> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Kubelet Make Iptables Util Chains Argument Set To True

### More Info:

The kubelet --make-iptables-util-chains argument should be set to true so the kubelet manages the iptables rules needed for correct network traffic handling on the node.

### Risk Level

Medium

### Address

Security

### Compliance Standards

* CIS OKE

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. On every worker node, open the kubelet systemd drop-in for editing:
           ```bash theme={null}
           sudo vi /etc/systemd/system/kubelet.service.d/00-default.conf
           ```
           In the line that starts with `ExecStart=`, ensure the kubelet is started with `--make-iptables-util-chains=true`, for example:
           ```ini theme={null}
           ExecStart=/usr/bin/kubelet \
             --config=/etc/kubernetes/kubelet-config.json \
             --make-iptables-util-chains=true \
             $KUBELET_EXTRA_ARGS
           ```

        2. If `--make-iptables-util-chains` is already present but set differently, change it to:
           ```ini theme={null}
           --make-iptables-util-chains=true
           ```

        3. Reload systemd configuration on every worker node:
           ```bash theme={null}
           sudo systemctl daemon-reload
           ```

        4. Restart the kubelet on every worker node (this will disrupt pod scheduling on that node briefly):
           ```bash theme={null}
           sudo systemctl restart kubelet.service
           ```

        5. Verify the kubelet is running correctly on every worker node:
           ```bash theme={null}
           sudo systemctl status kubelet -l
           ```

        6. Confirm the flag is set as required on every worker node:
           ```bash theme={null}
           /bin/ps -fC kubelet
           ```
           Ensure the output command line for `kubelet` includes:
           ```text theme={null}
           --make-iptables-util-chains=true
           ```
      </Accordion>

      <Accordion title="Using kubectl">
        kubectl cannot modify kubelet process flags or host-level config files such as `/etc/systemd/system/kubelet.service.d/00-default.conf` or `/etc/kubernetes/kubelet-config.json`; this setting must be changed directly on every worker node’s OS. See the Manual Steps section for the exact systemd and configuration file changes to set `--make-iptables-util-chains=true` and restart the kubelet.
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        #
        # Purpose: Ensure kubelet runs with --make-iptables-util-chains=true
        # Scope:   Run on every WORKER NODE as root
        # Safe:    Idempotent; can be re-run
        #

        set -euo pipefail

        KUBELET_DROPIN_DIR="/etc/systemd/system/kubelet.service.d"
        KUBELET_DROPIN_FILE="${KUBELET_DROPIN_DIR}/00-default.conf"
        REQUIRED_FLAG="--make-iptables-util-chains=true"

        echo "==> Ensuring kubelet drop-in directory exists: ${KUBELET_DROPIN_DIR}"
        mkdir -p "${KUBELET_DROPIN_DIR}"

        if [[ ! -f "${KUBELET_DROPIN_FILE}" ]]; then
          echo "==> ${KUBELET_DROPIN_FILE} not found, creating minimal drop-in"
          cat > "${KUBELET_DROPIN_FILE}" <<'EOF'
        [Service]
        Environment="KUBELET_EXTRA_ARGS="
        EOF
        fi

        echo "==> Ensuring ${REQUIRED_FLAG} is present in ${KUBELET_DROPIN_FILE}"

        # Normalize existing KUBELET_EXTRA_ARGS and append flag if missing
        if grep -q '^Environment="KUBELET_EXTRA_ARGS=' "${KUBELET_DROPIN_FILE}"; then
          # Extract current value
          current_line=$(grep '^Environment="KUBELET_EXTRA_ARGS=' "${KUBELET_DROPIN_FILE}")
          current_value=${current_line#Environment=\"KUBELET_EXTRA_ARGS=}
          current_value=${current_value%\"}

          # If flag is missing, append it
          if [[ "${current_value}" != *"${REQUIRED_FLAG}"* ]]; then
            new_value="${current_value} ${REQUIRED_FLAG}"
            # Collapse extra whitespace
            new_value=$(echo "${new_value}" | xargs)
            # Escape for sed
            esc_current=$(printf '%s\n' "${current_line}" | sed -e 's/[\/&]/\\&/g')
            esc_new=$(printf '%s\n' "Environment=\"KUBELET_EXTRA_ARGS=${new_value}\"" | sed -e 's/[\/&]/\\&/g')
            sed -i "s/${esc_current}/${esc_new}/" "${KUBELET_DROPIN_FILE}"
            echo "   - Updated KUBELET_EXTRA_ARGS to include ${REQUIRED_FLAG}"
          else
            echo "   - ${REQUIRED_FLAG} already present; no change needed"
          fi
        else
          # No KUBELET_EXTRA_ARGS line; add one under [Service]
          echo "   - Adding KUBELET_EXTRA_ARGS line with ${REQUIRED_FLAG}"
          awk -v flag="${REQUIRED_FLAG}" '
            /^\[Service\]/ {
              print;
              print "Environment=\"KUBELET_EXTRA_ARGS=" flag "\"";
              next
            }
            { print }
          ' "${KUBELET_DROPIN_FILE}" > "${KUBELET_DROPIN_FILE}.tmp"
          mv "${KUBELET_DROPIN_FILE}.tmp" "${KUBELET_DROPIN_FILE}"
        fi

        echo "==> Reloading systemd and restarting kubelet (this will restart kubelet on this node)"
        systemctl daemon-reload
        systemctl restart kubelet.service

        echo "==> Checking kubelet status"
        systemctl status kubelet -l --no-pager || true

        echo "==> Verifying kubelet process flags"
        /bin/ps -fC kubelet || {
          echo "ERROR: kubelet process not found after restart" >&2
          exit 1
        }

        if /bin/ps -fC kubelet | grep -q -- "${REQUIRED_FLAG}"; then
          echo "SUCCESS: kubelet is running with ${REQUIRED_FLAG}"
          exit 0
        else
          echo "ERROR: kubelet is NOT running with ${REQUIRED_FLAG}" >&2
          /bin/ps -fC kubelet
          exit 1
        fi
        ```
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
