Port 2379: etcd client API
TCP 2379 is the etcd client API port; peers in an etcd cluster talk to each other on 2380. Kubernetes uses etcd as the backing store for all cluster data, and its port reference lists 2379-2380 on control plane nodes for use by kube-apiserver and etcd.
Port Details
Security Exposure
Kubernetes documentation states that write access to etcd is equivalent to root on the entire cluster and that read access can be used to escalate quickly. Cluster secrets and configuration live in etcd, so an unauthenticated or plaintext client endpoint exposes them directly. The etcd docs describe client certificate authentication as an option that must be turned on with --client-cert-auth.
Hardening
- +Serve the client API over HTTPS and enable --client-cert-auth with --trusted-ca-file so only clients with valid certificates connect.
- +Firewall 2379 and 2380 so only the API servers and other etcd members can reach them.
- +Encrypt peer traffic with --peer-cert-file and --peer-key-file over HTTPS URLs.
- +Give non-control-plane components separate etcd instances or keyspace ACLs instead of access to the main cluster store.
Monitoring
Alert on client connections to 2379 from any address other than the API servers, and on TLS handshake failures that suggest unauthorized clients. Kubernetes audit logging records actions taken by the API for later analysis.
Tools for Auditing and Monitoring etcd
kube-bench
Open SourceGo tool that checks Kubernetes clusters against the CIS Kubernetes Benchmark across managed and self-hosted distributions.
Kubescape
Free / CommercialCNCF Kubernetes security scanner that checks clusters, workloads, and configurations against compliance and misconfiguration frameworks.
Falco
Open SourceCloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.
Related Tool Categories
Frequently Asked Questions
What is the difference between etcd ports 2379 and 2380?→
IANA registers 2379 for etcd client communication and 2380 for etcd server-to-server communication. Kubernetes lists both on control plane nodes.
Who needs access to etcd port 2379 in Kubernetes?→
Only the Kubernetes API servers. Kubernetes documentation recommends isolating etcd behind a firewall that only the API servers may access.
How is etcd client access authenticated?→
etcd checks client certificates signed by a trusted CA when --client-cert-auth is set together with TLS. Requests without a valid certificate are rejected.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 2379 is not guaranteed to be etcd. Exploited-in-the-wild data from the CISA KEV catalog (CC0).