diff --git a/docs/concepts/architecture/master-node-communication.md b/docs/concepts/architecture/master-node-communication.md index 1d78c5f920..23348771a3 100644 --- a/docs/concepts/architecture/master-node-communication.md +++ b/docs/concepts/architecture/master-node-communication.md @@ -64,12 +64,13 @@ or service through the apiserver's proxy functionality. ### apiserver -> kubelet -The connections from the apiserver to the kubelet are used for fetching logs -for pods, attaching (through kubectl) to running pods, and using the kubelet's -port-forwarding functionality. These connections terminate at the kubelet's -HTTPS endpoint. +The connections from the apiserver to the kubelet are used for: + * fetching logs for pods. + * attaching (through kubectl) to running pods. + * the kubelet's port-forwarding functionality. -By default, the apiserver does not verify the kubelet's serving certificate, +These connections terminate at the kubelet's HTTPS endpoint. By default, +the apiserver does not verify the kubelet's serving certificate, which makes the connection subject to man-in-the-middle attacks, and **unsafe** to run over untrusted and/or public networks.