Port 2379etcd

etcd client API traffic, used by clients and control planes to read and modify distributed key-value data.

transport
tcp

single transport

in transit
cleartext

payload readable on path

assignment
official

registered with iana

risk
8/10

risk

lookups
0

rank 994 of 4,021 · top 25%

also known as etcd-client, etcd client API, port 2379

Technical Details

what runs on :2379

etcd v3 clients normally use gRPC over HTTP/2 with Protocol Buffers on TCP 2379; the v2 API used HTTP/1.1 and JSON, and HTTP/JSON gateways may also be configured. TLS is enabled with certificate-related listen and client-cert flags rather than being inherent to the port, so a default or development deployment may use plaintext. The separate etcd peer endpoint normally listens on TCP 2380 for cluster replication traffic.

Security Information

exposure of :2379

risk score

8/ 10risk

treat as sensitive. widely scanned and regularly exploited when reachable — restrict it to known sources.

databases averages 3.2 across 124 ports — this one sits 4.8 above.

in transit

cleartext

credentials and payloads are readable by anyone on path

assignment

official

registered with iana for this service — scanners fingerprint it by number

reachable over

tcp

every listening transport is another surface to filter at the edge

security overview

This endpoint should not be exposed directly to the public internet. An unauthenticated or weakly protected client endpoint can allow attackers to read, modify, or delete key-value data and, in Kubernetes environments, potentially access or alter sensitive cluster state and secrets. Use TLS, client authentication, etcd authorization, network controls, and restrict access to trusted clients.

the 8 most looked-up other ports in databases — 124 ports carry that label.

risk mix of the 8 listed

  • caution100%

1 of 8 encrypted