Remove leading backslash

This commit is contained in:
Andy Pitcher
2023-09-18 12:29:07 -04:00
parent 7b36e0f01c
commit 8b158444d9
@@ -130,7 +130,7 @@ All configuration is passed in as arguments at container run time.
**Remediation:**
Run the below command (based on the file location on your system) on the control plane node.
For example, chmod 600 \<path/to/cni/files\>
For example, chmod 600 <path/to/cni/files\>
**Audit:**
@@ -152,7 +152,7 @@ ps -ef | grep kubelet | grep -- --cni-conf-dir | sed 's%.*cni-conf-dir[= ]\([^ ]
**Remediation:**
Run the below command (based on the file location on your system) on the control plane node.
For example,
chown root:root \<path/to/cni/files\>
chown root:root <path/to/cni/files\>
**Audit:**
@@ -463,7 +463,7 @@ root 4018 3998 5 Sep11 ? 01:03:21 kube-apiserver --advertise-address=172.31.4.22
**Remediation:**
Follow the documentation and configure alternate mechanisms for authentication. Then,
edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and remove the --token-auth-file=\<filename\> parameter.
on the control plane node and remove the --token-auth-file=<filename\> parameter.
**Audit:**
@@ -521,8 +521,8 @@ Follow the Kubernetes documentation and set up the TLS connection between the
apiserver and kubelets. Then, edit API server pod specification file
/etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the
kubelet client certificate and key parameters as below.
--kubelet-client-certificate=\<path/to/client-certificate-file\>
--kubelet-client-key=\<path/to/client-key-file\>
--kubelet-client-certificate=<path/to/client-certificate-file\>
--kubelet-client-key=<path/to/client-key-file\>
**Audit:**
@@ -552,7 +552,7 @@ Follow the Kubernetes documentation and setup the TLS connection between
the apiserver and kubelets. Then, edit the API server pod specification file
/etc/kubernetes/manifests/kube-apiserver.yaml on the control plane node and set the
--kubelet-certificate-authority parameter to the path to the cert file for the certificate authority.
--kubelet-certificate-authority=\<ca-string\>
--kubelet-certificate-authority=<ca-string\>
When generating serving certificates, functionality could break in conjunction with hostname overrides which are required for certain cloud providers.
### 1.2.6 Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
@@ -650,7 +650,7 @@ Follow the Kubernetes documentation and set the desired limits in a configuratio
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
and set the below parameters.
--enable-admission-plugins=...,EventRateLimit,...
--admission-control-config-file=\<path/to/configuration/file\>
--admission-control-config-file=<path/to/configuration/file\>
**Audit:**
@@ -1069,7 +1069,7 @@ root 4018 3998 5 Sep11 ? 01:03:22 kube-apiserver --advertise-address=172.31.4.22
Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and set the --service-account-key-file parameter
to the public key file for service accounts. For example,
--service-account-key-file=\<filename\>
--service-account-key-file=<filename\>
**Audit:**
@@ -1098,8 +1098,8 @@ root 4018 3998 5 Sep11 ? 01:03:22 kube-apiserver --advertise-address=172.31.4.22
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and set the etcd certificate and key file parameters.
--etcd-certfile=\<path/to/client-certificate-file\>
--etcd-keyfile=\<path/to/client-key-file\>
--etcd-certfile=<path/to/client-certificate-file\>
--etcd-keyfile=<path/to/client-key-file\>
**Audit:**
@@ -1128,8 +1128,8 @@ root 4018 3998 5 Sep11 ? 01:03:22 kube-apiserver --advertise-address=172.31.4.22
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and set the TLS certificate and private key file parameters.
--tls-cert-file=\<path/to/tls-certificate-file\>
--tls-private-key-file=\<path/to/tls-key-file\>
--tls-cert-file=<path/to/tls-certificate-file\>
--tls-private-key-file=<path/to/tls-key-file\>
**Audit:**
@@ -1158,7 +1158,7 @@ root 4018 3998 5 Sep11 ? 01:03:22 kube-apiserver --advertise-address=172.31.4.22
Follow the Kubernetes documentation and set up the TLS connection on the apiserver.
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and set the client certificate authority file.
--client-ca-file=\<path/to/client-ca-file\>
--client-ca-file=<path/to/client-ca-file\>
**Audit:**
@@ -1187,7 +1187,7 @@ root 4018 3998 5 Sep11 ? 01:03:22 kube-apiserver --advertise-address=172.31.4.22
Follow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and set the etcd certificate authority file parameter.
--etcd-cafile=\<path/to/ca-file\>
--etcd-cafile=<path/to/ca-file\>
**Audit:**
@@ -1216,7 +1216,7 @@ root 4018 3998 5 Sep11 ? 01:03:22 kube-apiserver --advertise-address=172.31.4.22
Follow the Kubernetes documentation and configure a EncryptionConfig file.
Then, edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml
on the control plane node and set the --encryption-provider-config parameter to the path of that file.
For example, --encryption-provider-config=\</path/to/EncryptionConfig/File\>
For example, --encryption-provider-config=</path/to/EncryptionConfig/File\>
**Audit:**
@@ -1386,7 +1386,7 @@ root 4184 4163 1 Sep11 ? 00:20:06 kube-controller-manager --configure-cloud-rout
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
on the control plane node and set the --service-account-private-key-file parameter
to the private key file for service accounts.
--service-account-private-key-file=\<filename\>
--service-account-private-key-file=<filename\>
**Audit:**
@@ -1414,7 +1414,7 @@ root 4184 4163 1 Sep11 ? 00:20:06 kube-controller-manager --configure-cloud-rout
**Remediation:**
Edit the Controller Manager pod specification file /etc/kubernetes/manifests/kube-controller-manager.yaml
on the control plane node and set the --root-ca-file parameter to the certificate bundle file`.
--root-ca-file=\<path/to/file\>
--root-ca-file=<path/to/file\>
**Audit:**
@@ -1538,8 +1538,8 @@ root 4339 4318 0 Sep11 ? 00:03:28 kube-scheduler --authentication-kubeconfig=/et
Follow the etcd service documentation and configure TLS encryption.
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml
on the master node and set the below parameters.
--cert-file=\</path/to/ca-file\>
--key-file=\</path/to/key-file\>
--cert-file=</path/to/ca-file\>
--key-file=</path/to/key-file\>
**Audit:**
@@ -1625,8 +1625,8 @@ Follow the etcd service documentation and configure peer TLS encryption as appro
for your etcd cluster.
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
master node and set the below parameters.
--peer-client-file=\</path/to/peer-cert-file\>
--peer-key-file=\</path/to/peer-key-file\>
--peer-client-file=</path/to/peer-cert-file\>
--peer-key-file=</path/to/peer-key-file\>
**Audit:**
@@ -1713,7 +1713,7 @@ Follow the etcd documentation and create a dedicated certificate authority setup
etcd service.
Then, edit the etcd pod specification file /etc/kubernetes/manifests/etcd.yaml on the
master node and set the below parameter.
--trusted-ca-file=\</path/to/ca-file\>
--trusted-ca-file=</path/to/ca-file\>
**Audit:**
@@ -1946,7 +1946,7 @@ root:root
**Remediation:**
Run the following command to modify the file permissions of the
--client-ca-file chmod 600 \<filename\>
--client-ca-file chmod 600 <filename\>
**Audit:**
@@ -1973,7 +1973,7 @@ permissions=644
**Remediation:**
Run the following command to modify the ownership of the --client-ca-file.
chown root:root \<filename\>
chown root:root <filename\>
**Audit:**
@@ -2106,7 +2106,7 @@ the location of the client CA file.
If using command line arguments, edit the kubelet service file
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
set the below parameter in KUBELET_AUTHZ_ARGS variable.
--client-ca-file=\<path/to/client-ca-file\>
--client-ca-file=<path/to/client-ca-file\>
Based on your system, restart the kubelet service. For example,
systemctl daemon-reload
systemctl restart kubelet.service
@@ -2317,8 +2317,8 @@ to the location of the corresponding private key file.
If using command line arguments, edit the kubelet service file
/etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
--tls-cert-file=\<path/to/tls-certificate-file\>
--tls-private-key-file=\<path/to/tls-key-file\>
--tls-cert-file=<path/to/tls-certificate-file\>
--tls-private-key-file=<path/to/tls-key-file\>
Based on your system, restart the kubelet service. For example,
systemctl daemon-reload
systemctl restart kubelet.service