Audit policy file is not configured

Configure the audit policy and output to retain necessary API activity records.

Description

When --audit-policy-file is omitted from kube-apiserver, audit events are not logged. Specifying an output path alone is insufficient.

Manage the resources and levels to record through an audit policy. This provides consistent information for incident response and audit trails.

Potential impact

  • Important API requests may not be recorded.
  • Investigations may lack metadata such as the user, time and operation.
  • Inconsistent policies across environments can weaken operational oversight.

Remediation

  • Set the kube-apiserver --audit-policy-file path.
  • Define recording levels and exclusions. Avoid unnecessarily logging sensitive request bodies, such as Secrets.
  • Configure the policy together with file or webhook output, and verify actual events after deployment.

Examples

These are API server argument excerpts. Match the image to the actual cluster version and mount a valid policy at the example path. Output and other API server settings are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: []

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--audit-policy-file=/etc/kubernetes/audit-policy.yaml"]

Explanation:

  • Before: No audit policy file is specified, so audit events are not logged.
  • After: The policy file is specified. Verify that its rules and the output configuration actually take effect.

References