1. Home
  2. Security Hardening
  3. CIS Kubernetes 1.13 Benchmark V1.4 1 L1
  4. Ensure that the admission control plugin EventRateLimit is set

Ensure that the admission control plugin EventRateLimit is set

Details

Limit the rate at which the API server accepts requests.

Rationale:

Using ‘EventRateLimit’ admission control enforces a limit on the number of events that the API Server will accept in a given time slice. In a large multi-tenant cluster, there might be a small percentage of misbehaving tenants which could have a significant impact on the performance of the cluster overall. Hence, it is recommended to limit the rate of events that the API server will accept.

Note: This is an Alpha feature in the Kubernetes 1.11 release.

Solution

Follow the Kubernetes documentation and set the desired limits in a configuration file.

Then, edit the API server pod specification file ‘/etc/kubernetes/manifests/kube-apiserver.yaml’ and set the below parameters.

–enable-admission-plugins=…,EventRateLimit,…
–admission-control-config-file=

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection, System and Information Integrity.This control applies to the following type of system Unix.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles