2018-10-09 22:57:37 +00:00
---
controls :
2019-10-14 14:37:10 +00:00
version : "1.11"
id : "2"
text : Worker Node Security Configuration
2018-10-09 22:57:37 +00:00
type : "node"
groups :
2019-10-14 14:37:10 +00:00
- id : "2.1"
text : Kubelet
2018-10-09 22:57:37 +00:00
checks :
- id : 2.1 .1
2019-10-14 14:37:10 +00:00
text : Ensure that the --allow-privileged argument is set to false (Scored)
audit : "ps -fC $kubeletbin "
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --allow-privileged
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : false
remediation : |
2019-02-27 21:28:02 +00:00
Edit the kubelet service file $kubeletsvc
2018-10-09 22:57:37 +00:00
on each worker node and set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable.
--allow-privileged=false
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .2
2019-10-14 14:37:10 +00:00
text : Ensure that the --anonymous-auth argument is set to false (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --anonymous-auth
path : '{.authentication.anonymous.enabled}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : false
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set authentication: anonymous : enabled to
false .
If using executable arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable.
2018-10-09 22:57:37 +00:00
--anonymous-auth=false
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .3
2019-10-14 14:37:10 +00:00
text : Ensure that the --authorization-mode argument is not set to AlwaysAllow (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --authorization-mode
path : '{.authorization.mode}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : nothave
2019-10-14 14:37:10 +00:00
value : AlwaysAllow
2018-10-09 22:57:37 +00:00
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set authorization : mode to Webhook.
If using executable arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_AUTHZ_ARGS variable.
2018-10-09 22:57:37 +00:00
--authorization-mode=Webhook
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .4
2019-10-14 14:37:10 +00:00
text : Ensure that the --client-ca-file argument is set as appropriate (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --client-ca-file
path : '{.authentication.x509.clientCAFile}'
2018-10-09 22:57:37 +00:00
set : true
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set authentication: x509 : clientCAFile to
the location of the client CA file.
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_AUTHZ_ARGS variable.
2018-10-09 22:57:37 +00:00
--client-ca-file=<path/to/client-ca-file>
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .5
2019-10-14 14:37:10 +00:00
text : Ensure that the --read-only-port argument is set to 0 (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --read-only-port
path : '{.readOnlyPort}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : 0
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set readOnlyPort to 0 .
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable.
2018-10-09 22:57:37 +00:00
--read-only-port=0
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .6
2019-10-14 14:37:10 +00:00
text : Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --streaming-connection-idle-timeout
path : '{.streamingConnectionIdleTimeout}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : noteq
value : 0
2019-10-14 14:37:10 +00:00
- flag : --streaming-connection-idle-timeout
path : '{.streamingConnectionIdleTimeout}'
2019-08-07 10:33:09 +00:00
set : false
2019-10-14 14:37:10 +00:00
bin_op : or
2018-10-09 22:57:37 +00:00
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set streamingConnectionIdleTimeout to a
value other than 0.
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable.
2018-10-09 22:57:37 +00:00
--streaming-connection-idle-timeout=5m
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .7
2019-10-14 14:37:10 +00:00
text : Ensure that the --protect-kernel-defaults argument is set to true (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --protect-kernel-defaults
path : '{.protectKernelDefaults}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : true
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set protectKernelDefaults : true .
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable.
2018-10-09 22:57:37 +00:00
--protect-kernel-defaults=true
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .8
2019-10-14 14:37:10 +00:00
text : Ensure that the --make-iptables-util-chains argument is set to true (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --make-iptables-util-chains
path : '{.makeIPTablesUtilChains}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : true
2019-10-14 14:37:10 +00:00
- flag : --make-iptables-util-chains
path : '{.makeIPTablesUtilChains}'
2018-11-07 23:57:38 +00:00
set : false
2019-10-14 14:37:10 +00:00
bin_op : or
2018-10-09 22:57:37 +00:00
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set makeIPTablesUtilChains : true .
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
remove the --make-iptables-util-chains argument from the
2018-10-09 22:57:37 +00:00
KUBELET_SYSTEM_PODS_ARGS variable.
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .9
2019-10-14 14:37:10 +00:00
text : Ensure that the --hostname-override argument is not set (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --hostname-override
path : '{.hostnameOverride}'
2018-10-09 22:57:37 +00:00
set : false
remediation : |
2019-02-27 21:28:02 +00:00
Edit the kubelet service file $kubeletsvc
2018-10-09 22:57:37 +00:00
on each worker node and remove the --hostname-override argument from the
KUBELET_SYSTEM_PODS_ARGS variable.
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .10
2019-10-14 14:37:10 +00:00
text : Ensure that the --event-qps argument is set to 0 (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --event-qps
path : '{.eventRecordQPS}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : 0
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set eventRecordQPS : 0 .
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameter in KUBELET_SYSTEM_PODS_ARGS variable.
2018-10-09 22:57:37 +00:00
--event-qps=0
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .11
2019-10-14 14:37:10 +00:00
text : Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --tls-cert-file
path : '{.tlsCertFile}'
2018-10-09 22:57:37 +00:00
set : true
2019-10-14 14:37:10 +00:00
- flag : --tls-private-key-file
path : '{.tlsPrivateKeyFile}'
2018-10-09 22:57:37 +00:00
set : true
2019-10-14 14:37:10 +00:00
bin_op : and
2018-10-09 22:57:37 +00:00
remediation : |
2018-10-13 19:48:50 +00:00
If using a Kubelet config file, edit the file to set tlsCertFile to the location of the certificate
file to use to identify this Kubelet, and tlsPrivateKeyFile to the location of the
corresponding private key file.
If using command line arguments, edit the kubelet service file
2019-02-27 21:28:02 +00:00
$kubeletsvc on each worker node and
2018-10-13 19:48:50 +00:00
set the below parameters in KUBELET_CERTIFICATE_ARGS variable.
2018-10-09 22:57:37 +00:00
--tls-cert-file=<path/to/tls-certificate-file>
file=<path/to/tls-key-file>
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .12
2019-10-14 14:37:10 +00:00
text : Ensure that the --cadvisor-port argument is set to 0 (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --cadvisor-port
path : '{.cadvisorPort}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : 0
2019-10-14 14:37:10 +00:00
- flag : --cadvisor-port
path : '{.cadvisorPort}'
2018-10-13 19:48:50 +00:00
set : false
2019-10-14 14:37:10 +00:00
bin_op : or
2018-10-09 22:57:37 +00:00
remediation : |
2019-02-27 21:28:02 +00:00
Edit the kubelet service file $kubeletsvc
2018-10-09 22:57:37 +00:00
on each worker node and set the below parameter in KUBELET_CADVISOR_ARGS variable.
--cadvisor-port=0
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .13
2019-10-14 14:37:10 +00:00
text : Ensure that the --rotate-certificates argument is not set to false (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --rotate-certificates
path : '{.rotateCertificates}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : true
2019-10-14 14:37:10 +00:00
- flag : --rotate-certificates
path : '{.rotateCertificates}'
2019-08-28 08:27:56 +00:00
set : false
2019-10-14 14:37:10 +00:00
bin_op : or
2018-10-09 22:57:37 +00:00
remediation : |
If using a Kubelet config file, edit the file to add the line rotateCertificates : true .
2019-10-14 14:37:10 +00:00
If using command line arguments, edit the kubelet service file $kubeletsvc
2018-10-13 19:48:50 +00:00
on each worker node and add --rotate-certificates=true argument to the KUBELET_CERTIFICATE_ARGS variable.
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
2018-10-09 22:57:37 +00:00
scored : true
- id : 2.1 .14
2019-10-14 14:37:10 +00:00
text : Ensure that the RotateKubeletServerCertificate argument is set to true (Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : RotateKubeletServerCertificate
path : '{.featureGates.RotateKubeletServerCertificate}'
set : true
2018-10-09 22:57:37 +00:00
compare :
op : eq
value : true
remediation : |
2019-02-27 21:28:02 +00:00
Edit the kubelet service file $kubeletsvc
2018-10-09 22:57:37 +00:00
on each worker node and set the below parameter in KUBELET_CERTIFICATE_ARGS variable.
--feature-gates=RotateKubeletServerCertificate=true
Based on your system, restart the kubelet service. For example :
systemctl daemon-reload
systemctl restart kubelet.service
scored : true
- id : 2.1 .15
2019-10-14 14:37:10 +00:00
text : Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Not Scored)
audit : "ps -fC $kubeletbin"
audit_config : "cat $kubeletconf"
2018-10-09 22:57:37 +00:00
tests :
test_items :
2019-10-14 14:37:10 +00:00
- flag : --tls-cipher-suites
path : '{.tlsCipherSuites}'
set : true
2018-10-09 22:57:37 +00:00
compare :
2019-09-03 12:36:47 +00:00
op : valid_elements
2019-10-14 14:37:10 +00:00
value : TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256
2018-10-09 22:57:37 +00:00
remediation : |
2019-06-25 14:18:46 +00:00
If using a Kubelet config file, edit the file to set TLSCipherSuites : to TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256
2019-08-30 14:21:41 +00:00
If using executable arguments, edit the kubelet service file $kubeletsvc on each worker node and set the below parameter.
2018-11-28 11:14:49 +00:00
--tls-cipher-suites=TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_256_GCM_SHA384,TLS_RSA_WITH_AES_128_GCM_SHA256
2018-10-09 22:57:37 +00:00
scored : false
2019-10-14 14:37:10 +00:00
- id : "2.2"
text : Configuration Files
2018-10-09 22:57:37 +00:00
checks :
2019-10-14 14:37:10 +00:00
- id : 2.2 .1
text : Ensure that the kubelet.conf file permissions are set to 644 or more restrictive (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletkubeconfig; then stat -c %a $kubeletkubeconfig; fi' ' '
tests :
test_items :
- flag : "644"
set : true
compare :
op : eq
value : "644"
- flag : "640"
set : true
compare :
op : eq
value : "640"
- flag : "600"
set : true
compare :
op : eq
value : "600"
bin_op : or
remediation : |
Run the below command (based on the file location on your system) on the each worker
node. For example,
chmod 644 $kubeletkubeconfig
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .2
text : Ensure that the kubelet.conf file ownership is set to root:root (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletkubeconfig; then stat -c %U:%G $kubeletkubeconfig; fi' ' '
tests :
test_items :
- flag : root:root
set : true
compare :
op : eq
value : root:root
remediation : |
Run the below command (based on the file location on your system) on the each worker
node. For example,
chown root:root $kubeletkubeconfig
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .3
text : Ensure that the kubelet service file permissions are set to 644 or more restrictive (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletsvc; then stat -c %a $kubeletsvc; fi' ' '
tests :
test_items :
- flag : "644"
set : true
compare :
op : eq
value : "644"
- flag : "640"
set : true
compare :
op : eq
value : "640"
- flag : "600"
set : true
compare :
op : eq
value : "600"
bin_op : or
remediation : |
Run the below command (based on the file location on your system) on the each worker
node. For example,
chmod 755 $kubeletsvc
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .4
text : Ensure that the kubelet service file ownership is set to root:root (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletsvc; then stat -c %U:%G $kubeletsvc; fi' ' '
tests :
test_items :
- flag : root:root
set : true
remediation : |
Run the below command (based on the file location on your system) on the each worker
node. For example,
chown root:root $kubeletsvc
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .5
text : Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Scored)
audit : '/bin/sh -c ' 'if test -e $proxykubeconfig; then stat -c %a $proxykubeconfig; fi' ' '
tests :
test_items :
- flag : "644"
set : true
compare :
op : eq
value : "644"
- flag : "640"
set : true
compare :
op : eq
value : "640"
- flag : "600"
set : true
compare :
op : eq
value : "600"
bin_op : or
remediation : |
Run the below command (based on the file location on your system) on the each worker
node. For example,
chmod 644 $proxykubeconfig
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .6
text : Ensure that the proxy kubeconfig file ownership is set to root:root (Scored)
audit : '/bin/sh -c ' 'if test -e $proxykubeconfig; then stat -c %U:%G $proxykubeconfig; fi' ' '
tests :
test_items :
- flag : root:root
set : true
remediation : |
Run the below command (based on the file location on your system) on the each worker
node. For example,
chown root:root $proxykubeconfig
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .7
text : Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Scored)
type : manual
remediation : |
Run the following command to modify the file permissions of the --client-ca-file
chmod 644 <filename>
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .8
text : Ensure that the client certificate authorities file ownership is set to root:root (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletcafile; then stat -c %U:%G $kubeletcafile; fi' ' '
tests :
test_items :
- flag : root:root
set : true
compare :
op : eq
value : root:root
remediation : |
Run the following command to modify the ownership of the --client-ca-file .
chown root:root <filename>
scored : true
2018-10-09 22:57:37 +00:00
2019-10-14 14:37:10 +00:00
- id : 2.2 .9
text : Ensure that the kubelet configuration file ownership is set to root:root (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletconf; then stat -c %U:%G $kubeletconf; fi' ' '
tests :
test_items :
- flag : root:root
set : true
remediation : |
Run the following command (using the config file location identied in the Audit step)
chown root:root $kubeletconf
scored : true
- id : 2.2 .10
text : Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Scored)
audit : '/bin/sh -c ' 'if test -e $kubeletconf; then stat -c %a $kubeletconf; fi' ' '
tests :
test_items :
- flag : "644"
set : true
compare :
op : eq
value : "644"
- flag : "640"
set : true
compare :
op : eq
value : "640"
- flag : "600"
set : true
compare :
op : eq
value : "600"
bin_op : or
remediation : |
Run the following command (using the config file location identied in the Audit step)
chmod 644 $kubeletconf
scored : true