From 1da3478637aeea9176fa3b0e88fd604fda35a29e Mon Sep 17 00:00:00 2001 From: Andy Pitcher Date: Mon, 18 Sep 2023 12:41:49 -0400 Subject: [PATCH] Remove leading backslash --- ...ssessment-guide-with-cis-v1.7-k8s-v1.25.md | 56 +++++++++---------- 1 file changed, 28 insertions(+), 28 deletions(-) diff --git a/docs/reference-guides/rancher-security/hardening-guides/k3s-hardening-guide/k3s-self-assessment-guide-with-cis-v1.7-k8s-v1.25.md b/docs/reference-guides/rancher-security/hardening-guides/k3s-hardening-guide/k3s-self-assessment-guide-with-cis-v1.7-k8s-v1.25.md index 548ba621080..2df99bcd4d7 100644 --- a/docs/reference-guides/rancher-security/hardening-guides/k3s-hardening-guide/k3s-self-assessment-guide-with-cis-v1.7-k8s-v1.25.md +++ b/docs/reference-guides/rancher-security/hardening-guides/k3s-hardening-guide/k3s-self-assessment-guide-with-cis-v1.7-k8s-v1.25.md @@ -128,7 +128,7 @@ Not Applicable. **Remediation:** Run the below command (based on the file location on your system) on the control plane node. -For example, chmod 600 \ +For example, chmod 600 Not Applicable. ### 1.1.10 Ensure that the Container Network Interface file ownership is set to root:root (Manual) @@ -139,7 +139,7 @@ Not Applicable. **Remediation:** Run the below command (based on the file location on your system) on the control plane node. For example, -chown root:root \ +chown root:root Not Applicable. ### 1.1.11 Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated) @@ -491,7 +491,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf **Remediation:** Follow the documentation and configure alternate mechanisms for authentication. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml -on the control plane node and remove the --token-auth-file=\ parameter. +on the control plane node and remove the --token-auth-file= parameter. **Audit:** @@ -549,8 +549,8 @@ Follow the Kubernetes documentation and set up the TLS connection between the apiserver and kubelets. Then, edit API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the kubelet client certificate and key parameters as below. ---kubelet-client-certificate=\ ---kubelet-client-key=\ +--kubelet-client-certificate= +--kubelet-client-key= **Audit:** @@ -580,7 +580,7 @@ Follow the Kubernetes documentation and setup the TLS connection between the apiserver and kubelets. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the --kubelet-certificate-authority parameter to the path to the cert file for the certificate authority. ---kubelet-certificate-authority=\ +--kubelet-certificate-authority= Permissive - When generating serving certificates, functionality could break in conjunction with hostname overrides which are required for certain cloud providers. ### 1.2.6 Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated) @@ -678,7 +678,7 @@ Follow the Kubernetes documentation and set the desired limits in a configuratio Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml and set the below parameters. --enable-admission-plugins=...,EventRateLimit,... ---admission-control-config-file=\ +--admission-control-config-file= **Audit:** @@ -1007,7 +1007,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the --service-account-key-file parameter to the public key file for service accounts. For example, ---service-account-key-file=\ +--service-account-key-file= ### 1.2.25 Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated) @@ -1018,8 +1018,8 @@ to the public key file for service accounts. For example, Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the etcd certificate and key file parameters. ---etcd-certfile=\ ---etcd-keyfile=\ +--etcd-certfile= +--etcd-keyfile= **Audit Script:** `check_for_k3s_etcd.sh` @@ -1111,8 +1111,8 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Follow the Kubernetes documentation and set up the TLS connection on the apiserver. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the TLS certificate and private key file parameters. ---tls-cert-file=\ ---tls-private-key-file=\ +--tls-cert-file= +--tls-private-key-file= **Audit:** @@ -1141,7 +1141,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Follow the Kubernetes documentation and set up the TLS connection on the apiserver. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the client certificate authority file. ---client-ca-file=\ +--client-ca-file= **Audit:** @@ -1170,7 +1170,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the etcd certificate authority file parameter. ---etcd-cafile=\ +--etcd-cafile= **Audit:** @@ -1199,7 +1199,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Follow the Kubernetes documentation and configure a EncryptionConfig file. Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the --encryption-provider-config parameter to the path of that file. -For example, --encryption-provider-config=\ +For example, --encryption-provider-config= Permissive - Enabling encryption changes how data can be recovered as data is encrypted. ### 1.2.30 Ensure that encryption providers are appropriately configured (Manual) @@ -1341,7 +1341,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml on the control plane node and set the --service-account-private-key-file parameter to the private key file for service accounts. ---service-account-private-key-file=\ +--service-account-private-key-file= **Audit:** @@ -1369,7 +1369,7 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf **Remediation:** Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml on the control plane node and set the --root-ca-file parameter to the certificate bundle file`. ---root-ca-file=\ +--root-ca-file= **Audit:** @@ -1493,8 +1493,8 @@ Sep 11 20:52:00 ip-172-31-12-34 k3s[2340]: time="2023-09-11T20:52:00Z" level=inf Follow the etcd service documentation and configure TLS encryption. Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the master node and set the below parameters. ---cert-file=\ ---key-file=\ +--cert-file= +--key-file= **Audit Script:** `check_for_k3s_etcd.sh` @@ -1756,7 +1756,7 @@ fi **Returned Value**: ```console -error: process ID list syntax error Usage: ps [options] Try 'ps --help \' or 'ps --help \' for additional help text. For more details see ps(1). cat: /proc//environ: No such file or directory +error: process ID list syntax error Usage: ps [options] Try 'ps --help ' or 'ps --help ' for additional help text. For more details see ps(1). cat: /proc//environ: No such file or directory ``` ### 2.4 Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated) @@ -1769,8 +1769,8 @@ Follow the etcd service documentation and configure peer TLS encryption as appro for your etcd cluster. Then, edit the etcd pod specification file /var/lib/rancher/k3s/server/db/etcd/config on the master node and set the below parameters. ---peer-client-file=\ ---peer-key-file=\ +--peer-client-file= +--peer-key-file= **Audit Script:** `check_for_k3s_etcd.sh` @@ -2032,7 +2032,7 @@ fi **Returned Value**: ```console -error: process ID list syntax error Usage: ps [options] Try 'ps --help \' or 'ps --help \' for additional help text. For more details see ps(1). cat: /proc//environ: No such file or directory +error: process ID list syntax error Usage: ps [options] Try 'ps --help ' or 'ps --help ' for additional help text. For more details see ps(1). cat: /proc//environ: No such file or directory ``` ### 2.7 Ensure that a unique Certificate Authority is used for etcd (Automated) @@ -2341,7 +2341,7 @@ root:root **Remediation:** Run the following command to modify the file permissions of the ---client-ca-file chmod 600 \ +--client-ca-file chmod 600 **Audit:** @@ -2368,7 +2368,7 @@ stat -c %a /var/lib/rancher/k3s/server/tls/server-ca.crt **Remediation:** Run the following command to modify the ownership of the --client-ca-file. -chown root:root \ +chown root:root **Audit:** @@ -2493,7 +2493,7 @@ the location of the client CA file. If using command line arguments, edit the kubelet service file /etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and set the below parameter in KUBELET_AUTHZ_ARGS variable. ---client-ca-file=\ +--client-ca-file= Based on your system, restart the kubelet service. For example, systemctl daemon-reload systemctl restart kubelet.service @@ -2674,8 +2674,8 @@ to the location of the corresponding private key file. If using command line arguments, edit the kubelet service file /etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and set the below parameters in KUBELET_CERTIFICATE_ARGS variable. ---tls-cert-file=\ ---tls-private-key-file=\ +--tls-cert-file= +--tls-private-key-file= Based on your system, restart the kubelet service. For example, systemctl daemon-reload systemctl restart kubelet.service