Skip to content

The default namespace should not be used

An XCCDF Rule

Description

Kubernetes provides a default namespace, where objects are placed if no namespace is specified for them. Placing objects in this namespace makes application of RBAC and other controls more difficult.

Rationale

Resources in a Kubernetes cluster should be segregated by namespace, to allow for security controls to be applied at that level and to make it easier to manage resources.

ID
xccdf_org.ssgproject.content_rule_general_default_namespace_use
Severity
Medium
References
Updated