Skip to main content

More Info:

Do not generally permit containers with capabilities assigned beyond the default set.

Risk Level

Medium

Address

Security

Compliance Standards

  • CIS Kubernetes

Triage and Remediation

Remediation

Using Console

List the policies in use for each namespace in the cluster, ensure that policies arepresent which prevent allowedCapabilities to be set to anything other than an emptyarray.

Additional Reading: