Files
rancher-docs/pages-for-subheaders/cis-scans.html
T

26 lines
29 KiB
HTML
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html>
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-pages-for-subheaders/cis-scans">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v2.3.1">
<title data-rh="true">CIS Scans | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="http://ranchermanager.docs.rancher.com/pages-for-subheaders/cis-scans"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="CIS Scans | Rancher"><meta data-rh="true" name="description" content="Rancher can run a security scan to check whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark. The CIS scans can run on any Kubernetes cluster, including hosted Kubernetes providers such as EKS, AKS, and GKE."><meta data-rh="true" property="og:description" content="Rancher can run a security scan to check whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark. The CIS scans can run on any Kubernetes cluster, including hosted Kubernetes providers such as EKS, AKS, and GKE."><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="canonical" href="http://ranchermanager.docs.rancher.com/pages-for-subheaders/cis-scans"><link data-rh="true" rel="alternate" href="http://ranchermanager.docs.rancher.com/pages-for-subheaders/cis-scans" hreflang="en"><link data-rh="true" rel="alternate" href="http://ranchermanager.docs.rancher.com/zh/pages-for-subheaders/cis-scans" hreflang="zh"><link data-rh="true" rel="alternate" href="http://ranchermanager.docs.rancher.com/pages-for-subheaders/cis-scans" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link rel="preconnect" href="https://www.googletagmanager.com">
<script>window.dataLayer=window.dataLayer||[]</script>
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.35be4547.css">
<link rel="preload" href="/assets/js/runtime~main.b0c4bb1a.js" as="script">
<link rel="preload" href="/assets/js/main.d8782442.js" as="script">
</head>
<body class="navigation-with-keyboard">
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/">v2.7</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/pages-for-subheaders/cis-scans">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/pages-for-subheaders/cis-scans">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/pages-for-subheaders/cis-scans">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4/pages-for-subheaders/cis-scans">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/pages-for-subheaders/cis-scans" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/pages-for-subheaders/cis-scans" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link navbar__github">GitHub<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><a href="https://rancher.com" target="_blank" rel="noopener noreferrer" class="navbar__item navbar__link">Rancher Home<svg width="13.5" height="13.5" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/pages-for-subheaders/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/pages-for-subheaders/best-practices">Reference Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/pages-for-subheaders/cloud-marketplace">Integrations in Rancher</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/cloud-marketplace">Cloud Marketplace Integration</a><button aria-label="Toggle the collapsible sidebar category &#x27;Cloud Marketplace Integration&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible menu__list-item-collapsible--active"><a class="menu__link menu__link--sublist menu__link--active" aria-current="page" aria-expanded="true" tabindex="0" href="/pages-for-subheaders/cis-scans">CIS Scans</a><button aria-label="Toggle the collapsible sidebar category &#x27;CIS Scans&#x27;" type="button" class="clean-btn menu__caret"></button></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/cis-scans/configuration-reference">Configuration</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/cis-scans/rbac-for-cis-scans">Roles-based Access Control</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/cis-scans/skipped-and-not-applicable-tests">Skipped and Not Applicable Tests</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/cis-scans/custom-benchmark">Creating a Custom Benchmark Version for Running a Cluster Scan</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/fleet-gitops-at-scale">Continuous Delivery with Fleet</a><button aria-label="Toggle the collapsible sidebar category &#x27;Continuous Delivery with Fleet&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/harvester">Harvester Integration</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/istio">Istio</a><button aria-label="Toggle the collapsible sidebar category &#x27;Istio&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/longhorn">Longhorn - Cloud native distributed block storage for Kubernetes</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/logging">Logging</a><button aria-label="Toggle the collapsible sidebar category &#x27;Logging&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/pages-for-subheaders/monitoring-and-alerting">Monitoring and Alerting</a><button aria-label="Toggle the collapsible sidebar category &#x27;Monitoring and Alerting&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/neuvector">NeuVector Integration</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/opa-gatekeeper">OPA Gatekeeper</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/integrations-in-rancher/rancher-extensions">Rancher Extensions</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/faq/general-faq">FAQ</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/troubleshooting/general-troubleshooting">Troubleshooting</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/contribute-to-rancher">Contributing to Rancher</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Integrations in Rancher</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">CIS Scans</span><meta itemprop="position" content="2"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: v2.7</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>CIS Scans</h1></header><p>Rancher can run a security scan to check whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark. The CIS scans can run on any Kubernetes cluster, including hosted Kubernetes providers such as EKS, AKS, and GKE.</p><p>The <code>rancher-cis-benchmark</code> app leverages <a href="https://github.com/aquasecurity/kube-bench" target="_blank" rel="noopener noreferrer">kube-bench,</a> an open-source tool from Aqua Security, to check clusters for CIS Kubernetes Benchmark compliance. Also, to generate a cluster-wide report, the application utilizes <a href="https://github.com/vmware-tanzu/sonobuoy" target="_blank" rel="noopener noreferrer">Sonobuoy</a> for report aggregation.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="about-the-cis-benchmark">About the CIS Benchmark<a href="#about-the-cis-benchmark" class="hash-link" aria-label="Direct link to About the CIS Benchmark" title="Direct link to About the CIS Benchmark">​</a></h2><p>The Center for Internet Security is a 501(c<!-- -->)<!-- -->(3) non-profit organization, formed in October 2000, with a mission to &quot;identify, develop, validate, promote, and sustain best practice solutions for cyber defense and build and lead communities to enable an environment of trust in cyberspace&quot;. The organization is headquartered in East Greenbush, New York, with members including large corporations, government agencies, and academic institutions.</p><p>CIS Benchmarks are best practices for the secure configuration of a target system. CIS Benchmarks are developed through the generous volunteer efforts of subject matter experts, technology vendors, public and private community members, and the CIS Benchmark Development team.</p><p><a href="https://learn.cisecurity.org/benchmarks" target="_blank" rel="noopener noreferrer">Sign up</a> at the CIS website to view the official Benchmark documents.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="about-the-generated-report">About the Generated Report<a href="#about-the-generated-report" class="hash-link" aria-label="Direct link to About the Generated Report" title="Direct link to About the Generated Report">​</a></h2><p>Each scan generates a report can be viewed in the Rancher UI and can be downloaded in CSV format.</p><p>By default, the CIS Benchmark v1.6 is used.</p><p>The Benchmark version is included in the generated report.</p><p>The Benchmark provides recommendations of two types: Automated and Manual. Recommendations marked as Manual in the Benchmark are not included in the generated report.</p><p>Some tests are designated as &quot;Not Applicable.&quot; These tests will not be run on any CIS scan because of the way that Rancher provisions RKE clusters. For information on how test results can be audited, and why some tests are designated to be not applicable, refer to Rancher&#x27;s <a href="/pages-for-subheaders/rancher-security#the-cis-benchmark-and-self-assessment">self-assessment guide</a> for the corresponding Kubernetes version.</p><p>The report contains the following information:</p><table><thead><tr><th>Column in Report</th><th>Description</th></tr></thead><tbody><tr><td><code>id</code></td><td>The ID number of the CIS Benchmark.</td></tr><tr><td><code>description</code></td><td>The description of the CIS Benchmark test.</td></tr><tr><td><code>remediation</code></td><td>What needs to be fixed in order to pass the test.</td></tr><tr><td><code>state</code></td><td>Indicates if the test passed, failed, was skipped, or was not applicable.</td></tr><tr><td><code>node_type</code></td><td>The node role, which affects which tests are run on the node. Master tests are run on controlplane nodes, etcd tests are run on etcd nodes, and node tests are run on the worker nodes.</td></tr><tr><td><code>audit</code></td><td>This is the audit check that <code>kube-bench</code> runs for this test.</td></tr><tr><td><code>audit_config</code></td><td>Any configuration applicable to the audit script.</td></tr><tr><td><code>test_info</code></td><td>Test-related info as reported by <code>kube-bench</code>, if any.</td></tr><tr><td><code>commands</code></td><td>Test-related commands as reported by <code>kube-bench</code>, if any.</td></tr><tr><td><code>config_commands</code></td><td>Test-related configuration data as reported by <code>kube-bench</code>, if any.</td></tr><tr><td><code>actual_value</code></td><td>The test&#x27;s actual value, present if reported by <code>kube-bench</code>.</td></tr><tr><td><code>expected_result</code></td><td>The test&#x27;s expected result, present if reported by <code>kube-bench</code>.</td></tr></tbody></table><p>Refer to <a href="/pages-for-subheaders/rancher-security">the table in the cluster hardening guide</a> for information on which versions of Kubernetes, the Benchmark, Rancher, and our cluster hardening guide correspond to each other. Also refer to the hardening guide for configuration files of CIS-compliant clusters and information on remediating failed tests.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="test-profiles">Test Profiles<a href="#test-profiles" class="hash-link" aria-label="Direct link to Test Profiles" title="Direct link to Test Profiles">​</a></h2><p>The following profiles are available:</p><ul><li>Generic CIS 1.6</li><li>Generic CIS 1.20</li><li>Generic CIS 1.23</li><li>RKE permissive 1.6</li><li>RKE hardened 1.6</li><li>RKE permissive 1.20</li><li>RKE hardened 1.20</li><li>RKE permissive 1.23</li><li>RKE hardened 1.23</li><li>RKE2 permissive 1.6</li><li>RKE2 hardened 1.6</li><li>RKE2 permissive 1.20</li><li>RKE2 hardened 1.20</li><li>RKE2 permissive 1.23</li><li>RKE2 hardened 1.23</li><li>K3s permissive 1.6</li><li>K3s hardened 1.6</li><li>K3s permissive 1.20</li><li>K3s hardened 1.20</li><li>K3s permissive 1.23</li><li>K3s hardened 1.23</li><li>AKS</li><li>EKS</li><li>GKE</li></ul><p>You also have the ability to customize a profile by saving a set of tests to skip.</p><p>All profiles will have a set of not applicable tests that will be skipped during the CIS scan. These tests are not applicable based on how a RKE cluster manages Kubernetes.</p><p>There are two types of RKE cluster scan profiles:</p><ul><li><strong>Permissive:</strong> This profile has a set of tests that have been will be skipped as these tests will fail on a default RKE Kubernetes cluster. Besides the list of skipped tests, the profile will also not run the not applicable tests.</li><li><strong>Hardened:</strong> This profile will not skip any tests, except for the non-applicable tests.</li></ul><p>The EKS and GKE cluster scan profiles are based on CIS Benchmark versions that are specific to those types of clusters.</p><p>In order to pass the &quot;Hardened&quot; profile, you will need to follow the steps on the <a href="/pages-for-subheaders/rancher-security#rancher-hardening-guide">hardening guide</a> and use the <code>cluster.yml</code> defined in the hardening guide to provision a hardened cluster.</p><p>The default profile and the supported CIS benchmark version depends on the type of cluster that will be scanned:</p><p>The <code>rancher-cis-benchmark</code> supports the CIS 1.6 Benchmark version.</p><ul><li>For RKE Kubernetes clusters, the RKE Permissive 1.6 profile is the default.</li><li>EKS and GKE have their own CIS Benchmarks published by <code>kube-bench</code>. The corresponding test profiles are used by default for those clusters.</li><li>For RKE2 Kubernetes clusters, the RKE2 Permissive 1.6 profile is the default.</li><li>For cluster types other than RKE, RKE2, EKS and GKE, the Generic CIS 1.5 profile will be used by default.</li></ul><h2 class="anchor anchorWithStickyNavbar_LWe7" id="about-skipped-and-not-applicable-tests">About Skipped and Not Applicable Tests<a href="#about-skipped-and-not-applicable-tests" class="hash-link" aria-label="Direct link to About Skipped and Not Applicable Tests" title="Direct link to About Skipped and Not Applicable Tests">​</a></h2><p>For a list of skipped and not applicable tests, refer to <a href="/how-to-guides/advanced-user-guides/cis-scan-guides/skip-tests">this page</a>.</p><p>For now, only user-defined skipped tests are marked as skipped in the generated report.</p><p>Any skipped tests that are defined as being skipped by one of the default profiles are marked as not applicable.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="roles-based-access-control">Roles-based Access Control<a href="#roles-based-access-control" class="hash-link" aria-label="Direct link to Roles-based Access Control" title="Direct link to Roles-based Access Control">​</a></h2><p>For information about permissions, refer to <a href="/integrations-in-rancher/cis-scans/rbac-for-cis-scans">this page</a></p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="configuration">Configuration<a href="#configuration" class="hash-link" aria-label="Direct link to Configuration" title="Direct link to Configuration">​</a></h2><p>For more information about configuring the custom resources for the scans, profiles, and benchmark versions, refer to <a href="/integrations-in-rancher/cis-scans/configuration-reference">this page</a></p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="how-to-guides">How-to Guides<a href="#how-to-guides" class="hash-link" aria-label="Direct link to How-to Guides" title="Direct link to How-to Guides">​</a></h2><p>Please refer to the <a href="/pages-for-subheaders/cis-scan-guides">CIS Scan Guides</a> to learn how to run CIS scans.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/pages-for-subheaders/cis-scans.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2023-03-03T18:28:50.000Z">Mar 3, 2023</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages navigation"><a class="pagination-nav__link pagination-nav__link--prev" href="/integrations-in-rancher/cloud-marketplace/supportconfig"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">Supportconfig bundle</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/integrations-in-rancher/cis-scans/configuration-reference"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">Configuration</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#about-the-cis-benchmark" class="table-of-contents__link toc-highlight">About the CIS Benchmark</a></li><li><a href="#about-the-generated-report" class="table-of-contents__link toc-highlight">About the Generated Report</a></li><li><a href="#test-profiles" class="table-of-contents__link toc-highlight">Test Profiles</a></li><li><a href="#about-skipped-and-not-applicable-tests" class="table-of-contents__link toc-highlight">About Skipped and Not Applicable Tests</a></li><li><a href="#roles-based-access-control" class="table-of-contents__link toc-highlight">Roles-based Access Control</a></li><li><a href="#configuration" class="table-of-contents__link toc-highlight">Configuration</a></li><li><a href="#how-to-guides" class="table-of-contents__link toc-highlight">How-to Guides</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2023 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
<script src="/assets/js/runtime~main.b0c4bb1a.js"></script>
<script src="/assets/js/main.d8782442.js"></script>
</body>
</html>