SV-242392r712532_rule
V-242392
SRG-APP-000033-CTR-000095
CNTR-K8-000380
CAT I
10
Edit the Kubernetes Kubelet file in the/etc/sysconfig/ directory on the Kubernetes Master and Worker nodes.
Set the argument --authorization-mode to "Webhook".
Restart each kubelet service after the change is made using the command:
service kubelet restart
Change to the /etc/sysconfig/ directory on the Kubernetes Master Node. Run the command:
grep -i authorization-mode kubelet
On each Worker node, change to the /etc/sysconfig/ directory. Run the command:
grep -i authorization-mode kubelet
If authorization-mode is missing or is set to "AllowAlways" on the Master node or any of the Worker nodes, this is a finding.
V-242392
False
CNTR-K8-000380
Change to the /etc/sysconfig/ directory on the Kubernetes Master Node. Run the command:
grep -i authorization-mode kubelet
On each Worker node, change to the /etc/sysconfig/ directory. Run the command:
grep -i authorization-mode kubelet
If authorization-mode is missing or is set to "AllowAlways" on the Master node or any of the Worker nodes, this is a finding.
M
5376