Port 10250: Kubernetes kubelet HTTPS API
IANA has not assigned 10250; it falls in the unassigned block 10202 to 10251. Kubernetes lists inbound TCP 10250 for the kubelet API on control plane and worker nodes, used by the node itself and the control plane.
Port Details
Security Exposure
The Kubernetes documentation says the kubelet API gives access to data of varying sensitivity and allows operations with varying levels of power on the node and inside containers. By default the kubelet treats unauthenticated requests as anonymous and uses the AlwaysAllow authorization mode, so a kubelet without hardened flags accepts requests from anyone who reaches 10250.
Hardening
- +Set --anonymous-auth=false on the kubelet to reject unauthenticated requests.
- +Use --authorization-mode=Webhook so the API server authorizes kubelet requests.
- +Enable X.509 client certificate authentication with --client-ca-file and give the API server a kubelet client certificate.
- +Allow 10250 only from the control plane and required monitoring components.
Monitoring
Alert on connections to 10250 from sources other than control plane nodes, and audit kubelet configuration for anonymous authentication and AlwaysAllow authorization.
Tools for Auditing and Monitoring Kubelet API
kube-bench
Open SourceGo tool that checks Kubernetes clusters against the CIS Kubernetes Benchmark across managed and self-hosted distributions.
Kubescape
Free / CommercialCNCF Kubernetes security scanner that checks clusters, workloads, and configurations against compliance and misconfiguration frameworks.
Falco
Open SourceCloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.
Related Tool Categories
Frequently Asked Questions
What is port 10250 in Kubernetes?→
It is the kubelet API on each node. Kubernetes lists it as an inbound port on both control plane and worker nodes, used by the node and the control plane.
Does the kubelet allow anonymous access on 10250?→
Upstream defaults treat unauthenticated requests as anonymous. Setting --anonymous-auth=false and using Webhook authorization closes that gap.
Should port 10250 be open to the internet?→
No. It should only be reachable from the control plane and approved components inside the cluster network.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 10250 is not guaranteed to be Kubelet API. Exploited-in-the-wild data from the CISA KEV catalog (CC0).