CIS Kubernetes Benchmark

XEIZE supports major Kubernetes IaC checks related to the CIS Kubernetes Benchmark.

Control Plane

Section Area Description
1.2 API Server Authentication, authorization, audit logging, TLS, and admission controller configuration
1.3 Controller Manager Service account tokens, RotateKubeletServerCertificate, and disabling profiling
1.4 Scheduler Profiling, bind addresses, and related settings
2 Etcd TLS certificates, protection of client and peer communication, and disabling peer-auto-tls
3 Control Plane Configuration General authentication and logging recommendations

Worker Node

Section Area Description
4.2 Kubelet Blocking anonymous authentication, authorization mode, TLS, disabling the read-only port, streaming-connection-idle-timeout, and related settings

Policies

Section Area Description
5.1 RBAC and Service Accounts Least privilege and disabling automatic token mounts for the default ServiceAccount
5.2 Pod Security Policies / Pod Security Standards Controls on privileged, hostPath, hostNetwork, hostPID, and hostIPC; minimizing capabilities
5.3 Network Policies and CNI Applying NetworkPolicy in all namespaces
5.4 Secrets Management Managing Secrets through files or external secret stores rather than environment variables
5.7 General Policies Namespace separation, securityContext settings, and default-deny policies

References