Skip to main content

More Info:

The special group system:masters should not be used to grant permissions to any user or service account, except where strictly necessary (e.g. bootstrapping access prior to RBAC being fully available)

Risk Level

High

Address

Security

Compliance Standards

  • CIS Kubernetes

Triage and Remediation

Remediation

Using Console

Review a list of all credentials which have access to the cluster and ensure that thegroup system:masters is not used.

Additional Reading: