Timeouts for streaming connections in an AKS worker node should be enabled

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Description

Timeouts on streaming connections should be enabled. Setting idle timeouts ensures that the node is protected against Denial-of-Service attacks, inactive connections, and running out of ephemeral ports.

Remediation

Choose one of the following remediation methods. For both methods, a restart of the Kubelet service is required.

Kubelet config file

  1. Add the following JSON to the /etc/kubernetes/kubelet/kubelet-config.json file.
"streamingConnectionIdleTimeout": "4h0m0s"

Executable arguments

  1. Edit the Kubelet service file on each worker node and ensure the following parameters are part of the KUBELET_ARGS variable string.
--streaming-connection-idle-timeout=4h0m0s