Kubernetes

Security, availability and operational configuration guidance for Kubernetes components and workloads.

Documentation

Article Path
AlwaysAdmit admission plugin is configured k8s/always_admit_admission_control_plugin_set
AlwaysPullImages admission plugin not enabled k8s/always_pull_images_admission_control_plugin_not_set
Anonymous authentication is not disabled k8s/anonymous_auth_is_not_set_to_false
Audit log path is not configured k8s/audit_log_path_not_set
Audit policy file is not configured k8s/audit_policy_file_not_defined
Authorization mode is set to AlwaysAllow k8s/authorization_mode_set_to_always_allow
Review Node authorizer settings k8s/authorization_mode_node_not_set
Review RBAC authorization settings k8s/authorization_mode_rbac_not_set
Docker daemon socket exposed to a container k8s/docker_daemon_socket_is_exposed_to_containers
Encryption provider configuration is not specified k8s/encryption_provider_config_is_not_defined
Review encryption provider configuration k8s/encryption_provider_not_properly_configured
Review replica management for HPA-targeted Deployments k8s/hpa_targeted_deployments_with_configured_replica_count
Shared host IPC namespace k8s/shared_host_ipc_namespace
Shared host network namespace k8s/shared_host_network_namespace
Workload exposure through an Ingress controller k8s/ingress_controller_exposes_workload
Kubelet certificate authority is not configured k8s/kubelet_certificate_authority_not_set
Kubelet client certificate or key is not configured k8s/kubelet_client_certificate_or_key_not_set
Kubelet client certificate rotation is disabled k8s/kubelet_client_periodic_certificate_switch_disabled
Kubelet HTTPS is disabled k8s/kubelet_https_set_to_false
Review kubelet kernel-setting protection k8s/kubelet_protect_kernel_defaults_set_to_false
Unauthenticated kubelet read-only port enabled k8s/kubelet_read_only_port_is_not_set_to_zero
Review kubelet streaming connection timeouts k8s/kubelet_streaming_connection_timeout_disabled
Review kubelet iptables utility-chain settings k8s/kubelet_not_managing_ip_tables
Review Kubernetes AppArmor profiles k8s/missing_app_armor_config
Review Kubernetes container CPU limits k8s/cpu_limits_not_set
Review Kubernetes container CPU requests k8s/cpu_requests_not_set
Review Kubernetes cluster-admin binding permissions k8s/cluster_admin_role_binding_with_super_user_permissions
Review the Kubernetes CronJob start deadline k8s/cronjob_deadline_not_configured
Review Kubernetes Dashboard use k8s/dashboard_is_enabled
Review Kubernetes Deployment Pod placement k8s/deployment_has_no_pod_anti_affinity
Review Kubernetes Deployment PodDisruptionBudget configuration k8s/deployment_without_pod_disruption_budget
Review Kubernetes Event request limits k8s/event_rate_limit_admission_control_plugin_not_set
Review Kubernetes HPA Object metric references k8s/hpa_targets_invalid_object
Review Kubernetes image admission policy k8s/image_policy_webhook_admission_control_plugin_not_set
Review Kubernetes NamespaceLifecycle admission settings k8s/namespace_lifecycle_admission_control_plugin_disabled
Review Kubernetes namespace LimitRange configuration k8s/pod_or_container_without_limit_range
Review Kubernetes namespace resource quotas k8s/pod_or_container_without_resource_quota
Review Kubernetes NetworkPolicy Pod selection k8s/network_policy_is_not_targeting_any_pod
Review Kubernetes Pod and container security contexts k8s/pod_or_container_without_security_context
Review Kubernetes control plane profiling settings k8s/profiling_not_set_to_false
Review Kubernetes Secret delivery through environment variables k8s/secrets_as_environment_variables
Review Kubernetes NodePort access scope k8s/service_type_is_nodeport
Review Kubernetes Service targets and port mapping k8s/service_does_not_target_pod
Review Kubernetes kubelet event rate settings k8s/kubelet_event_qps_not_properly_set
Review kubelet hostname override settings k8s/kubelet_hostname_override_is_set
Review Kubernetes audit log backup count k8s/audit_log_maxbackup_not_properly_set
Review Kubernetes audit log retention settings k8s/audit_log_maxage_not_properly_set
Review Kubernetes audit log rotation size k8s/audit_log_maxsize_not_properly_set
Review Kubernetes audit policy coverage k8s/audit_policy_not_cover_key_security_concerns
Review Kubernetes Secret management k8s/using_kubernetes_native_secret_management
Review Kubernetes metadata label syntax k8s/metadata_label_is_invalid
Review Kubernetes image digest pinning k8s/image_without_digest
Review Kubernetes container image version selection k8s/invalid_image
Review Kubernetes API version support k8s/object_is_using_a_deprecated_api_version
Review Kubernetes container Linux capability reduction k8s/no_drop_capabilities_for_containers
Review Kubernetes container image pull policy k8s/image_pull_policy_of_container_is_not_always
Review Kubernetes container root filesystem write access k8s/root_container_not_mounted_as_read_only
Review container memory limits k8s/memory_limits_not_defined
Review container memory requests k8s/memory_requests_not_defined
Review removal of NET_RAW capability k8s/net_raw_capabilities_not_being_dropped
Review NetworkPolicy enforcement configuration k8s/cni_plugin_does_not_support_network_policies
NodeRestriction admission plugin is not enabled k8s/node_restriction_admission_control_plugin_not_set
PSP allows host PID sharing k8s/psp_allows_sharing_host_pid
PSP does not require dropping NET_RAW k8s/net_raw_capabilities_disabled_for_psp
Review capability restrictions in legacy PodSecurityPolicy k8s/not_limited_capabilities_for_pod_security_policy
Broad Pod creation permissions k8s/permissive_access_to_create_pods
Legacy PodSecurityPolicy enforcement needs review on kube-apiserver k8s/pod_security_policy_admission_control_plugin_not_set
RBAC roles permit privilege escalation k8s/rbac_roles_allow_privilege_escalation
RBAC permits attaching to containers k8s/rbac_roles_with_attach_permission
RBAC permits command execution in containers k8s/rbac_roles_with_exec_permission
RBAC permits impersonation k8s/rbac_roles_with_impersonate_permission
RBAC permits Pod port forwarding k8s/rbac_roles_with_portforwarding_permissions
RBAC permits reading Secrets k8s/rbac_roles_with_read_secrets_permissions
Readiness probe is not configured k8s/readiness_probe_is_not_configured
Review API server request timeouts k8s/request_timeout_not_properly_set
Review controller API server CA trust settings k8s/root_ca_file_not_defined
Root containers admitted k8s/root_containers_admitted
Review container protection against root execution k8s/containers_running_as_root
Review kubelet serving certificate rotation k8s/rotate_kubelet_server_certificate_not_active
Kubernetes container has the SYS_ADMIN capability k8s/containers_with_sys_admin_capabilities
Review seccomp profile settings k8s/seccomp_profile_is_not_configured
Review policies replacing SecurityContextDeny k8s/security_context_deny_admission_control_plugin_not_set
Review service account token verification keys k8s/service_account_key_file_not_properly_set
Review service account token signing keys k8s/service_account_private_key_file_not_defined
Automatic service account token mounting not disabled k8s/service_account_token_automount_not_disabled
ServiceAccount admission plugin disabled k8s/service_account_admission_control_plugin_disabled
ServiceAccount shared between workloads k8s/shared_service_account
ServiceAccount name not specified k8s/service_account_name_undefined_or_empty
ServiceAccount access to Secrets k8s/service_account_allows_access_secrets
Review StatefulSet volume access modes k8s/incorrect_volume_claim_access_mode_read_write_once
Review StatefulSet replica placement k8s/statefulset_has_no_pod_anti_affinity
Review the StatefulSet headless Service connection k8s/statefulset_without_service_name
Review StatefulSet PodDisruptionBudget settings k8s/statefulset_without_pod_disruption_budget
Review StatefulSet persistent storage requirements k8s/statefulset_requests_storage
Review TLS serving certificate configuration k8s/tls_connection_certificate_not_setup
Review terminated Pod cleanup thresholds k8s/terminated_pod_garbage_collector_threshold_not_properly_set
Kubernetes workload runs Tiller from Helm 2 k8s/tiller_is_deployed
Kubernetes configuration allows an Unmasked proc mount k8s/container_runs_unmasked
Individual controller service account credentials disabled k8s/use_service_account_credentials_not_set_to_true
kube-apiserver uses a basic authentication file k8s/basic_auth_file_is_set
etcd automatic TLS is enabled k8s/auto_tls_set_to_true
Review etcd client certificate authentication k8s/etcd_client_certificate_authentication_set_to_false
API server etcd CA file configuration needs review k8s/etcd_client_certificate_file_not_defined
etcd peer auto TLS is enabled k8s/peer_auto_tls_set_to_true
Review etcd peer certificate authentication k8s/etcd_peer_client_certificate_authentication_set_to_false
etcd TLS certificate file configuration is incomplete k8s/etcd_tls_certificate_files_not_properly_set
Review etcd peer TLS certificate and key settings k8s/etcd_peer_tls_certificate_files_not_properly_set
PodSecurityPolicy permits sharing host IPC k8s/psp_allows_sharing_host_ipc
Kubernetes workload shares the host PID namespace k8s/shared_host_pid_namespace
PodSecurityPolicy permits sharing the host network namespace k8s/psp_containers_share_host_network_namespace
HostPath restrictions need review in PodSecurityPolicy k8s/psp_with_unrestricted_access_to_host_path
Review direct hostPort bindings k8s/workload_host_port_not_specified
Review legacy kube-apiserver insecure binding settings k8s/insecure_bind_address_set
Review the legacy kube-apiserver insecure port setting k8s/insecure_port_not_properly_set
Incomplete etcd TLS client certificate settings in kube-apiserver k8s/etcd_tls_certificate_not_properly_configured
Workload outside kube-system uses hostPath k8s/non_kube_system_pod_with_host_mount
Review whether a container needs a liveness probe k8s/liveness_probe_is_not_defined
PodSecurityPolicy permits privilege escalation k8s/psp_allows_privilege_escalation
Kubernetes container permits privilege escalation k8s/privilege_escalation_allowed
PodSecurityPolicy permits privileged containers k8s/psp_set_to_privileged
Kubernetes container runs in privileged mode k8s/container_is_privileged
kube-apiserver secure-port is set to zero k8s/secure_port_set_to_zero
kube-apiserver service-account-lookup is false k8s/service_account_lookup_set_to_false
Review kube-apiserver static token file authentication k8s/token_auth_file_is_set
Kubernetes configuration permits unsafe sysctls k8s/cluster_allows_unsafe_sysctls
Kubernetes RBAC rule with wildcard permissions k8s/rbac_wildcard_in_rule
Review control plane certificate authority trust k8s/not_unique_certificate_authority
Review workload namespace organization k8s/using_unrecommended_namespace
RoleBinding targets a default ServiceAccount k8s/role_binding_to_default_service_account
Review container UID settings k8s/containers_run_with_low_uid
Review administrative boundaries for Kubernetes resources k8s/ensure_administrative_boundaries_between_resources
Kubernetes workload mounts a sensitive OS directory k8s/workload_mounting_with_sensitive_os_directory
Tiller Service has not been removed k8s/tiller_service_is_not_deleted
Kubernetes OS directory mount protections need review k8s/volume_mount_with_os_directory_write_permissions
Review Kubernetes TLS cipher suites k8s/weak_tls_cipher_suites
External LoadBalancer Service in use k8s/service_with_external_load_balancer
Misconfigured Pod NetworkPolicy k8s/pod_misconfigured_network_policy
Container with added Linux capabilities k8s/containers_with_added_capabilities
Additional capability permissions need review in PodSecurityPolicy k8s/psp_with_added_capabilities
Review control plane bind-address access scope k8s/bind_address_not_properly_set
Review Kubernetes client-certificate CA configuration k8s/client_certificate_authentication_not_setup_properly
Tiller access from within the cluster needs restriction k8s/tiller_deployment_is_accessible_from_within_the_cluster

Related pages142

AlwaysAdmit admission plugin is configured

Remove AlwaysAdmit, which provides no validation, and verify effective admission policies.

AlwaysPullImages admission plugin not enabled

Review image pull policy and registry authentication to control reuse of private images on shared nodes.

Anonymous authentication is not disabled

Restrict unnecessary anonymous authentication and permissions to protect API and node access.

Audit log path is not configured

Verify the destination used to record and retain API audit events.

Audit policy file is not configured

Configure the audit policy and output to retain necessary API activity records.

Authorization mode is set to AlwaysAllow

Use component-appropriate authorization policies instead of AlwaysAllow.

Review Node authorizer settings

Constrain kubelet permissions with the Node authorizer and correct node identities.

Review RBAC authorization settings

Review the RBAC authorizer with roles and bindings to enforce least privilege.

Docker daemon socket exposed to a container

Remove unnecessary Docker socket mounts and isolate access to the host runtime.

Encryption provider configuration is not specified

Protect the API server encryption configuration and keys, and verify existing data is covered.

Review encryption provider configuration

Check encryption provider order and key management to protect stored data.

Review replica management for HPA-targeted Deployments

Avoid repeatedly overwriting the same replica count through autoscaling and deployment tools.

Shared host IPC namespace

Remove unnecessary hostIPC sharing to preserve separation from host IPC resources.

Shared host network namespace

Remove unnecessary hostNetwork sharing and manage service network exposure.

Workload exposure through an Ingress controller

Ingress can create an unintended public route when it exposes a workload intended for internal use.

Kubelet certificate authority is not configured

Provide a trusted CA so the API server can verify kubelet HTTPS serving certificates.

Kubelet client certificate or key is not configured

Certificate authentication from the API server to kubelet requires a client certificate and its private key.

Kubelet client certificate rotation is disabled

Manage kubelet client certificates so they are renewed before expiry.

Kubelet HTTPS is disabled

Protect management traffic between the API server and kubelet with HTTPS.

Review kubelet kernel-setting protection

Manage kernel settings before startup and review whether kubelet should adjust them automatically.

Unauthenticated kubelet read-only port enabled

Disable the unauthenticated kubelet read-only port and move required monitoring to a protected path.

Review kubelet streaming connection timeouts

Verify effective streaming idle timeouts so unnecessary sessions do not remain open.

Review kubelet iptables utility-chain settings

Check the kubelet iptables utility-chain settings required by the node network configuration.

Review Kubernetes AppArmor profiles

Use node-supported AppArmor profiles to restrict container access to system resources.

Review Kubernetes container CPU limits

Assess CPU caps and throttling against workload requirements.

Review Kubernetes container CPU requests

Set scheduling requests that reflect actual CPU needs.

Review Kubernetes cluster-admin binding permissions

Grant cluster-wide administrative permissions only to identities that need them.

Review the Kubernetes CronJob start deadline

Choose the allowed start delay according to the job’s timing requirements.

Review Kubernetes Dashboard use

Remove unnecessary Dashboards and restrict access paths and permissions for required management UIs.

Review Kubernetes Deployment Pod placement

Spread replicas across the required failure domains and verify actual placement.

Review Kubernetes Deployment PodDisruptionBudget configuration

Set an acceptable level of voluntary disruption for maintenance.

Review Kubernetes Event request limits

Limit Event floods and verify that required operational Events remain available.

Review Kubernetes HPA Object metric references

Distinguish the measured object from the workload being scaled.

Review Kubernetes image admission policy

Verify that required image policies are actually enforced at deployment.

Review Kubernetes NamespaceLifecycle admission settings

Keep the default control that prevents resource creation in inappropriate namespace states.

Review Kubernetes namespace LimitRange configuration

Define resource constraints appropriate for individual objects in the namespace.

Review Kubernetes namespace resource quotas

Manage namespace allocation separately from individual container limits.

Review Kubernetes NetworkPolicy Pod selection

Verify that the policy selects the intended namespace and Pods.

Review Kubernetes Pod and container security contexts

Specify the execution identity, permissions and filesystem protections each workload needs.

Review Kubernetes control plane profiling settings

Disable unnecessary profiling and restrict access to diagnostic endpoints that are needed.

Review Kubernetes Secret delivery through environment variables

Reduce secret exposure through output and debugging, and plan consumer updates during rotation.

Review Kubernetes NodePort access scope

Choose the required service entry path and restrict the networks that can use it.

Review Kubernetes Service targets and port mapping

Check selectors, ready Pods and the application’s actual listening port together.

Review Kubernetes kubelet event rate settings

Balance event visibility against API server load.

Review kubelet hostname override settings

Keep the node identity consistent with authentication and operational configuration.

Review Kubernetes audit log backup count

Choose the rotated-file count for actual log volume and retention needs.

Review Kubernetes audit log retention settings

Match actual audit record retention to investigation and operational needs.

Review Kubernetes audit log rotation size

Manage file size and backup count together to retain the records you need.

Review Kubernetes audit policy coverage

Record needed API activity while controlling sensitive data in request and response bodies.

Review Kubernetes Secret management

Choose secret management that meets access-control, rotation and audit requirements.