Skip to main content

More Info:

Kubernetes secrets at rest in etcd are not encrypted by default in OKE clusters. Use an external secrets manager such as OCI Vault or encrypt secrets at rest when creating the cluster.

Risk Level

Medium

Address

Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.