Skip to main content

Port Details

Port
2379
Transport
TCP
Service
etcd
IANA service name
etcd-client
Range
User port (1024-49151)
Related ports
23806443

Security Exposure

Kubernetes documentation states that write access to etcd is equivalent to root on the entire cluster and that read access can be used to escalate quickly. Cluster secrets and configuration live in etcd, so an unauthenticated or plaintext client endpoint exposes them directly. The etcd docs describe client certificate authentication as an option that must be turned on with --client-cert-auth.

Hardening

  • +Serve the client API over HTTPS and enable --client-cert-auth with --trusted-ca-file so only clients with valid certificates connect.
  • +Firewall 2379 and 2380 so only the API servers and other etcd members can reach them.
  • +Encrypt peer traffic with --peer-cert-file and --peer-key-file over HTTPS URLs.
  • +Give non-control-plane components separate etcd instances or keyspace ACLs instead of access to the main cluster store.

Monitoring

Alert on client connections to 2379 from any address other than the API servers, and on TLS handshake failures that suggest unauthorized clients. Kubernetes audit logging records actions taken by the API for later analysis.

Tools for Auditing and Monitoring etcd

kube-bench

Open Source
Cloud Security Tools

Go tool that checks Kubernetes clusters against the CIS Kubernetes Benchmark across managed and self-hosted distributions.

LicenseApache-2.0
PlatformLinux

Kubescape

Free / Commercial
Cloud Security Tools

CNCF Kubernetes security scanner that checks clusters, workloads, and configurations against compliance and misconfiguration frameworks.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Falco

Open Source
Cloud Security Tools

Cloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.

LicenseApache-2.0
PlatformLinux

Frequently Asked Questions

What is the difference between etcd ports 2379 and 2380?→

IANA registers 2379 for etcd client communication and 2380 for etcd server-to-server communication. Kubernetes lists both on control plane nodes.

Who needs access to etcd port 2379 in Kubernetes?→

Only the Kubernetes API servers. Kubernetes documentation recommends isolating etcd behind a firewall that only the API servers may access.

How is etcd client access authenticated?→

etcd checks client certificates signed by a trusted CA when --client-cert-auth is set together with TLS. Requests without a valid certificate are rejected.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 2379 is not guaranteed to be etcd. Exploited-in-the-wild data from the CISA KEV catalog (CC0).