Control Plane
| Section | Area | Description |
|---|---|---|
| 1.2 | API Server | Authentication, authorization, audit logging, TLS, and admission controller configuration |
| 1.3 | Controller Manager | Service account tokens, RotateKubeletServerCertificate, and disabling profiling |
| 1.4 | Scheduler | Profiling, bind addresses, and related settings |
| 2 | Etcd | TLS certificates, protection of client and peer communication, and disabling peer-auto-tls |
| 3 | Control Plane Configuration | General authentication and logging recommendations |
Worker Node
| Section | Area | Description |
|---|---|---|
| 4.2 | Kubelet | Blocking anonymous authentication, authorization mode, TLS, disabling the read-only port, streaming-connection-idle-timeout, and related settings |
Policies
| Section | Area | Description |
|---|---|---|
| 5.1 | RBAC and Service Accounts | Least privilege and disabling automatic token mounts for the default ServiceAccount |
| 5.2 | Pod Security Policies / Pod Security Standards | Controls on privileged, hostPath, hostNetwork, hostPID, and hostIPC; minimizing capabilities |
| 5.3 | Network Policies and CNI | Applying NetworkPolicy in all namespaces |
| 5.4 | Secrets Management | Managing Secrets through files or external secret stores rather than environment variables |
| 5.7 | General Policies | Namespace separation, securityContext settings, and default-deny policies |