--- title: Creating a Custom Benchmark Version for Running a Cluster Scan ---
Each Benchmark Version defines a set of test configuration files that define the Compliance tests to be run by the kube-bench tool. The `rancher-compliance` application installs a few default Benchmark Versions which are listed under Compliance application menu. But in the following cases, a custom configuration or remediation may be required: - Non-standard file locations: When Kubernetes binaries, configuration or certificate paths deviate from upstream benchmark defaults. Example: Unlike traditional Kubernetes, K3s bundles control plane components into a single binary. Therefore,` --anonymous-auth` flag presence and configuration should be verified in K3s' logs (`journalctl`), not via `kube-apiserver` process checks (`ps`). - Alternative risk mitigations: If a setup doesn't meet a check but has an equally effective compensating control with justification. Or simply is not concerned by the check requirement because of its design. Example: By default, K3s embeds the api server within the k3s process. There is no API server pod specification file, so verifying the latter's file permissions is not required. ## 1. Prepare the Custom Benchmark Version ConfigMap To create a custom benchmark version, first you need to create a ConfigMap containing the benchmark version's config files and upload it to your Kubernetes cluster where you want to run the scan. To prepare a custom benchmark version ConfigMap, suppose we want to add a custom Benchmark Version named `foo`. 1. Create a directory named `foo` and inside this directory, place all the config YAML files that the kube-bench tool looks for. For example, here are the config YAML files for a Generic CIS 1.5 Benchmark Version https://github.com/aquasecurity/kube-bench/tree/master/cfg/cis-1.5 1. Place the complete `config.yaml` file, which includes all the components that should be tested. 1. Add the Benchmark version name to the `target_mapping` section of the `config.yaml`: ```yaml target_mapping: "foo": - "master" - "node" - "controlplane" - "etcd" - "policies" ``` 1. Upload this directory to your Kubernetes Cluster by creating a ConfigMap: ```yaml kubectl create configmap -n