Alibaba > ACK >

Kubernetes Web Dashboard Disabled

MEDIUM
Source
CloudSploit
ID
kubernetes-web-dashboard-disabled

Kubernetes Web Dashboard Disabled

Ensure that Kubernetes cluster web UI/Dashboard is not enabled.

The Kubernetes Web UI (Dashboard) is backed by a highly privileged Kubernetes Service Account. It is recommended to use ACK User Console instead of Dashboard to avoid any privileged escalation via compromise the dashboard.

In ACK console, select the target cluster,choose the kube-system namespace in the Namespace pop-menu, input “dashboard” in the deploy filter bar, verify no result exists after the filter, and delete the dashboard deployment by selecting Delete in the More pop-menu.