert-auth="true"

确保集群间通过 tls 通讯

spec:
  containers:
  - command:
    - etcd
    - --peer-cert-file=/etc/kubernetes/pki/etcd/peer.crt
    - --peer-key-file=/etc/kubernetes/pki/etcd/peer.key

确保集群间通过 tls 认证

spec:
  containers:
  - command:
    - etcd
    --peer-client-cert-auth=true

确保配置正确的 ca 用于验证

spec:
  containers:
  - command:
    - etcd
    - --peer-trusted-ca-file=/etc/kubernetes/pki/etcd/ca.crt
    - --trusted-ca-file=/etc/kubernetes/pki/etcd/ca.crt



最后修改 2023.10.09: docs: update cis (1559d7c)