Control Plane
| 섹션 | 항목 | 설명 |
|---|---|---|
| 1.2 | API Server | 인증·인가, 감사 로깅, TLS, admission controller 구성 |
| 1.3 | Controller Manager | 서비스 어카운트 토큰, RotateKubeletServerCertificate, profiling 비활성화 |
| 1.4 | Scheduler | profiling·바인드 주소 등 |
| 2 | Etcd | TLS 인증서, 클라이언트·피어 통신 보호, peer-auto-tls 차단 |
| 3 | Control Plane Configuration | 인증·로깅 일반 권고 |
Worker Node
| 섹션 | 항목 | 설명 |
|---|---|---|
| 4.2 | Kubelet | 익명 인증 차단, 인가 모드, TLS, 읽기 전용 포트 차단, streaming-connection-idle-timeout 등 |
Policies
| 섹션 | 항목 | 설명 |
|---|---|---|
| 5.1 | RBAC and Service Accounts | 최소 권한 원칙, 기본 ServiceAccount 토큰 자동 마운트 차단 |
| 5.2 | Pod Security Policies / Pod Security Standards | privileged·hostPath·hostNetwork·hostPID·hostIPC 제어, Capabilities 최소화 |
| 5.3 | Network Policies and CNI | 모든 네임스페이스에 NetworkPolicy 적용 |
| 5.4 | Secrets Management | Secret을 환경 변수보다 파일·외부 시크릿 저장소로 관리 |
| 5.7 | General Policies | 네임스페이스 분리, securityContext 적용, 기본 deny 방향 정책 |