etcd unauthenticated
etcd guarda todo el estado del cluster incluyendo secrets en texto plano (a menos que haya encryption at rest).
Categoría: Container & Kubernetes 🎯 Trinchera — etcd guarda todo el estado del cluster incluyendo secrets en texto plano (a menos que haya encryption at rest). Sin auth en:2379, dump del etcd = todos los secrets,
service tokens, configs.
🔗 Kill chain — etcdctl --endpoints=http://node:2379 get / --prefix
→ secrets, kubeconfig, tokens de SA.
📡 Huella defensiva — Calls etcdctl get desde IPs no apiserver.
⚠️ Falso amigo — Encryption at rest (encryptionConfig) es
opcional y muchos clusters legacy no lo tienen.
🛡️ Remediación — etcd con TLS mutual auth obligatorio,
network policy, encryption-at-rest activo, audit en clientes etcd.
← Volver al glosario completo Última actualización: 2026-06-11