Skip to main content

Port Details

Port
10250
Transport
TCP
Service
Kubelet API
IANA service name
unassigned
Range
User port (1024-49151)
Related ports
644310259102572379

Security Exposure

The Kubernetes documentation says the kubelet API gives access to data of varying sensitivity and allows operations with varying levels of power on the node and inside containers. By default the kubelet treats unauthenticated requests as anonymous and uses the AlwaysAllow authorization mode, so a kubelet without hardened flags accepts requests from anyone who reaches 10250.

Hardening

  • +Set --anonymous-auth=false on the kubelet to reject unauthenticated requests.
  • +Use --authorization-mode=Webhook so the API server authorizes kubelet requests.
  • +Enable X.509 client certificate authentication with --client-ca-file and give the API server a kubelet client certificate.
  • +Allow 10250 only from the control plane and required monitoring components.

Monitoring

Alert on connections to 10250 from sources other than control plane nodes, and audit kubelet configuration for anonymous authentication and AlwaysAllow authorization.

Tools for Auditing and Monitoring Kubelet API

kube-bench

Open Source
Cloud Security Tools

Go tool that checks Kubernetes clusters against the CIS Kubernetes Benchmark across managed and self-hosted distributions.

LicenseApache-2.0
PlatformLinux

Kubescape

Free / Commercial
Cloud Security Tools

CNCF Kubernetes security scanner that checks clusters, workloads, and configurations against compliance and misconfiguration frameworks.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Falco

Open Source
Cloud Security Tools

Cloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.

LicenseApache-2.0
PlatformLinux

Frequently Asked Questions

What is port 10250 in Kubernetes?→

It is the kubelet API on each node. Kubernetes lists it as an inbound port on both control plane and worker nodes, used by the node and the control plane.

Does the kubelet allow anonymous access on 10250?→

Upstream defaults treat unauthenticated requests as anonymous. Setting --anonymous-auth=false and using Webhook authorization closes that gap.

Should port 10250 be open to the internet?→

No. It should only be reachable from the control plane and approved components inside the cluster network.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 10250 is not guaranteed to be Kubelet API. Exploited-in-the-wild data from the CISA KEV catalog (CC0).