Skip to main content

More Info:

When anonymous authentication is enabled, requests not rejected by other authenticators are treated as anonymous and may reach kubelet APIs. Disabling anonymous auth is a hard requirement to prevent unauthenticated control-plane access on nodes.

Risk Level

Critical

Address

Compliance, Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.