Checks Performed
- Apply Security Context To Your Pods And Containers
- Apply Security Context Your Pods And Containers
- Azure Json File Ownership Set To Root Root
- Azure Json File Permissions Set To 644 Or More Restrictive
- Consider External Secret Storage
- Consider External Secret Storage
- Create Administrative Boundaries Between Resources Using Namespaces
- Create Administrative Boundaries Between Resources Using Namespaces
- Enable Audit Logs
- Enable Audit Logs
- Enable Image Vulnerability Scanning With Microsoft Defender
- Encrypt Traffic Https Load Balancers With Tls Certificates
- Encrypt Traffic To HTTPS Load Balancers With TLS Certificates
- Ensure Anonymous Auth Argument Is Disabled
- Ensure Authorization Mode Argument Is Not Set Always Allow
- Ensure Client Ca File Argument Is Set Appropriate
- Ensure Cluster Admin Role Is Only Used Where Required
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Nodes
- Ensure Clusters Are Created With Private Nodes
- Ensure Clusters Use Private Endpoint With Public Access Disabled
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Event Record Qps Argument Is Set 0 Level Which Ensures Appropriate Event Capture
- Ensure Hostname Override Argument Is Not Set
- Ensure Image Vulnerability Scanning Using Azure Defender Image Scanning Third Party Provider
- Ensure Kubeconfig File Permissions Are Restrictive
- Ensure Kubelet Configuration File Has Permissions Restrictive
- Ensure Kubelet Configuration File Ownership Is Set Root
- Ensure Kubelet Kubeconfig File Ownership Is Set Root
- Ensure Kubernetes Secrets Are Encrypted
- Ensure Kubernetes Secrets Are Encrypted
- Ensure Latest Cni Version Is Used
- Ensure Latest CNI Version Is Used
- Ensure Make Ptables Util Chains Argument Is Enabled
- Ensure Network Policy Is Enabled And Appropriate
- Ensure Network Policy Is Enabled And Set Appropriately
- Ensure Protect Kernel Defaults Argument Is Enabled
- Ensure Read Only Port Is Secured
- Ensure Rotate Certificates Argument Is Not Disabled
- Ensure Rotate Kubelet Server Certificate Argument Is Enabled
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Streaming Connection Idle Timeout Argument Is Not Set 0
- Ensure That All Namespaces Have Network Policies Defined
- Ensure That All Namespaces Network Policies Defined
- Ensure The Cluster-Admin Role Is Only Used Where Required
- Hostile Multi Tenant Workloads
- Kubelet Anonymous Auth Set To False
- Kubelet Authorization Mode Not Set To AlwaysAllow
- Kubelet Client CA File Set As Appropriate
- Kubelet Event Record QPS Set For Appropriate Event Capture
- Kubelet Kubeconfig File Ownership Set To Root Root
- Kubelet Kubeconfig File Permissions Set To 644 Or More Restrictive
- Kubelet Make IPTables Util Chains Set To True
- Kubelet Read Only Port Secured
- Kubelet Rotate Certificates Not Set To False
- Kubelet RotateKubeletServerCertificate Set To True
- Kubelet Streaming Connection Idle Timeout Not Set To Zero
- Limit Use Of The Bind, Impersonate And Escalate Permissions
- Manage Kubernetes Rbac Users With Azure Ad
- Manage Kubernetes RBAC Users With Azure AD
- Minimize Access Secrets
- Minimize Access To Create Persistent Volumes
- Minimize Access To Create Pods
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Access To The Approval Sub-Resource Of CertificateSigningRequests
- Minimize Access To The Proxy Sub-Resource Of Nodes
- Minimize Access To The Service Account Token Creation
- Minimize Access To Webhook Configuration Objects
- Minimize Cluster Access Read Only Azure Container Registry
- Minimize Cluster Access To Read-Only For Azure Container Registry
- Minimize Container Registries Only Those Approved
- Minimize Container Registries To Only Those Approved
- Minimize The Admission Containers Wishing Share The Host Ipc Namespace
- Minimize The Admission Containers Wishing Share The Host Network Namespace
- Minimize The Admission Containers With Added Capabilities
- Minimize The Admission Containers With Allowprivilegeescalation
- Minimize The Admission Containers With Capabilities Assigned
- Minimize The Admission Containers With Net_Raw Capability
- Minimize The Admission Of Containers Sharing The Host IPC Namespace
- Minimize The Admission Of Containers Sharing The Host Network Namespace
- Minimize The Admission Of Containers Sharing The Host Process ID Namespace
- Minimize The Admission Of Containers Wishing To Share The Host Process Id Namespace
- Minimize The Admission Of Containers With allowPrivilegeEscalation
- Minimize The Admission Of Privileged Containers
- Minimize The Admission Privileged Container
- Minimize The Admission Root Containers
- Minimize User Access Azure Container Registry
- Minimize User Access To Azure Container Registry
- Minimize Wildcard Use In Roles And ClusterRoles
- Minimize Wildcard Use Roles And Clusterroles
- Prefer Using Dedicated AKS Service Accounts
- Prefer Using Dedicated Aks Service Accounts
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Prefer Using Secrets Files Over Secrets As Environment Variables
- Restrict Access To The Control Plane Endpoint
- Restrict Untrusted Workloads
- The Default Namespace Should Not Be Used
- The Default Namespace Should Not Be Used
- Use Azure RBAC For Kubernetes Authorization
- Use Azure Rbac Kubernetes Authorization
- Verify That Admission Controllers Are Working Expected

