Ensure that the admin.conf file ownership is set to root:root Details Ensure that the admin.conf file ownership is set to root:root. Rationale: The admin.conf file contains the admin credentials for...
Ensure that the admin.conf file permissions are set to 644 or more restrictive Details Ensure that the admin.conf file has permissions of 644 or more restrictive. Rationale: The admin.conf is the administrator kubeconfig...
Ensure that the admission control plugin AlwaysAdmit is not set Details Do not allow all requests. Rationale: Setting admission control plugin AlwaysAdmit allows all requests and do not filter any...
Ensure that the admission control plugin AlwaysPullImages is set Details Always pull images. Rationale: Setting admission control policy to AlwaysPullImages forces every new pod to pull the required images...
Ensure that the admission control plugin EventRateLimit is set Details Limit the rate at which the API server accepts requests. Rationale: Using EventRateLimit admission control enforces a limit on...
Ensure that the admission control plugin NamespaceLifecycle is set Details Reject creating objects in a namespace that is undergoing termination. Rationale: Setting admission control policy to NamespaceLifecycle ensures that...
Ensure that the admission control plugin NodeRestriction is set Details Limit the Node and Pod objects that a kubelet could modify. Rationale: Using the NodeRestriction plug-in ensures that the...
Ensure that the admission control plugin PodSecurityPolicy is set Details Reject creating pods that do not match Pod Security Policies. Rationale: A Pod Security Policy is a cluster-level resource...
Ensure that the admission control plugin SecurityContextDeny is set if PodSecurityPolicy is not used Details The SecurityContextDeny admission controller can be used to deny pods which make use of some SecurityContext fields which could...
Ensure that the admission control plugin ServiceAccount is set Details Automate service accounts management. Rationale: When you create a pod, if you do not specify a service account, it...