Checks Performed
- An Admission Policy Engine Should Enforce Workload Policy
- API Server Audit Log Maxage Should Be 30 Or More
- API Server Audit Log Maxbackup Should Be 10 Or More
- API Server Audit Log Maxsize Should Be 100 Or More
- API Server Authorization Mode Should Include Node
- API Server Authorization Mode Should Include RBAC
- API Server Authorization Mode Should Not Be AlwaysAllow
- API Server Encryption Providers Should Be Appropriately Configured
- API Server Pod Specification File Ownership Should Be root:root
- API Server Pod Specification File Permissions Should Be 600 Or More Restrictive
- API Server Request Timeout Should Be Set As Appropriate
- API Server Service Account Key File Should Be Set
- API Server Service Account Lookup Should Be True
- API Server Should Disable Anonymous Authentication
- API Server Should Disable Profiling
- API Server Should Disable Service Account Extend Token Expiration
- API Server Should Enable The AlwaysPullImages Admission Plugin
- API Server Should Enable The DenyServiceExternalIPs Admission Plugin
- API Server Should Enable The EventRateLimit Admission Plugin
- API Server Should Enable The NamespaceLifecycle Admission Plugin
- API Server Should Enable The NodeRestriction Admission Plugin
- API Server Should Enable The ServiceAccount Admission Plugin
- API Server Should Not Enable The AlwaysAdmit Admission Plugin
- API Server Should Set An Audit Log Path
- API Server Should Set Client CA File
- API Server Should Set Encryption Provider Config
- API Server Should Set Etcd CA File
- API Server Should Set Etcd Client Certificate And Key
- API Server Should Set Kubelet Certificate Authority
- API Server Should Set Kubelet Client Certificate And Key
- API Server Should Set TLS Certificate And Private Key
- API Server Should Use Strong Cryptographic Ciphers
- API Server Token Auth File Should Not Be Set
- Apply Security Context For Pods And Containers
- Apply SecurityContext To Your Pods And Containers
- Audit Logging Should Be Enabled And Shipped Off-Cluster
- Avoid Use Of System Masters Group
- Avoid Use Of The System:Masters Group
- Bootstrap Token Authentication Should Not Be Used For Users
- Certificate Authorities File Permissions Set To 644 Or More Restrictive
- Client Certificate Authentication Should Not Be Used For Users
- Client Certificate Authentication Should Not Be Used For Users
- Client Certificate Authorities File Ownership Set To root:root
- Configure Image Provenance ImagePolicyWebhook Admission Controller
- Configure Image Provenance Using ImagePolicyWebhook Admission Controller
- Consider External Secret Storage
- Consider External Secret Storage
- Container Images Should Not Use The latest Or Untagged Tag
- Container Network Interface File Ownership Should Be root:root
- Container Network Interface File Permissions Should Be 600 Or More Restrictive
- Containers Should Define Liveness And Readiness Probes
- Containers Should Disallow Privilege Escalation
- Containers Should Drop All Linux Capabilities
- Containers Should Not Run In Privileged Mode
- Containers Should Run As Non-Root
- Containers Should Set CPU And Memory Limits
- Containers Should Set CPU And Memory Requests
- Containers Should Use A Read-Only Root Filesystem
- Controller Manager Bind Address Should Be 127.0.0.1
- Controller Manager Kubeconfig File Ownership Should Be root:root
- Controller Manager Kubeconfig File Permissions Should Be 600 Or More Restrictive
- Controller Manager Pod Specification File Ownership Should Be root:root
- Controller Manager Pod Specification File Permissions Should Be 600 Or More Restrictive
- Controller Manager Should Disable Profiling
- Controller Manager Should Enable RotateKubeletServerCertificate
- Controller Manager Should Set Root CA File
- Controller Manager Should Set Service Account Private Key File
- Controller Manager Should Use Individual Service Account Credentials
- Controller Manager Terminated Pod GC Threshold Should Be Set
- Create Administrative Boundaries Between Resources Namespaces
- Create Administrative Boundaries Between Resources Using Namespaces
- Default Administrative Credential File Ownership Should Be root:root
- Default Administrative Credential File Permissions Should Be 600
- Ensure A Unique Certificate Authority Is Used For Etcd
- Ensure Admin Configuration File Ownership Is Root
- Ensure Admin Configuration File Permissions Are 600
- Ensure Admission Control Plugin AlwaysAdmit Is Not Set
- Ensure Admission Control Plugin AlwaysPullImages Is Set
- Ensure Admission Control Plugin EventRateLimit Is Set
- Ensure Admission Control Plugin NamespaceLifecycle Is Set
- Ensure Admission Control Plugin NodeRestriction Is Set
- Ensure Admission Control Plugin SecurityContextDeny Is Set If PodSecurityPolicy Is Not Used
- Ensure Admission Control Plugin ServiceAccount Is Set
- Ensure All Namespaces Have NetworkPolicies Defined
- Ensure All Namespaces Network Policies Defined
- Ensure Anonymous Auth Argument Is Disabled
- Ensure Anonymous Auth Argument Is False
- Ensure API Server Only Uses Strong Cryptographic Ciphers
- Ensure API Server Pod Specification File Ownership Is Root
- Ensure API Server Pod Specification Permissions Are Restrictive
- Ensure Audit Log Maxage Argument Is Appropriate
- Ensure Audit Log Maxbackup Argument Is Appropriate
- Ensure Audit Log Path Argument Is Set
- Ensure Audit Policy Covers Key Security Concerns
- Ensure Audit-Log-Maxsize Argument Is Appropriate
- Ensure Authorization Mode Argument Includes Node
- Ensure Authorization Mode Argument Includes RBAC
- Ensure Authorization Mode Argument Is Not AlwaysAllow
- Ensure Authorization Mode Argument Is Not AlwaysAllow
- Ensure Auto Tls Argument Is Disabled
- Ensure Bind Address Argument Is 127.0.0.1
- Ensure Bind Address Argument Is 127.0.0.1
- Ensure Cert File And Key File Arguments Are Appropriate
- Ensure Certificate Authorities File Permissions Are Restrictive
- Ensure Client Ca File Argument Is Appropriate
- Ensure Client Ca File Argument Is Appropriate
- Ensure Client Cert Auth Argument Is Enabled
- Ensure Client Certificate Authorities File Ownership Is Root
- Ensure Cluster Active Policy Control Mechanisms In Place
- Ensure Cluster Admin Role Is Only Used Where Required
- Ensure CNI Supports Network Policies
- Ensure Container Network Interface File Ownership Is Root
- Ensure Container Network Interface File Permissions Are Restrictive
- Ensure Controller Manager Configuration File Ownership Is Root
- Ensure Controller Manager Configuration File Permissions Are Restrictive
- Ensure Controller Manager Pod Specification File Ownership Is Root
- Ensure Controller Manager Pod Specification File Permissions Are Restrictive
- Ensure Controller Profiling Argument Is False
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Default Service Accounts Are Not Actively Used.
- Ensure DenyServiceExternalIPs Is Not Set
- Ensure Encryption Provider Config Argument Is Appropriate
- Ensure Encryption Providers Are Appropriately Configured
- Ensure Etcd Auto-TLS Argument Is Not Set To True
- Ensure Etcd Cafile Argument Is Appropriate
- Ensure Etcd Cert-File And Key-File Arguments Are Set
- Ensure Etcd Certfile And Etcd Keyfile Arguments Are Appropriate
- Ensure Etcd Client-Cert-Auth Argument Is Set To True
- Ensure Etcd Data Directory Ownership Is Etcd
- Ensure Etcd Data Directory Permissions Are Restrictive
- Ensure Etcd Peer-Auto-TLS Argument Is Not Set To True
- Ensure Etcd Peer-Cert-File And Peer-Key-File Arguments Are Set
- Ensure Etcd Peer-Client-Cert-Auth Argument Is Set To True
- Ensure Etcd Pod Specification File Ownership Is Root
- Ensure Etcd Pod Specification File Permissions Are Restrictive
- Ensure EventRecordQPS Argument Is Level Which Ensures Appropriate Event Capture
- Ensure Hostname Override Argument Is Disabled
- Ensure Kubeconfig Kubelet Conf File Ownership Is Root
- Ensure Kubeconfig Kubelet Conf File Permissions Are Restrictive
- Ensure Kubelet Certificate Authority Argument Is Appropriate
- Ensure Kubelet Client Certificate And Key Arguments Are Appropriate
- Ensure Kubelet Config File Ownership Is Root
- Ensure Kubelet Config File Permissions Are Restrictive
- Ensure Kubelet Https Argument Is Enabled
- Ensure Kubelet Only Makes Use Strong Cryptographic Ciphers
- Ensure Kubelet Service File Ownership Is Root
- Ensure Kubelet Service File Permissions Are Restrictive
- Ensure Kubernetes PKI Certificate File Permissions Are Restrictive
- Ensure Kubernetes PKI Directory And File Ownership Is Root
- Ensure Kubernetes PKI Key File Permissions Are 600
- Ensure Make Iptables Util Chains Argument Is Enabled
- Ensure Minimal Audit Policy Is Created
- Ensure Peer Auto Tls Argument Is Disabled
- Ensure Peer Cert File And Peer Key File Arguments Are Appropriate
- Ensure Peer Client Cert Auth Argument Is Enabled
- Ensure Profiling Argument Is Disabled
- Ensure Profiling Argument Is Set False
- Ensure Protect Kernel Defaults Argument Is Enabled
- Ensure Request Timeout Argument Is Appropriate
- Ensure Root CA File Argument Is Appropriate
- Ensure Rotate Certificates Argument Is Enabled
- Ensure Rotate Kubelet Server Certificate Argument Is Enabled
- Ensure Scheduler Configuration File Ownership Is Root
- Ensure Scheduler Configuration File Permissions Are Restrictive
- Ensure Scheduler Pod Specification File Ownership Is Root
- Ensure Scheduler Pod Specification File Permissions Are Restrictive
- Ensure Seccomp Profile Is docker Default Your Pod Definitions
- Ensure Secure Port Argument Is Not Set 0
- Ensure Service Account key File Argument Is Appropriate
- Ensure Service Account Lookup Argument Is Set True
- Ensure Service Account Private Key File Argument Is Appropriate
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Streaming Connection Idle Timeout Argument Is Not Set 0
- Ensure Terminated Pod GC Threshold Argument Appropriate
- Ensure That A Minimal Audit Policy Is Created
- Ensure That The Audit Policy Covers Key Security Concerns
- Ensure The Cluster Has At Least One Active Policy Control Mechanism
- Ensure The Cluster-Admin Role Is Only Used Where Required
- Ensure The CNI In Use Supports NetworkPolicies
- Ensure The Seccomp Profile Is Set To docker/default In Pod Definitions
- Ensure Tls Cert File And Tls Private Key File Arguments Are Appropriate
- Ensure Tls Cert File And Tls Private Key File Arguments Are Appropriate
- Ensure Token Auth File Parameter Is Not Set
- Ensure Unique Certificate Authority Is Used For Etcd
- Ensure Use Service Account Credentials Argument Is Enabled
- Etcd Data Directory Ownership Should Be etcd:etcd
- Etcd Data Directory Permissions Should Be 700 Or More Restrictive
- Etcd Pod Specification File Ownership Should Be root:root
- Etcd Pod Specification File Permissions Should Be 600 Or More Restrictive
- Every Non-System Namespace Should Have A Default-Deny NetworkPolicy
- If Proxy Kubeconfig File Exists Ensure Ownership Is Root
- If Proxy Kubeconfig File Exists Ensure Permissions Are Restrictive
- Kube-Proxy Metrics Service Bound To Localhost
- Kubelet Anonymous Auth Argument Set To False
- Kubelet Authorization Mode Not Set To AlwaysAllow
- Kubelet Client CA File Argument Set As Appropriate
- Kubelet config.yaml File Ownership Set To root:root
- Kubelet config.yaml File Permissions Set To 600 Or More Restrictive
- Kubelet Event Record QPS Set To Ensure Appropriate Event Capture
- Kubelet Hostname Override Argument Not Set
- Kubelet Kubeconfig File Ownership Set To root:root
- Kubelet Kubeconfig File Permissions Set To 600 Or More Restrictive
- Kubelet Make Iptables Util Chains Argument Set To True
- Kubelet Only Makes Use Of Strong Cryptographic Ciphers
- Kubelet Pod PIDs Limit Is Set
- Kubelet Read Only Port Argument Set To 0
- Kubelet Rotate Certificates Argument Not Set To False
- Kubelet RotateKubeletServerCertificate Argument Set To True
- Kubelet Seccomp Default Parameter Set To True
- Kubelet Service File Ownership Set To root:root
- Kubelet Service File Permissions Set To 600 Or More Restrictive
- Kubelet Streaming Connection Idle Timeout Not Set To 0
- Kubelet TLS Cert File And Private Key File Arguments Set As Appropriate
- Kubernetes PKI Certificate File Permissions Should Be 644 Or More Restrictive
- Kubernetes PKI Directory And File Ownership Should Be root:root
- Kubernetes PKI Key File Permissions Should Be 600
- Limit Use Of Bind Impersonate And Escalate Permissions Kubernetes Cluster
- Limit Use Of The Bind, Impersonate And Escalate Permissions
- Minimize Access To Create Persistent Volumes
- Minimize Access To Create Pods
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Access To Secrets
- Minimize Access To Service Account Token Creation
- Minimize Access To The Approval Sub-Resource Of CertificateSigningRequests
- Minimize Access To The Proxy Sub-Resource Of Nodes
- Minimize Access To Webhook Configuration Objects
- Minimize Admission Containers AllowPrivilegeEscalation
- Minimize Admission Containers Wishing Host IPC Namespace
- Minimize Admission Containers Wishing Host Network Namespace
- Minimize Admission Containers Wishing Host Process ID Namespace
- Minimize Admission Of Containers Added Capabilities
- Minimize Admission Of Containers Capabilities Assigned
- Minimize Admission Of Containers HostPorts
- Minimize Admission Of Containers With NET_RAW Capability
- Minimize Admission Of HostPath Volumes
- Minimize Admission Of Privileged Containers
- Minimize Admission Of Root Containers
- Minimize Admission Of Windows HostProcess Containers
- Minimize The Admission Of Containers Sharing The Host IPC Namespace
- Minimize The Admission Of Containers Sharing The Host Network Namespace
- Minimize The Admission Of Containers Sharing The Host Process ID Namespace
- Minimize The Admission Of Containers Which Use HostPorts
- Minimize The Admission Of Containers With allowPrivilegeEscalation
- Minimize The Admission Of Containers With Capabilities Assigned
- Minimize The Admission Of Containers With The NET_RAW Capability
- Minimize The Admission Of HostPath Volumes
- Minimize The Admission Of Privileged Containers
- Minimize The Admission Of Root Containers
- Minimize The Admission Of Windows HostProcess Containers
- Minimize Wildcard Use In Roles And ClusterRoles
- Minimize Wildcard Use Roles And ClusterRoles
- Multi-Replica Deployments Should Have A PodDisruptionBudget
- Mutable Image Tags Should Use imagePullPolicy Always
- Namespaces Should Enforce Pod Security Admission Baseline Or Stricter
- No RoleBinding Should Grant Access To Anonymous Or Unauthenticated Users
- No ServiceAccount Should Be Bound To cluster-admin
- No Workloads Should Run In The default Namespace
- Pods Should Be Managed By A Controller
- Pods Should Not Mount HostPath Volumes
- Pods Should Not Share Host Namespaces
- Pods That Do Not Use The API Should Disable Token Automount
- pods/exec Should Not Be Granted To Broad Subjects
- Prefer Bound Projected ServiceAccount Tokens Over Secret Tokens
- Prefer Secrets Files Over Secrets Environment Variables
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Proxy Kubeconfig File Ownership Set To root:root
- Proxy Kubeconfig File Permissions Set To 600 Or More Restrictive
- Scheduler Bind Address Should Be 127.0.0.1
- Scheduler Kubeconfig File Ownership Should Be root:root
- Scheduler Kubeconfig File Permissions Should Be 600 Or More Restrictive
- Scheduler Pod Specification File Ownership Should Be root:root
- Scheduler Pod Specification File Permissions Should Be 600 Or More Restrictive
- Scheduler Should Disable Profiling
- Secrets Should Be Encrypted At Rest
- Sensitive Values Should Not Be Passed As Literal Env Vars
- Service Account Token Authentication Should Not Be Used For Users
- Tenant Namespaces Should Have A ResourceQuota
- The Default Namespace Should Not Be Used
- The Default Namespace Should Not Used
- Verify Read Only Port Argument Is Set 0
- Verify RotateKubeletServerCertificate Argument Is Enabled

