Skip to main content

More Info:

Kubelet must require client certificate authentication (x509) for incoming requests. Without TLS-based client auth, control-plane components or attackers within the network can issue privileged kubelet requests.

Risk Level

High

Address

Compliance, Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.