Port 6443: Kubernetes API server (HTTPS)
Port 6443 is the default TLS port of the Kubernetes API server, which kubectl, client libraries and cluster components use to manage the cluster. Kubernetes documentation lists TCP 6443 inbound on the control plane, used by all components. IANA assigns 6443 to sun-sr-https, which differs from this common use.
Port Details
Security Exposure
The API server controls every workload and secret in the cluster, so any authentication or authorization gap is serious. Anonymous access is enabled by default when an authorization mode other than AlwaysAllow is used, and RBAC grants anonymous requests whatever is explicitly bound to system:anonymous or system:unauthenticated. Shadowserver reports API servers on 6443 and 443 that answer unauthenticated /version requests, noting they leak version and build details.
Hardening
- +Restrict 6443 to administrator networks, node subnets and CI systems with firewall or cloud security group rules.
- +Disable anonymous authentication with --anonymous-auth=false where health checks do not need it.
- +Use RBAC with least privilege and review bindings for system:anonymous and system:unauthenticated.
- +Enable API server audit logging, which Kubernetes describes as a chronological record of actions by users, applications and the control plane.
- +Keep the control plane on a supported Kubernetes release.
Monitoring
Enable Kubernetes audit logs and alert on requests from system:anonymous, failed authentications and changes to RBAC bindings or secrets.
Tools for Auditing and Monitoring Kubernetes API
kube-bench
Open SourceGo tool that checks Kubernetes clusters against the CIS Kubernetes Benchmark across managed and self-hosted distributions.
Kubescape
Free / CommercialCNCF Kubernetes security scanner that checks clusters, workloads, and configurations against compliance and misconfiguration frameworks.
Falco
Open SourceCloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.
Related Tool Categories
Frequently Asked Questions
What is port 6443 used for?→
It is the default secure port of the Kubernetes API server. Kubernetes documentation notes that in a typical production cluster the API serves on 443, and the port is set with --secure-port.
Should the Kubernetes API be reachable from the internet?→
Shadowserver treats internet-accessible API servers as unnecessarily exposed attack surface, so access should be limited to trusted networks.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 6443 is not guaranteed to be Kubernetes API. Exploited-in-the-wild data from the CISA KEV catalog (CC0).