SV-242461r712739_rule
V-242461
SRG-APP-000516-CTR-001335
CNTR-K8-003280
CAT II
10
Edit the Kubernetes API Server manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Set the argument "--audit-policy-file" to "log file directory".
Change to the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Run the command:
grep -i audit-policy-file *
If the setting "audit-policy-file" is not set or is found in the Kubernetes API manifest file without valid content, this is a finding.
V-242461
False
CNTR-K8-003280
Change to the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Run the command:
grep -i audit-policy-file *
If the setting "audit-policy-file" is not set or is found in the Kubernetes API manifest file without valid content, this is a finding.
M
5376