An XCCDF Group - A logical subset of the XCCDF Benchmark
RotateKubeletServerCertificate
true
openshift-kube-controller-manager
"extendedArguments": { ... "port": ["0"], ...
"extendedArguments": { ... ...
"extendedArguments": { ... "feature-gates": [ ... "RotateKubeletServerCertificate=true", ... ...
"extendedArguments": { ... "secure-port": ["10257"], ...
masterCA
"extendedArguments": { ... "root-ca-file": [ "/etc/kubernetes/static-pod-resources/configmaps/serviceaccount-ca/ca-bundle.crt" ], ...
privateKeyFile
"extendedArguments": { ... "service-account-private-key-file": [ "/etc/kubernetes/static-pod-resources/secrets/service-account-private-key/service-account.key" ], ...
use-service-account-credentials
"extendedArguments": { ... "use-service-account-credentials": [ "true" ], ...