# How can I secure my single node installation?

**URL:** <https://discuss.kubernetes.io/t/how-can-i-secure-my-single-node-installation/8816>\
**Category:** General Discussions\
**Created:** [November 25, 2019, 10:34pm UTC](https://discuss.kubernetes.io/t/how-can-i-secure-my-single-node-installation/8816 "2019-11-25T22:34:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mygithubthrowaway](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mygithubthrowaway/32/4143_2.png) [@mygithubthrowaway](https://discuss.kubernetes.io/u/mygithubthrowaway)\
**Post date:** [November 25, 2019, 10:34pm UTC](https://discuss.kubernetes.io/t/how-can-i-secure-my-single-node-installation/8816/1 "2019-11-25T22:34:08Z")

</div>

### Cluster information:

Kubernetes version: 1.16  
Cloud being used: bare-metal  
Installation method: kubeadm  
Host OS: Archlinux  
CNI and version: flannel  
CRI and version: cri-o 1.16

### 

Hi,

using kubeadm I’ve bootstrap a single instance master node.  
Now if I see listen tcp ports on my cluster:

```
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name    
tcp 0 0 127.0.0.1:10248 0.0.0.0:* LISTEN 15361/kubelet       
tcp 0 0 127.0.0.1:10249 0.0.0.0:* LISTEN 1800/kube-proxy     
tcp 0 0 127.0.0.1:10251 0.0.0.0:* LISTEN 1440/kube-scheduler 
tcp 0 0 my.pub.lic.ip:2379 0.0.0.0:* LISTEN 1603/etcd           
tcp 0 0 127.0.0.1:2379 0.0.0.0:* LISTEN 1603/etcd           
tcp 0 0 my.pub.lic.ip:2380 0.0.0.0:* LISTEN 1603/etcd           
tcp 0 0 127.0.0.1:2381 0.0.0.0:* LISTEN 1603/etcd           
tcp 0 0 127.0.0.1:10257 0.0.0.0:* LISTEN 1490/kube-controlle 
tcp 0 0 127.0.0.1:10259 0.0.0.0:* LISTEN 1440/kube-scheduler 
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 429/sshd            
tcp 0 0 127.0.0.1:42071 0.0.0.0:* LISTEN 447/crio            
tcp6 0 0 :::10250 :::* LISTEN 15361/kubelet       
tcp6 0 0 :::6443 :::* LISTEN 1481/kube-apiserver 
tcp6 0 0 :::10252 :::* LISTEN 1490/kube-controlle         
tcp6 0 0 :::10256 :::* LISTEN 1800/kube-proxy     
tcp6 0 0 :::22 :::* LISTEN 429/sshd            

```

in the kubeadmin config file I tried this

```
---
apiVersion: kubeadm.k8s.io/v1beta2
kind: ClusterConfiguration
[...]
controllerManager:
   extraArgs:
       bind-address: 127.0.0.1
scheduler:
   extraArgs:
       address: 127.0.0.1
[...]

```

but those directive didn’t work.

Questions:

1. i’ve managed to put kubelet to listen localhost only but the `logs` command is not working, this is the correct behavior?
2. how I can put controll manager and kube-proxy to listen localhost only? And can I do it without break something?
3. I can set the etcd to listen local only? And can I do it without break something?

obv I don’t want to add others master/worker nodes in the future

thanks and sorry for bad English

---

<div class="post-metadata">

**Author:** ![georgio](https://avatars.discourse-cdn.com/v4/letter/g/b5ac83/32.png) [@georgio](https://discuss.kubernetes.io/u/georgio)\
**Post date:** [November 26, 2019, 6:28am UTC](https://discuss.kubernetes.io/t/how-can-i-secure-my-single-node-installation/8816/2 "2019-11-26T06:28:37Z")

</div>

I had the similar question about securing Kubernetes with a firewall but nobody had answered yet. [Kubernetes + Docker + iptables](https://discuss.kubernetes.io/t/kubernetes-docker-iptables/8793)  
As far as I understood, kubernetes’ nodes are not supposed to have white IP addresses. You need an external router, which connects your cluster with the Internet and opens the only resourses you want to expose. You can use a virtual or hardware router depends on your cluster location.  
PS I do not recommend you to manually change any system services, in 99% you will mess up the kubernetes networking.
