Skip to main content

Port Details

Port
6443
Transport
TCP
Service
Kubernetes API
IANA service name
sun-sr-https
Range
User port (1024-49151)
Related ports

Security Exposure

The API server controls every workload and secret in the cluster, so any authentication or authorization gap is serious. Anonymous access is enabled by default when an authorization mode other than AlwaysAllow is used, and RBAC grants anonymous requests whatever is explicitly bound to system:anonymous or system:unauthenticated. Shadowserver reports API servers on 6443 and 443 that answer unauthenticated /version requests, noting they leak version and build details.

Hardening

  • +Restrict 6443 to administrator networks, node subnets and CI systems with firewall or cloud security group rules.
  • +Disable anonymous authentication with --anonymous-auth=false where health checks do not need it.
  • +Use RBAC with least privilege and review bindings for system:anonymous and system:unauthenticated.
  • +Enable API server audit logging, which Kubernetes describes as a chronological record of actions by users, applications and the control plane.
  • +Keep the control plane on a supported Kubernetes release.

Monitoring

Enable Kubernetes audit logs and alert on requests from system:anonymous, failed authentications and changes to RBAC bindings or secrets.

Tools for Auditing and Monitoring Kubernetes API

kube-bench

Open Source
Cloud Security Tools

Go tool that checks Kubernetes clusters against the CIS Kubernetes Benchmark across managed and self-hosted distributions.

LicenseApache-2.0
PlatformLinux

Kubescape

Free / Commercial
Cloud Security Tools

CNCF Kubernetes security scanner that checks clusters, workloads, and configurations against compliance and misconfiguration frameworks.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Falco

Open Source
Cloud Security Tools

Cloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.

LicenseApache-2.0
PlatformLinux

Frequently Asked Questions

What is port 6443 used for?→

It is the default secure port of the Kubernetes API server. Kubernetes documentation notes that in a typical production cluster the API serves on 443, and the port is set with --secure-port.

Should the Kubernetes API be reachable from the internet?→

Shadowserver treats internet-accessible API servers as unnecessarily exposed attack surface, so access should be limited to trusted networks.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 6443 is not guaranteed to be Kubernetes API. Exploited-in-the-wild data from the CISA KEV catalog (CC0).