制御プレーン
| セクション | 項目 | 説明 |
|---|---|---|
| 1.2 | API Server | 認証・認可、監査ログ、TLS、admission controller の設定 |
| 1.3 | Controller Manager | サービスアカウントのトークン、RotateKubeletServerCertificate、profiling の無効化 |
| 1.4 | Scheduler | profiling、バインド先アドレスなど |
| 2 | Etcd | TLS 証明書、クライアント・ピア間通信の保護、peer-auto-tls の無効化 |
| 3 | Control Plane Configuration | 認証とログに関する一般的な推奨事項 |
ワーカーノード
| セクション | 項目 | 説明 |
|---|---|---|
| 4.2 | Kubelet | 匿名認証のブロック、認可モード、TLS、読み取り専用ポートの無効化、streaming-connection-idle-timeout など |
ポリシー
| セクション | 項目 | 説明 |
|---|---|---|
| 5.1 | RBAC and Service Accounts | 最小権限、デフォルトの ServiceAccount のトークン自動マウントの無効化 |
| 5.2 | Pod Security Policies / Pod Security Standards | privileged・hostPath・hostNetwork・hostPID・hostIPC の制御、capability の最小化 |
| 5.3 | Network Policies and CNI | すべてのネームスペースへの NetworkPolicy の適用 |
| 5.4 | Secrets Management | 環境変数ではなく、ファイルや外部シークレットストアによる Secret の管理 |
| 5.7 | General Policies | ネームスペースの分離、securityContext の設定、デフォルト拒否のポリシー |