Skip to content

Kubernetes Controller Manager must disable profiling.

An XCCDF Rule

Description

Kubernetes profiling provides the ability to analyze and troubleshoot Controller Manager events over a web interface on a host port. Enabling this service can expose details about the Kubernetes architecture. This service must not be enabled unless deemed necessary.

ID
SV-242409r960963_rule
Version
CNTR-K8-000910
Severity
Medium
References
Updated

Remediation Templates

A Manual Procedure

Edit the Kubernetes Controller Manager manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Control Plane. Set the argument "--profiling value" to "false".