#Konnectivity
Yes, style l'auto-update de k0s, konnectivity, VIP de l'API-Server (le tout géré directement par k0s sans outil externe)
February 28, 2025 at 5:07 PM
Y'a pas konnectivity chez aws déjà. Et konnectivity demande forcemént de passer les certs pour faire du mtls quand il est déployé.
April 20, 2025 at 3:56 PM
Linode ってリリースノートが出てから実際に使えるまでにちょっと時間がかかるんですね…… もうリリースノートは v1.36.3 になってますが、ノード作ったら 1.36.2 になっちゃいます……
techdocs.akamai.com/cloud-comput...
Aug 20, 2026 — LKE updates
Existing clusters created prior to the release on June 22nd 2026 have switched from using WireGuard to Konnectivity for communication between the control plane and worker nodes. When upgrading, this will cause a brief outage. Since clusters created after June 22nd are already using Konnectivity, the…
techdocs.akamai.com
August 21, 2026 at 2:21 PM
Уязвимость CVE-2026-16242 в Konnectivity: угрозы для hosted control plane и способы защиты

https://kripta.biz/posts/D8BD48A3-9D3C-425B-B209-707E19E30FFA
August 2, 2026 at 2:42 PM
深度解析 CVE-2026-16242:Konnectivity 代理服务器配置漏洞对云原生安全的威胁与防护策略

https://qian.cx/posts/67E6DD1E-F8AB-41D3-ADC4-8BE663B08F1D
August 2, 2026 at 2:42 PM
CVE-2026-16242 - Critical authentication bypass in Konnectivity proxy-server. CVSS 9.4. Unpatched. Attackers can intercept control-plane traffic. Isolate affected systems immediately. #CVE #Konnectivity #infosec

https://www.valtersit.com/cve/CVE-2026-16242/
July 20, 2026 at 12:07 PM
CVE-2026-16242 - Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
CVE ID : CVE-2026-16242

Published : July 20, 2026, 8:16 a.m. | 1 hour, 5 minutes ago

Description : A flaw was found in the Konnectivity proxy-server co...
CVE-2026-16242 - Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing …
cvefeed.io
July 20, 2026 at 9:25 AM
CVE-2026-16242 - red hat openshift container platform 4
The Konnectivity proxy-server in Hypershift does not verify the identity of agents connecting to it. This means an attacker who can reach the proxy could connect…

Too many irrelevant or confusing CVEs? Use stackflag.com

#redhat #CVE #infosec
CVE-2026-16242: Hypershift Konnectivity Proxy Allows Unauthenticated Agent Connections
The Konnectivity proxy-server in Hypershift does not verify the identity of agents connecting to it.
stackflag.com
July 20, 2026 at 8:22 AM
🚨 EUVD-2026-45897
📊 9.4/10

📝 A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and with...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45897

#cybersecurity #infosec #cve #euvd
July 20, 2026 at 10:00 AM
Red Hat Logging Subsystem for OpenShift hit by CRITICAL CVE-2026-16242 (CVSS 9.4): missing agent auth exposes control-plane traffic. Restrict endpoint access & stay updated via https://radar.offseq.com/threat/cve-2026-16242-missing-authentication-for-critical-function-in-red-hat-logging-subsystem...
CVE-2026-16242: Missing Authentication for Critical Function in Red Hat Logging
This vulnerability in the Konnectivity proxy-server configuration for hosted control planes in Red Hat OpenShift occurs due to missing authentication mechanisms. Specifically, the agent-facing listener is started without the --cluster-ca-ce
radar.offseq.com
July 20, 2026 at 10:30 AM
CVE-2020-8562 exposes a TOCTOU race in Kubernetes API server proxy, enabling bypass of IP filters via DNS rebinding to access internal control plane services. Mitigations include DNS TTL enforcement and Konnectivity. #KubernetesVuln #TOCTOU #USA
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562
CVE-2020-8562 is a TOCTOU vulnerability in the Kubernetes API server proxy that can be combined with DNS rebinding to bypass an IP-based filter and reach internal services like the control plane metadata or kube-proxy config endpoints. The issue is most concerning for managed Kubernetes control planes because exploitation requires creating Node objects and using the API server proxy, and mitigations include enforcing minimum DNS TTLs or using Konnectivity. #CVE-2020-8562 #Kubernetes
www.hendryadrian.com
April 10, 2026 at 6:45 AM
ご自宅クラスタならk0sかk3sあたりがおすすめ感ある〜 konnectivityとかkube-proxyの設定なんかをyamlで記載してクラスタ自体をディスポーザブルにできるk0sが好み
March 10, 2025 at 2:19 PM
gkeconnect.projectID. Removed support in the Konnectivity server (konnectivity-server) for the following weak cryptographic cipher suites: TLS_RSA_WITH_AES_256_GCM_SHA384 and TLS_RSA_WITH_AES_128_GCM_SHA256
May 6, 2025 at 4:31 PM
The following functional change was made in 1.30.800-gke.66: Removed support in the Konnectivity server (konnectivity-server) for the following weak cryptographic cipher suites: TLS_RSA_WITH_AES_256_GCM_SHA384 and TLS_RSA_WITH_AES_128_GCM_SHA256
April 14, 2025 at 10:31 PM