Description
When --audit-policy-file is omitted from kube-apiserver, audit events are not logged. Specifying an output path alone is insufficient.
Manage the resources and levels to record through an audit policy. This provides consistent information for incident response and audit trails.
Potential impact
- Important API requests may not be recorded.
- Investigations may lack metadata such as the user, time and operation.
- Inconsistent policies across environments can weaken operational oversight.
Remediation
- Set the kube-apiserver
--audit-policy-filepath. - Define recording levels and exclusions. Avoid unnecessarily logging sensitive request bodies, such as Secrets.
- Configure the policy together with file or webhook output, and verify actual events after deployment.
Examples
These are API server argument excerpts. Match the image to the actual cluster version and mount a valid policy at the example path. Output and other API server settings are omitted.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: []
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--audit-policy-file=/etc/kubernetes/audit-policy.yaml"]
Explanation:
- Before: No audit policy file is specified, so audit events are not logged.
- After: The policy file is specified. Verify that its rules and the output configuration actually take effect.