Skip to main content

More Info:

The Kubernetes API endpoint should be reachable only from approved networks (VCN CIDRs, bastions, or specific NSG members). Open control-plane endpoints are a primary target for credential and token abuse.

Risk Level

Critical

Address

Compliance, Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.