Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VPA admission-controller: About 0.0.0.0:8000 listen and insecure tls protocols #7823

Closed
novahe opened this issue Feb 11, 2025 · 5 comments
Closed
Labels
area/vertical-pod-autoscaler kind/support Categorizes issue or PR as a support question.

Comments

@novahe
Copy link
Contributor

novahe commented Feb 11, 2025

I found some listening ports with 0.0.0.0 during the scanning process, such as 8000. Moreover, the insecure TLS 1.0 and 1.1 protocols, as well as insecure cipher suites (for example, using RSA as the key exchange algorithm and cipher suites containing CBC symmetric cipher algorithms in the TLS protocol) are being used for port 8000. May I ask if there is any plan to address these issues?

@voelzmo
Copy link
Contributor

voelzmo commented Feb 11, 2025

The admission-controller is a webhook, which needs to expose an endpoint. The default port for this is 8000.

Regarding the findings for the TLS protocols, it would be helpful if you pointed out where you found TLS 1.0 being used. Note that the flag --min-tls-version exists, which you can use to adjust the minimum required TLS version to your liking. It defaults to tls1_2, which makes me curious where you found TLS 1.0.

Hope that helps!

@voelzmo
Copy link
Contributor

voelzmo commented Feb 11, 2025

/area vertical-pod-autoscaler
/kind support

@k8s-ci-robot k8s-ci-robot added area/vertical-pod-autoscaler kind/support Categorizes issue or PR as a support question. labels Feb 11, 2025
@adrianmoisey
Copy link
Member

Can you also mention which version of the VPA you are running?

@novahe
Copy link
Contributor Author

novahe commented Feb 14, 2025

We use 1.2.2 and note that the latest version is supported. We are going to try the latest version. Thank you very much for your support. @voelzmo @adrianmoisey

@novahe novahe closed this as completed Feb 14, 2025
@adrianmoisey
Copy link
Member

We use 1.2.2 and note that the latest version is supported. We are going to try the latest version. Thank you very much for your support.

I think 1.2.2 is new enough that we can help you here.

I think the comments that Marco left are worth looking into

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/vertical-pod-autoscaler kind/support Categorizes issue or PR as a support question.
Projects
None yet
Development

No branches or pull requests

4 participants