More Info:
The etcd server must be configured with the —cert-file and —key-file arguments so that client-to-server traffic is served over TLS. Without them, etcd traffic carrying all cluster state and secrets is unencrypted.Risk Level
CriticalAddress
SecurityCompliance Standards
- CIS Kubernetes
Triage and Remediation
- Remediation
Remediation
Using Console
Using Console
Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.

