I - Mission Critical Public
Rules and Groups employed by this XCCDF Profile
-
SRG-APP-000439-CTR-001080
Group -
Kubernetes API Server must disable basic authentication to protect information in transit.
Kubernetes basic authentication sends and receives request containing username, uid, groups, and other fields over a clear text HTTP communication. Basic authentication does not provide any securit...Rule High Severity -
SRG-APP-000439-CTR-001080
Group -
Kubernetes API Server must disable token authentication to protect information in transit.
Kubernetes token authentication uses password known as secrets in a plaintext file. This file contains sensitive information such as token, username and user uid. This token is used by service acco...Rule High Severity -
SRG-APP-000439-CTR-001080
Group -
Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit.
Kubernetes control plane and external communication is managed by API Server. The main implementation of the API Server is to manage hardware resources for pods and container using horizontal or ve...Rule High Severity -
SRG-APP-000342-CTR-000775
Group -
Kubernetes must have a Pod Security Admission control file configured.
An admission controller intercepts and processes requests to the Kubernetes API prior to persistence of the object, but after the request is authenticated and authorized. Kubernetes (> v1.23)offer...Rule High Severity -
SRG-APP-000342-CTR-000775
Group -
Kubernetes must enable PodSecurity admission controller on static pods and Kubelets.
PodSecurity admission controller is a component that validates and enforces security policies for pods running within a Kubernetes cluster. It is responsible for evaluating the security context and...Rule High Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.