Checks Performed
- Access Control And Container Engine For Kubernetes
- Access Control And Container Engine For Kubernetes
- Apply Security Context To Your Pods And Containers
- Apply Security Context To Your Pods And Containers
- Client Certificate Authentication Should Not Be Used For Users
- Client Certificate Authentication Should Not Be Used For Users
- Consider External Secret Storage
- Consider External Secret Storage
- Create Administrative Boundaries Between Resources Using Namespaces
- Create Administrative Boundaries Between Resources Using Namespaces
- Encrypt Traffic Https Load Balancers With Tls Certificates
- Encrypt Traffic To HTTPS Load Balancers With TLS Certificates
- Encrypting Kubernetes Secrets At Rest In Etcd
- Encrypting Kubernetes Secrets At Rest In Etcd
- Ensure Access To OCI Audit Service Log For OKE
- Ensure Access To OCI Audit Service Log For OKE
- Ensure All Namespaces Have Network Policies Defined
- Ensure Anonymous Auth Argument Is Disabled
- Ensure Authorization Mode Argument Is Not Set Always Allow
- Ensure Client Ca File Argument Is Set Appropriate
- Ensure Cluster Admin Role Is Only Used Where Required
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Nodes
- Ensure Clusters Are Created With Private Nodes
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Event Qps Argument Is Set To 0 Or A Level Which Ensures Appropriate Event Capture
- Ensure Kubelet Configuration File Has Permissions Set Restrictive
- Ensure Kubelet Configuration File Ownership Is Set Root
- Ensure Kubelet Kubeconfig File Ownership Is Set Root
- Ensure Kubelet Kubeconfig File Permissions Are Set Restrictive
- Ensure Latest Cni Version Is Used
- Ensure Latest CNI Version Is Used
- Ensure Make Iptables Util Chains Argument Is Enabled
- Ensure Network Policy Is Enabled And Set Appropriate
- Ensure Network Policy Is Enabled And Set As Appropriate
- Ensure Read Only Port Argument Is Set To 0
- Ensure Rotate Certificates Argument Is Not Set Disabled
- Ensure Rotate Server Certificates Argument Is Enabled
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Streaming Connection Idle Timeout Argument Is Not Set 0
- Ensure That All Namespaces Have Network Policies Defined
- Ensure Tls Cert File And Tls Private Key File Arguments Are Set Appropriate
- Kubelet Anonymous Auth Argument Set To False
- Kubelet Authorization Mode Not Set To AlwaysAllow
- Kubelet Client CA File Argument Set As Appropriate
- Kubelet Configuration File Ownership Set To root:root
- Kubelet Configuration File Permissions Set To 644 Or More Restrictive
- Kubelet Event QPS Argument Set For Appropriate Event Capture
- Kubelet Kubeconfig File Ownership Set To root:root
- Kubelet Kubeconfig File Permissions Set To 644 Or More Restrictive
- Kubelet Make Iptables Util Chains Argument Set To True
- Kubelet Read Only Port Argument Set To 0
- Kubelet Rotate Certificates Argument Not Set To False
- Kubelet Rotate Server Certificates Argument Set To True
- Kubelet Streaming Connection Idle Timeout Not Set To 0
- Kubelet TLS Cert File And TLS Private Key File Arguments Set As Appropriate
- Minimize Access Create Pods
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Access To Secrets
- Minimize Admission Of Containers Sharing The Host IPC Namespace
- Minimize Admission Of Containers Sharing The Host Network Namespace
- Minimize Admission Of Containers Sharing The Host Process ID Namespace
- Minimize Admission Of Containers With allowPrivilegeEscalation
- Minimize Cluster Access To Read Only
- Minimize Cluster Access To Read-Only
- Minimize Container Registries To Only Those Approved
- Minimize Container Registries To Only Those Approved
- Minimize The Admission Of Containers Wishing To Share The Host Ipc Namespace
- Minimize The Admission Of Containers Wishing To Share The Host Network Namespace
- Minimize The Admission Of Containers Wishing To Share The Host Process Id Namespace
- Minimize The Admission Of Containers With Allow Privilege Escalation
- Minimize The Admission Of Privileged Containers
- Minimize The Admission Of Privileged Containers
- Minimize User Access Control To Container Engine For Kubernetes
- Minimize User Access Control To Container Engine For Kubernetes
- Minimize Wildcard Use In Roles And Cluster Roles
- Minimize Wildcard Use In Roles And ClusterRoles
- Oracle Cloud Security Penetration and Vulnerability Testing
- Oracle Cloud Security Penetration And Vulnerability Testing
- Prefer Using Dedicated Service Accounts
- Prefer Using Dedicated Service Accounts
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Prefer Using Secrets Files Over Secrets Environment Variables
- Restrict Access To The Control Plane Endpoint
- Restrict Use Of Cluster-Admin Role
- The Default Namespace Should Not Be Used
- The Default Namespace Should Not Be Used

