mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-27 13:38:07 +00:00
Enclose in backticks so <&tag> aren't processed as HTML tags - 3
This commit is contained in:
@@ -296,8 +296,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -307,7 +307,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
@@ -562,7 +562,7 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -590,7 +590,7 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2177,7 +2177,7 @@ if test -e $CAFILE; then stat -c permissions=%a $CAFILE; fi
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:root <filename>
|
`chown root:root <filename>`
|
||||||
|
|
||||||
**Audit Script:** `check_cafile_ownership.sh`
|
**Audit Script:** `check_cafile_ownership.sh`
|
||||||
|
|
||||||
|
|||||||
@@ -754,7 +754,7 @@ on the master node and set the below parameter.
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -782,7 +782,7 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2273,7 +2273,7 @@ stat -c %a /var/lib/rancher/rke2/server/tls/server-ca.crt
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:roset: trueot <filename>
|
`chown root:roset: trueot <filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -296,8 +296,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -307,7 +307,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+3
-3
@@ -298,8 +298,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -309,7 +309,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+3
-3
@@ -651,7 +651,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -679,7 +679,7 @@ root 4643 4626 22 16:15 ? 00:00:46 kube-apiserver --etcd-keyfil
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
@@ -2322,7 +2322,7 @@ if test -e $CAFILE; then stat -c permissions=%a $CAFILE; fi
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:root <filename>
|
`chown root:root <filename>`
|
||||||
|
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|||||||
+3
-3
@@ -296,8 +296,8 @@ This table shows cluster-autoscaler parameters for fine tuning:
|
|||||||
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
|node-deletion-delay-timeout|"2m"|Maximum time CA waits for removing delay-deletion.cluster-autoscaler.kubernetes.io/ annotations before deleting the node|
|
||||||
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
|scan-interval|"10s"|How often cluster is reevaluated for scale up or down|
|
||||||
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
|max-nodes-total|0|Maximum number of nodes in all node groups. Cluster autoscaler will not grow the cluster beyond this number|
|
||||||
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|cores-total|"0:320000"|Minimum and maximum number of cores in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format <min>:<max>. Cluster autoscaler will not scale the cluster beyond these numbers|
|
|memory-total|"0:6400000"|Minimum and maximum number of gigabytes of memory in cluster, in the format `<min>:<max>.` Cluster autoscaler will not scale the cluster beyond these numbers|
|
||||||
cloud-provider|-|Cloud provider type|
|
cloud-provider|-|Cloud provider type|
|
||||||
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
|max-bulk-soft-taint-count|10|Maximum number of nodes that can be tainted/untainted PreferNoSchedule at the same time. Set to 0 to turn off such tainting|
|
||||||
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
|max-bulk-soft-taint-time|"3s"|Maximum duration of tainting/untainting nodes as PreferNoSchedule at the same time|
|
||||||
@@ -307,7 +307,7 @@ cloud-provider|-|Cloud provider type|
|
|||||||
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
|ok-total-unready-count|3|Number of allowed unready nodes, irrespective of max-total-unready-percentage|
|
||||||
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
|scale-up-from-zero|true|Should CA scale up when there 0 ready nodes|
|
||||||
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
|max-node-provision-time|"15m"|Maximum time CA waits for node to be provisioned|
|
||||||
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: <min>:<max>:<other...>|
|
|nodes|-|sets min,max size and other configuration data for a node group in a format accepted by cloud provider. Can be used multiple times. Format: `<min>:<max>:<other...>`|
|
||||||
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
|node-group-auto-discovery|-|One or more definition(s) of node group auto-discovery. A definition is expressed `<name of discoverer>:[<key>[=<value>]]`|
|
||||||
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
|estimator|-|"binpacking"|Type of resource estimator to be used in scale up. Available values: ["binpacking"]|
|
||||||
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
|expander|"random"|Type of node group expander to be used in scale up. Available values: `["random","most-pods","least-waste","price","priority"]`|
|
||||||
|
|||||||
+3
-3
@@ -558,7 +558,7 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -586,7 +586,7 @@ root 121142 121120 7 12:27 ? 00:06:27 kube-apiserver --audit-log-maxsize=100 --e
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2173,7 +2173,7 @@ if test -e $CAFILE; then stat -c permissions=%a $CAFILE; fi
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:root <filename>
|
`chown root:root <filename>`
|
||||||
|
|
||||||
**Audit Script:** `check_cafile_ownership.sh`
|
**Audit Script:** `check_cafile_ownership.sh`
|
||||||
|
|
||||||
|
|||||||
+3
-3
@@ -750,7 +750,7 @@ on the master node and set the below parameter.
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --basic-auth-file=<filename> parameter.
|
on the master node and remove the `--basic-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -778,7 +778,7 @@ root 5275 5222 15 14:58 ? 00:01:26 kube-apiserver --audit-policy-file=/etc/ranch
|
|||||||
**Remediation:**
|
**Remediation:**
|
||||||
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
Follow the documentation and configure alternate mechanisms for authentication. Then,
|
||||||
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
edit the API server pod specification file /var/lib/rancher/rke2/agent/pod-manifests/kube-apiserver.yaml
|
||||||
on the master node and remove the --token-auth-file=<filename> parameter.
|
on the master node and remove the `--token-auth-file=<filename>` parameter.
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
@@ -2269,7 +2269,7 @@ stat -c %a /var/lib/rancher/rke2/server/tls/server-ca.crt
|
|||||||
|
|
||||||
**Remediation:**
|
**Remediation:**
|
||||||
Run the following command to modify the ownership of the --client-ca-file.
|
Run the following command to modify the ownership of the --client-ca-file.
|
||||||
chown root:roset: trueot <filename>
|
`chown root:roset: trueot <filename>`
|
||||||
|
|
||||||
**Audit:**
|
**Audit:**
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user