> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Kubelet Kubeconfig File Ownership Set To root:root

### More Info:

The kubelet kubeconfig file should be owned by root:root. Improper ownership could let non-root users tamper with the kubelets cluster credentials.

### Risk Level

Medium

### Address

Security

### Compliance Standards

* CIS OKE

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. On every worker node, confirm the kubelet kubeconfig path (from the finding it is `/var/lib/kubelet/kubeconfig`):
           ```bash theme={null}
           ls -l /var/lib/kubelet/kubeconfig
           ```

        2. On every worker node, change the ownership of the kubelet kubeconfig file to `root:root`:
           ```bash theme={null}
           sudo chown root:root /var/lib/kubelet/kubeconfig
           ```

        3. (Optional but recommended) Confirm file permissions are appropriately restrictive (e.g. `600`):
           ```bash theme={null}
           sudo chmod 600 /var/lib/kubelet/kubeconfig
           ```

        4. On every worker node, verify the ownership is now `root:root`:
           ```bash theme={null}
           stat -c %U:%G /var/lib/kubelet/kubeconfig
           ```
      </Accordion>

      <Accordion title="Using kubectl">
        This setting is a host-level file ownership issue on each worker node and cannot be changed via kubectl or any Kubernetes API object. To fix it, adjust the file ownership directly on the nodes’ filesystem (for `/var/lib/kubelet/kubeconfig` on every worker node) and follow the guidance in the Manual Steps section.
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        #
        # Fix ownership of the kubelet kubeconfig file on worker nodes
        # Scope: run on every worker node (e.g., via SSH, Ansible shell, or a node startup script)
        # Idempotent: safe to re-run

        set -euo pipefail

        # Path from the finding
        KUBELET_KUBECONFIG="/var/lib/kubelet/kubeconfig"

        echo "==> Checking kubelet kubeconfig at ${KUBELET_KUBECONFIG}"

        if [ ! -e "${KUBELET_KUBECONFIG}" ]; then
          echo "File not found: ${KUBELET_KUBECONFIG}"
          echo "Nothing to change on this node."
          exit 0
        fi

        # Show current ownership
        current_owner="$(stat -c '%U:%G' "${KUBELET_KUBECONFIG}")"
        echo "Current ownership: ${current_owner}"

        # Apply fix (idempotent: chown to same value is safe)
        echo "Setting ownership to root:root ..."
        chown root:root "${KUBELET_KUBECONFIG}"

        # Verification
        echo "Verifying ownership ..."
        new_owner="$(stat -c '%U:%G' "${KUBELET_KUBECONFIG}")"
        echo "New ownership: ${new_owner}"

        if [ "${new_owner}" != "root:root" ]; then
          echo "ERROR: Failed to set ownership to root:root for ${KUBELET_KUBECONFIG}" >&2
          exit 1
        fi

        echo "Success: ${KUBELET_KUBECONFIG} is owned by root:root"

        #
        # Example: run across all worker nodes from a control machine
        # (replace with your actual worker node hostnames/IPs and SSH options)
        #
        # WORKERS=("worker1" "worker2" "worker3")
        # for node in "${WORKERS[@]}"; do
        #   echo "=== ${node} ==="
        #   scp ./fix-kubelet-kubeconfig-ownership.sh "root@${node}:/tmp/fix-kubelet-kubeconfig-ownership.sh"
        #   ssh "root@${node}" "bash /tmp/fix-kubelet-kubeconfig-ownership.sh"
        # done
        ```
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
