Timeouts for streaming connections in an EKS worker node should be enabled
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
Description
Timeouts on streaming connections should be enabled. Setting idle timeouts ensures that the node is protected against Denial-of-Service attacks, inactive connections, and running out of ephemeral ports.
Choose a remediation method from below. For both steps, a restart of the Kubelet service is required.
Kubelet config file
- Add the json below to this file:
/etc/kubernetes/kubelet/kubelet-config.json
"streamingConnectionIdleTimeout": "4h0m0s"
Executable arguments
- Edit the Kubelet service file on each worker node and ensure the below parameters are part of the
KUBELET_ARGS
variable string.
--streaming-connection-idle-timeout=4h0m0s