Kubernetes
Security, availability and operational configuration guidance for Kubernetes components and workloads.
Related pages142
AlwaysAdmit admission plugin is configured
Remove AlwaysAdmit, which provides no validation, and verify effective admission policies.
AlwaysPullImages admission plugin not enabled
Review image pull policy and registry authentication to control reuse of private images on shared nodes.
Anonymous authentication is not disabled
Restrict unnecessary anonymous authentication and permissions to protect API and node access.
Audit log path is not configured
Verify the destination used to record and retain API audit events.
Audit policy file is not configured
Configure the audit policy and output to retain necessary API activity records.
Authorization mode is set to AlwaysAllow
Use component-appropriate authorization policies instead of AlwaysAllow.
Review Node authorizer settings
Constrain kubelet permissions with the Node authorizer and correct node identities.
Review RBAC authorization settings
Review the RBAC authorizer with roles and bindings to enforce least privilege.
Docker daemon socket exposed to a container
Remove unnecessary Docker socket mounts and isolate access to the host runtime.
Encryption provider configuration is not specified
Protect the API server encryption configuration and keys, and verify existing data is covered.
Review encryption provider configuration
Check encryption provider order and key management to protect stored data.
Review replica management for HPA-targeted Deployments
Avoid repeatedly overwriting the same replica count through autoscaling and deployment tools.
Shared host IPC namespace
Remove unnecessary hostIPC sharing to preserve separation from host IPC resources.
Shared host network namespace
Remove unnecessary hostNetwork sharing and manage service network exposure.
Workload exposure through an Ingress controller
Ingress can create an unintended public route when it exposes a workload intended for internal use.
Kubelet certificate authority is not configured
Provide a trusted CA so the API server can verify kubelet HTTPS serving certificates.
Kubelet client certificate or key is not configured
Certificate authentication from the API server to kubelet requires a client certificate and its private key.
Kubelet client certificate rotation is disabled
Manage kubelet client certificates so they are renewed before expiry.
Kubelet HTTPS is disabled
Protect management traffic between the API server and kubelet with HTTPS.
Review kubelet kernel-setting protection
Manage kernel settings before startup and review whether kubelet should adjust them automatically.
Unauthenticated kubelet read-only port enabled
Disable the unauthenticated kubelet read-only port and move required monitoring to a protected path.
Review kubelet streaming connection timeouts
Verify effective streaming idle timeouts so unnecessary sessions do not remain open.
Review kubelet iptables utility-chain settings
Check the kubelet iptables utility-chain settings required by the node network configuration.
Review Kubernetes AppArmor profiles
Use node-supported AppArmor profiles to restrict container access to system resources.
Review Kubernetes container CPU limits
Assess CPU caps and throttling against workload requirements.
Review Kubernetes container CPU requests
Set scheduling requests that reflect actual CPU needs.
Review Kubernetes cluster-admin binding permissions
Grant cluster-wide administrative permissions only to identities that need them.
Review the Kubernetes CronJob start deadline
Choose the allowed start delay according to the job’s timing requirements.
Review Kubernetes Dashboard use
Remove unnecessary Dashboards and restrict access paths and permissions for required management UIs.
Review Kubernetes Deployment Pod placement
Spread replicas across the required failure domains and verify actual placement.
Review Kubernetes Deployment PodDisruptionBudget configuration
Set an acceptable level of voluntary disruption for maintenance.
Review Kubernetes Event request limits
Limit Event floods and verify that required operational Events remain available.
Review Kubernetes HPA Object metric references
Distinguish the measured object from the workload being scaled.
Review Kubernetes image admission policy
Verify that required image policies are actually enforced at deployment.
Review Kubernetes NamespaceLifecycle admission settings
Keep the default control that prevents resource creation in inappropriate namespace states.
Review Kubernetes namespace LimitRange configuration
Define resource constraints appropriate for individual objects in the namespace.
Review Kubernetes namespace resource quotas
Manage namespace allocation separately from individual container limits.
Review Kubernetes NetworkPolicy Pod selection
Verify that the policy selects the intended namespace and Pods.
Review Kubernetes Pod and container security contexts
Specify the execution identity, permissions and filesystem protections each workload needs.
Review Kubernetes control plane profiling settings
Disable unnecessary profiling and restrict access to diagnostic endpoints that are needed.
Review Kubernetes Secret delivery through environment variables
Reduce secret exposure through output and debugging, and plan consumer updates during rotation.
Review Kubernetes NodePort access scope
Choose the required service entry path and restrict the networks that can use it.
Review Kubernetes Service targets and port mapping
Check selectors, ready Pods and the application’s actual listening port together.
Review Kubernetes kubelet event rate settings
Balance event visibility against API server load.
Review kubelet hostname override settings
Keep the node identity consistent with authentication and operational configuration.
Review Kubernetes audit log backup count
Choose the rotated-file count for actual log volume and retention needs.
Review Kubernetes audit log retention settings
Match actual audit record retention to investigation and operational needs.
Review Kubernetes audit log rotation size
Manage file size and backup count together to retain the records you need.
Review Kubernetes audit policy coverage
Record needed API activity while controlling sensitive data in request and response bodies.
Review Kubernetes Secret management
Choose secret management that meets access-control, rotation and audit requirements.