Skip to main content

More Info:

The kubelet —rotate-server-certificates argument should be set to true so the kubelet automatically requests and rotates its serving certificates. Disabling this increases exposure to expired or compromised server certificates.

Risk Level

High

Address

Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.