mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-29 14:38:50 +00:00
Add Rancher Security Best Practices to version 2.7 and 2.8
This commit is contained in:
@@ -87,3 +87,7 @@ Rancher is committed to informing the community of security issues in our produc
|
|||||||
### Kubernetes Security Best Practices
|
### Kubernetes Security Best Practices
|
||||||
|
|
||||||
For recommendations on securing your Kubernetes cluster, refer to the [Kubernetes Security Best Practices](../reference-guides/rancher-security/kubernetes-security-best-practices.md) guide.
|
For recommendations on securing your Kubernetes cluster, refer to the [Kubernetes Security Best Practices](../reference-guides/rancher-security/kubernetes-security-best-practices.md) guide.
|
||||||
|
|
||||||
|
### Rancher Security Best Practices
|
||||||
|
|
||||||
|
For recommendations on securing your Rancher Manager deployments, refer to the [Rancher Security Best Practices](../reference-guides/rancher-security/rancher-security-best-practices.md) guide.
|
||||||
|
|||||||
+15
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
title: Rancher Security Best Practices
|
||||||
|
---
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/reference-guides/rancher-security/rancher-security-best-practices"/>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
### Restrict Public Access to /version and /rancherversion Path
|
||||||
|
|
||||||
|
The upstream (local) Rancher instance provides information about the Rancher version it is running and the Go version that was used to build it. That information is accessible via the `/version` path, which is used for tasks such as automating version bumps, or confirming that a deployment was successful. The upstream instance also provides Rancher version information accessible via the `/rancherversion` path.
|
||||||
|
|
||||||
|
Adversaries can misuse this information to identify the running Rancher version and cross-relate it with potential bugs to exploit. If your upstream Rancher instance is publicly available on the web, use a Layer 7 firewall to block `/version` and `/rancherversion`.
|
||||||
|
|
||||||
|
See [OWASP Web Application Security Testing - Enumerate Infrastructure and Application Admin Interfaces](https://owasp.org/www-project-web-security-testing-guide/stable/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/05-Enumerate_Infrastructure_and_Application_Admin_Interfaces.html) for more information on protecting your server.
|
||||||
@@ -88,6 +88,10 @@ Rancher is committed to informing the community of security issues in our produc
|
|||||||
|
|
||||||
For recommendations on securing your Kubernetes cluster, refer to the [Kubernetes Security Best Practices](../reference-guides/rancher-security/kubernetes-security-best-practices.md) guide.
|
For recommendations on securing your Kubernetes cluster, refer to the [Kubernetes Security Best Practices](../reference-guides/rancher-security/kubernetes-security-best-practices.md) guide.
|
||||||
|
|
||||||
|
### Rancher Security Best Practices
|
||||||
|
|
||||||
|
For recommendations on securing your Rancher Manager deployments, refer to the [Rancher Security Best Practices](../reference-guides/rancher-security/rancher-security-best-practices.md) guide.
|
||||||
|
|
||||||
### Rancher Webhook Hardening
|
### Rancher Webhook Hardening
|
||||||
|
|
||||||
The Rancher webhook deploys on both the upstream Rancher cluster and all provisioned clusters. For recommendations on hardening the Rancher webhook, see the [Hardening the Rancher Webhook](../reference-guides/rancher-security/rancher-webhook-hardening.md) guide.
|
The Rancher webhook deploys on both the upstream Rancher cluster and all provisioned clusters. For recommendations on hardening the Rancher webhook, see the [Hardening the Rancher Webhook](../reference-guides/rancher-security/rancher-webhook-hardening.md) guide.
|
||||||
|
|||||||
+15
@@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
title: Rancher Security Best Practices
|
||||||
|
---
|
||||||
|
|
||||||
|
<head>
|
||||||
|
<link rel="canonical" href="https://ranchermanager.docs.rancher.com/reference-guides/rancher-security/rancher-security-best-practices"/>
|
||||||
|
</head>
|
||||||
|
|
||||||
|
### Restrict Public Access to /version and /rancherversion Path
|
||||||
|
|
||||||
|
The upstream (local) Rancher instance provides information about the Rancher version it is running and the Go version that was used to build it. That information is accessible via the `/version` path, which is used for tasks such as automating version bumps, or confirming that a deployment was successful. The upstream instance also provides Rancher version information accessible via the `/rancherversion` path.
|
||||||
|
|
||||||
|
Adversaries can misuse this information to identify the running Rancher version and cross-relate it with potential bugs to exploit. If your upstream Rancher instance is publicly available on the web, use a Layer 7 firewall to block `/version` and `/rancherversion`.
|
||||||
|
|
||||||
|
See [OWASP Web Application Security Testing - Enumerate Infrastructure and Application Admin Interfaces](https://owasp.org/www-project-web-security-testing-guide/stable/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/05-Enumerate_Infrastructure_and_Application_Admin_Interfaces.html) for more information on protecting your server.
|
||||||
@@ -1075,6 +1075,7 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"reference-guides/rancher-security/kubernetes-security-best-practices",
|
"reference-guides/rancher-security/kubernetes-security-best-practices",
|
||||||
|
"reference-guides/rancher-security/rancher-security-best-practices",
|
||||||
"reference-guides/rancher-security/security-advisories-and-cves",
|
"reference-guides/rancher-security/security-advisories-and-cves",
|
||||||
"reference-guides/rancher-security/psa-restricted-exemptions"
|
"reference-guides/rancher-security/psa-restricted-exemptions"
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -1075,6 +1075,7 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
"reference-guides/rancher-security/kubernetes-security-best-practices",
|
"reference-guides/rancher-security/kubernetes-security-best-practices",
|
||||||
|
"reference-guides/rancher-security/rancher-security-best-practices",
|
||||||
"reference-guides/rancher-security/security-advisories-and-cves",
|
"reference-guides/rancher-security/security-advisories-and-cves",
|
||||||
"reference-guides/rancher-security/psa-restricted-exemptions",
|
"reference-guides/rancher-security/psa-restricted-exemptions",
|
||||||
"reference-guides/rancher-security/rancher-webhook-hardening"
|
"reference-guides/rancher-security/rancher-webhook-hardening"
|
||||||
|
|||||||
Reference in New Issue
Block a user