etcd

etcd and the Cluster's Single Source of Truth

etcd 137,357 (github.com/etcd-io/etcd (https://github.com/etcd-io/etcd 52,314 ), Apache-2.0) is a consistent key-value store. Its members elect a leader with the Raft algorithm and accept a write only when a majority stored it, so three members survive losing one. Everything Kubernetes 5,150 knows lives under /registry/. The etcd Pod ships etcdctl, which authenticates with the certificates kubeadm 5,150 put on the node:

Reading Kubernetes' own keys from etcd with etcdctlYAML
etcd() {
  kubectl -n kube-system exec etcd-l3-booknest-control-plane -- etcdctl \
    --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/server.crt \
    --key=/etc/kubernetes/pki/etcd/server.key "$@"
}
etcd version | head -1
etcd get /registry/namespaces --prefix --keys-only | grep .
etcd get /registry/namespaces/default --print-value-only | od -c | head -3
Output
etcdctl version: 3.7.0
/registry/namespaces/default
/registry/namespaces/kube-node-lease
/registry/namespaces/kube-public
/registry/namespaces/kube-system
/registry/namespaces/local-path-storage
0000000   k   8   s  \0  \n 017  \n 002   v   1 022  \t   N   a   m   e
0000020   s   p   a   c   e 022 206 002  \n 353 001  \n  \a   d   e   f
0000040   a   u   l   t 022  \0 032  \0   "  \0   *   $   b   9   7   b

Keys follow /registry/<resource>/<namespace>/<name>. Built-in types are stored as Protobuf 59,573 , marked by the k8s\0 prefix, then the v1 Namespace type and the name default. Secrets are stored the same way unless you enable encryption at rest (Encryption at Rest), so access to etcd equals control of the cluster. Never write to etcd directly, since that skips authorization, admission and validation; do back it up with etcdctl snapshot save.