mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-10-11 12:26:04 +00:00
1 line
131 KiB
JavaScript
1 line
131 KiB
JavaScript
"use strict";(self.webpackChunkrancher_docs=self.webpackChunkrancher_docs||[]).push([[78770],{3905:(e,t,n)=>{n.d(t,{Zo:()=>u,kt:()=>m});var r=n(67294);function a(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function o(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);t&&(r=r.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,r)}return n}function i(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?o(Object(n),!0).forEach((function(t){a(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):o(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function s(e,t){if(null==e)return{};var n,r,a=function(e,t){if(null==e)return{};var n,r,a={},o=Object.keys(e);for(r=0;r<o.length;r++)n=o[r],t.indexOf(n)>=0||(a[n]=e[n]);return a}(e,t);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);for(r=0;r<o.length;r++)n=o[r],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(a[n]=e[n])}return a}var l=r.createContext({}),p=function(e){var t=r.useContext(l),n=t;return e&&(n="function"==typeof e?e(t):i(i({},t),e)),n},u=function(e){var t=p(e.components);return r.createElement(l.Provider,{value:t},e.children)},c={inlineCode:"code",wrapper:function(e){var t=e.children;return r.createElement(r.Fragment,{},t)}},d=r.forwardRef((function(e,t){var n=e.components,a=e.mdxType,o=e.originalType,l=e.parentName,u=s(e,["components","mdxType","originalType","parentName"]),d=p(n),m=a,k=d["".concat(l,".").concat(m)]||d[m]||c[m]||o;return n?r.createElement(k,i(i({ref:t},u),{},{components:n})):r.createElement(k,i({ref:t},u))}));function m(e,t){var n=arguments,a=t&&t.mdxType;if("string"==typeof e||a){var o=n.length,i=new Array(o);i[0]=d;var s={};for(var l in t)hasOwnProperty.call(t,l)&&(s[l]=t[l]);s.originalType=e,s.mdxType="string"==typeof e?e:a,i[1]=s;for(var p=2;p<o;p++)i[p]=n[p];return r.createElement.apply(null,i)}return r.createElement.apply(null,n)}d.displayName="MDXCreateElement"},936:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>i,default:()=>c,frontMatter:()=>o,metadata:()=>s,toc:()=>p});var r=n(87462),a=(n(67294),n(3905));const o={title:"CIS 1.5 Benchmark - Self-Assessment Guide - Rancher v2.5"},i=void 0,s={unversionedId:"reference-guides/rancher-security/rancher-v2.5-hardening-guides/self-assessment-guide-with-cis-v1.5-benchmark",id:"version-2.5/reference-guides/rancher-security/rancher-v2.5-hardening-guides/self-assessment-guide-with-cis-v1.5-benchmark",title:"CIS 1.5 Benchmark - Self-Assessment Guide - Rancher v2.5",description:"CIS v1.5 Kubernetes Benchmark - Rancher v2.5 with Kubernetes v1.15",source:"@site/versioned_docs/version-2.5/reference-guides/rancher-security/rancher-v2.5-hardening-guides/self-assessment-guide-with-cis-v1.5-benchmark.md",sourceDirName:"reference-guides/rancher-security/rancher-v2.5-hardening-guides",slug:"/reference-guides/rancher-security/rancher-v2.5-hardening-guides/self-assessment-guide-with-cis-v1.5-benchmark",permalink:"/v2.5/reference-guides/rancher-security/rancher-v2.5-hardening-guides/self-assessment-guide-with-cis-v1.5-benchmark",draft:!1,editUrl:"https://github.com/rancher/rancher-docs/edit/main/versioned_docs/version-2.5/reference-guides/rancher-security/rancher-v2.5-hardening-guides/self-assessment-guide-with-cis-v1.5-benchmark.md",tags:[],version:"2.5",lastUpdatedAt:1663953084,formattedLastUpdatedAt:"Sep 23, 2022",frontMatter:{title:"CIS 1.5 Benchmark - Self-Assessment Guide - Rancher v2.5"}},l={},p=[{value:"CIS v1.5 Kubernetes Benchmark - Rancher v2.5 with Kubernetes v1.15",id:"cis-v15-kubernetes-benchmark---rancher-v25-with-kubernetes-v115",level:3},{value:"Overview",id:"overview",level:4},{value:"Testing controls methodology",id:"testing-controls-methodology",level:4},{value:"Controls",id:"controls",level:3},{value:"1 Master Node Security Configuration",id:"1-master-node-security-configuration",level:2},{value:"1.1 Master Node Configuration Files",id:"11-master-node-configuration-files",level:3},{value:"1.1.1 Ensure that the API server pod specification file permissions are set to <code>644</code> or more restrictive (Scored)",id:"111-ensure-that-the-api-server-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.2 Ensure that the API server pod specification file ownership is set to <code>root:root</code> (Scored)",id:"112-ensure-that-the-api-server-pod-specification-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.3 Ensure that the controller manager pod specification file permissions are set to <code>644</code> or more restrictive (Scored)",id:"113-ensure-that-the-controller-manager-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.4 Ensure that the controller manager pod specification file ownership is set to <code>root:root</code> (Scored)",id:"114-ensure-that-the-controller-manager-pod-specification-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.5 Ensure that the scheduler pod specification file permissions are set to <code>644</code> or more restrictive (Scored)",id:"115-ensure-that-the-scheduler-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.6 Ensure that the scheduler pod specification file ownership is set to <code>root:root</code> (Scored)",id:"116-ensure-that-the-scheduler-pod-specification-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.7 Ensure that the etcd pod specification file permissions are set to <code>644</code> or more restrictive (Scored)",id:"117-ensure-that-the-etcd-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.8 Ensure that the etcd pod specification file ownership is set to <code>root:root</code> (Scored)",id:"118-ensure-that-the-etcd-pod-specification-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.11 Ensure that the etcd data directory permissions are set to <code>700</code> or more restrictive (Scored)",id:"1111-ensure-that-the-etcd-data-directory-permissions-are-set-to-700-or-more-restrictive-scored",level:4},{value:"1.1.12 Ensure that the etcd data directory ownership is set to <code>etcd:etcd</code> (Scored)",id:"1112-ensure-that-the-etcd-data-directory-ownership-is-set-to-etcdetcd-scored",level:4},{value:"1.1.13 Ensure that the <code>admin.conf</code> file permissions are set to <code>644</code> or more restrictive (Scored)",id:"1113-ensure-that-the-adminconf-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.14 Ensure that the admin.conf file ownership is set to <code>root:root</code> (Scored)",id:"1114-ensure-that-the-adminconf-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.15 Ensure that the <code>scheduler.conf</code> file permissions are set to <code>644</code> or more restrictive (Scored)",id:"1115-ensure-that-the-schedulerconf-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.16 Ensure that the <code>scheduler.conf</code> file ownership is set to <code>root:root</code> (Scored)",id:"1116-ensure-that-the-schedulerconf-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.17 Ensure that the <code>controller-manager.conf</code> file permissions are set to <code>644</code> or more restrictive (Scored)",id:"1117-ensure-that-the-controller-managerconf-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.18 Ensure that the <code>controller-manager.conf</code> file ownership is set to <code>root:root</code> (Scored)",id:"1118-ensure-that-the-controller-managerconf-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.19 Ensure that the Kubernetes PKI directory and file ownership is set to <code>root:root</code> (Scored)",id:"1119-ensure-that-the-kubernetes-pki-directory-and-file-ownership-is-set-to-rootroot-scored",level:4},{value:"1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to <code>644</code> or more restrictive (Scored)",id:"1120-ensure-that-the-kubernetes-pki-certificate-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"1.1.21 Ensure that the Kubernetes PKI key file permissions are set to <code>600</code> (Scored)",id:"1121-ensure-that-the-kubernetes-pki-key-file-permissions-are-set-to-600-scored",level:4},{value:"1.2 API Server",id:"12-api-server",level:3},{value:"1.2.2 Ensure that the <code>--basic-auth-file</code> argument is not set (Scored)",id:"122-ensure-that-the---basic-auth-file-argument-is-not-set-scored",level:4},{value:"1.2.3 Ensure that the <code>--token-auth-file</code> parameter is not set (Scored)",id:"123-ensure-that-the---token-auth-file-parameter-is-not-set-scored",level:4},{value:"1.2.4 Ensure that the <code>--kubelet-https</code> argument is set to true (Scored)",id:"124-ensure-that-the---kubelet-https-argument-is-set-to-true-scored",level:4},{value:"1.2.5 Ensure that the <code>--kubelet-client-certificate</code> and <code>--kubelet-client-key</code> arguments are set as appropriate (Scored)",id:"125-ensure-that-the---kubelet-client-certificate-and---kubelet-client-key-arguments-are-set-as-appropriate-scored",level:4},{value:"1.2.6 Ensure that the <code>--kubelet-certificate-authority</code> argument is set as appropriate (Scored)",id:"126-ensure-that-the---kubelet-certificate-authority-argument-is-set-as-appropriate-scored",level:4},{value:"1.2.7 Ensure that the <code>--authorization-mode</code> argument is not set to <code>AlwaysAllow</code> (Scored)",id:"127-ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-scored",level:4},{value:"1.2.8 Ensure that the <code>--authorization-mode</code> argument includes <code>Node</code> (Scored)",id:"128-ensure-that-the---authorization-mode-argument-includes-node-scored",level:4},{value:"1.2.9 Ensure that the <code>--authorization-mode</code> argument includes <code>RBAC</code> (Scored)",id:"129-ensure-that-the---authorization-mode-argument-includes-rbac-scored",level:4},{value:"1.2.11 Ensure that the admission control plugin <code>AlwaysAdmit</code> is not set (Scored)",id:"1211-ensure-that-the-admission-control-plugin-alwaysadmit-is-not-set-scored",level:4},{value:"1.2.14 Ensure that the admission control plugin <code>ServiceAccount</code> is set (Scored)",id:"1214-ensure-that-the-admission-control-plugin-serviceaccount-is-set-scored",level:4},{value:"1.2.15 Ensure that the admission control plugin <code>NamespaceLifecycle</code> is set (Scored)",id:"1215-ensure-that-the-admission-control-plugin-namespacelifecycle-is-set-scored",level:4},{value:"1.2.16 Ensure that the admission control plugin <code>PodSecurityPolicy</code> is set (Scored)",id:"1216-ensure-that-the-admission-control-plugin-podsecuritypolicy-is-set-scored",level:4},{value:"1.2.17 Ensure that the admission control plugin <code>NodeRestriction</code> is set (Scored)",id:"1217-ensure-that-the-admission-control-plugin-noderestriction-is-set-scored",level:4},{value:"1.2.18 Ensure that the <code>--insecure-bind-address</code> argument is not set (Scored)",id:"1218-ensure-that-the---insecure-bind-address-argument-is-not-set-scored",level:4},{value:"1.2.19 Ensure that the <code>--insecure-port</code> argument is set to <code>0</code> (Scored)",id:"1219-ensure-that-the---insecure-port-argument-is-set-to-0-scored",level:4},{value:"1.2.20 Ensure that the <code>--secure-port</code> argument is not set to <code>0</code> (Scored)",id:"1220-ensure-that-the---secure-port-argument-is-not-set-to-0-scored",level:4},{value:"1.2.21 Ensure that the <code>--profiling</code> argument is set to <code>false</code> (Scored)",id:"1221-ensure-that-the---profiling-argument-is-set-to-false-scored",level:4},{value:"1.2.22 Ensure that the <code>--audit-log-path</code> argument is set (Scored)",id:"1222-ensure-that-the---audit-log-path-argument-is-set-scored",level:4},{value:"1.2.23 Ensure that the <code>--audit-log-maxage</code> argument is set to <code>30</code> or as appropriate (Scored)",id:"1223-ensure-that-the---audit-log-maxage-argument-is-set-to-30-or-as-appropriate-scored",level:4},{value:"1.2.24 Ensure that the <code>--audit-log-maxbackup</code> argument is set to <code>10</code> or as appropriate (Scored)",id:"1224-ensure-that-the---audit-log-maxbackup-argument-is-set-to-10-or-as-appropriate-scored",level:4},{value:"1.2.25 Ensure that the <code>--audit-log-maxsize</code> argument is set to <code>100</code> or as appropriate (Scored)",id:"1225-ensure-that-the---audit-log-maxsize-argument-is-set-to-100-or-as-appropriate-scored",level:4},{value:"1.2.26 Ensure that the <code>--request-timeout</code> argument is set as appropriate (Scored)",id:"1226-ensure-that-the---request-timeout-argument-is-set-as-appropriate-scored",level:4},{value:"1.2.27 Ensure that the <code>--service-account-lookup</code> argument is set to <code>true</code> (Scored)",id:"1227-ensure-that-the---service-account-lookup-argument-is-set-to-true-scored",level:4},{value:"1.2.28 Ensure that the <code>--service-account-key-file</code> argument is set as appropriate (Scored)",id:"1228-ensure-that-the---service-account-key-file-argument-is-set-as-appropriate-scored",level:4},{value:"1.2.29 Ensure that the <code>--etcd-certfile</code> and <code>--etcd-keyfile</code> arguments are set as appropriate (Scored)",id:"1229-ensure-that-the---etcd-certfile-and---etcd-keyfile-arguments-are-set-as-appropriate-scored",level:4},{value:"1.2.30 Ensure that the <code>--tls-cert-file</code> and <code>--tls-private-key-file</code> arguments are set as appropriate (Scored)",id:"1230-ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-scored",level:4},{value:"1.2.31 Ensure that the <code>--client-ca-file</code> argument is set as appropriate (Scored)",id:"1231-ensure-that-the---client-ca-file-argument-is-set-as-appropriate-scored",level:4},{value:"1.2.32 Ensure that the <code>--etcd-cafile</code> argument is set as appropriate (Scored)",id:"1232-ensure-that-the---etcd-cafile-argument-is-set-as-appropriate-scored",level:4},{value:"1.2.33 Ensure that the <code>--encryption-provider-config</code> argument is set as appropriate (Scored)",id:"1233-ensure-that-the---encryption-provider-config-argument-is-set-as-appropriate-scored",level:4},{value:"1.2.34 Ensure that encryption providers are appropriately configured (Scored)",id:"1234-ensure-that-encryption-providers-are-appropriately-configured-scored",level:4},{value:"1.3 Controller Manager",id:"13-controller-manager",level:3},{value:"1.3.1 Ensure that the <code>--terminated-pod-gc-threshold</code> argument is set as appropriate (Scored)",id:"131-ensure-that-the---terminated-pod-gc-threshold-argument-is-set-as-appropriate-scored",level:4},{value:"1.3.2 Ensure that the <code>--profiling</code> argument is set to false (Scored)",id:"132-ensure-that-the---profiling-argument-is-set-to-false-scored",level:4},{value:"1.3.3 Ensure that the <code>--use-service-account-credentials</code> argument is set to <code>true</code> (Scored)",id:"133-ensure-that-the---use-service-account-credentials-argument-is-set-to-true-scored",level:4},{value:"1.3.4 Ensure that the <code>--service-account-private-key-file</code> argument is set as appropriate (Scored)",id:"134-ensure-that-the---service-account-private-key-file-argument-is-set-as-appropriate-scored",level:4},{value:"1.3.5 Ensure that the <code>--root-ca-file</code> argument is set as appropriate (Scored)",id:"135-ensure-that-the---root-ca-file-argument-is-set-as-appropriate-scored",level:4},{value:"1.3.6 Ensure that the <code>RotateKubeletServerCertificate</code> argument is set to <code>true</code> (Scored)",id:"136-ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-scored",level:4},{value:"1.3.7 Ensure that the <code>--bind-address argument</code> is set to <code>127.0.0.1</code> (Scored)",id:"137-ensure-that-the---bind-address-argument-is-set-to-127001-scored",level:4},{value:"1.4 Scheduler",id:"14-scheduler",level:3},{value:"1.4.1 Ensure that the <code>--profiling</code> argument is set to <code>false</code> (Scored)",id:"141-ensure-that-the---profiling-argument-is-set-to-false-scored",level:4},{value:"1.4.2 Ensure that the <code>--bind-address</code> argument is set to <code>127.0.0.1</code> (Scored)",id:"142-ensure-that-the---bind-address-argument-is-set-to-127001-scored",level:4},{value:"2 Etcd Node Configuration",id:"2-etcd-node-configuration",level:2},{value:"2 Etcd Node Configuration Files",id:"2-etcd-node-configuration-files",level:3},{value:"2.1 Ensure that the <code>--cert-file</code> and <code>--key-file</code> arguments are set as appropriate (Scored)",id:"21-ensure-that-the---cert-file-and---key-file-arguments-are-set-as-appropriate-scored",level:4},{value:"2.2 Ensure that the <code>--client-cert-auth</code> argument is set to <code>true</code> (Scored)",id:"22-ensure-that-the---client-cert-auth-argument-is-set-to-true-scored",level:4},{value:"2.3 Ensure that the <code>--auto-tls</code> argument is not set to <code>true</code> (Scored)",id:"23-ensure-that-the---auto-tls-argument-is-not-set-to-true-scored",level:4},{value:"2.4 Ensure that the <code>--peer-cert-file</code> and <code>--peer-key-file</code> arguments are set as appropriate (Scored)",id:"24-ensure-that-the---peer-cert-file-and---peer-key-file-arguments-are-set-as-appropriate-scored",level:4},{value:"2.5 Ensure that the <code>--peer-client-cert-auth</code> argument is set to <code>true</code> (Scored)",id:"25-ensure-that-the---peer-client-cert-auth-argument-is-set-to-true-scored",level:4},{value:"2.6 Ensure that the <code>--peer-auto-tls</code> argument is not set to <code>true</code> (Scored)",id:"26-ensure-that-the---peer-auto-tls-argument-is-not-set-to-true-scored",level:4},{value:"3 Control Plane Configuration",id:"3-control-plane-configuration",level:2},{value:"3.2 Logging",id:"32-logging",level:3},{value:"3.2.1 Ensure that a minimal audit policy is created (Scored)",id:"321-ensure-that-a-minimal-audit-policy-is-created-scored",level:4},{value:"4 Worker Node Security Configuration",id:"4-worker-node-security-configuration",level:2},{value:"4.1 Worker Node Configuration Files",id:"41-worker-node-configuration-files",level:3},{value:"4.1.1 Ensure that the kubelet service file permissions are set to <code>644</code> or more restrictive (Scored)",id:"411-ensure-that-the-kubelet-service-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"4.1.2 Ensure that the kubelet service file ownership is set to <code>root:root</code> (Scored)",id:"412-ensure-that-the-kubelet-service-file-ownership-is-set-to-rootroot-scored",level:4},{value:"4.1.3 Ensure that the proxy kubeconfig file permissions are set to <code>644</code> or more restrictive (Scored)",id:"413-ensure-that-the-proxy-kubeconfig-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"4.1.4 Ensure that the proxy kubeconfig file ownership is set to <code>root:root</code> (Scored)",id:"414-ensure-that-the-proxy-kubeconfig-file-ownership-is-set-to-rootroot-scored",level:4},{value:"4.1.5 Ensure that the kubelet.conf file permissions are set to <code>644</code> or more restrictive (Scored)",id:"415-ensure-that-the-kubeletconf-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"4.1.6 Ensure that the kubelet.conf file ownership is set to <code>root:root</code> (Scored)",id:"416-ensure-that-the-kubeletconf-file-ownership-is-set-to-rootroot-scored",level:4},{value:"4.1.7 Ensure that the certificate authorities file permissions are set to <code>644</code> or more restrictive (Scored)",id:"417-ensure-that-the-certificate-authorities-file-permissions-are-set-to-644-or-more-restrictive-scored",level:4},{value:"4.1.8 Ensure that the client certificate authorities file ownership is set to <code>root:root</code> (Scored)",id:"418-ensure-that-the-client-certificate-authorities-file-ownership-is-set-to-rootroot-scored",level:4},{value:"4.1.9 Ensure that the kubelet configuration file has permissions set to <code>644</code> or more restrictive (Scored)",id:"419-ensure-that-the-kubelet-configuration-file-has-permissions-set-to-644-or-more-restrictive-scored",level:4},{value:"4.1.10 Ensure that the kubelet configuration file ownership is set to <code>root:root</code> (Scored)",id:"4110-ensure-that-the-kubelet-configuration-file-ownership-is-set-to-rootroot-scored",level:4},{value:"4.2 Kubelet",id:"42-kubelet",level:3},{value:"4.2.1 Ensure that the <code>--anonymous-auth argument</code> is set to false (Scored)",id:"421-ensure-that-the---anonymous-auth-argument-is-set-to-false-scored",level:4},{value:"4.2.2 Ensure that the <code>--authorization-mode</code> argument is not set to <code>AlwaysAllow</code> (Scored)",id:"422-ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-scored",level:4},{value:"4.2.3 Ensure that the <code>--client-ca-file</code> argument is set as appropriate (Scored)",id:"423-ensure-that-the---client-ca-file-argument-is-set-as-appropriate-scored",level:4},{value:"4.2.4 Ensure that the <code>--read-only-port</code> argument is set to <code>0</code> (Scored)",id:"424-ensure-that-the---read-only-port-argument-is-set-to-0-scored",level:4},{value:"4.2.5 Ensure that the <code>--streaming-connection-idle-timeout</code> argument is not set to <code>0</code> (Scored)",id:"425-ensure-that-the---streaming-connection-idle-timeout-argument-is-not-set-to-0-scored",level:4},{value:"4.2.6 Ensure that the <code>--protect-kernel-defaults</code> argument is set to <code>true</code> (Scored)",id:"426-ensure-that-the---protect-kernel-defaults-argument-is-set-to-true-scored",level:4},{value:"4.2.7 Ensure that the <code>--make-iptables-util-chains</code> argument is set to <code>true</code> (Scored)",id:"427-ensure-that-the---make-iptables-util-chains-argument-is-set-to-true-scored",level:4},{value:"4.2.10 Ensure that the <code>--tls-cert-file</code> and <code>--tls-private-key-file</code> arguments are set as appropriate (Scored)",id:"4210-ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-scored",level:4},{value:"4.2.11 Ensure that the <code>--rotate-certificates</code> argument is not set to <code>false</code> (Scored)",id:"4211-ensure-that-the---rotate-certificates-argument-is-not-set-to-false-scored",level:4},{value:"4.2.12 Ensure that the <code>RotateKubeletServerCertificate</code> argument is set to <code>true</code> (Scored)",id:"4212-ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-scored",level:4},{value:"5 Kubernetes Policies",id:"5-kubernetes-policies",level:2},{value:"5.1 RBAC and Service Accounts",id:"51-rbac-and-service-accounts",level:3},{value:"5.1.5 Ensure that default service accounts are not actively used. (Scored)",id:"515-ensure-that-default-service-accounts-are-not-actively-used-scored",level:4},{value:"5.2 Pod Security Policies",id:"52-pod-security-policies",level:3},{value:"5.2.2 Minimize the admission of containers wishing to share the host process ID namespace (Scored)",id:"522-minimize-the-admission-of-containers-wishing-to-share-the-host-process-id-namespace-scored",level:4},{value:"5.2.3 Minimize the admission of containers wishing to share the host IPC namespace (Scored)",id:"523-minimize-the-admission-of-containers-wishing-to-share-the-host-ipc-namespace-scored",level:4},{value:"5.2.4 Minimize the admission of containers wishing to share the host network namespace (Scored)",id:"524-minimize-the-admission-of-containers-wishing-to-share-the-host-network-namespace-scored",level:4},{value:"5.2.5 Minimize the admission of containers with <code>allowPrivilegeEscalation</code> (Scored)",id:"525-minimize-the-admission-of-containers-with-allowprivilegeescalation-scored",level:4},{value:"5.3 Network Policies and CNI",id:"53-network-policies-and-cni",level:3},{value:"5.3.2 Ensure that all Namespaces have Network Policies defined (Scored)",id:"532-ensure-that-all-namespaces-have-network-policies-defined-scored",level:4},{value:"5.6 General Policies",id:"56-general-policies",level:3},{value:"5.6.4 The default namespace should not be used (Scored)",id:"564-the-default-namespace-should-not-be-used-scored",level:4}],u={toc:p};function c(e){let{components:t,...n}=e;return(0,a.kt)("wrapper",(0,r.Z)({},u,n,{components:t,mdxType:"MDXLayout"}),(0,a.kt)("h3",{id:"cis-v15-kubernetes-benchmark---rancher-v25-with-kubernetes-v115"},"CIS v1.5 Kubernetes Benchmark - Rancher v2.5 with Kubernetes v1.15"),(0,a.kt)("p",null,(0,a.kt)("a",{parentName:"p",href:"https://releases.rancher.com/documents/security/2.5/Rancher_1.5_Benchmark_Assessment.pdf"},"Click here to download a PDF version of this document")),(0,a.kt)("h4",{id:"overview"},"Overview"),(0,a.kt)("p",null,"This document is a companion to the Rancher v2.5 security hardening guide. The hardening guide provides prescriptive guidance for hardening a production installation of Rancher, and this benchmark guide is meant to help you evaluate the level of security of the hardened cluster against each control in the benchmark."),(0,a.kt)("p",null,"This guide corresponds to specific versions of the hardening guide, Rancher, CIS Benchmark, and Kubernetes:"),(0,a.kt)("table",null,(0,a.kt)("thead",{parentName:"table"},(0,a.kt)("tr",{parentName:"thead"},(0,a.kt)("th",{parentName:"tr",align:null},"Hardening Guide Version"),(0,a.kt)("th",{parentName:"tr",align:null},"Rancher Version"),(0,a.kt)("th",{parentName:"tr",align:null},"CIS Benchmark Version"),(0,a.kt)("th",{parentName:"tr",align:null},"Kubernetes Version"))),(0,a.kt)("tbody",{parentName:"table"},(0,a.kt)("tr",{parentName:"tbody"},(0,a.kt)("td",{parentName:"tr",align:null},"Hardening Guide with CIS 1.5 Benchmark"),(0,a.kt)("td",{parentName:"tr",align:null},"Rancher v2.5"),(0,a.kt)("td",{parentName:"tr",align:null},"CIS v1.5"),(0,a.kt)("td",{parentName:"tr",align:null},"Kubernetes v1.15")))),(0,a.kt)("p",null,"Because Rancher and RKE install Kubernetes services as Docker containers, many of the control verification checks in the CIS Kubernetes Benchmark don't apply and will have a result of ",(0,a.kt)("inlineCode",{parentName:"p"},"Not Applicable"),". This guide will walk through the various controls and provide updated example commands to audit compliance in Rancher-created clusters."),(0,a.kt)("p",null,"This document is to be used by Rancher operators, security teams, auditors and decision makers."),(0,a.kt)("p",null,"For more detail about each audit, including rationales and remediations for failing tests, you can refer to the corresponding section of the CIS Kubernetes Benchmark v1.5. You can download the benchmark after logging in to ",(0,a.kt)("a",{parentName:"p",href:"https://www.cisecurity.org/benchmark/kubernetes/"},"CISecurity.org"),"."),(0,a.kt)("h4",{id:"testing-controls-methodology"},"Testing controls methodology"),(0,a.kt)("p",null,"Rancher and RKE install Kubernetes services via Docker containers. Configuration is defined by arguments passed to the container at the time of initialization, not via configuration files."),(0,a.kt)("p",null,"Where control audits differ from the original CIS benchmark, the audit commands specific to Rancher Labs are provided for testing.\nWhen performing the tests, you will need access to the Docker command line on the hosts of all three RKE roles. The commands also make use of the the ",(0,a.kt)("a",{parentName:"p",href:"https://stedolan.github.io/jq/"},"jq")," and ",(0,a.kt)("a",{parentName:"p",href:"https://kubernetes.io/docs/tasks/tools/install-kubectl/"},"kubectl")," (with valid config) tools to and are required in the testing and evaluation of test results."),(0,a.kt)("blockquote",null,(0,a.kt)("p",{parentName:"blockquote"},"NOTE: only scored tests are covered in this guide.")),(0,a.kt)("h3",{id:"controls"},"Controls"),(0,a.kt)("hr",null),(0,a.kt)("h2",{id:"1-master-node-security-configuration"},"1 Master Node Security Configuration"),(0,a.kt)("h3",{id:"11-master-node-configuration-files"},"1.1 Master Node Configuration Files"),(0,a.kt)("h4",{id:"111-ensure-that-the-api-server-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.1 Ensure that the API server pod specification file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the API server. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"112-ensure-that-the-api-server-pod-specification-file-ownership-is-set-to-rootroot-scored"},"1.1.2 Ensure that the API server pod specification file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the API server. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"113-ensure-that-the-controller-manager-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.3 Ensure that the controller manager pod specification file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the controller manager. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"114-ensure-that-the-controller-manager-pod-specification-file-ownership-is-set-to-rootroot-scored"},"1.1.4 Ensure that the controller manager pod specification file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the controller manager. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"115-ensure-that-the-scheduler-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.5 Ensure that the scheduler pod specification file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the scheduler. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"116-ensure-that-the-scheduler-pod-specification-file-ownership-is-set-to-rootroot-scored"},"1.1.6 Ensure that the scheduler pod specification file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the scheduler. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"117-ensure-that-the-etcd-pod-specification-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.7 Ensure that the etcd pod specification file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for etcd. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"118-ensure-that-the-etcd-pod-specification-file-ownership-is-set-to-rootroot-scored"},"1.1.8 Ensure that the etcd pod specification file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for etcd. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"1111-ensure-that-the-etcd-data-directory-permissions-are-set-to-700-or-more-restrictive-scored"},"1.1.11 Ensure that the etcd data directory permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"700")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nOn the etcd server node, get the etcd data directory, passed as an argument ",(0,a.kt)("inlineCode",{parentName:"p"},"--data-dir"),",\nfrom the below command:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"ps -ef | grep etcd\n")),(0,a.kt)("p",null,"Run the below command (based on the etcd data directory found above). For example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chmod 700 /var/lib/etcd\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 1.1.11.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"#!/bin/bash -e\n\netcd_bin=${1}\n\ntest_dir=$(ps -ef | grep ${etcd_bin} | grep -- --data-dir | sed 's%.*data-dir[= ]\\([^ ]*\\).*%\\1%')\n\ndocker inspect etcd | jq -r '.[].HostConfig.Binds[]' | grep \"${test_dir}\" | cut -d \":\" -f 1 | xargs stat -c %a\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./1.1.11.sh etcd\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'700' is equal to '700'\n")),(0,a.kt)("h4",{id:"1112-ensure-that-the-etcd-data-directory-ownership-is-set-to-etcdetcd-scored"},"1.1.12 Ensure that the etcd data directory ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"etcd:etcd")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nOn the etcd server node, get the etcd data directory, passed as an argument ",(0,a.kt)("inlineCode",{parentName:"p"},"--data-dir"),",\nfrom the below command:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"ps -ef | grep etcd\n")),(0,a.kt)("p",null,"Run the below command (based on the etcd data directory found above).\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chown etcd:etcd /var/lib/etcd\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 1.1.12.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"#!/bin/bash -e\n\netcd_bin=${1}\n\ntest_dir=$(ps -ef | grep ${etcd_bin} | grep -- --data-dir | sed 's%.*data-dir[= ]\\([^ ]*\\).*%\\1%')\n\ndocker inspect etcd | jq -r '.[].HostConfig.Binds[]' | grep \"${test_dir}\" | cut -d \":\" -f 1 | xargs stat -c %U:%G\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./1.1.12.sh etcd\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'etcd:etcd' is present\n")),(0,a.kt)("h4",{id:"1113-ensure-that-the-adminconf-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.13 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"admin.conf")," file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE does not store the kubernetes default kubeconfig credentials file on the nodes. It\u2019s presented to user where RKE is run.\nWe recommend that this ",(0,a.kt)("inlineCode",{parentName:"p"},"kube_config_cluster.yml")," file be kept in secure store."),(0,a.kt)("h4",{id:"1114-ensure-that-the-adminconf-file-ownership-is-set-to-rootroot-scored"},"1.1.14 Ensure that the admin.conf file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE does not store the kubernetes default kubeconfig credentials file on the nodes. It\u2019s presented to user where RKE is run.\nWe recommend that this ",(0,a.kt)("inlineCode",{parentName:"p"},"kube_config_cluster.yml")," file be kept in secure store."),(0,a.kt)("h4",{id:"1115-ensure-that-the-schedulerconf-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.15 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"scheduler.conf")," file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the scheduler. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"1116-ensure-that-the-schedulerconf-file-ownership-is-set-to-rootroot-scored"},"1.1.16 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"scheduler.conf")," file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the scheduler. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"1117-ensure-that-the-controller-managerconf-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.17 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"controller-manager.conf")," file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the controller manager. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"1118-ensure-that-the-controller-managerconf-file-ownership-is-set-to-rootroot-scored"},"1.1.18 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"controller-manager.conf")," file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the controller manager. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"1119-ensure-that-the-kubernetes-pki-directory-and-file-ownership-is-set-to-rootroot-scored"},"1.1.19 Ensure that the Kubernetes PKI directory and file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the master node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chown -R root:root /etc/kubernetes/ssl\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"stat -c %U:%G /etc/kubernetes/ssl\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'root:root' is present\n")),(0,a.kt)("h4",{id:"1120-ensure-that-the-kubernetes-pki-certificate-file-permissions-are-set-to-644-or-more-restrictive-scored"},"1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the master node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chmod -R 644 /etc/kubernetes/ssl\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," check_files_permissions.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},'#!/usr/bin/env bash\n\n# This script is used to ensure the file permissions are set to 644 or\n# more restrictive for all files in a given directory or a wildcard\n# selection of files\n#\n# inputs:\n# $1 = /full/path/to/directory or /path/to/fileswithpattern\n# ex: !(*key).pem\n#\n# $2 (optional) = permission (ex: 600)\n#\n# outputs:\n# true/false\n\n# Turn on "extended glob" for use of \'!\' in wildcard\nshopt -s extglob\n\n# Turn off history to avoid surprises when using \'!\'\nset -H\n\nUSER_INPUT=$1\n\nif [[ "${USER_INPUT}" == "" ]]; then\n echo "false"\n exit\nfi\n\n\nif [[ -d ${USER_INPUT} ]]; then\n PATTERN="${USER_INPUT}/*"\nelse\n PATTERN="${USER_INPUT}"\nfi\n\nPERMISSION=""\nif [[ "$2" != "" ]]; then\n PERMISSION=$2\nfi\n\nFILES_PERMISSIONS=$(stat -c %n\\ %a ${PATTERN})\n\nwhile read -r fileInfo; do\n p=$(echo ${fileInfo} | cut -d\' \' -f2)\n\n if [[ "${PERMISSION}" != "" ]]; then\n if [[ "$p" != "${PERMISSION}" ]]; then\n echo "false"\n exit\n fi\n else\n if [[ "$p" != "644" && "$p" != "640" && "$p" != "600" ]]; then\n echo "false"\n exit\n fi\n fi\ndone <<< "${FILES_PERMISSIONS}"\n\n\necho "true"\nexit\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./check_files_permissions.sh '/etc/kubernetes/ssl/*.pem'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is present\n")),(0,a.kt)("h4",{id:"1121-ensure-that-the-kubernetes-pki-key-file-permissions-are-set-to-600-scored"},"1.1.21 Ensure that the Kubernetes PKI key file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"600")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the master node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chmod -R 600 /etc/kubernetes/ssl/certs/serverca\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 1.1.21.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},'#!/bin/bash -e\ncheck_dir=${1:-/etc/kubernetes/ssl}\n\nfor file in $(find ${check_dir} -name "*key.pem"); do\n file_permission=$(stat -c %a ${file})\n if [[ "${file_permission}" == "600" ]]; then\n continue\n else\n echo "FAIL: ${file} ${file_permission}"\n exit 1\n fi\ndone\n\necho "pass"\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./1.1.21.sh /etc/kubernetes/ssl\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'pass' is present\n")),(0,a.kt)("h3",{id:"12-api-server"},"1.2 API Server"),(0,a.kt)("h4",{id:"122-ensure-that-the---basic-auth-file-argument-is-not-set-scored"},"1.2.2 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--basic-auth-file")," argument is not set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the documentation and configure alternate mechanisms for authentication. Then,\nedit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--basic-auth-file=<filename>")," parameter."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--basic-auth-file' is not present\n")),(0,a.kt)("h4",{id:"123-ensure-that-the---token-auth-file-parameter-is-not-set-scored"},"1.2.3 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--token-auth-file")," parameter is not set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the documentation and configure alternate mechanisms for authentication. Then,\nedit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--token-auth-file=<filename>")," parameter."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--token-auth-file' is not present\n")),(0,a.kt)("h4",{id:"124-ensure-that-the---kubelet-https-argument-is-set-to-true-scored"},"1.2.4 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--kubelet-https")," argument is set to true (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml\non the master node and remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--kubelet-https")," parameter."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--kubelet-https' is present OR '--kubelet-https' is not present\n")),(0,a.kt)("h4",{id:"125-ensure-that-the---kubelet-client-certificate-and---kubelet-client-key-arguments-are-set-as-appropriate-scored"},"1.2.5 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--kubelet-client-certificate")," and ",(0,a.kt)("inlineCode",{parentName:"h4"},"--kubelet-client-key")," arguments are set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and set up the TLS connection between the\napiserver and kubelets. Then, edit API server pod specification file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml")," on the master node and set the\nkubelet client certificate and key parameters as below."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--kubelet-client-certificate=<path/to/client-certificate-file>\n--kubelet-client-key=<path/to/client-key-file>\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--kubelet-client-certificate' is present AND '--kubelet-client-key' is present\n")),(0,a.kt)("h4",{id:"126-ensure-that-the---kubelet-certificate-authority-argument-is-set-as-appropriate-scored"},"1.2.6 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--kubelet-certificate-authority")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and setup the TLS connection between\nthe apiserver and kubelets. Then, edit the API server pod specification file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml")," on the master node and set the\n",(0,a.kt)("inlineCode",{parentName:"p"},"--kubelet-certificate-authority")," parameter to the path to the cert file for the certificate authority.\n",(0,a.kt)("inlineCode",{parentName:"p"},"--kubelet-certificate-authority=<ca-string>")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--kubelet-certificate-authority' is present\n")),(0,a.kt)("h4",{id:"127-ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-scored"},"1.2.7 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--authorization-mode")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"AlwaysAllow")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--authorization-mode")," parameter to values other than ",(0,a.kt)("inlineCode",{parentName:"p"},"AlwaysAllow"),".\nOne such example could be as below."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--authorization-mode=RBAC\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'Node,RBAC' not have 'AlwaysAllow'\n")),(0,a.kt)("h4",{id:"128-ensure-that-the---authorization-mode-argument-includes-node-scored"},"1.2.8 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--authorization-mode")," argument includes ",(0,a.kt)("inlineCode",{parentName:"h4"},"Node")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--authorization-mode")," parameter to a value that includes ",(0,a.kt)("inlineCode",{parentName:"p"},"Node"),"."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--authorization-mode=Node,RBAC\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'Node,RBAC' has 'Node'\n")),(0,a.kt)("h4",{id:"129-ensure-that-the---authorization-mode-argument-includes-rbac-scored"},"1.2.9 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--authorization-mode")," argument includes ",(0,a.kt)("inlineCode",{parentName:"h4"},"RBAC")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--authorization-mode")," parameter to a value that includes RBAC,\nfor example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--authorization-mode=Node,RBAC\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'Node,RBAC' has 'RBAC'\n")),(0,a.kt)("h4",{id:"1211-ensure-that-the-admission-control-plugin-alwaysadmit-is-not-set-scored"},"1.2.11 Ensure that the admission control plugin ",(0,a.kt)("inlineCode",{parentName:"h4"},"AlwaysAdmit")," is not set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and either remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--enable-admission-plugins")," parameter, or set it to a\nvalue that does not include ",(0,a.kt)("inlineCode",{parentName:"p"},"AlwaysAdmit"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' not have 'AlwaysAdmit' OR '--enable-admission-plugins' is not present\n")),(0,a.kt)("h4",{id:"1214-ensure-that-the-admission-control-plugin-serviceaccount-is-set-scored"},"1.2.14 Ensure that the admission control plugin ",(0,a.kt)("inlineCode",{parentName:"h4"},"ServiceAccount")," is set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the documentation and create ServiceAccount objects as per your environment.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and ensure that the ",(0,a.kt)("inlineCode",{parentName:"p"},"--disable-admission-plugins")," parameter is set to a\nvalue that does not include ",(0,a.kt)("inlineCode",{parentName:"p"},"ServiceAccount"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' has 'ServiceAccount' OR '--enable-admission-plugins' is not present\n")),(0,a.kt)("h4",{id:"1215-ensure-that-the-admission-control-plugin-namespacelifecycle-is-set-scored"},"1.2.15 Ensure that the admission control plugin ",(0,a.kt)("inlineCode",{parentName:"h4"},"NamespaceLifecycle")," is set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--disable-admission-plugins")," parameter to\nensure it does not include ",(0,a.kt)("inlineCode",{parentName:"p"},"NamespaceLifecycle"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--disable-admission-plugins' is present OR '--disable-admission-plugins' is not present\n")),(0,a.kt)("h4",{id:"1216-ensure-that-the-admission-control-plugin-podsecuritypolicy-is-set-scored"},"1.2.16 Ensure that the admission control plugin ",(0,a.kt)("inlineCode",{parentName:"h4"},"PodSecurityPolicy")," is set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the documentation and create Pod Security Policy objects as per your environment.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--enable-admission-plugins")," parameter to a\nvalue that includes ",(0,a.kt)("inlineCode",{parentName:"p"},"PodSecurityPolicy"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--enable-admission-plugins=...,PodSecurityPolicy,...\n")),(0,a.kt)("p",null,"Then restart the API Server."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' has 'PodSecurityPolicy'\n")),(0,a.kt)("h4",{id:"1217-ensure-that-the-admission-control-plugin-noderestriction-is-set-scored"},"1.2.17 Ensure that the admission control plugin ",(0,a.kt)("inlineCode",{parentName:"h4"},"NodeRestriction")," is set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and configure ",(0,a.kt)("inlineCode",{parentName:"p"},"NodeRestriction")," plug-in on kubelets.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--enable-admission-plugins")," parameter to a\nvalue that includes ",(0,a.kt)("inlineCode",{parentName:"p"},"NodeRestriction"),"."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--enable-admission-plugins=...,NodeRestriction,...\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'NamespaceLifecycle,LimitRanger,ServiceAccount,DefaultStorageClass,DefaultTolerationSeconds,MutatingAdmissionWebhook,ValidatingAdmissionWebhook,ResourceQuota,NodeRestriction,Priority,TaintNodesByCondition,PersistentVolumeClaimResize,PodSecurityPolicy,EventRateLimit' has 'NodeRestriction'\n")),(0,a.kt)("h4",{id:"1218-ensure-that-the---insecure-bind-address-argument-is-not-set-scored"},"1.2.18 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--insecure-bind-address")," argument is not set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--insecure-bind-address")," parameter."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--insecure-bind-address' is not present\n")),(0,a.kt)("h4",{id:"1219-ensure-that-the---insecure-port-argument-is-set-to-0-scored"},"1.2.19 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--insecure-port")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"0")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--insecure-port=0\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'0' is equal to '0'\n")),(0,a.kt)("h4",{id:"1220-ensure-that-the---secure-port-argument-is-not-set-to-0-scored"},"1.2.20 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--secure-port")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"0")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and either remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--secure-port")," parameter or\nset it to a different ",(0,a.kt)("strong",{parentName:"p"},"(non-zero)")," desired port."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"6443 is greater than 0 OR '--secure-port' is not present\n")),(0,a.kt)("h4",{id:"1221-ensure-that-the---profiling-argument-is-set-to-false-scored"},"1.2.21 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--profiling")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"false")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--profiling=false\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'false' is equal to 'false'\n")),(0,a.kt)("h4",{id:"1222-ensure-that-the---audit-log-path-argument-is-set-scored"},"1.2.22 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--audit-log-path")," argument is set (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--audit-log-path")," parameter to a suitable path and\nfile where you would like audit logs to be written, for example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--audit-log-path=/var/log/apiserver/audit.log\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--audit-log-path' is present\n")),(0,a.kt)("h4",{id:"1223-ensure-that-the---audit-log-maxage-argument-is-set-to-30-or-as-appropriate-scored"},"1.2.23 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--audit-log-maxage")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"30")," or as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--audit-log-maxage")," parameter to ",(0,a.kt)("inlineCode",{parentName:"p"},"30")," or as an appropriate number of days:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--audit-log-maxage=30\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"30 is greater or equal to 30\n")),(0,a.kt)("h4",{id:"1224-ensure-that-the---audit-log-maxbackup-argument-is-set-to-10-or-as-appropriate-scored"},"1.2.24 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--audit-log-maxbackup")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"10")," or as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--audit-log-maxbackup")," parameter to ",(0,a.kt)("inlineCode",{parentName:"p"},"10")," or to an appropriate\nvalue."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--audit-log-maxbackup=10\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"10 is greater or equal to 10\n")),(0,a.kt)("h4",{id:"1225-ensure-that-the---audit-log-maxsize-argument-is-set-to-100-or-as-appropriate-scored"},"1.2.25 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--audit-log-maxsize")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"100")," or as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--audit-log-maxsize")," parameter to an appropriate size in ",(0,a.kt)("strong",{parentName:"p"},"MB"),".\nFor example, to set it as ",(0,a.kt)("inlineCode",{parentName:"p"},"100")," ",(0,a.kt)("strong",{parentName:"p"},"MB"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--audit-log-maxsize=100\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"100 is greater or equal to 100\n")),(0,a.kt)("h4",{id:"1226-ensure-that-the---request-timeout-argument-is-set-as-appropriate-scored"},"1.2.26 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--request-timeout")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\nand set the below parameter as appropriate and if needed.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--request-timeout=300s\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--request-timeout' is not present OR '--request-timeout' is present\n")),(0,a.kt)("h4",{id:"1227-ensure-that-the---service-account-lookup-argument-is-set-to-true-scored"},"1.2.27 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--service-account-lookup")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--service-account-lookup=true\n")),(0,a.kt)("p",null,"Alternatively, you can delete the ",(0,a.kt)("inlineCode",{parentName:"p"},"--service-account-lookup")," parameter from this file so\nthat the default takes effect."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--service-account-lookup' is not present OR 'true' is equal to 'true'\n")),(0,a.kt)("h4",{id:"1228-ensure-that-the---service-account-key-file-argument-is-set-as-appropriate-scored"},"1.2.28 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--service-account-key-file")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--service-account-key-file")," parameter\nto the public key file for service accounts:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--service-account-key-file=<filename>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--service-account-key-file' is present\n")),(0,a.kt)("h4",{id:"1229-ensure-that-the---etcd-certfile-and---etcd-keyfile-arguments-are-set-as-appropriate-scored"},"1.2.29 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--etcd-certfile")," and ",(0,a.kt)("inlineCode",{parentName:"h4"},"--etcd-keyfile")," arguments are set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("strong",{parentName:"p"},"etcd")," certificate and ",(0,a.kt)("strong",{parentName:"p"},"key")," file parameters."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--etcd-certfile=<path/to/client-certificate-file>`\n`--etcd-keyfile=<path/to/client-key-file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--etcd-certfile' is present AND '--etcd-keyfile' is present\n")),(0,a.kt)("h4",{id:"1230-ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-scored"},"1.2.30 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--tls-cert-file")," and ",(0,a.kt)("inlineCode",{parentName:"h4"},"--tls-private-key-file")," arguments are set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and set up the TLS connection on the apiserver.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the TLS certificate and private key file parameters."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--tls-cert-file=<path/to/tls-certificate-file>`\n`--tls-private-key-file=<path/to/tls-key-file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--tls-cert-file' is present AND '--tls-private-key-file' is present\n")),(0,a.kt)("h4",{id:"1231-ensure-that-the---client-ca-file-argument-is-set-as-appropriate-scored"},"1.2.31 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--client-ca-file")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and set up the TLS connection on the apiserver.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the client certificate authority file."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--client-ca-file=<path/to/client-ca-file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--client-ca-file' is present\n")),(0,a.kt)("h4",{id:"1232-ensure-that-the---etcd-cafile-argument-is-set-as-appropriate-scored"},"1.2.32 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--etcd-cafile")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and set up the TLS connection between the apiserver and etcd.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the etcd certificate authority file parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--etcd-cafile=<path/to/ca-file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--etcd-cafile' is present\n")),(0,a.kt)("h4",{id:"1233-ensure-that-the---encryption-provider-config-argument-is-set-as-appropriate-scored"},"1.2.33 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--encryption-provider-config")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and configure a EncryptionConfig file.\nThen, edit the API server pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-apiserver.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--encryption-provider-config")," parameter to the path of that file:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--encryption-provider-config=</path/to/EncryptionConfig/File>\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-apiserver | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--encryption-provider-config' is present\n")),(0,a.kt)("h4",{id:"1234-ensure-that-encryption-providers-are-appropriately-configured-scored"},"1.2.34 Ensure that encryption providers are appropriately configured (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the Kubernetes documentation and configure a ",(0,a.kt)("inlineCode",{parentName:"p"},"EncryptionConfig")," file.\nIn this file, choose ",(0,a.kt)("strong",{parentName:"p"},"aescbc"),", ",(0,a.kt)("strong",{parentName:"p"},"kms")," or ",(0,a.kt)("strong",{parentName:"p"},"secretbox")," as the encryption provider."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 1.2.34.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},'#!/bin/bash -e\n\ncheck_file=${1}\n\ngrep -q -E \'aescbc|kms|secretbox\' ${check_file}\nif [ $? -eq 0 ]; then\n echo "--pass"\n exit 0\nelse\n echo "fail: encryption provider found in ${check_file}"\n exit 1\nfi\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./1.2.34.sh /etc/kubernetes/ssl/encryption.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--pass' is present\n")),(0,a.kt)("h3",{id:"13-controller-manager"},"1.3 Controller Manager"),(0,a.kt)("h4",{id:"131-ensure-that-the---terminated-pod-gc-threshold-argument-is-set-as-appropriate-scored"},"1.3.1 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--terminated-pod-gc-threshold")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--terminated-pod-gc-threshold")," to an appropriate threshold,\nfor example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--terminated-pod-gc-threshold=10\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--terminated-pod-gc-threshold' is present\n")),(0,a.kt)("h4",{id:"132-ensure-that-the---profiling-argument-is-set-to-false-scored"},"1.3.2 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--profiling")," argument is set to false (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--profiling=false\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'false' is equal to 'false'\n")),(0,a.kt)("h4",{id:"133-ensure-that-the---use-service-account-credentials-argument-is-set-to-true-scored"},"1.3.3 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--use-service-account-credentials")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node to set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--use-service-account-credentials=true\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is not equal to 'false'\n")),(0,a.kt)("h4",{id:"134-ensure-that-the---service-account-private-key-file-argument-is-set-as-appropriate-scored"},"1.3.4 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--service-account-private-key-file")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--service-account-private-key-file")," parameter\nto the private key file for service accounts."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--service-account-private-key-file=<filename>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--service-account-private-key-file' is present\n")),(0,a.kt)("h4",{id:"135-ensure-that-the---root-ca-file-argument-is-set-as-appropriate-scored"},"1.3.5 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--root-ca-file")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--root-ca-file")," parameter to the certificate bundle file`."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--root-ca-file=<path/to/file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--root-ca-file' is present\n")),(0,a.kt)("h4",{id:"136-ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-scored"},"1.3.6 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"RotateKubeletServerCertificate")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node and set the ",(0,a.kt)("inlineCode",{parentName:"p"},"--feature-gates")," parameter to include ",(0,a.kt)("inlineCode",{parentName:"p"},"RotateKubeletServerCertificate=true"),"."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--feature-gates=RotateKubeletServerCertificate=true\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'RotateKubeletServerCertificate=true' is equal to 'RotateKubeletServerCertificate=true'\n")),(0,a.kt)("h4",{id:"137-ensure-that-the---bind-address-argument-is-set-to-127001-scored"},"1.3.7 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--bind-address argument")," is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"127.0.0.1")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Controller Manager pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-controller-manager.yaml"),"\non the master node and ensure the correct value for the ",(0,a.kt)("inlineCode",{parentName:"p"},"--bind-address")," parameter."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-controller-manager | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--bind-address' argument is set to 127.0.0.1\n")),(0,a.kt)("h3",{id:"14-scheduler"},"1.4 Scheduler"),(0,a.kt)("h4",{id:"141-ensure-that-the---profiling-argument-is-set-to-false-scored"},"1.4.1 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--profiling")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"false")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Scheduler pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-scheduler.yaml")," file\non the master node and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--profiling=false\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-scheduler | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'false' is equal to 'false'\n")),(0,a.kt)("h4",{id:"142-ensure-that-the---bind-address-argument-is-set-to-127001-scored"},"1.4.2 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--bind-address")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"127.0.0.1")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the Scheduler pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/kube-scheduler.yaml"),"\non the master node and ensure the correct value for the ",(0,a.kt)("inlineCode",{parentName:"p"},"--bind-address")," parameter."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | grep kube-scheduler | grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--bind-address' argument is set to 127.0.0.1\n")),(0,a.kt)("h2",{id:"2-etcd-node-configuration"},"2 Etcd Node Configuration"),(0,a.kt)("h3",{id:"2-etcd-node-configuration-files"},"2 Etcd Node Configuration Files"),(0,a.kt)("h4",{id:"21-ensure-that-the---cert-file-and---key-file-arguments-are-set-as-appropriate-scored"},"2.1 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--cert-file")," and ",(0,a.kt)("inlineCode",{parentName:"h4"},"--key-file")," arguments are set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the etcd service documentation and configure TLS encryption.\nThen, edit the etcd pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/etcd.yaml"),"\non the master node and set the below parameters."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--cert-file=</path/to/ca-file>`\n`--key-file=</path/to/key-file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--cert-file' is present AND '--key-file' is present\n")),(0,a.kt)("h4",{id:"22-ensure-that-the---client-cert-auth-argument-is-set-to-true-scored"},"2.2 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--client-cert-auth")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the etcd pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/etcd.yaml")," on the master\nnode and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},'--client-cert-auth="true"\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is equal to 'true'\n")),(0,a.kt)("h4",{id:"23-ensure-that-the---auto-tls-argument-is-not-set-to-true-scored"},"2.3 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--auto-tls")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the etcd pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/etcd.yaml")," on the master\nnode and either remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--auto-tls")," parameter or set it to ",(0,a.kt)("inlineCode",{parentName:"p"},"false"),"."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"}," --auto-tls=false\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--auto-tls' is not present OR '--auto-tls' is not present\n")),(0,a.kt)("h4",{id:"24-ensure-that-the---peer-cert-file-and---peer-key-file-arguments-are-set-as-appropriate-scored"},"2.4 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--peer-cert-file")," and ",(0,a.kt)("inlineCode",{parentName:"h4"},"--peer-key-file")," arguments are set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the etcd service documentation and configure peer TLS encryption as appropriate\nfor your etcd cluster. Then, edit the etcd pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/etcd.yaml")," on the\nmaster node and set the below parameters."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--peer-client-file=</path/to/peer-cert-file>`\n`--peer-key-file=</path/to/peer-key-file>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--peer-cert-file' is present AND '--peer-key-file' is present\n")),(0,a.kt)("h4",{id:"25-ensure-that-the---peer-client-cert-auth-argument-is-set-to-true-scored"},"2.5 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--peer-client-cert-auth")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the etcd pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/etcd.yaml")," on the master\nnode and set the below parameter."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--peer-client-cert-auth=true\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is equal to 'true'\n")),(0,a.kt)("h4",{id:"26-ensure-that-the---peer-auto-tls-argument-is-not-set-to-true-scored"},"2.6 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--peer-auto-tls")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the etcd pod specification file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/kubernetes/manifests/etcd.yaml")," on the master\nnode and either remove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--peer-auto-tls")," parameter or set it to ",(0,a.kt)("inlineCode",{parentName:"p"},"false"),"."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--peer-auto-tls=false\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -ef | /bin/grep etcd | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--peer-auto-tls' is not present OR '--peer-auto-tls' is present\n")),(0,a.kt)("h2",{id:"3-control-plane-configuration"},"3 Control Plane Configuration"),(0,a.kt)("h3",{id:"32-logging"},"3.2 Logging"),(0,a.kt)("h4",{id:"321-ensure-that-a-minimal-audit-policy-is-created-scored"},"3.2.1 Ensure that a minimal audit policy is created (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nCreate an audit policy file for your cluster."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 3.2.1.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"#!/bin/bash -e\n\napi_server_bin=${1}\n\n/bin/ps -ef | /bin/grep ${api_server_bin} | /bin/grep -v ${0} | /bin/grep -v grep\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./3.2.1.sh kube-apiserver\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--audit-policy-file' is present\n")),(0,a.kt)("h2",{id:"4-worker-node-security-configuration"},"4 Worker Node Security Configuration"),(0,a.kt)("h3",{id:"41-worker-node-configuration-files"},"4.1 Worker Node Configuration Files"),(0,a.kt)("h4",{id:"411-ensure-that-the-kubelet-service-file-permissions-are-set-to-644-or-more-restrictive-scored"},"4.1.1 Ensure that the kubelet service file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the kubelet service. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"412-ensure-that-the-kubelet-service-file-ownership-is-set-to-rootroot-scored"},"4.1.2 Ensure that the kubelet service file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the kubelet service. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"413-ensure-that-the-proxy-kubeconfig-file-permissions-are-set-to-644-or-more-restrictive-scored"},"4.1.3 Ensure that the proxy kubeconfig file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the each worker node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chmod 644 /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/sh -c 'if test -e /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; then stat -c %a /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; fi'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'644' is present OR '640' is present OR '600' is equal to '600' OR '444' is present OR '440' is present OR '400' is present OR '000' is present\n")),(0,a.kt)("h4",{id:"414-ensure-that-the-proxy-kubeconfig-file-ownership-is-set-to-rootroot-scored"},"4.1.4 Ensure that the proxy kubeconfig file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the each worker node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chown root:root /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/sh -c 'if test -e /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; then stat -c %U:%G /etc/kubernetes/ssl/kubecfg-kube-proxy.yaml; fi'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'root:root' is present\n")),(0,a.kt)("h4",{id:"415-ensure-that-the-kubeletconf-file-permissions-are-set-to-644-or-more-restrictive-scored"},"4.1.5 Ensure that the kubelet.conf file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the each worker node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chmod 644 /etc/kubernetes/ssl/kubecfg-kube-node.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/sh -c 'if test -e /etc/kubernetes/ssl/kubecfg-kube-node.yaml; then stat -c %a /etc/kubernetes/ssl/kubecfg-kube-node.yaml; fi'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'644' is present OR '640' is present OR '600' is equal to '600' OR '444' is present OR '440' is present OR '400' is present OR '000' is present\n")),(0,a.kt)("h4",{id:"416-ensure-that-the-kubeletconf-file-ownership-is-set-to-rootroot-scored"},"4.1.6 Ensure that the kubelet.conf file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the below command (based on the file location on your system) on the each worker node.\nFor example,"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chown root:root /etc/kubernetes/ssl/kubecfg-kube-node.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/sh -c 'if test -e /etc/kubernetes/ssl/kubecfg-kube-node.yaml; then stat -c %U:%G /etc/kubernetes/ssl/kubecfg-kube-node.yaml; fi'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'root:root' is equal to 'root:root'\n")),(0,a.kt)("h4",{id:"417-ensure-that-the-certificate-authorities-file-permissions-are-set-to-644-or-more-restrictive-scored"},"4.1.7 Ensure that the certificate authorities file permissions are set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the following command to modify the file permissions of the"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--client-ca-file chmod 644 <filename>`\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"stat -c %a /etc/kubernetes/ssl/kube-ca.pem\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'644' is equal to '644' OR '640' is present OR '600' is present\n")),(0,a.kt)("h4",{id:"418-ensure-that-the-client-certificate-authorities-file-ownership-is-set-to-rootroot-scored"},"4.1.8 Ensure that the client certificate authorities file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRun the following command to modify the ownership of the ",(0,a.kt)("inlineCode",{parentName:"p"},"--client-ca-file"),"."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"chown root:root <filename>\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/sh -c 'if test -e /etc/kubernetes/ssl/kube-ca.pem; then stat -c %U:%G /etc/kubernetes/ssl/kube-ca.pem; fi'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'root:root' is equal to 'root:root'\n")),(0,a.kt)("h4",{id:"419-ensure-that-the-kubelet-configuration-file-has-permissions-set-to-644-or-more-restrictive-scored"},"4.1.9 Ensure that the kubelet configuration file has permissions set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"644")," or more restrictive (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the kubelet service. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"4110-ensure-that-the-kubelet-configuration-file-ownership-is-set-to-rootroot-scored"},"4.1.10 Ensure that the kubelet configuration file ownership is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"root:root")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the kubelet service. All configuration is passed in as arguments at container run time."),(0,a.kt)("h3",{id:"42-kubelet"},"4.2 Kubelet"),(0,a.kt)("h4",{id:"421-ensure-that-the---anonymous-auth-argument-is-set-to-false-scored"},"4.2.1 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--anonymous-auth argument")," is set to false (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set authentication: ",(0,a.kt)("inlineCode",{parentName:"p"},"anonymous"),": enabled to\n",(0,a.kt)("inlineCode",{parentName:"p"},"false"),".\nIf using executable arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nset the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_SYSTEM_PODS_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--anonymous-auth=false\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'false' is equal to 'false'\n")),(0,a.kt)("h4",{id:"422-ensure-that-the---authorization-mode-argument-is-not-set-to-alwaysallow-scored"},"4.2.2 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--authorization-mode")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"AlwaysAllow")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set authorization: ",(0,a.kt)("inlineCode",{parentName:"p"},"mode")," to ",(0,a.kt)("inlineCode",{parentName:"p"},"Webhook"),". If\nusing executable arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nset the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_AUTHZ_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--authorization-mode=Webhook\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'Webhook' not have 'AlwaysAllow'\n")),(0,a.kt)("h4",{id:"423-ensure-that-the---client-ca-file-argument-is-set-as-appropriate-scored"},"4.2.3 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--client-ca-file")," argument is set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set authentication: ",(0,a.kt)("inlineCode",{parentName:"p"},"x509"),": ",(0,a.kt)("inlineCode",{parentName:"p"},"clientCAFile")," to\nthe location of the client CA file.\nIf using command line arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nset the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_AUTHZ_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"`--client-ca-file=<path/to/client-ca-file>`\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--client-ca-file' is present\n")),(0,a.kt)("h4",{id:"424-ensure-that-the---read-only-port-argument-is-set-to-0-scored"},"4.2.4 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--read-only-port")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"0")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set ",(0,a.kt)("inlineCode",{parentName:"p"},"readOnlyPort")," to ",(0,a.kt)("inlineCode",{parentName:"p"},"0"),".\nIf using command line arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nset the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_SYSTEM_PODS_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--read-only-port=0\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'0' is equal to '0'\n")),(0,a.kt)("h4",{id:"425-ensure-that-the---streaming-connection-idle-timeout-argument-is-not-set-to-0-scored"},"4.2.5 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--streaming-connection-idle-timeout")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"0")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set ",(0,a.kt)("inlineCode",{parentName:"p"},"streamingConnectionIdleTimeout")," to a\nvalue other than ",(0,a.kt)("inlineCode",{parentName:"p"},"0"),".\nIf using command line arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nset the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_SYSTEM_PODS_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--streaming-connection-idle-timeout=5m\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'30m' is not equal to '0' OR '--streaming-connection-idle-timeout' is not present\n")),(0,a.kt)("h4",{id:"426-ensure-that-the---protect-kernel-defaults-argument-is-set-to-true-scored"},"4.2.6 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--protect-kernel-defaults")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set ",(0,a.kt)("inlineCode",{parentName:"p"},"protectKernelDefaults"),": ",(0,a.kt)("inlineCode",{parentName:"p"},"true"),".\nIf using command line arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nset the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_SYSTEM_PODS_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--protect-kernel-defaults=true\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is equal to 'true'\n")),(0,a.kt)("h4",{id:"427-ensure-that-the---make-iptables-util-chains-argument-is-set-to-true-scored"},"4.2.7 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--make-iptables-util-chains")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to set ",(0,a.kt)("inlineCode",{parentName:"p"},"makeIPTablesUtilChains"),": ",(0,a.kt)("inlineCode",{parentName:"p"},"true"),".\nIf using command line arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nremove the ",(0,a.kt)("inlineCode",{parentName:"p"},"--make-iptables-util-chains")," argument from the\n",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_SYSTEM_PODS_ARGS")," variable.\nBased on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is equal to 'true' OR '--make-iptables-util-chains' is not present\n")),(0,a.kt)("h4",{id:"4210-ensure-that-the---tls-cert-file-and---tls-private-key-file-arguments-are-set-as-appropriate-scored"},"4.2.10 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--tls-cert-file")," and ",(0,a.kt)("inlineCode",{parentName:"h4"},"--tls-private-key-file")," arguments are set as appropriate (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," Not Applicable"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nRKE doesn\u2019t require or maintain a configuration file for the kubelet service. All configuration is passed in as arguments at container run time."),(0,a.kt)("h4",{id:"4211-ensure-that-the---rotate-certificates-argument-is-not-set-to-false-scored"},"4.2.11 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"--rotate-certificates")," argument is not set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"false")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nIf using a Kubelet config file, edit the file to add the line ",(0,a.kt)("inlineCode",{parentName:"p"},"rotateCertificates"),": ",(0,a.kt)("inlineCode",{parentName:"p"},"true")," or\nremove it altogether to use the default value.\nIf using command line arguments, edit the kubelet service file\n",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf")," on each worker node and\nremove ",(0,a.kt)("inlineCode",{parentName:"p"},"--rotate-certificates=false")," argument from the ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_CERTIFICATE_ARGS"),"\nvariable.\nBased on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--rotate-certificates' is present OR '--rotate-certificates' is not present\n")),(0,a.kt)("h4",{id:"4212-ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-scored"},"4.2.12 Ensure that the ",(0,a.kt)("inlineCode",{parentName:"h4"},"RotateKubeletServerCertificate")," argument is set to ",(0,a.kt)("inlineCode",{parentName:"h4"},"true")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEdit the kubelet service file ",(0,a.kt)("inlineCode",{parentName:"p"},"/etc/systemd/system/kubelet.service.d/10-kubeadm.conf"),"\non each worker node and set the below parameter in ",(0,a.kt)("inlineCode",{parentName:"p"},"KUBELET_CERTIFICATE_ARGS")," variable."),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"--feature-gates=RotateKubeletServerCertificate=true\n")),(0,a.kt)("p",null,"Based on your system, restart the kubelet service. For example:"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"systemctl daemon-reload\nsystemctl restart kubelet.service\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/ps -fC kubelet\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Config:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"/bin/cat /var/lib/kubelet/config.yaml\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'true' is equal to 'true'\n")),(0,a.kt)("h2",{id:"5-kubernetes-policies"},"5 Kubernetes Policies"),(0,a.kt)("h3",{id:"51-rbac-and-service-accounts"},"5.1 RBAC and Service Accounts"),(0,a.kt)("h4",{id:"515-ensure-that-default-service-accounts-are-not-actively-used-scored"},"5.1.5 Ensure that default service accounts are not actively used. (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nCreate explicit service accounts wherever a Kubernetes workload requires specific access\nto the Kubernetes API server.\nModify the configuration of each default service account to include this value"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre",className:"language-bash"},"automountServiceAccountToken: false\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 5.1.5.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},'#!/bin/bash\n\nexport KUBECONFIG=${KUBECONFIG:-/root/.kube/config}\n\nkubectl version > /dev/null\nif [ $? -ne 0 ]; then\n echo "fail: kubectl failed"\n exit 1\nfi\n\naccounts="$(kubectl --kubeconfig=${KUBECONFIG} get serviceaccounts -A -o json | jq -r \'.items[] | select(.metadata.name=="default") | select((.automountServiceAccountToken == null) or (.automountServiceAccountToken == true)) | "fail \\(.metadata.name) \\(.metadata.namespace)"\')"\n\nif [[ "${accounts}" != "" ]]; then\n echo "fail: automountServiceAccountToken not false for accounts: ${accounts}"\n exit 1\nfi\n\ndefault_binding="$(kubectl get rolebindings,clusterrolebindings -A -o json | jq -r \'.items[] | select(.subjects[].kind=="ServiceAccount" and .subjects[].name=="default" and .metadata.name=="default").metadata.uid\' | wc -l)"\n\nif [[ "${default_binding}" -gt 0 ]]; then\n echo "fail: default service accounts have non default bindings"\n exit 1\nfi\n\necho "--pass"\nexit 0\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./5.1.5.sh\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'--pass' is present\n")),(0,a.kt)("h3",{id:"52-pod-security-policies"},"5.2 Pod Security Policies"),(0,a.kt)("h4",{id:"522-minimize-the-admission-of-containers-wishing-to-share-the-host-process-id-namespace-scored"},"5.2.2 Minimize the admission of containers wishing to share the host process ID namespace (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nCreate a PSP as described in the Kubernetes documentation, ensuring that the\n",(0,a.kt)("inlineCode",{parentName:"p"},".spec.hostPID")," field is omitted or set to ",(0,a.kt)("inlineCode",{parentName:"p"},"false"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"kubectl --kubeconfig=/root/.kube/config get psp -o json | jq .items[] | jq -r 'select((.spec.hostPID == null) or (.spec.hostPID == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"1 is greater than 0\n")),(0,a.kt)("h4",{id:"523-minimize-the-admission-of-containers-wishing-to-share-the-host-ipc-namespace-scored"},"5.2.3 Minimize the admission of containers wishing to share the host IPC namespace (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nCreate a PSP as described in the Kubernetes documentation, ensuring that the\n",(0,a.kt)("inlineCode",{parentName:"p"},".spec.hostIPC")," field is omitted or set to ",(0,a.kt)("inlineCode",{parentName:"p"},"false"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"kubectl --kubeconfig=/root/.kube/config get psp -o json | jq .items[] | jq -r 'select((.spec.hostIPC == null) or (.spec.hostIPC == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"1 is greater than 0\n")),(0,a.kt)("h4",{id:"524-minimize-the-admission-of-containers-wishing-to-share-the-host-network-namespace-scored"},"5.2.4 Minimize the admission of containers wishing to share the host network namespace (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nCreate a PSP as described in the Kubernetes documentation, ensuring that the\n",(0,a.kt)("inlineCode",{parentName:"p"},".spec.hostNetwork")," field is omitted or set to ",(0,a.kt)("inlineCode",{parentName:"p"},"false"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"kubectl --kubeconfig=/root/.kube/config get psp -o json | jq .items[] | jq -r 'select((.spec.hostNetwork == null) or (.spec.hostNetwork == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"1 is greater than 0\n")),(0,a.kt)("h4",{id:"525-minimize-the-admission-of-containers-with-allowprivilegeescalation-scored"},"5.2.5 Minimize the admission of containers with ",(0,a.kt)("inlineCode",{parentName:"h4"},"allowPrivilegeEscalation")," (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nCreate a PSP as described in the Kubernetes documentation, ensuring that the\n",(0,a.kt)("inlineCode",{parentName:"p"},".spec.allowPrivilegeEscalation")," field is omitted or set to ",(0,a.kt)("inlineCode",{parentName:"p"},"false"),"."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"kubectl --kubeconfig=/root/.kube/config get psp -o json | jq .items[] | jq -r 'select((.spec.allowPrivilegeEscalation == null) or (.spec.allowPrivilegeEscalation == false))' | jq .metadata.name | wc -l | xargs -I {} echo '--count={}'\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"1 is greater than 0\n")),(0,a.kt)("h3",{id:"53-network-policies-and-cni"},"5.3 Network Policies and CNI"),(0,a.kt)("h4",{id:"532-ensure-that-all-namespaces-have-network-policies-defined-scored"},"5.3.2 Ensure that all Namespaces have Network Policies defined (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nFollow the documentation and create ",(0,a.kt)("inlineCode",{parentName:"p"},"NetworkPolicy")," objects as you need them."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 5.3.2.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},'#!/bin/bash -e\n\nexport KUBECONFIG=${KUBECONFIG:-"/root/.kube/config"}\n\nkubectl version > /dev/null\nif [ $? -ne 0 ]; then\n echo "fail: kubectl failed"\n exit 1\nfi\n\nfor namespace in $(kubectl get namespaces -A -o json | jq -r \'.items[].metadata.name\'); do\n policy_count=$(kubectl get networkpolicy -n ${namespace} -o json | jq \'.items | length\')\n if [ ${policy_count} -eq 0 ]; then\n echo "fail: ${namespace}"\n exit 1\n fi\ndone\n\necho "pass"\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./5.3.2.sh\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'pass' is present\n")),(0,a.kt)("h3",{id:"56-general-policies"},"5.6 General Policies"),(0,a.kt)("h4",{id:"564-the-default-namespace-should-not-be-used-scored"},"5.6.4 The default namespace should not be used (Scored)"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Result:")," PASS"),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Remediation:"),"\nEnsure that namespaces are created to allow for appropriate segregation of Kubernetes\nresources and that all new resources are created in a specific namespace."),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Script:")," 5.6.4.sh"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},'#!/bin/bash -e\n\nexport KUBECONFIG=${KUBECONFIG:-/root/.kube/config}\n\nkubectl version > /dev/null\nif [[ $? -gt 0 ]]; then\n echo "fail: kubectl failed"\n exit 1\nfi\n\ndefault_resources=$(kubectl get all -o json | jq --compact-output \'.items[] | select((.kind == "Service") and (.metadata.name == "kubernetes") and (.metadata.namespace == "default") | not)\' | wc -l)\n\necho "--count=${default_resources}"\n')),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Audit Execution:")),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"./5.6.4.sh\n")),(0,a.kt)("p",null,(0,a.kt)("strong",{parentName:"p"},"Expected result"),":"),(0,a.kt)("pre",null,(0,a.kt)("code",{parentName:"pre"},"'0' is equal to '0'\n")))}c.isMDXComponent=!0}}]); |