Port 10250 (TCP) is the standard for Kubernetes kubelet API. kubelet — agent on every K8s node. Port 10250 — secure API for controller-manager and kube-apiserver. 10255 — deprecated read-only port (removed in K8s 1.20+). Access to kube
Below: what uses this port, security considerations, online check, FAQ.
Kubernetes kubelet API
kubelet — agent on every K8s node. Port 10250 — secure API for controller-manager and kube-apiserver. 10255 — deprecated read-only port (removed in K8s 1.20+). Access to kubelet = pod exec = node takeover.
kubelet 10250 exposed without auth = critical vuln (Tesla hack 2018). Cilium/Calico network policies mandatory. Firewall inside cluster.
Enterno.io Ping + Port checker tests TCP reachability of any port from 3 regions (Moscow / Frankfurt / Virginia).
Ping sends ICMP packets to a host and measures response time. Port scanning checks which TCP ports are open and accepting connections — helping diagnose serviceavailability issues.
Choose packet count (3, 4, 6, 10). Stats: min/avg/max latency and packet loss.
Check 14 key ports: HTTP, HTTPS, SSH, FTP, SMTP, MySQL, PostgreSQL, and more.
Testing from our server — see site availability from outside, not just your local network.
Need constant monitoring? Create a monitor — checks every minute with notifications.
availability diagnosis
TCP port scanning
connection debugging
basic health check
Ping check history, host availability monitoring and downtime alerts.
Sign up freeNo, modern cloud providers (AWS, Google Cloud, Yandex) close all incoming ports by default. You must explicitly allow port 10250 in a Security Group or firewall.
Use <a href="/en/ping">Enterno Ping + Port Checker</a>. Or in shell: <code>nc -vz example.com 10250</code>.
Depends on the service. Kubernetes kubelet API should never be exposed publicly without authentication + TLS. See <a href="/en/s/research-open-ports-exposure-2026">our 2026 exposure research</a>.