Description
An audit policy selects which Kubernetes API calls to record and at what level. Missing important resources or administrative operations can leave gaps in investigation records. Conversely, Request and RequestResponse levels can place sensitive request or response content in logs.
Rules are evaluated in order and the first match applies. Review API groups, users and verbs, along with resource names and earlier rules.
Potential impact
- Missing API records can make it harder to establish who performed an action.
- Excessive body logging can expose secrets through audit logs.
Remediation
- Consider Metadata for sensitive resources such as secrets, configmaps and tokenreviews to avoid logging their bodies. Set appropriate scope and levels for pods, deployments, and exec, portforward and proxy operations too.
- Configure the policy file and audit backend, then verify records with actual requests. Restrict log access and retention, and assess sensitive data and storage volume before enabling body logging.
Examples
These policies compare audit settings. The original empty rules list is not a valid audit policy. The revised policy still leaves unlisted requests unlogged, so review the complete policy requirements separately.
Before
apiVersion: audit.k8s.io/v1
kind: Policy
rules: []
The policy has no rules and can be rejected on loading. Do not treat it as a valid policy that merely records less.
After
apiVersion: audit.k8s.io/v1
kind: Policy
omitStages:
- RequestReceived
rules:
- level: Metadata
resources:
- group: ""
resources: ["secrets", "configmaps"]
- group: "authentication.k8s.io"
resources: ["tokenreviews"]
- level: Metadata
resources:
- group: ""
resources: ["pods"]
- group: "apps"
resources: ["deployments"]
- level: RequestResponse
resources:
- group: ""
resources: ["pods/exec", "pods/portforward", "pods/proxy", "services/proxy"]
tokenreviews uses the authentication.k8s.io group and deployments uses apps. Sensitive resources use Metadata; selected administrative operations use RequestResponse. This does not record all input and output of exec sessions.